Session Objectives and Takeaways

Size: px
Start display at page:

Download "Session Objectives and Takeaways"

Transcription

1

2

3

4

5 Session Objectives and Takeaways

6 Session Objectives and Takeaways

7

8

9 Active Directory Forest Step1: run: ADPREP /ForestPrep Schema Master Infrastructure Master WS 2008 R2 Domain Controller Step 2: run: ADPREP /DomainPrep (each domain) run: ADPREP /DomainPrep /GPPrep (each domain) run: ADPREP /DomainPrep /RODCPREP (optional, depends on using RODC or not) Step 3: Install Fresh or Upgrade

10

11

12

13

14

15

16

17

18

19

20

21 Demote the original DC gracefully and disconnect from network Fresh install a Windows server 2008 R2 on a new hardware Rename to the original name and join to domain Promote to Windows server 2008 R2 DC Transfer back all the FSMO roles

22 Demote the original DC gracefully and disconnect from network Fresh install a Windows server 2008 R2 on a new hardware Rename to the original name and join to domain Promote to Windows server 2008 R2 DC Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before

23 Demote the original DC gracefully and disconnect from network Fresh install a Windows server 2008 R2 on a new hardware Rename to the original name and join to domain Promote to Windows server 2008 R2 DC Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade DC one by one

24 Demote the original DC gracefully and disconnect from network Fresh install a Windows server 2008 R2 on a new hardware Rename to the original name and join to domain Promote to Windows server 2008 R2 DC Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade DC one by one 10. Change domain and forest functional mode

25 Considerations netsh Printbrm.exe CA backup and restore

26 New Domain Functional Level

27 New Forest Functional Level

28

29 DES Encryption For Kerberos

30 DES Encryption For Kerberos

31 DES Encryption For Kerberos

32 Encryption Criteria for Kerberos Role O.S Supported encryption level for Kerberos DC Windows 2003 RC4 and DES Client Windows XP DES and RC4 Resource Server Non Windows Kerberos Server DES

33 DES Encryption is Disabled So, what? Role O.S Supported encryption level for Kerberos DC Windows 2003 RC4 and DES Client Windows 7 AES and RC4 Resource Server Non Windows Kerberos Server DES

34 Authoritative Restore of the Krbtgt

35 Authoritative Restore of the Krbtgt

36 Authoritative Restore of the Krbtgt

37 Authoritative Restore of the Krbtgt

38 Invalid FSMO Role Holder

39 Invalid FSMO Role Holder

40 Invalid FSMO Role Holder

41 Invalid FSMO Role Holder

42 LDAP Query Policy Hard Limits

43 LDAP Query Policy Hard Limits

44 LDAP Query Policy Hard Limits

45 LDAP Query Policy Hard Limits

46 LDAP Query Policy Hard Limits

47 NT4 Crypto

48 Dynamic Port Range

49 Dynamic Port Range

50 Dynamic Port Range

51 Miscellaneous

52 Considerations before Upgrade

53 Considerations before Upgrade

54

55 RODC Benefits

56 Branch office.

57 RODC Features

58 58 RODC Authentication and Client Operations How it works: Password caching during first logon Hub Branch Hub Writable DC Read Only DC `

59 59 RODC Authentication and Client Operations How it works: Password caching during first logon Hub Branch 1. AS_Req sent to RODC (request for TGT) Hub Writable DC Read Only DC 1 `

60 60 RODC Authentication and Client Operations How it works: Password caching during first logon Hub 1. AS_Req sent to RODC (request for TGT) Branch 2. RODC: Looks in DB: "I don't have the users password " Hub Writable DC Read Only DC 2 1 `

61 61 RODC Authentication and Client Operations How it works: Password caching during first logon Hub 1. AS_Req sent to RODC (request for TGT) Branch 2. RODC: Looks in DB: "I don't have the users password " 3. Forwards Request to a writeable DC Hub Writable DC 3 Read Only DC 2 1 `

62 62 RODC Authentication and Client Operations How it works: Password caching during first logon Hub Hub Writable DC 3 Branch 2. RODC: Looks in DB: "I don't have the users password " 3. Forwards Request to a writeable DC Read Only DC 1. AS_Req sent to RODC (request for TGT) 4. Writeable DC authenticates request `

63 63 RODC Authentication and Client Operations How it works: Password caching during first logon 4 Hub Hub Writable DC 5 3 Branch 2. RODC: Looks in DB: "I don't have the users password " 3. Forwards Request to a writeable DC Read Only DC 2 1. AS_Req sent to RODC (request for TGT) 4. Writeable DC authenticates request 5. Returns authentication response and TGT back to the RODC 1 `

64 64 RODC Authentication and Client Operations How it works: Password caching during first logon 4 Hub Hub Writable DC Branch 2. RODC: Looks in DB: "I don't have the users password " 3. Forwards Request to a writeable DC Read Only DC AS_Req sent to RODC (request for TGT) 4. Writeable DC authenticates request 5. Returns authentication response and TGT back to the RODC 6. RODC gives TGT to User and Queues a replication request for the password `

