· 9 years ago · Jan 04, 2017, 09:04 AM
11
200:00:00,000 --> 00:00:07,900
3For just about every business IT environment these days, active directory has become an almost indivisible
42
500:00:08,000 --> 00:00:12,900
6part of the Microsoft Windows experience. And what's curious about that is that active directory
73
800:00:13,000 --> 00:00:15,900
9is by no means a required part of that experience.
104
1100:00:16,000 --> 00:00:20,899
12In fact active directory is not necessary in Windows environments, it's completely optional.
135
1400:00:21,000 --> 00:00:26,899
15And I've worked with businesses before, even some large organizations that have managed to operate
166
1700:00:27,000 --> 00:00:30,899
18without an active directory presence. But those businesses tend to be sort of the one offs,
197
2000:00:31,000 --> 00:00:36,899
21they may be very small, they may be the exception to the rule. The reason for that is because
228
2300:00:37,000 --> 00:00:41,899
24active directory as a completely free feature in the Windows server operating system, is something
259
2600:00:42,000 --> 00:00:46,899
27that most organizations very quickly recognize that they need. You can run a bunch of machines
2810
2900:00:47,000 --> 00:00:51,899
30in a work group for a pretty reasonable period of time, but as the number of machines gets
3111
3200:00:52,000 --> 00:00:57,899
33much beyond just a handful the need to consolidate them together, their permissioning, their authentication,
3412
3500:00:58,000 --> 00:01:02,899
36their authorization. The need to have a central location where all of those things get aggregated
3713
3800:01:03,000 --> 00:01:09,900
39becomes very important. And it is for that reason that you see active directory in just about everywhere these days.
4014
4100:01:10,000 --> 00:01:13,900
42Well what may surprise you for a technology that is so mission critical that active directory
4315
4400:01:14,000 --> 00:01:18,900
45in MCSE generations gone past was quite a bit more heavily tested on than the variety of different tests
4616
4700:01:19,000 --> 00:01:23,900
48that you were required to take. These days active directory gets one objective in a long
4917
5000:01:24,000 --> 00:01:29,900
51list of those that include other things, like file and file services and installing Windows and so on.
5218
5300:01:30,000 --> 00:01:34,900
54And even as you move through to the other tests in your MCSA or MCSC exploration,
5519
5600:01:35,000 --> 00:01:39,900
57you'll find that active directory is not the most important thing that you'll be working with.
5820
5900:01:40,000 --> 00:01:43,900
60That may be in part to the fact that active directory is already everywhere and so the number of
6121
6200:01:44,000 --> 00:01:49,900
63people that have an opportunity to create a production active directory infrastructure from scratch,
6422
6500:01:50,000 --> 00:01:54,900
66is just simply getting less and less because those opportunities don't necessarily present itself.
6723
6800:01:55,000 --> 00:01:58,900
69As a consequence, what you'll find here in this objective, and then all the other AD related objects
7024
7100:01:59,000 --> 00:02:04,900
72that follow in all the tests that follow. That the very foundations of active directory are perhaps
7325
7400:02:05,000 --> 00:02:09,900
75a little less important than knowing what to do with it once it's in place.
7626
7700:02:10,000 --> 00:02:16,900
78Now if you're just joining us here, this is our learning path for the 70-410, the first in the MCSA curriculum.
7927
8000:02:17,000 --> 00:02:19,900
81And this is number four in a long list of seven different courses that we've put together that make
8228
8300:02:20,000 --> 00:02:27,900
84up all the different content for that 410 exam. We began first with a look at the MCSA and the 70-410 exam itself
8529
8600:02:28,000 --> 00:02:31,900
87and very specifically on the RT version of this exam. And everything we'll be dealing with here
8830
8900:02:32,000 --> 00:02:38,900
90in this learning path has to do with that extra content that exists with the release of Windows server 2012 R2.
9131
9200:02:39,000 --> 00:02:42,900
93We then took a look at installing and configuring servers, some of the very manual ways in which you can
9432
9500:02:43,000 --> 00:02:47,900
96get servers installed and then some of the PowerShell and command line ways in which you can get them configured.
9733
9800:02:48,000 --> 00:02:51,900
99And then Jason took a look at the deployment and configuration of core network services,
10034
10100:02:52,000 --> 00:02:57,900
102these are things like DNS and DHCP. As well as a fairly extended review of just how you get servers
10335
10400:02:58,000 --> 00:03:03,900
105and services on the network, via IPV4 or IPV6. It is that prerequisite that takes us here
10636
10700:03:04,000 --> 00:03:08,900
108to our discussion on installing and administering active directory. And it's here where I will freely
10937
11000:03:09,000 --> 00:03:13,900
111admit Jason and I had to kind of determine which order these last two courses needed to go in,
11238
11300:03:14,000 --> 00:03:17,900
114because in order to have active directory you have to have DNS services.
11539
11600:03:18,000 --> 00:03:23,900
117And in some cases in order to have DNS and DHCP services, you had to have active directory.
11840
11900:03:24,000 --> 00:03:28,900
120So you'll find Jason back on that last course and then me here in this course, kind of waving our hands
12141
12200:03:29,000 --> 00:03:33,900
123in hair when it comes to a couple of the prerequisites that are required in order to get these things up and running.
12442
12500:03:34,000 --> 00:03:37,900
126So please bear with us if we seem to be jumping around just a bit. Here in this course
12743
12800:03:38,000 --> 00:03:40,900
129we have three different topics we have to talk about, each one mapping to one of the objectives
13044
13100:03:41,000 --> 00:03:45,900
132in the 410, the first of which is to install domain controllers. And what's interesting about installing
13345
13400:03:46,000 --> 00:03:53,900
135domain controllers is that even today in server 2012 R2 these steps to do so, although are fairly highly automated,
13646
13700:03:54,000 --> 00:03:58,900
138still require a couple of prerequisites. There are still of a couple of gotchas you just have to be aware of
13947
14000:03:59,000 --> 00:04:02,900
141when it comes time to install your first or may not your first AD/DC.
14248
14300:04:03,000 --> 00:04:06,900
144We'll go through what those are, I'll show you the different ways in which you can install a domain controller
14549
14600:04:07,000 --> 00:04:10,900
147both using the graphical user interfaces, as well as at the command line.
14850
14900:04:11,000 --> 00:04:15,900
150And then from there we'll talk about how you can create and manage your active directory users and computers.
15151
15200:04:16,000 --> 00:04:19,899
153Now you might be looking at this and saying, well gosh Greg, are we really going to go through the process
15452
15500:04:20,000 --> 00:04:24,899
156to right-click and create a new user or a new computer? Well sort of, I guess.
15753
15800:04:25,000 --> 00:04:30,899
159But more importantly these days, and particularly with this current generation of the MCSA and MCSE
16054
16100:04:31,000 --> 00:04:34,899
162knowing how to perform these tasks, not only from the user interface, the graphical user interface,
16355
16400:04:35,000 --> 00:04:38,899
165but also from the command line, is perhaps a little bit more important.
16656
16700:04:39,000 --> 00:04:42,899
168So we'll talk about not only how to create users and computers, but some of the bulk and automated
16957
17000:04:43,000 --> 00:04:47,899
171ways in which you can accomplish the same tasks via the command line and via scripting.
17258
17300:04:48,000 --> 00:04:51,899
174We will then conclude with a third module and objective here on creating and managing active directory
17559
17600:04:52,000 --> 00:04:55,899
177groups and organizational units. In this third module we'll take a look at the different groups
17860
17900:04:56,000 --> 00:05:01,899
180that are out there, how they can interrelate, as well as the organizational units, what they're used for
18161
18200:05:02,000 --> 00:05:06,899
183and how best to use them. It is this foundation that will get our environment ready to go for the
18462
18500:05:07,000 --> 00:05:12,899
186implementation of a variety of different network services that Jason will talk about in the course following.