65 65 RODC Authentication and Client Operations How it works: Password caching during first logon 4 7 Hub Hub Writable DC Branch 2. RODC: Looks in DB: "I don't have the users password " 3. Forwards Request to a writeable DC Read Only DC AS_Req sent to RODC (request for TGT) 4. Writeable DC authenticates request 5. Returns authentication response and TGT back to the RODC 6. RODC gives TGT to User and Queues a replication request for the password ` 7) Hub DC checks Password Replication Policy to see if Password can be replicated Note: At this point the user will have a hub signed TGT

66 RODC Limitations

67 RODC Considerations

68 Fine Grain Password Policy (FGPP)

69 Creating a Fine Grain Password Policy

70 FGPP Implementation Considerations

71 FGPP Defining Scope

72 FGPP Best Practices

73 Active Directory Web Services Listens on port 9389 Advertised via DC Locator nltest /dsgetdc:domain /ws

74 C GUI ADUC/ADSS/ADDT L I E MMC ADSI WSH CLI N T DS RPC-Based Protocols SAM DSR LDAP S E R V E R DS RPC-Based Protocols SAM DSR AD Core.NET S.DS.P / S.DS.AM / S.DS.AD LDAP

75 C L I E N T GUI MMC ADUC/ADSS/ADDT DS RPC-Based Protocols SAM DSR ADSI LDAP WSH CLI.NET BPA AD PowerShell WCF AD Admin Center MUX WPF GUI.NET WCF.NET S E R V E R DS RPC-Based Protocols SAM DSR AD Core.NET AD Web Services S.DS.P / S.DS.AM / S.DS.AD LDAP

76 Recycle Bin Windows Server 2008 No Recycle bin feature Delete Live Object Tombstone Object Garbage Collection Windows Server 2008 R2 with Recycle Bin enabled Auth Restore Tombstone Lifetime 180 Days Delete Live Object Deleted Object Recycled Object Garbage Collection Undelete Deleted Object Lifetime 180 Days Tombstone Lifetime 180 Days

77 Recovering Multiple Objects Deleted Objects container A flat list of all objects in the Deleted state DN is mangled, attributes preserved, lastknownparent Restore objects to live parent Deleted objects must be restored to a live parent Perform restore in top-down order lastknownparent and lastknownrdn properties useful in rebuilding hierarchy RDN over 128 chars truncated \0ADEL:

78 Recovering Multiple Objects Deleted Objects container A flat list of all objects in the Deleted state DN is mangled, attributes preserved, lastknownparent Restore objects to live parent Deleted objects must be restored to a live parent Perform restore in top-down order lastknownparent and lastknownrdn properties useful in rebuilding hierarchy RDN over 128 chars truncated Delete \0ADEL: \0ADEL: \0ADEL: \0ADEL: \0ADEL: \0ADEL:...

79 Recovering Multiple Objects Deleted Objects container A flat list of all objects in the Deleted state DN is mangled, attributes preserved, lastknownparent Restore objects to live parent Deleted objects must be restored to a live parent Perform restore in top-down order lastknownparent and lastknownrdn properties useful in rebuilding hierarchy RDN over 128 chars truncated \0ADEL: \0ADEL: \0ADEL: \0ADEL: \0ADEL: \0ADEL:...

80 Recovering Multiple Objects Deleted Objects container A flat list of all objects in the Deleted state DN is mangled, attributes preserved, lastknownparent Restore objects to live parent Deleted objects must be restored to a live parent Perform restore in top-down order lastknownparent and lastknownrdn properties useful in rebuilding hierarchy RDN over 128 chars truncated Undelete \0ADEL: \0ADEL: \0ADEL: \0ADEL: \0ADEL: \0ADEL:...

81 Recovering Multiple Objects Deleted Objects container A flat list of all objects in the Deleted state DN is mangled, attributes preserved, lastknownparent Restore objects to live parent Deleted objects must be restored to a live parent Perform restore in top-down order lastknownparent and lastknownrdn properties useful in rebuilding hierarchy RDN over 128 chars truncated Undelete \0ADEL: \0ADEL:

82 Recovering Multiple Objects Deleted Objects container A flat list of all objects in the Deleted state DN is mangled, attributes preserved, lastknownparent Restore objects to live parent Deleted objects must be restored to a live parent Perform restore in top-down order lastknownparent and lastknownrdn properties useful in rebuilding hierarchy RDN over 128 chars truncated \0ADEL:

83 Recycle Bin Considerations

84 Key new features overview

85

86

Change Schema Active Directory Domain Name Windows 2008 R2

Change Schema Active Directory Domain Name Windows 2008 R2 Change Schema Active Directory Domain Name Windows 2008 R2 In Windows Server 2008 and Windows Server 2008 R2, the directory service is its own unique Domain Name System (DNS) name such as Corp.nwtraders.msft.

More information

Migrating from Window Server 2003 to Windows Server 2008 on Different Hardware Server. Pre-requisites

Migrating from Window Server 2003 to Windows Server 2008 on Different Hardware Server. Pre-requisites Migrating from Window Server 2003 to Windows Server 2008 on Different Hardware Server Pre-requisites These are the prerequisites for migrating from 2003 domain controller to 2008 domain controller on different

More information

Windows 2012 Active Directory Schema Snap-in Is Not Connected To The Schema Operations Master

Windows 2012 Active Directory Schema Snap-in Is Not Connected To The Schema Operations Master Windows 2012 Active Directory Schema Snap-in Is Not Connected To The Schema Operations Master The Infrastructure Master role needs to run on a domain controller that is not a are still using Windows NT

More information

WELCOME TO TECH IMMERSION

WELCOME TO TECH IMMERSION WELCOME TO TECH IMMERSION Track: The Active Directory Recycle Bin Presenter: Brian McCann Global Platforms Engineer - Brian@Intel.com Agenda What the AD Recycle Bin (ADRB) can do and requirements needed

More information

70-742: Identity in Windows Server Course Overview

70-742: Identity in Windows Server Course Overview 70-742: Identity in Windows Server 2016 Course Overview This course provides students with the knowledge and skills to install and configure domain controllers, manage Active Directory objects, secure

More information

Transfer The Schema Master Active Directory Forest Exchange 2003

Transfer The Schema Master Active Directory Forest Exchange 2003 Transfer The Schema Master Active Directory Forest Exchange 2003 Explains what are operations master roles in Active Directory Domain Services data exchange and invocation of functionality residing in

More information

Change Active Directory Schema Master Windows 2008

Change Active Directory Schema Master Windows 2008 Change Active Directory Schema Master Windows 2008 In Windows Server 2008 and Windows Server 2008 R2, the directory service is named Changes to the schema must be written only on the schema master. Note

More information

Unable To Change Schema Master Windows 2008

Unable To Change Schema Master Windows 2008 Unable To Change Schema Master Windows 2008 The situation is: I have only one dc (Windows Server 2012 trial, its name To transfer the schema master role to the targeted schema FSMO holder below, click.

More information

Add new AD to an existing AD Forest

Add new AD to an existing AD Forest By: Loc Huynh Date: 13 Oct 2009 Add new AD to an existing AD Forest Please see the following for the instruction of adding a new AD to an existing AD Forest. Note: Need to run adprep /forestprep and adprep

More information

70-647: Windows Server Enterprise Administration Course 01 Planning for Active Directory

70-647: Windows Server Enterprise Administration Course 01 Planning for Active Directory 70-647: Windows Server Enterprise Administration Course 01 Planning for Active Directory Slide 1 Course 1 Planning for Active Directory Planning the Domains and Forest Structure Planning for Sites and

More information

TestOut Server Pro 2016: Identity - English 4.0.x LESSON PLAN. Revised

TestOut Server Pro 2016: Identity - English 4.0.x LESSON PLAN. Revised TestOut Server Pro 2016: Identity - English 4.0.x LESSON PLAN Revised 2018-08-06 Table of Contents Introduction Section 0.1: Server Pro 2016: Identity Introduction... 4 Section 0.2: The TestOut Lab Simulator...

More information

Change Schema Active Directory Domain Name Server 2008 R2

Change Schema Active Directory Domain Name Server 2008 R2 Change Schema Active Directory Domain Name Server 2008 R2 In Windows Server 2008 and Windows Server 2008 R2, the directory service is its own unique Domain Name System (DNS) name such as Corp.nwtraders.msft.

More information

Microsoft TS: Windows Server 2008 Active Directory, Configuring.

Microsoft TS: Windows Server 2008 Active Directory, Configuring. Microsoft 83-640 TS: Windows Server 2008 Active Directory, Configuring http://killexams.com/exam-detail/83-640 B. Set event log subscriptions and configure it C. Initiate the System Performance data collector

More information

Microsoft Windows Server 2008 Functionality Changes. Powered by Microsoft TechNet

Microsoft Windows Server 2008 Functionality Changes. Powered by Microsoft TechNet Microsoft Windows Server 2008 Functionality Changes Powered by Microsoft TechNet 2 Table of Contents Chapter 1 New in Active Directory Certificate Services... 3 Chapter 2 What's New in Active Directory

More information

Microsoft - Configuring Windows Server 2008 Active Directory Domain Services (M6425)

Microsoft - Configuring Windows Server 2008 Active Directory Domain Services (M6425) Microsoft - Configuring Windows Server 2008 Active Directory Domain Services (M6425) Code: 6123 Lengt h: URL: 5 days View Online In this comprehensive course you will not only discuss the crucial concepts

More information

Windows Server 2008 Active Directory, Configuring

Windows Server 2008 Active Directory, Configuring Windows Server 2008 Active Directory, Configuring Number: 70-640 Passing Score: 700 Time Limit: 145 min File Version: 1.0 http://www.gratisexam.com/ This dump supposedly contains the new 2013 May questions.

More information

Change Schema Active Directory Domain Name 2003

Change Schema Active Directory Domain Name 2003 Change Schema Active Directory Domain Name 2003 The Active Directory directory service is a distributed database that stores and Server and Windows Server 2003, the directory service is named Active Directory.

More information

Changing Schema Active Directory Domain Name Server 2008 R2

Changing Schema Active Directory Domain Name Server 2008 R2 Changing Schema Active Directory Domain Name Server 2008 R2 In Windows Server 2008 and Windows Server 2008 R2, the directory service is named its own unique Domain Name System (DNS) name such as Corp.nwtraders.msft.