18763
18800:05:13,000 --> 00:05:16,899
189These will be things like file services and print and document services and so on.
19064
19100:05:17,000 --> 00:05:20,899
192All of those additional services are ones that make a lot more sense once you have an active directory
19365
19400:05:21,000 --> 00:05:28,899
195infrastructure in place and all the users and computers and groups and OUs that populate that active director, but for now
19666
19700:05:29,000 --> 00:05:32,899
198let's go ahead and go through the process of getting an active directory on line and getting a couple
19967
20000:05:33,000 --> 00:05:37,899
201of servers built into that environment. Coming up next, we begin that process with the installation
20268
20300:05:38,000 --> 00:05:42,899
204of a domain controller and the creation of an active directory forest and domain.
20569
20600:05:43,000 --> 00:05:46,899
207I will tell you that an active directory, in and amongst all the different components that make it work,
20870
20900:05:47,000 --> 00:05:52,899
210has a lot of different pieces that connect together. And whereas the tasks that the exam tests you on,
21171
21200:05:53,000 --> 00:05:57,899
213maybe a little disconnected from the academics or the terminology for those components,
21472
21500:05:58,000 --> 00:06:02,899
216will start with the foundations. And take a look at those components individually so we can see
21773
21800:06:03,000 --> 00:06:08,899
219where they interconnect together to create this experience that is our active directory infrastructure.
22074
22100:06:09,000 --> 00:06:12,899
222And then from there we'll go through the click by click and step by step process you'll go through
22375
22400:06:13,000 --> 00:06:18,399
225to implement active directory, your very first domain controller and then all the other domain controllers after that.
22676
22700:06:18,500 --> 23:59:59,899
228All that and more is the topic for our next module coming up.
22977
23000:00:00,000 --> 00:00:06,900
231Sitting back and analyzing the title of this our first objective on installing domain controllers
23278
23300:00:07,000 --> 00:00:12,900
234the actual words that Microsoft uses here are very specific in terms of what I believe they want you to know.
23579
23600:00:13,000 --> 00:00:17,899
237Notice here that what Microsoft is not talking about is installing active directory or any of the
23880
23900:00:18,000 --> 00:00:21,899
240tasks involved with preparing for the installation of active directory.
24181
24200:00:22,000 --> 00:00:24,899
243And in that's a really important thing to think about as we're going through the variety
24482
24500:00:25,000 --> 00:00:30,899
246of tasks that this module and that objective can cover. Active directory is a very large
24783
24800:00:31,000 --> 00:00:34,899
249set of things and all of which have to work together in order to create that experience that we're used to.
25084
25100:00:35,000 --> 00:00:42,899
252And so Microsoft kind of punts a bit on a lot of the foundational content that is active directory itself,
25385
25400:00:43,000 --> 00:00:48,899
255like forests and domains and what not. And I'm going to focus your attentions down for this objective
25686
25700:00:49,000 --> 00:00:52,899
258on just the things you would do with the domain controllers themselves.
25987
26000:00:53,000 --> 00:00:56,899
261Here in this module we'll talk about how you can go about adding or removing domain controllers
26288
26300:00:57,000 --> 00:01:02,899
264from a domain. And this is a very specific click by click or type by type series of steps that you
26589
26600:01:03,000 --> 00:01:07,900
267would go through to add that domain controller from the domain. We'll talk about also the
26890
26900:01:08,000 --> 00:01:11,900
270installation of a domain controller using IFM or install from media.
27191
27200:01:12,000 --> 00:01:15,900
273Every so often you may have the situation where a domain controller needs to get deployed
27492
27500:01:16,000 --> 00:01:21,900
276in some location where the internet connection to that location is really, really poor.
27793
27800:01:22,000 --> 00:01:25,900
279And because of that, the replication of that content can take an extremely long period of time.
28094
28100:01:26,000 --> 00:01:31,900
282Well the install from media approach allows you to kind of preposition some information on
28395
28400:01:32,000 --> 00:01:35,900
285that domain controller to reduce the amount of replication that's required to get the domain controller
28696
28700:01:36,000 --> 00:01:41,900
288up and operational. We'll also take everything we've talked about having to do with the installation
28997
29000:01:42,000 --> 00:01:47,900
291of ADDS and translate that to the command line having to do with the installation of a domain controller
29298
29300:01:48,000 --> 00:01:51,900
294on server core. Just a couple of PowerShell commands you need to be aware of here, as well as a
29599
29600:01:52,000 --> 00:01:56,900
297variety of just different switches that go with those PowerShell commands different parameters.
298100
29900:01:57,000 --> 00:02:00,900
300We'll talk also about kind of the two ways, the more or less old school way and the new school
301101
30200:02:01,000 --> 00:02:04,900
303way involving PowerShell that you can go through in installing the domain controller on server core.
304102
30500:02:05,000 --> 00:02:08,900
306And then we'll take everything we've learned and talk a bit about upgrading a domain controller.
307103
30800:02:09,000 --> 00:02:12,900
309And in fact I'm going to go just a bit further with this particular task and give you a
310104
31100:02:13,000 --> 00:02:18,900
312little bit of additional information that may or may not be on the test, probably isn't on the exam.
313105
31400:02:19,000 --> 00:02:24,900
315That has to do not only with upgrading domain controllers, but upgrading domains and upgrading forests.
316106
31700:02:25,000 --> 00:02:31,900
318These can be handy when you have the situation where you need to go from a server 2008 R2 active directory domain
319107
32000:02:32,000 --> 00:02:36,900
321to one's that server 2012 R2 or so on. And just so knowing the quick five step process to upgrade
322108
32300:02:37,000 --> 00:02:42,900
324a domain controller and the domain and forest it resides in, is something you probably should know.
325109
32600:02:43,000 --> 00:02:46,900
327Now active directory, the way in which the clients find the servers and services and the way in which
328110
32900:02:47,000 --> 00:02:53,900
330each server finds each other, has to do with DNS. And the different kinds of SRV or service records
331111
33200:02:54,000 --> 00:02:57,900
333in DNS that are published by each active directory domain controller.
334112
33500:02:58,000 --> 00:03:02,900
336Now every so often you can end up with a situation where a record gets removed or corrupted
337113
33800:03:03,000 --> 00:03:07,900
339or for some reason or another the domain controller can't update that record or populate that record.
340114
34100:03:08,000 --> 00:03:11,900
342Well when that's the case, you need to figure out how to actually go through resolving those
343115
34400:03:12,000 --> 00:03:15,900
345record registration issues. And there are a couple, kind of really slick ways in which
346116
34700:03:16,000 --> 00:03:19,900
348you can accomplish that, I'll show both of those when we get to this part of our module here.
349117
35000:03:20,000 --> 00:03:24,900
351We'll talk also about configuring global catalogs and global catalog servers, there's a checkbox
352118
35300:03:25,000 --> 00:03:27,900
354you need to know, there's probably a PowerShell command there too you'll need to know that will
355119
35600:03:28,000 --> 00:03:31,900
357enable global catalog on any of the machines that you intend to.
358120
35900:03:32,000 --> 00:03:37,900
360Back in the old days, back when our network connections between sites was much, much smaller than it is today,
361121
36200:03:38,000 --> 00:03:42,900
363the determination as to where your global catalog should go was much more important.
364122
36500:03:43,000 --> 00:03:47,900
366But these days the amount of traffic that occurs between global catalog servers in combination
367123
36800:03:48,000 --> 00:03:51,900
369with just the amount of pipeline that we tend to have between our different sites,
370124
37100:03:52,000 --> 00:03:55,900
372means that in a lot of environments, at least the ones that I see, you'll find global catalog
373125
37400:03:56,000 --> 00:04:02,900
375turned on on every domain controller. Doing so greatly simplifies the planning of your active directory
376126
37700:04:03,000 --> 00:04:08,900
378and more importantly it just greatly simplifies knowing where it's at, because every DC is also a GC.