More information

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services 6425 - Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Duration: 5 days Course Price: $2,975 Software Assurance Eligible Course Description Microsoft Windows Server

More information

Windows Server 2008 Training

Windows Server 2008 Training Windows Server 2008 Training Day -4 Vijay Bhalerao BCS, MCM, CISA, DCL,MCTS, ISO 27001 LA univijay2001@yahoo.com 1 Day-4 Troubleshooting AD & issues- Solutions Server Security Measures - Installation &

More information

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services (Course 6425A)

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services (Course 6425A) Duration Five days Introduction This five-day instructor-led course provides to teach Active Directory Technology Specialists with the knowledge and skills to configure in a distributed environment, implement

More information

The Windows Server 2008 R2 Schema Extension Must Be Applied To The Ad Schema For The Forest

The Windows Server 2008 R2 Schema Extension Must Be Applied To The Ad Schema For The Forest The Windows Server 2008 R2 Schema Extension Must Be Applied To The Ad Schema For The Forest For Windows Server 2003 R2, see Extending Your Active Directory Schema in Windows of an AD DS installation or

More information

How To Replicate Active Directory Manually 2008 With Windows Backup

How To Replicate Active Directory Manually 2008 With Windows Backup How To Replicate Active Directory Manually 2008 With Windows Backup In Windows Server 2008 R2 and Windows Server 2008 and, the directory service is Replication with Windows NT 4.0 backup domain controllers

More information

MOC 6419B: Configuring, Managing and Maintaining Windows Server based Servers

MOC 6419B: Configuring, Managing and Maintaining Windows Server based Servers MOC 6419B: Configuring, Managing and Maintaining Windows Server 2008- based Servers Course Overview This instructor-led course provides students with the knowledge and skills that are required to manage

More information

How To Manually Remove A Domain Controller From Active Directory 2003

How To Manually Remove A Domain Controller From Active Directory 2003 How To Manually Remove A Domain Controller From Active Directory 2003 Instead, you must update the forest metadata manually after you remove the domain controller. If you use the version of the Active

More information

Install and Configure Active Directory Domain Services

Install and Configure Active Directory Domain Services Active Directory 101 Install and Configure Active Directory Domain Services Sander Berkouwer CTO at SCCT 10-fold Microsoft MVP Active Directory aficionado Daniel Goater Systems Engineer Netwrix Active

More information

This course provides students with the knowledge and skills to administer Windows Server 2012.

This course provides students with the knowledge and skills to administer Windows Server 2012. MOC 20411C: Administering Windows Server 2012 Course Overview This course provides students with the knowledge and skills to administer Windows Server 2012. Course Introduction Course Introduction 6m Module

More information

Determine Schema Master Domain Controller 2008

Determine Schema Master Domain Controller 2008 Determine Schema Master Domain Controller 2008 Before you add the first domain controller that runs a version of Windows Server that is later than 2008 R2 or upgrade one of the existing domain controllers

More information

Extend Your Server 2003 Active Directory Schema For Windows 7 And Server 2008

Extend Your Server 2003 Active Directory Schema For Windows 7 And Server 2008 Extend Your Server 2003 Active Directory Schema For Windows 7 And Server 2008 When you are using Windows Server 2003 or Windows Server 2008 32bit Active Directory promotion wizard automatically extend

More information

Identity with Windows Server 2016 (742)

Identity with Windows Server 2016 (742) Identity with Windows Server 2016 (742) Install and Configure Active Directory Domain Services (AD DS) Install and configure domain controllers This objective may include but is not limited to: Install

More information

5.1. Functional Level

5.1. Functional Level 5.1. Functional Level A functional level is a set of operation constraints that determine the functions that can be performed by an Active Directory domain or forest. A functional level defines: Which

More information

Schema Preparation Requires Active Directory Administrative Tools To Be Installed

Schema Preparation Requires Active Directory Administrative Tools To Be Installed Schema Preparation Requires Active Directory Administrative Tools To Be Installed When existing class and attribute definitions in the Active Directory schema do in Administrative Tools that is installed

More information

Univention Corporate Server. Extended Windows integration documentation

Univention Corporate Server. Extended Windows integration documentation Univention Corporate Server Extended Windows integration documentation 2 Table of Contents 1. Advanced Samba documentation... 4 1.1. Operating Samba 4 as a read-only domain controller... 4 1.2. Uninstallation

More information

MOC 20411B: Administering Windows Server Course Overview

MOC 20411B: Administering Windows Server Course Overview MOC 20411B: Administering Windows Server 2012 Course Overview This course is part two in a series of three courses that provides the skills and knowledge necessary to implement a core Windows Server 2012

More information

PROPOSAL OF WINDOWS NETWORK

PROPOSAL OF WINDOWS NETWORK PROPOSAL OF WINDOWS NETWORK By: Class: CMIT 370 Administering Windows Servers Author: Rev: 1.0 Date: 01.07.2017 Page 1 of 10 OVERVIEW This is a proposal for Ear Dynamics to integrate a Windows Network

More information

Configuring, Managing, and Maintaining Windows Server 2008 R2 Servers

Configuring, Managing, and Maintaining Windows Server 2008 R2 Servers Configuring, Managing, and Maintaining Windows Server 2008 R2 Servers Course 6419B - Five Days - Instructor-led - Hands on Introduction This five-day instructor-led course provides students with the knowledge

More information

70-647: Windows Server Enterprise Administration. Course Overview. Course Outline

70-647: Windows Server Enterprise Administration. Course Overview. Course Outline 70-647: Windows Server Enterprise Administration Course Overview Windows Server Enterprise Administration teaches the student how to maintain the Windows Server 2008 R2 environment. Students will learn

More information

Administering Windows Server 2012

Administering Windows Server 2012 Course 20411D: Administering Windows Server 2012 Module 1: Configuring and Troubleshooting Domain Name System This module explains how to configure and troubleshoot DNS, including DNS replication and caching.