379127
38000:04:09,000 --> 00:04:12,900
381And then our final topic here for this module is deploying active directory in Microsoft Azure,
382128
38300:04:13,000 --> 00:04:16,899
384which I think you will find is perhaps a little less exciting than it might seem to be.
385129
38600:04:17,000 --> 00:04:20,899
387The key reason here why I say that, is that little acronym there in the middle marked IAAS,
388130
38900:04:21,000 --> 00:04:25,899
390which is a shorthand for I'm creating active directory on a virtual machine.
391131
39200:04:26,000 --> 00:04:28,899
393And so really what we're talking about here in deploying active directory is deploying
394132
39500:04:29,000 --> 00:04:33,899
396a domain controller in Microsoft Azure. There are and in the future will be other ways
397133
39800:04:34,000 --> 00:04:41,399
399in which active directory can be manifested inside of Azure, more align with a service than a service on a VM.
400134
40100:04:41,500 --> 00:04:45,399
402But for our purposes here, I want to spend just a couple of minutes showing you that indeed this is
403135
40400:04:45,500 --> 00:04:48,899
405possible and giving you a couple of the things you should be aware of should you decide
406136
40700:04:49,000 --> 00:00:01,553
408to deploy active directory and a domain controller into the Microsoft Azure cloud.
409137
41000:00:01,653 --> 00:00:05,554
411First up on our list of things to talk about, before we get into the specific tasks that this
412138
41300:00:05,653 --> 00:00:09,554
414objective requires, I want to spend just a minute going through some of the foundations
415139
41600:00:09,653 --> 00:00:15,554
417the vocabulary, if you will, of active directory. Now this is not directly testable on the exam,
418140
41900:00:15,653 --> 00:00:20,553
420at least based off of how the objectives are worded, but you kind of have to know what these things are
421141
42200:00:20,653 --> 00:00:23,553
423to appreciate the later things that you're going to be asked to do.
424142
42500:00:23,653 --> 00:00:28,553
426The first of which is just recognizing what an active directory domain is and how an active directory
427143
42800:00:28,653 --> 00:00:35,554
429domain and an active directory forest are interrelated. This may be entirely review or just
430144
43100:00:35,654 --> 00:00:39,554
432completely something that's unnecessary for you, so feel free to click through to the next clip
433145
43400:00:39,654 --> 00:00:45,554
435if you find this to be uninteresting or un-useful. But if you're brand new to the notion of active directory
436146
43700:00:45,654 --> 00:00:50,554
438or if you've been in an active directory that is a very simple one, this explanation of some very
439147
44000:00:50,654 --> 00:00:56,554
441complex ones can be helpful has you begin working through the different questions that this exam may require.
442148
44300:00:56,654 --> 00:01:01,554
444Now an active directory domain is something that we are intending to install here onto this our domain controller
445149
44600:01:01,654 --> 00:01:05,554
447we'll be dealing with here in just a minute. And in most places an active directory domain,
448150
44900:01:05,653 --> 00:01:09,554
450at least in Microsoft parlons, the domain is represented by a triangle, so you're going to see
451151
45200:01:09,653 --> 00:01:13,554
453a lot of triangles here coming up. But what I want to show you here is that an active directory
454152
45500:01:13,653 --> 00:01:18,554
456domain is sort of the boundary of authentication for a set of users and computers and the different
457153
45800:01:18,653 --> 00:01:24,554
459resources that they work with. So when you log into your machine at company.pri you're logging
460154
46100:01:24,653 --> 00:01:32,554
462into the domain that is company.pri. Today, these days, most organizations work within
463155
46400:01:32,653 --> 00:01:36,554
465what is called a single domain single forest model. And so, the entirety of the workspace
466156
46700:01:36,653 --> 00:01:42,554
468that you're dealing with is this thing called company.pri, but what I want to show you here
469157
47000:01:42,653 --> 00:01:46,554
471is that it is possible to take multiple domains and connect them together to create
472158
47300:01:46,653 --> 00:01:51,554
474a tree of domains or a forest, if you will, of domains. Should you have that need to do so.
475159
47600:01:51,653 --> 00:02:00,554
477So, for example, sub to my company.pri domain, it is entirely possible for me to create another domain
478160
47900:02:00,653 --> 00:02:06,554
480that sits below. This other domain, Denver.company.pri, is one that perhaps was created for
481161
48200:02:06,653 --> 00:02:11,554
483one reason or another. Maybe it's a different company called Denver, maybe it's a different
484162
48500:02:11,653 --> 00:02:17,554
486group of people that want to have their own consolidated set of users and computers and resources.
487163
48800:02:17,653 --> 00:02:22,554
489They want their own boundary to be different than the root domain there with company.pri.
490164
49100:02:22,653 --> 00:02:27,554
492In the 412, 70-412 exam, we'll talk more about the reasons why you would make these decisions,
493165
49400:02:27,653 --> 00:02:32,554
495but for now just recognize that it is entirely possible to create these multi-domain structures
496166
49700:02:32,653 --> 00:02:37,554
498that are automatically connected together. Now one thing that's important to recognize here
499167
50000:02:37,653 --> 00:02:43,554
501with the connection between my company.pri domain and my Denver domain, is that the two name spaces
502168
50300:02:43,653 --> 00:02:50,554
504I'm looking at here, the namespace being the words, company.pri, are what we call contiguous.
505169
50600:02:50,653 --> 00:02:55,554
507Meaning that Denver.company.pri is effectively a subset of company.pri.
508170
50900:02:55,653 --> 00:03:00,554
510Now in the oldest of days, it was necessary for us to maintain a contiguous namespace between
511171
51200:03:00,653 --> 00:03:04,554
513any domains that were connected together into a single forest, but these days it's actually
514172
51500:03:04,653 --> 00:03:11,554
516possible to create noncontiguous namespaces as well. So, I could have a subdomain of company.pri
517173
51800:03:11,653 --> 00:03:18,554
519being taco, for example. Or anything that I want. Now again, when we move the 412 you'll learn
520174
52100:03:18,653 --> 00:03:22,554
522more about why I would do that versus why I would not and some of the gotchas and things
523175
52400:03:22,653 --> 00:03:27,554
525you have to be aware of should you go down the noncontiguous namespace route.
526176
52700:03:27,653 --> 00:03:32,554
528But here in 2012 R2 we do have the ability to create these noncontiguous namespaces.
529177
53000:03:32,653 --> 00:03:38,554
531Domains also needn't necessarily be just a single layer deep, we can have multiple layers of different domains.
532178
53300:03:38,653 --> 00:03:46,554
534So test.denver.company.pri, and prod.denver.company.pri, and I can even go noncontiguous into my
535179
53600:03:46,653 --> 00:03:52,554
537subdomains as well, so taco.pri and burrito.com needn't necessarily be organized with each other
538180
53900:03:52,653 --> 00:03:56,554
540except to be in a completely different branch of the tree. Now I'm showing you this not because
541181
54200:03:56,653 --> 00:04:02,554
543I'm trying to incent you towards creating this large and complicated multi-domain structure.
544182
54500:04:02,653 --> 00:04:09,554
546In fact as I'd mentioned before, in most organizations we have moved to a single domain single forest structure,
547183
54800:04:09,653 --> 00:04:13,554
549because trying to figure out where users are and the management of users and computers and resources
550184
55100:04:13,653 --> 00:04:19,553
552across the domain boundaries, it gets just really, really complicated.
553185
55400:04:19,653 --> 00:04:24,553
555Because of that, the very slight benefits that people get out of multi-domains are in many
556186
55700:04:24,653 --> 00:04:30,553
558cases outweighed by the incredible headache that's involved with figuring out where stuff goes
559187
56000:04:30,653 --> 00:00:01,583
561and how you can simply address it.