More information

Configuring, Managing and Maintaining Windows Server 2008-based Servers (Course 6419)

Configuring, Managing and Maintaining Windows Server 2008-based Servers (Course 6419) Length: 5 Days About this Course This five-day instructor-led course provides students with the knowledge and skills that are required to manage accounts and resources, maintain server resources, monitor

More information

IT222 Microsoft Network Operating Systems II

IT222 Microsoft Network Operating Systems II 1 ITT Technical Institute IT222 Microsoft Network Operating Systems II Unit 1: Chapters 1 & 2 2 Chapter 1 OVERVIEW OF ACTIVE DIRECTORY Chapter 1: Overview of Active Directory, pp. 1 23 Chapter 2, Implementing

More information

Chapter 1: Windows Platform and Architecture. You will learn:

Chapter 1: Windows Platform and Architecture. You will learn: Chapter 1: Windows Platform and Architecture Windows 2000 product family. New features/facilities of. Windows architecture. Changes to the kernel and kernel architecture. New features/facilities. Kernel

More information

exam.164q. Number: Passing Score: 800 Time Limit: 120 min File Version: 1. Microsoft Administering Windows Server 2012

exam.164q. Number: Passing Score: 800 Time Limit: 120 min File Version: 1. Microsoft Administering Windows Server 2012 70-411.exam.164q Number: 70-411 Passing Score: 800 Time Limit: 120 min File Version: 1 Microsoft 70-411 Administering Windows Server 2012 Sections 1. Volume A 2. Volume B Exam A QUESTION 1 Your network

More information

Course Outline 20742B

Course Outline 20742B Course Outline 20742B Module 1: Installing and configuring domain controllers This module describes the features of AD DS and how to install domain controllers (DCs). It also covers the considerations

More information

Server : Manage and Administer 3 1 x

Server : Manage and Administer 3 1 x Server : Manage and Administer 3 1 x Revised 2016/05/17 TestOut Server Pro: Manage and Administer English 3.1.x Videos: 56 (4:25:22) Demonstrations: 87 (10:14:13) Simulations: 63 Written Lessons: 72 Section

More information

Active Directory Recycle Bin

Active Directory Recycle Bin REANIMATING DELETED OBJECTS IN ACTIVE DIRECTORY WHITEPAPER The Active Directory is arguably the most important part of the IT infrastructure. Administrators have to maintain constant vigilance when making

More information

TestOut Server Pro: Advanced Services English 3.1.x LESSON PLAN. Revised 2016/05/17

TestOut Server Pro: Advanced Services English 3.1.x LESSON PLAN. Revised 2016/05/17 TestOut Server Pro: Advanced Services English 3.1.x LESSON PLAN Revised 2016/05/17 Table of Contents Course Overview... 4 Course Introduction for Instructors... 6 Section 1.1: Multi-Domain Forests... 8

More information

Force Active Directory Replication After Tombstone

Force Active Directory Replication After Tombstone Force Active Directory Replication After Tombstone This topic explains how to troubleshoot Active Directory replication error the last replication with this server has exceeded the tombstone lifetime'.

More information

MOC 6232A: Implementing a Microsoft SQL Server 2008 Database

MOC 6232A: Implementing a Microsoft SQL Server 2008 Database MOC 6232A: Implementing a Microsoft SQL Server 2008 Database Course Number: 6232A Course Length: 5 Days Course Overview This course provides students with the knowledge and skills to implement a Microsoft

More information

Administering Windows Server 2012

Administering Windows Server 2012 Administering Windows Server 2012 Course Details Course Outline Module 1: Configuring and Troubleshooting Domain Name System This module explains how to configure and troubleshoot DNS, including DNS replication

More information

ACS 5.x: LDAP Server Configuration Example

ACS 5.x: LDAP Server Configuration Example ACS 5.x: LDAP Server Configuration Example Document ID: 113473 Contents Introduction Prerequisites Requirements Components Used Conventions Background Information Directory Service Authentication Using

More information

Manually Configure The Directory Server 2008 R2 Core Domain Controller

Manually Configure The Directory Server 2008 R2 Core Domain Controller Manually Configure The Directory Server 2008 R2 Core Domain Controller Active Directory Domain Services for Windows Server 2008 R2 On the Summary page, to save the settings that you selected to an answer

More information

70-411: Administrating Windows Server 2012

70-411: Administrating Windows Server 2012 70-411: Administrating Windows Server 2012 Course Overview This course provides students with the knowledge and skills to administer a Windows Server 2012 infrastructure in an enterprise environment. Course