562188
56300:00:01,683 --> 00:00:06,584
564Now whereas the multi-domain structure is something that just seems to be getting less and less these days,
565189
56600:00:06,684 --> 00:00:10,583
567it's not unlikely for you to occasionally see a multi-forest structure.
568190
56900:00:10,683 --> 00:00:13,583
570And again we'll talk more about the different ways in which you can connect forests together
571191
57200:00:13,683 --> 00:00:19,583
573in the 412 content, but for now just recognize that one of the ways that you can go about
574192
57500:00:19,684 --> 00:00:23,583
576connecting forests together happens through what is called a forest trust.
577193
57800:00:23,684 --> 00:00:29,583
579Let's assume here that I have my company.pri domain and forest here, so single forest, single domain,
580194
58100:00:29,684 --> 00:00:35,583
582and I need to attach to some other company. So maybe that's the specialized.NET domain and forest.
583195
58400:00:35,683 --> 00:00:41,583
585Maybe we acquired them, maybe they've been brought out underneath our organization and we
586196
58700:00:41,683 --> 00:00:45,583
588need to take them under our wing for one reason or another. Well it is possible to create what is called
589197
59000:00:45,683 --> 00:00:52,583
591a forest trust between the top most level of these two domains that facilitates the communication
592198
59300:00:52,683 --> 00:00:57,583
594and the authorization between this domain and that domain. By creating this forest trust
595199
59600:00:57,683 --> 00:01:01,583
597and then applying permissions in the appropriate ways, I can sitting here in company.pri,
598200
59900:01:01,683 --> 00:01:07,584
600then access resources in specialized.NET. Now the neat part about these forest trusts is that
601201
60200:01:07,683 --> 00:01:12,584
603depending on how you configure them, it is entirely possible for all of the different sub domains
604202
60500:01:12,683 --> 00:01:19,584
606beneath that main triangle to also have access to the resources in that other forest.
607203
60800:01:19,683 --> 00:01:23,584
609Now if you thought that the multi-domain model was complex, you can imagine how the multi-forest
610204
61100:01:23,683 --> 00:01:28,584
612multi-domain model gets even more complex. So you tend to see in most organizations
613205
61400:01:28,683 --> 00:01:33,584
615when there is a forest trust laid into place. A lot of times that can be done for perhaps
616206
61700:01:33,683 --> 00:01:39,584
618a temporary reason until that remote trust can get consumed by the main domain.
619207
62000:01:39,683 --> 00:01:44,584
621Or in some cases you'll see it by different partner companies that are working together for one reason or another.
622208
62300:01:44,683 --> 00:01:50,584
624In another case, you may have some quasi approved forest that was created by a shadow IT organization
625209
62600:01:50,683 --> 00:01:53,584
627that needs to get connected up to the main forest. And so in order to do that you've got to
628210
62900:01:53,683 --> 00:01:58,584
630connect them together via a trust, but for whatever reason you're creating it, there is the
631211
63200:01:58,683 --> 00:02:03,584
633abilities to bridge from one organization's active directory infrastructure to another
634212
63500:02:03,683 --> 00:02:08,584
636by use of what are called trusts. Again we'll learn more about this in 412, the whole concept of trusts
637213
63800:02:08,683 --> 00:00:01,655
639and how they get implemented in 412, but at least this gives you an idea of what we're attempting to accomplish.
640214
64100:00:01,756 --> 00:00:04,363
642Now in addition to the domains and forests
643215
64400:00:04,463 --> 00:00:08,362
645there is also the abilities to create multiple different sites in active directory as well.
646216
64700:00:08,462 --> 00:00:14,362
648And it is perhaps the sites that are the least paid attention to in today's modern world
649217
65000:00:14,462 --> 00:00:20,362
651in part because it's easy to forget about them and also because the organic constantly growing
652218
65300:00:20,463 --> 00:00:26,362
654constantly changing behaviors of our business, sometimes means that the geographic sites
655219
65600:00:26,463 --> 00:00:31,362
657that make up our company may not necessarily directly map to the active directory sites that
658220
65900:00:31,463 --> 00:00:36,362
660we've configured logically. Now let's assume again that we have this domain company.pri
661221
66200:00:36,463 --> 00:00:39,362
663and we're going to deal with a single forest, single domain in this example.
664222
66500:00:39,463 --> 00:00:46,362
666In this example I may have three different geographic sites that my domain extends into,
667223
66800:00:46,463 --> 00:00:51,362
669Denver, Las Vegas, and Phoenix. These three different geographic sites are just three places
670224
67100:00:51,463 --> 00:00:55,362
672where people are working, maybe I have an office in Denver and an office in Las Vegas
673225
67400:00:55,463 --> 00:01:01,362
675and an office in Phoenix. Now these three sites correspond with three areas of high network
676226
67700:01:01,463 --> 00:01:06,362
678connectivity that happen to be interconnected by probably less powerful network lines, right.
679227
68000:01:06,462 --> 00:01:12,362
681You're not going to have 10 megabits or gigabit connections between these different locations, or maybe you will,
682228
68300:01:12,462 --> 00:01:18,362
684but the definition of a site is a location of high network connectivity that may connect up to other
685229
68600:01:18,462 --> 00:01:25,362
687locations that are similarly configured. Now in this configuration, the Denver, Las Vegas, and Phoenix site,
688230
68900:01:25,462 --> 00:01:29,362
690these three sites are defined by the subnet that has been configured on each site.
691231
69200:01:29,462 --> 00:01:34,362
693And this is something that you're network team would have done before the implementation of active directory
694232
69500:01:34,462 --> 00:01:41,362
696in sites and services and so on. And so the Denver site corresponds with the 192,168.0 net and the
697233
69800:01:41,462 --> 00:01:46,362
699Las Vegas site to the 2 net and the Phoenix site to the 3 net. These three different subnets
700234
70100:01:46,462 --> 00:01:52,362
702are what allow active directory to define the geographic constraints for this site.
703235
70400:01:52,462 --> 00:01:55,362
705Now what's important to recognize is that we're still talking about the same domain,
706236
70700:01:55,462 --> 00:02:02,362
708everyone here still logs on to company.pri, but as you can imagine when I've got users that are
709237
71000:02:02,462 --> 00:02:08,362
711being added and subtracted and their passwords are changed and they're being given different permission sets.
712238
71300:02:08,462 --> 00:02:13,362
714All of this change to the content in the active directory database can occasionally mean that
715239
71600:02:13,462 --> 00:02:20,362
717I may need to better control the traffic that is going on in the connections between these independent sites.
718240
71900:02:20,462 --> 00:02:26,362
720So for example, if I make a change to a user in Denver, maybe I want to slow down the propagation
721241
72200:02:26,462 --> 00:02:34,362
723of that change to Las Vegas and Phoenix, because doing so will consume that precious network bandwidth.
724242
72500:02:34,462 --> 00:02:36,362
726Now this makes a lot more sense, maybe not in the three site world,
727243
72800:02:36,462 --> 00:02:42,362
729but in a situation where I may have more than three sites. So let's say your organizations got very
730244
73100:02:42,462 --> 00:02:47,362
732large now you were, you had Denver and Las Vegas and Phoenix and that was working out well for you.
733245
73400:02:47,462 --> 00:02:51,362
735But then suddenly you start buying additional sites, so you open an office in San Francisco and then
736246
73700:02:51,462 --> 00:02:57,362
738you open another office in Chicago and there another in Boston and another one in Miami.
739247
74000:02:57,462 --> 00:03:03,362
741Well these lines here correspond then with the network connections that pull this single network
742248
74300:03:03,462 --> 00:03:07,362
744space together, the actual logical connections that are created with your provider.
745249
74600:03:07,462 --> 00:03:15,362
747Well in these cases some of these connections maybe at a lower performance, less bandwidth than the others.
748250
74900:03:15,462 --> 00:03:21,362
750And so because of that, you may need to go through and define what the cost of that connection will be.
751251
75200:03:21,462 --> 00:03:26,362
753Without getting too much into the details of how we configure these, for connections with a higher cost
754252
75500:03:26,462 --> 00:03:30,362
756you may want to throttle down how much active directory content is being replicated.
757253
75800:03:30,462 --> 00:03:35,362
759So you don't end up using all the bandwidth so that people have no abilities to use it for other things.
760254
76100:03:35,462 --> 00:03:39,362
762Now I don't want to get too much into detail here in terms of how you make these configurations,
763255
76400:03:39,462 --> 00:03:45,362
765again, more of this happens in the 412 content. But just recognize that the sites and services
766256
76700:03:45,462 --> 00:03:50,362
768active directory sites and services console is the place where much of this ends up being configured.
769257
77000:03:50,462 --> 00:00:01,988
771And it has everything to do with how your active directory domain is broken up by geographic location.
772258
77300:00:02,088 --> 00:00:05,989
774Now I introduce all of this because, well it's the sites where you need to determine whether or not
775259
77600:00:06,089 --> 00:00:10,989
777you need to install a domain controller or not. Or even multiple domain controllers.
778260
77900:00:11,089 --> 00:00:14,989
780When we're talking about DCs, the main controllers are the host of the active directory.
781261
78200:00:15,089 --> 00:00:19,988
783They're the ones that contain the active directory database. And every active directory domain
784262
78500:00:20,088 --> 00:00:24,988
786controller generally has an equal copy of the AD database, as every other domain controller.
787263
78800:00:25,088 --> 00:00:31,988
789It's a multi-master model with each one transferring its contents to the other so that everyone
790264
79100:00:32,088 --> 00:00:38,988
792has a shared vision of what that database is. Now generally in most configurations, a minimum of
793265
79400:00:39,088 --> 00:00:42,988
795two domain controllers is required for a single domain. Those two domain controllers
796266
79700:00:43,088 --> 00:00:48,988
798ensure that should you power one off, or reboot one for the purposes of patching or it just dies
799267
80000:00:49,088 --> 00:00:53,988
801or what have you. You still have additional services that are out there to support this very mission
802268
80300:00:54,088 --> 00:00:57,988
804critical service that is active directory. But things get a little bit more complex when you start
805269
80600:00:58,088 --> 00:01:04,989
807moving into the world of multiple sites. So in multiple sites I may need to have multiple domain
808270
80900:01:05,088 --> 00:01:10,989
810controllers in my primary location, maybe Denver where most of the users sit.
811271
81200:01:11,088 --> 00:01:14,989
813I may also need to have additional domain controllers in another site, like Las Vegas.
814272
81500:01:15,088 --> 00:01:20,989
816Maybe I have a lot of users in Las Vegas as well and so putting an additional two DCs in Las Vegas
817273
81800:01:21,088 --> 00:01:25,989
819to handle their load can become important as well. Maybe Phoenix is a smaller site and so only
820274
82100:01:26,088 --> 00:01:31,989
822a single domain controller is sufficient to service their needs. So when you're thinking about
823275
82400:01:32,088 --> 00:01:34,989
825planning your active directory you kind of have to think about how much hardware does each
826276
82700:01:35,088 --> 00:01:39,989
828individual site need. And it is the definition of these different sites and services
829277
83000:01:40,088 --> 00:00:01,977
831and how they're configured, which ends up driving those decisions.
832278
83300:00:02,077 --> 00:00:04,978
834Now in addition to domain controllers, we have another decision that has to be made as well,
835279
83600:00:05,078 --> 00:00:10,477
837and that has to do with global catalogs and the different servers that will serve as a global catalog.
838280
83900:00:10,577 --> 00:00:15,977
840You should be aware, at least at this point, that a global catalog provides a subset of the total
841281
84200:00:16,077 --> 00:00:22,977
843active directory domain, the database, in order to serve as the logging in the logging out of clients.
844282
84500:00:23,077 --> 00:00:28,977
846The general authentication of clients. And as I mentioned before, back in the old days the positioning
847283
84800:00:29,077 --> 00:00:33,978
849of global catalogs was much more important when the network connections between our different sites
850284
85100:00:34,078 --> 00:00:37,978
852was very small in comparison with the amount of data we were trying to push through them.
853285
85400:00:38,078 --> 00:00:42,978
855These days that amount of global catalog traffic or the replication traffic is quite a bit less
856286
85700:00:43,078 --> 00:00:49,978
858and so in a lot of environments you find that global catalogs get installed just about everywhere.
859287
86000:00:50,078 --> 00:00:54,978
861But a global catalog effectively is another configuration that you apply onto a domain controller.
862288
86300:00:55,078 --> 00:00:58,978
864Let's say for example, that this domain controller is the very first one that we've installed in our environment.
865289
86600:00:59,078 --> 00:01:04,978
867And so because of that has been configured as a global catalog. You have to have a global catalog
868290
86900:01:05,078 --> 00:01:09,978
870in your environment in order to log in clients. And so because of that we've got one sitting here in Denver.
871291
87200:01:10,078 --> 00:01:14,978
873Well as you go about configuring your other domain controllers, you may determine to add additional
874292
87500:01:15,078 --> 00:01:19,978
876global catalog services at least into each site. So that one of the domain controllers in each site
877293
87800:01:20,078 --> 00:01:24,978
879can serve as a global catalog. This can be a good practice to ensure that you have good
880294
88100:01:25,078 --> 00:01:28,978
882performing logons as users are going about logging onto their machines.
883295
88400:01:29,078 --> 00:01:33,978
885Well catalogs also help you locate objects within the forest as well as providing information about
886296
88700:01:34,078 --> 00:01:37,978
888universal groups. Now again, in the old days you'd see these configured in such a way that
889297
89000:01:38,078 --> 00:01:42,978
891at least you would have one global catalog probably per site. But the more common practice,
892298
89300:01:43,078 --> 00:01:47,978
894whether or not it's an established best practice or not. The more common practice these days
895299
89600:01:48,078 --> 00:01:52,978
897is to configure every domain controller as a global catalog. In a world where bandwidth is
898300
89900:01:53,078 --> 00:01:56,978
900no longer at the premium it once was, this allows every domain controller to operate with all the
901301
90200:01:57,078 --> 00:02:01,978
903functionality required to support the needs of its users. A little later on in this module we'll
904302
90500:02:02,078 --> 00:02:06,478
906talk about how you can go about configuring a domain controller as a global catalog server.
907303
90800:02:06,578 --> 00:00:01,806
909And it's something you're probably going to want to do.
910304
91100:00:01,907 --> 00:00:06,307
912Now another topic worth discussing here in our review of the foundations of active directory,
913305
91400:00:06,407 --> 00:00:12,807
915has to do with organizational units. And honestly OUs are routinely misunderstood in terms of
916306
91700:00:12,907 --> 00:00:18,306
918what their value is for the organization. I want to show you what an OU is and then show you
919307
92000:00:18,407 --> 00:00:22,306
921at least my impression of where you should implement them. Because all too often you find
922308
92300:00:22,407 --> 00:00:29,806
924organizations that have implemented OUs in ways that cause them no end of heartache in regular operations.
925309
92600:00:29,907 --> 00:00:34,906
927An organizational unit is designed very different from a group, like an active directory group,
928310
92900:00:35,006 --> 00:00:42,806
930is designed as a mechanism for the division of user accounts and computer accounts for the purposes
931311
93200:00:42,906 --> 00:00:48,906
933of IT and IT alone. So for example, an OU could be created for users and then a sub OU could
934312
93500:00:49,006 --> 00:00:54,806
936be created for finance users. On the computer side, we could create an OU for computers and then
937313
93800:00:54,906 --> 00:01:00,906
939a sub OU for IT computers or another one for high security computers.