More information

COURSE OUTLINE MOC 20411: ADMINISTERING WINDOWS SERVER 2012 MODULE 1: CONFIGURING AND TROUBLESHOOTING DOMAIN NAME SYSTEM

COURSE OUTLINE MOC 20411: ADMINISTERING WINDOWS SERVER 2012 MODULE 1: CONFIGURING AND TROUBLESHOOTING DOMAIN NAME SYSTEM COURSE OUTLINE MOC 20411: ADMINISTERING WINDOWS SERVER 2012 MODULE 1: CONFIGURING AND TROUBLESHOOTING DOMAIN NAME SYSTEM This module explains how to configure and troubleshoot DNS, including DNS replication

More information

Microsoft Configuring, Managing and Maintaining Windows Server 2008

Microsoft Configuring, Managing and Maintaining Windows Server 2008 1800 ULEARN (853 276) www.ddls.com.au Microsoft 6419 - Configuring, Managing and Maintaining Windows Server 2008 Length 5 days Price $4290.00 (inc GST) Overview This five-day instructor-led course provides

More information

Windows Server 2008 Administration

Windows Server 2008 Administration Hands-On Course Description This course provides hands on experience installing and configuring Windows Server 2008 to work with clients including Windows Vista. Students will perform full and core CD-based

More information

70-640_formatted. Number: Passing Score: 800 Time Limit: 120 min File Version: 1.0.

70-640_formatted.  Number: Passing Score: 800 Time Limit: 120 min File Version: 1.0. 70-640_formatted Number: 000-000 Passing Score: 800 Time Limit: 120 min File Version: 1.0 http://www.gratisexam.com/ Microsoft 70-640 TS: Windows Server 2008 Active Directory, Configuring Version: 32.7

More information

FUNCTIONAL LEVELS AND FSMO

FUNCTIONAL LEVELS AND FSMO Ondřej Ševeček GOPAS a.s. MCM: Directory Services MVP: Enterprise Security CISA ondrej@sevecek.com www.sevecek.com FUNCTIONAL LEVELS AND FSMO Active Directory Troubleshooting FUNCTIONAL LEVELS Domain vs.

More information

Active Directory Force Replication Command Line 2003

Active Directory Force Replication Command Line 2003 Active Directory Force Replication Command Line 2003 You can use command-line tools as well as GUI tools to check the replication status to check AD replication status since the release of Windows Server

More information

[MS-ADOD-Diff]: Active Directory Protocols Overview. Intellectual Property Rights Notice for Open Specifications Documentation

[MS-ADOD-Diff]: Active Directory Protocols Overview. Intellectual Property Rights Notice for Open Specifications Documentation [MS-ADOD-Diff]: Intellectual Property Rights Notice for Open Specifications Documentation Technical Documentation. Microsoft publishes Open Specifications documentation ( this documentation ) for protocols,

More information

6425C MCT USE ONLY. STUDENT USE PROHIBITED. Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Volume 2

6425C MCT USE ONLY. STUDENT USE PROHIBITED. Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Volume 2 OFFICIAL MICROSOFT LEARNING PRODUCT 6425C Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Volume 2 ii Configuring and Troubleshooting Windows Server 2008 Active Directory

More information

Identity with Windows Server 2016

Identity with Windows Server 2016 Identity with Windows Server 2016 20742B; 5 days, Instructor-led Course Description This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain Services (AD

More information

Understanding The Ad Lds Schema Editor

Understanding The Ad Lds Schema Editor Understanding The Ad Lds Schema Editor For more information about bind redirection, refer to Understanding ADAM bind Open the AD DS/LDS schema analyzer (ADSchemaAnalyzer.exe) in the file is generated from

More information

Identity with Microsoft Windows Server 2016 (MS-20742)

Identity with Microsoft Windows Server 2016 (MS-20742) Identity with Microsoft Windows Server 2016 (MS-20742) Modality: Virtual Classroom Duration: 5 Days SATV Value: 5 Days SUBSCRIPTION: Master, Premium About this course Windows Server vnext, which we now

More information

3 Administering Active Directory

3 Administering Active Directory 3 Administering Active Directory Exam Objectives in this Chapter: Set an Active Directory forest and domain functional level based upon requirements. Manage schema modifications. Add or remove a UPN suffix.

More information

M20742-Identity with Windows Server 2016

M20742-Identity with Windows Server 2016 M20742-Identity with Windows Server 2016 Course Number: M20742 Category: Technical Microsoft Duration: 5 days Certification: 70-742 Overview This five-day instructor-led course teaches IT Pros how to deploy

More information

Identity with Windows Server 2016 (20742)

Identity with Windows Server 2016 (20742) Identity with Windows Server 2016 (20742) Formato do curso: Presencial Preço: 1630 Duração: 35 horas This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain

More information

Vendor: Microsoft. Exam Code: Exam Name: Administering Windows Server Version: Demo

Vendor: Microsoft. Exam Code: Exam Name: Administering Windows Server Version: Demo Vendor: Microsoft Exam Code: 70-411 Exam Name: Administering Windows Server 2012 Version: Demo DEMO QUESTION 1 You have a server named Server1 that runs Windows Server 2012 R2. You need to configure Server1

More information

Windows Server 2003 Network Administration Goals

Windows Server 2003 Network Administration Goals Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts relating to Windows Server 2003 network management