940314
94100:01:01,006 --> 00:01:04,907
942Now it is this definition I think that confuses a lot of people, especially when they start
943315
94400:01:05,007 --> 00:01:09,807
945working with active directory and see this nifty new thing that is organizational units.
946316
94700:01:09,906 --> 00:01:16,907
948The OU is designed for consumption by IT only, it's an administrative function only.
949317
95000:01:17,007 --> 00:01:22,807
951And further, the biggest reason for the existence of organizational units is for the separation
952318
95300:01:22,906 --> 00:01:27,207
954of active directory group policy and the application of group policy.
955319
95600:01:27,307 --> 00:01:31,907
957You can create and manipulate OUs to your hearts content, you can move active directory users
958320
95900:01:32,007 --> 00:01:38,307
960and computer groups around into different OUs and really have no fundamental change to how they end up operating.
961321
96200:01:38,406 --> 00:01:42,307
963Except when you begin to go through the process of implementing group policy.
964322
96500:01:42,406 --> 00:01:46,907
966And I say that because in order to implement group policy you have to tag a group policy
967323
96800:01:47,007 --> 00:01:52,807
969object to an organizational unit. Now it's here where I kind want to step away from the exam
970324
97100:01:52,906 --> 00:01:58,807
972for just a second and talk a bit about how you might implement things in your actual active directory environment.
973325
97400:01:58,906 --> 00:02:03,907
975When you're building your organizational units, if you recognize that the only real use for OUs
976326
97700:02:04,007 --> 00:02:10,807
978is for the application of group policy. It is, at least Greg's best practice, to only create
979327
98000:02:10,907 --> 00:02:16,907
981organizational units when you need to do so for the application of group policy.
982328
98300:02:17,007 --> 00:02:21,807
984Now this sounds like a, kind of a duh moment, but you find all the time out in the world
985329
98600:02:21,907 --> 00:02:26,307
987you find organizations that have created dozens or hundreds of different OUs that break down
988330
98900:02:26,407 --> 00:02:33,807
990their users and computers into various subcontainers and sub subcontainers, in some cases sub sub subcontainers.
991331
99200:02:33,907 --> 00:02:39,907
993But all too often what happens is that the creation of this structure is awesome until the moment
994332
99500:02:40,007 --> 00:02:47,807
996that you have to go about ensuring that the proper users and computers are always in the right location.
997333
99800:02:47,907 --> 00:02:54,807
999A user account and a computer account can only exist in a single OU at a time.
1000334
100100:02:54,907 --> 00:02:58,907
1002And so on the user side where it may be easy to make sure that Bob in accounting
1003335
100400:02:59,007 --> 00:03:04,807
1005is always in the accounting OU. It's quite a bit more difficult on a day to day basis
1006336
100700:03:04,907 --> 00:03:09,807
1008to know whether or not his computer, which who knows what the name of that computer is,
1009337
101000:03:09,907 --> 00:03:14,907
1011also exists in the appropriate computer oriented organizational unit.
1012338
101300:03:15,007 --> 00:03:20,307
1014If Bob swaps out his laptop for another machine, are you 100% sure that you'll be able to
1015339
101600:03:20,407 --> 00:03:25,807
1017remove that old computer account and add the new one in every time that action happens?
1018340
101900:03:25,907 --> 00:03:30,807
1020In my experience that doesn't happen that often and the more complex the OU structure you find,
1021341
102200:03:30,907 --> 00:03:36,807
1023the less it maps to the real world, shall we say. So Greg's advice, keep your OU structure
1024342
102500:03:36,907 --> 00:00:01,723
1026as simple as possible until you find a group policy oriented reason to separate it out for one reason or another.
1027343
102800:00:01,824 --> 00:00:06,724
1029Now our last of these foundation topics that we have to talk about is also one that I suspect
1030344
103100:00:06,823 --> 00:00:10,724
1032is not tested directly on in the exam, but if something you just have to know because it is
1033345
103400:00:10,823 --> 00:00:16,724
1035one of the basics of active directory. And those are the flexible single master operations roles.
1036346
103700:00:16,824 --> 00:00:21,724
1038Now Microsoft in attempting to create a multi-master model for the active directory database
1039347
104000:00:21,824 --> 00:00:26,724
1041one where every copy of the database was exactly the same. And there was no single master
1042348
104300:00:26,824 --> 00:00:32,723
1044where everyone pulled their content from, realize that a small subset of the activities of active directory
1045349
104600:00:32,823 --> 00:00:38,723
1047could not be made multi-master. Some of these things worked best, or worked at all, when a single
1048350
104900:00:38,823 --> 00:00:43,723
1050computer was responsible for the execution of that task. These created what we now know
1051351
105200:00:43,823 --> 00:00:52,723
1053of as the FSMO roles. These five FSMO roles define a set of activities that have to occur on a specific machine.
1054352
105500:00:52,823 --> 00:00:58,723
1056The first of which is the schema master. Anytime you do any update to the active directory schema,
1057353
105800:00:58,823 --> 00:01:04,724
1059not necessarily changing content in the database, but changing the structure of the database itself.
1060354
106100:01:04,823 --> 00:01:10,724
1062Updates like the AD prep command, Microsoft exchanges updates, any other applications that are going
1063355
106400:01:10,823 --> 00:01:16,724
1065to modify the active directory schema. Those changes have to happen on the domain controller server
1066356
106700:01:16,823 --> 00:01:22,724
1068that has been configured as the schema master. There's only one per forest and generally that's
1069357
107000:01:22,823 --> 00:01:27,724
1071schema master is placed on the forest route PDC. And hold onto that we'll get to the PDC emulator in a minute,
1072358
107300:01:27,823 --> 00:01:35,724
1074but that schema master is generally placed on the PDC emulator role holder in the forest route domain.
1075359
107600:01:35,823 --> 00:01:39,724
1077Most important thing to know here is that in order to do any changes to the schema, you have to have
1078360
107900:01:39,823 --> 00:01:43,724
1080a schema master up and operational. We have another role here called the domain naming master,
1081361
108200:01:43,823 --> 00:01:49,724
1083which is responsible for, you guessed it, the naming of domains. This role was what's responsible
1084362
108500:01:49,823 --> 00:01:53,724
1086for adding a removing domains and application partitions from the active directory forest
1087363
108800:01:53,823 --> 00:01:59,724
1089and has to be online anytime you're doing any of those adds or removes to domains or app partitions.
1090364
109100:01:59,823 --> 00:02:05,724
1092As with the schema master, the domain naming master is generally placed on that forest root PDC.
1093365
109400:02:05,823 --> 00:02:12,724
1095Which is this our third role. Back in the old days, before we had a multi-master model for active directory,
1096366
109700:02:12,824 --> 00:02:17,724
1098we use to have an approach where we had a single machine that served as the primary domain controller.
1099367
110000:02:17,824 --> 00:02:24,724
1101And we had all other machines serving a secondary domain controllers or backup domain controllers, BDCs.
1102368
110300:02:24,824 --> 00:02:33,724
1104These BDCs grabbed their content from the PDC, where a single master authoritative copy of the content always existed.
1105369
110600:02:33,824 --> 00:02:40,724
1107All changes occurred at the PDC. Well with that change to a multi-master replication model for active directory
1108370
110900:02:40,824 --> 00:02:47,724
1110database it still made sense for some of the action, some of the tasks, to occur on a single specified machine.
1111371
111200:02:47,824 --> 00:02:52,724
1113That machine today is known of as the PDC emulator. The PDC emulator handles password changes,
1114372
111500:02:52,824 --> 00:02:57,724
1116so if you're doing computer user accounts on DCs it handles the password changes.
1117373
111800:02:57,824 --> 00:03:01,724
1119It's consulted by your replica domain controllers when you have service authorization requests
1120374
112100:03:01,824 --> 00:03:09,724
1122with mismatched passwords. It is the default target DC anytime you're doing any group policy updates.
1123375
112400:03:09,824 --> 00:03:15,724
1125It is also the default target DC when you have any legacy applications that need to perform writable operations.
1126376
112700:03:15,824 --> 00:03:21,724
1128And some of the old school admin tools still point to the PDC emulators and very old school admin
1129377
113000:03:21,824 --> 00:03:26,724
1131tools in order to accomplish their tasks. And also, not listed here, the PDC emulator tends to
1132378
113300:03:26,824 --> 00:03:33,724
1134also be the time keeper for the domain and forest. Your PDC emulator, because of obviously these things,
1135379
113600:03:33,824 --> 00:03:38,724
1137needs to be online and accessible at all times. And so you generally can't operate for a very
1138380
113900:03:38,824 --> 00:03:44,724
1140long period of time without having a PDC emulator up and running. Many of the other FSMO roles
1141381
114200:03:44,824 --> 00:03:49,724
1143can exist in a state where that domain controller is down for a period of time.
1144382
114500:03:49,824 --> 00:03:54,724
1146I mean you don't often do schema changes, you don't often add and remove domains from your forest,
1147383
114800:03:54,824 --> 00:03:58,724
1149but because of these things the PDC emulator does, it's generally expected to be online and
1150384
115100:03:58,824 --> 00:04:03,724
1152accessible at all times. And it's generally also placed on higher performance hardware
1153385
115400:04:03,824 --> 00:04:11,724
1155in a reliable hub site alongside other domain controllers that can handle your everyday user authentication traffic.
1156386
115700:04:11,824 --> 00:04:16,723
1158When you're in a very large organization, where the emulator is doing a lot of tasks for a very large
1159387
116000:04:16,824 --> 00:04:22,723
1161number of users and computers. Of the five, the PDC emulator is perhaps the most important to
1162388
116300:04:22,824 --> 00:04:27,723
1164keep up and operational. Now the fourth of these is the RID master. And it's the job of the RID
1165389
116600:04:27,824 --> 00:04:33,723
1167master to create what are called relative IDs or the different objects that require permissions or what not
1168390
116900:04:33,824 --> 00:04:39,723
1170to be associated with them. A RID is a string of characters that is used to uniquely identify
1171391
117200:04:39,824 --> 00:04:45,723
1173an object in a domain. The SID, which you're probably more familiar with, is just simply the RID
1174392
117500:04:45,824 --> 00:04:48,723
1176plus an additional series of characters that is its domain identifier.
1177393
117800:04:48,824 --> 00:04:56,723
1179So SID equals RID plus domain ID. The RID master's got to be online, so that any newly promoted DCs
1180394
118100:04:56,824 --> 00:05:03,723
1182can obtain a local RID pool. Generally the RIDs are distributed by the individual DCs
1183395
118400:05:03,824 --> 00:05:08,723
1185and only when they run out of RIDs in their pool do they request another set of them from the RID master.
1186396
118700:05:08,824 --> 00:05:13,723
1188And it generally is also placed on the forest root PDC, as you can see here that PDC has got a lot
1189397
119000:05:13,824 --> 00:05:17,723
1191of different roles that are generally held on it. Again the RID master's not quite as important
1192398
119300:05:17,824 --> 00:05:23,723
1194as the PDC emulator because it's job is to maintain the pools that it distributes out to the domain controllers
1195399
119600:05:23,824 --> 00:05:28,723
1197or actually assigning out those RIDs to individual objects. So you can have it shut down for a period
1198400
119900:05:28,824 --> 00:05:32,723
1200of time, but you tend not to want to keep these things down for very long.
1201401
120200:05:32,824 --> 00:05:38,723
1203The last of these is the infrastructure master and its job is to update references in the local domain
1204402
120500:05:38,824 --> 00:05:44,723
1206for many objects that exist in other domains. So these cross domain references.
1207403
120800:05:44,824 --> 00:05:49,723
1209You've seen this if you have a domain where your domain trusts another domain, either inside of a forest
1210404
121100:05:49,824 --> 00:05:55,723
1212or outside through some forest trust. If you've had that situation where instead of seeing
1213405
121400:05:55,824 --> 00:06:01,723
1215a user name you've seen a long list of numbers in the permissions dialog box and you're trying
1216406
121700:06:01,824 --> 00:06:06,723
1218to assign permissions. It's the job of the infrastructure master to translate that SID into
1219407
122000:06:06,824 --> 00:06:11,723
1221a friendly name. So you actually know what you're looking at. It's also the job of the infrastructure master
1222408
122300:06:11,824 --> 00:06:17,723
1224to manage any phantoms or tombstones out of the global catalog. And these are topics, these are kind of
1225409
122600:06:17,824 --> 00:06:22,723
1227dance topics that have to do with how objects get deleted and preserved and potentially resurrected.
1228410
122900:06:22,824 --> 00:06:28,723
1230But recognize that it's the infrastructure master's job just to maintain those cross domain references.
1231411
123200:06:28,824 --> 00:06:33,723
1233Now a separate infrastructure master is created for each application partition including the
1234412
123500:06:33,824 --> 00:06:38,723
1236default forest wide and domain wide partitions. So it's possible you may see more than one
1237413
123800:06:38,824 --> 00:06:42,723
1239infrastructure master in your domain depending on if you've created additional app partitions.
1240414
124100:06:42,824 --> 00:06:46,723
1242And that's an extremely advanced topic we'll leave for another day.
1243415
124400:06:46,824 --> 00:06:52,723
1245But these five FSMO roles are those that you should be aware of, probably for the exam
1246416
124700:06:52,824 --> 00:06:57,723
1248but more importantly for the implementation in your own active directory domain and forests.
1249417
125000:06:57,824 --> 00:07:02,723
1251Because by default all five roles will get held by the very first machine to come on line.
1252418
125300:07:02,824 --> 00:07:05,723
1254And so it may become necessary for you to transfer those roles to different machines,
1255419
125600:07:05,824 --> 00:07:10,723
1257should you have an outage event or should you need to just distribute the load.
1258420
125900:07:10,824 --> 00:07:13,723
1260Now my last slide here is one that you used to be an awesome test question because
1261421
126200:07:13,824 --> 00:07:18,723
1263it was one of those really ridiculous if/then statements having to do with the infrastructure master
1264422
126500:07:18,824 --> 00:07:22,723
1266and its positioning. But who knows these days if Microsoft still cares.
1267423
126800:07:22,824 --> 00:07:28,723
1269The infrastructure master was a bit of an odd duck in with the other FSMO roles because of how
1270424
127100:07:28,824 --> 00:07:34,723
1272it needed to be placed. So this is that if/then statement, that again I present to you because
1273425
127400:07:34,824 --> 00:07:39,723
1275it's been just one of those wacky ones in the past and who knows if it's still necessary today.
1276426
127700:07:39,824 --> 00:07:45,723
1278In a single domain forest, so you have a single domain, single forest, the infrastructure master
1279427
128000:07:45,824 --> 00:07:49,723
1281could be placed on any domain controller. This is the case because the infrastructure master
1282428
128300:07:49,824 --> 00:07:53,723
1284in a single domain forest that doesn't have any connections or other domains to deal with,
1285429
128600:07:53,824 --> 00:07:59,723
1287it doesn't have that much to do. However in a multi-domain forest, the infrastructure master
1288430
128900:07:59,824 --> 00:08:03,723
1290is generally placed on a domain controller that is not a global catalog.
1291431
129200:08:03,824 --> 00:08:10,723
1293And in fact, shouldn't be placed on a DC that's not a GC, except in the case where all of the
1294432
129500:08:10,824 --> 00:08:15,723
1296DCs are global catalogs. And in that case, it just doesn't matter.