More information

Administration Of Active Directory Schema Snap In 2003 R2 Missing

Administration Of Active Directory Schema Snap In 2003 R2 Missing Administration Of Active Directory Schema Snap In 2003 R2 Missing Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server An Active Directory Domain Services (AD DS) Administrative Tools

More information

Microsoft Actualanswers Exam Questions & Answers

Microsoft Actualanswers Exam Questions & Answers Microsoft Actualanswers 70-412 Exam Questions & Answers Number: 70-412 Passing Score: 800 Time Limit: 120 min File Version: 25.7 http://www.gratisexam.com/ Microsoft 70-412 Exam Questions & Answers Exam

More information

KillTest *KIJGT 3WCNKV[ $GVVGT 5GTXKEG Q&A NZZV ]]] QORRZKYZ IUS =K ULLKX LXKK [VJGZK YKX\OIK LUX UTK _KGX

KillTest *KIJGT 3WCNKV[ $GVVGT 5GTXKEG Q&A NZZV ]]] QORRZKYZ IUS =K ULLKX LXKK [VJGZK YKX\OIK LUX UTK _KGX KillTest Q&A Exam : 70-640 Title : Windows Server 2008 Active Directory. Configuring Version : Demo 1 / 28 1.You have a single Active Directory domain. All domain controllers run Windows Server 2008 and

More information

Best Practices for Virtualizing Active Directory

Best Practices for Virtualizing Active Directory Best Practices for Virtualizing Active Directory Breakout Session AP01 Chris Skinner Senior Technical Instructor,VMware, Inc. February 25, 2009 Disclaimer This session may contain product features that

More information

20742: Identity with Windows Server 2016

20742: Identity with Windows Server 2016 Course Content Course Description: This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain Services (AD DS) in a distributed environment, how to implement

More information

Identity with Windows Server 2016

Identity with Windows Server 2016 Identity with Windows Server 2016 Course 20742B - 5 Days - Instructor-led, Hands on Introduction This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain

More information

METHODOLOGY This program will be conducted with interactive lectures, PowerPoint presentations, discussions and practical exercises.

METHODOLOGY This program will be conducted with interactive lectures, PowerPoint presentations, discussions and practical exercises. CENTER OF KNOWLEDGE, PATH TO SUCCESS Website: IDENTITY WITH WINDOWS SERVER 2016 Course 20742: 5 days; Instructor-Led INTRODUCTION This five-day instructor-led course teaches IT Pros how to deploy and configure

More information

Course Content of MCSA ( Microsoft Certified Solutions Associate )

Course Content of MCSA ( Microsoft Certified Solutions Associate ) Course Content of MCSA 2012 - ( Microsoft Certified Solutions Associate ) Total Duration of MCSA : 45 Days Exam 70-410 - Installing and Configuring Windows Server 2012 (Course 20410A Duration : 40 hrs

More information

Manage and Maintain Active Directory Domain Services

Manage and Maintain Active Directory Domain Services Active Directory 101 Manage and Maintain Active Directory Domain Services Sander Berkouwer CTO at SCCT 10-fold Microsoft MVP Active Directory aficionado Daniel Goater Systems Engineer Netwrix Active Directory

More information

CISNTWK-11. Microsoft Network Server. Chapter 4

CISNTWK-11. Microsoft Network Server. Chapter 4 CISNTWK-11 Microsoft Network Server Chapter 4 User and Group Accounts 1 Usage Notes Throughout these slides, the term Active Directory Domain implies Domains Based on Windows Server 2008 Based on Windows

More information

Step-by-step guide to Install an Additional Domain Controller by Using IFM

Step-by-step guide to Install an Additional Domain Controller by Using IFM Step-by-step guide to Install an Additional Domain Controller by Using IFM Teacher s copy 3 Votes You can create an additional domain controller in a domain by installing Active Directory Domain Services

More information

Administering Windows Server 2012

Administering Windows Server 2012 Page 1 of 10 Overview Get hands-on instruction and practice administering Windows Server 2012, including Windows R2, in this five-day Microsoft Official Course. This course is part two in a series of three

More information

Managing External Identity Sources

Managing External Identity Sources CHAPTER 5 The Cisco Identity Services Engine (Cisco ISE) integrates with external identity sources to validate credentials in user authentication functions, and to retrieve group information and other

More information

Exam Name: TS: Upgrading from Windows Server 2003 MCSA to Windows Server 2008,Technology Specializations

Exam Name: TS: Upgrading from Windows Server 2003 MCSA to Windows Server 2008,Technology Specializations Vendor: Microsoft Exam Code: 70-648 Exam Name: TS: Upgrading from Windows Server 2003 MCSA to Windows Server 2008,Technology Specializations Version: DEMO QUESTION 1 Your company has an Active Directory

More information

Designing and Operating a Secure Active Directory.

Designing and Operating a Secure Active Directory. Designing and Operating a Secure Active Directory Introduction Gil Kirkpatrick, CTO, NetPro Architect of NetPro Active Directory products Author of Active Directory Programming from SAMS Founder of the

More information

COPYRIGHTED MATERIAL. Contents

COPYRIGHTED MATERIAL. Contents Contents Introduction... xxi Chapter 1 Installing Windows Small Business Server 2008...1 Windows Small Business Server 2008 Overview...1 What s Included in SBS 2008?...2 Limitations of Small Business Server

More information

Configure advanced audit policies

Configure advanced audit policies 7 LESSON Configuring Advanced Audit Policies 70-411 EXAM OBJECTIVE Objective 2.4 Configure advanced audit policies. This objective may include but is not limited to: implement auditing using Group Policy

More information

Developing Microsoft Azure Solutions (70-532) Syllabus

Developing Microsoft Azure Solutions (70-532) Syllabus Developing Microsoft Azure Solutions (70-532) Syllabus Cloud Computing Introduction What is Cloud Computing Cloud Characteristics Cloud Computing Service Models Deployment Models in Cloud Computing Advantages

More information

Active Directory trust relationships

Active Directory trust relationships Active Directory trust relationships A trust relationship consists of two domains and provides the necessary configuration between them to grant security principals on one side of the trust permission

More information

10 Active Directory Misconfigurations That Lead to Total Compromise Austin, TX 201 W 5th St.

10 Active Directory Misconfigurations That Lead to Total Compromise Austin, TX 201 W 5th St. 10 Active Directory Misconfigurations That Lead to Total Compromise hello@javelin-networks.com +1-888-867-5179 Austin, TX 201 W 5th St. 1. Group Policy Preferences Visible Passwords Group Policy Preferences

More information

Administering. Windows Server 2012 R2. Exam Wiley. Patrick Regan

Administering. Windows Server 2012 R2. Exam Wiley. Patrick Regan Administering Windows Server 2012 R2 Exam 70-411 Patrick Regan Wiley Contents j Lesson 1: Deploying and Managing Server Images 1 Using Windows Deployment Services 2 Installing the Windows Deployment Services

More information

Updating Your Windows Server 2003 Technology Skills to Windows Server 2008

Updating Your Windows Server 2003 Technology Skills to Windows Server 2008 6416D: Updating Your Windows Server 2003 Technology Skills to Windows Server 2008 Page 1 of 10 Updating Your Windows Server 2003 Technology Skills to Windows Server 2008 Course 6416D: 4 days; Instructor-Led

More information

The return of the vampires

The return of the vampires The return of the vampires Günther Deschner (Red Hat / Samba Team) Windows replication protocols Windows NT 4 Single Master replication Per Domain: One primary (PDC) and many Backup Domain

More information

ASM Educational Center (ASM) Est. 1992

ASM Educational Center (ASM) Est. 1992 MCSA Windows Server 2012 Certification Course Outline 70-410: Installing and Configuring Windows Server 2012 R2 Module 01 - Server 2012 Overview Server 2012 Overview On Premise vs. Cloud Common Cloud Computing

More information

Administration Of Active Directory Schema Version Checking

Administration Of Active Directory Schema Version Checking Administration Of Active Directory Schema Version Checking Interoperability between Different Versions of Configuration Manager Extending the Active Directory schema is optional for Configuration Manager.

More information

Pass-the-Hash Attacks

Pass-the-Hash Attacks Pass-the-Hash Attacks Mgr. Michael Grafnetter www.dsinternals.com Agenda PtH Attack Anatomy Mitigation Proactive Reactive Windows 10 + Windows Server 2016 Microsoft Advanced Threat Analytics PtH Attack

More information

Course Outline. Pearson: MCSA Cert Guide: Identity with Windows Server 2016 (Course & Lab)

Course Outline. Pearson: MCSA Cert Guide: Identity with Windows Server 2016 (Course & Lab) Course Outline Pearson: MCSA 70-742 Cert Guide: Identity with Windows Server 2016 (Course & Lab) 27 Jun 2018 Contents 1. Course Objective 2. Pre-Assessment 3. Exercises, Quizzes, Flashcards & Glossary

More information

Domain Restructuring Windows Server 2008

Domain Restructuring Windows Server 2008 Domain Restructuring Windows Server 2008 Introduction: This document will describe design decision to add Additional Domain Controller in the existing Active Directory Forest. The infrastructure is assumed

More information

Pass-the-Hash Attacks. Michael Grafnetter

Pass-the-Hash Attacks. Michael Grafnetter Pass-the-Hash Attacks Michael Grafnetter www.dsinternals.com Agenda PtH Attack Anatomy Mitigation Proactive Reactive Windows 10 + Windows Server 2016 PtH History and Future 1988 Microsoft releases Lan

More information

Forest Active Directory Schema Snap In 2008 R2

Forest Active Directory Schema Snap In 2008 R2 Forest Active Directory Schema Snap In 2008 R2 Missing When existing class and attribute definitions in the Active Directory schema do not meet In Windows Server 2008 and Windows Server 2008 R2, the directory

More information

Active Directory Attacks and Detection

Active Directory Attacks and Detection Active Directory Attacks and Detection #Whoami Working as an Information Security Executive Blog : www.akijosberryblog.wordpress.com You can follow me on Twitter: @AkiJos This talk is Based on Tim Madin

More information

Exchange Server 2003 To Exchange Server 2010 Active Directory Schema Changes Reference

Exchange Server 2003 To Exchange Server 2010 Active Directory Schema Changes Reference Exchange Server 2003 To Exchange Server 2010 Active Directory Schema Changes Reference Prepare Active Directory and domains Upgrade from Exchange 2010 to Exchange 2013 Deployment reference Before you install

More information