1297433
129800:08:15,824 --> 00:08:19,723
1299So again, I present this to you because those are the roles and this one is a little bit wacky
1300434
130100:08:19,824 --> 00:08:24,723
1302in comparison with the other ones, but in reality whether or not it's important for the exam
1303435
130400:08:24,824 --> 00:08:27,223
1305this is one thing you might take a look at in your own domain to make sure that you've
1306436
130700:08:27,324 --> 00:00:01,680
1308got your infrastructure master placed in the appropriate location.
1309437
131000:00:01,780 --> 00:00:05,681
1311Alright so with the introduction out of the way, the foundations and the vocabulary,
1312438
131300:00:05,780 --> 00:00:10,681
1314let's get into the click by click and command by command mechanisms that we'll go through
1315439
131600:00:10,781 --> 00:00:14,681
1317to implement our active directory infrastructure. Starting first with this first task
1318440
131900:00:14,781 --> 00:00:19,680
1320titled add and remove a domain controller from a domain. We're back here on our machine DC,
1321441
132200:00:19,780 --> 00:00:25,680
1323this is the same machine that you were working with Jason back in that last course on the DNS and DHCP
1324442
132500:00:25,780 --> 00:00:29,680
1326on network services. And this machine is currently still in a work group, I have it here with the
1327443
132800:00:29,780 --> 00:00:36,680
1329address, 192.168.0.100 and I have also have, as you can see here, DNS services installed onto the machine.
1330444
133100:00:36,780 --> 00:00:38,680
1332So, there may be a little
1333445
133400:00:38,780 --> 00:00:42,680
1335misalignment here between what you see here and what you saw back when you were working with Jason,
1336446
133700:00:42,780 --> 00:00:46,680
1338but at the very least we've got the very basics in place so that we can get an active directory
1339447
134000:00:46,780 --> 00:00:51,680
1341infrastructure up and running. I do want to show you here, under DNS manager, that I have a forward
1342448
134300:00:51,780 --> 00:00:58,680
1344lookup zone created for company.pri and I also have a reverse lookup zone created for the 192.168.0 net.
1345449
134600:00:58,780 --> 00:01:05,681
1347And there's not much here, right, I have my DC and I have my DC2 computer currently in this reverse zone.
1348450
134900:01:05,781 --> 00:01:11,681
1350And then over here on the other side I have DC and DC2 both here in company.pri.
1351451
135200:01:11,781 --> 00:01:16,681
1353So, I include this here in this review of DNS because one of the ways in which you can
1354452
135500:01:16,781 --> 00:01:20,681
1356go through a pretty simple test to see if this machine is ready to be promoted into an
1357453
135800:01:20,781 --> 00:01:26,681
1359active directory domain controller. Is to first verify whether or not you can correctly resolve
1360454
136100:01:26,781 --> 00:01:30,681
1362all the possible ways that this machine may need to be resolved. Now I'm going to show you how we can
1363455
136400:01:30,781 --> 00:01:33,681
1365accomplish that, at least one way we can, and that's to bring up
1366456
136700:01:33,781 --> 00:01:37,681
1368the command prompt here. And what I want to show you that here within the command prompt there
1369457
137000:01:37,781 --> 00:01:42,681
1371is the command nslookup, that you probably dealt with back with Jason was talking about DNS.
1372458
137300:01:42,781 --> 00:01:49,681
1374That you can use for checking DNS records or records for a machine in a DNS database.
1375459
137600:01:49,781 --> 00:01:53,681
1377What I'm going to show you is probably not on the exam, but is my own little cheat
1378460
137900:01:53,781 --> 00:01:58,681
1380to make sure that I've got all the DNS bits in place so that I can resolve appropriately
1381461
138200:01:58,781 --> 00:02:04,681
1383and guarantee myself, or almost guarantee myself, a successful promotion of an active directory domain controller.
1384462
138500:02:04,781 --> 00:02:10,681
1386There are three different tests that I use, the first of which is to just the short name for the machine.
1387463
138800:02:10,781 --> 00:02:16,681
1389Here if I type in nslookup dc you'll see the dc.company.pri indeed resolves down here
1390464
139100:02:16,781 --> 00:02:22,681
1392against the same server, which is this server dc.company.pri. If I have exactly this response
1393465
139400:02:22,781 --> 00:02:28,681
1395meaning a successful response without any problems, then that's a success for the first of the three tests.
1396466
139700:02:28,781 --> 00:02:35,681
1398The second test for me, is to then try to do an ns lookup across the entire fully qualified domain name
1399467
140000:02:35,781 --> 00:02:41,681
1401of the DC I'm about to promote. That would be in this case dc.company.pri.
1402468
140300:02:41,781 --> 00:02:44,681
1404And once again you can see here that we have a completely successful test coming back
1405469
140600:02:44,781 --> 00:02:50,681
1407from our DNS server. In some cases, you may end up where the first of these tests
1408470
140900:02:50,781 --> 00:02:56,681
1410resolves correctly, but the second of these tests does not. And this happens most often when
1411471
141200:02:56,781 --> 00:02:59,681
1413back up here when we were taking a look at
1414472
141500:02:59,781 --> 00:03:03,681
1416server manager. When you went about configuring the computer name for this machine
1417473
141800:03:03,781 --> 00:03:08,681
1419one of the things that you can ignore doing in just about every circumstance, except for the
1420474
142100:03:08,781 --> 00:03:12,681
1422case where you're creating a new active directory domain controller.
1423475
142400:03:12,781 --> 00:03:18,681
1425Is in changing not only the full computer name, but down here under the more tab, making sure that
1426476
142700:03:18,781 --> 00:03:23,681
1428you populate the primary DNS suffix for this computer. Again, most of the time we just ignore
1429477
143000:03:23,781 --> 00:03:26,681
1431this step and don't worry about it when we're making a change to a computer name,
1432478
143300:03:26,781 --> 00:03:32,681
1434but in this case, if I don't end up populating this primary DNS suffix for this computer.
1435479
143600:03:32,781 --> 00:03:34,681
1437I'll end up with this second
1438480
143900:03:34,781 --> 00:03:38,681
1440test here ending up with some kind of error messages as opposed to what I'm seeing.
1441481
144200:03:38,781 --> 00:03:44,681
1443The third test then is to do the reverse lookup, which would be 192.168.0.100.
1444482
144500:03:44,781 --> 00:03:48,681
1446And again I get the same response here. So as I said, this has nothing to do with the exam,
1447483
144800:03:48,781 --> 00:03:52,681
1449but I like to use this as just a little test to make sure that I've done
1450484
145100:03:52,781 --> 00:03:58,681
1452everything correctly to prepare myself for adding a new machine as a possible domain controller.
1453485
145400:03:58,781 --> 00:04:02,681
1455We now have to go through that process of doing that addition, so essentially promoting
1456486
145700:04:02,781 --> 00:04:08,681
1458this machine from a member server into a domain controller. And here in Windows Server 2012 and R2
1459487
146000:04:08,781 --> 00:04:13,681
1461the way in which we accomplish that is now two steps as opposed to just one. Let me come back
1462488
146300:04:13,781 --> 00:04:15,681
1464over here to the dashboard and choose to add
1465489
146600:04:15,781 --> 00:04:20,680
1467roles and features. And it's here where I want to show you the first of the two steps.
1468490
146900:04:20,781 --> 00:04:24,680
1470Back in the old days there was a command called DC promo, which you may still need to know here
1471491
147200:04:24,781 --> 00:04:28,680
1473for this exam, but it has been deprecated in this version of the operating system.
1474492
147500:04:28,781 --> 00:04:32,680
1476In the old days DC promo would complete the installation of the necessary bits and then go
1477493
147800:04:32,781 --> 00:04:37,680
1479through the promotion activity to turn a member server into a domain controller.
1480494
148100:04:37,781 --> 00:04:43,680
1482But these days the activity requires you here in Server 2012 and R2 to first install the
1483495
148400:04:43,781 --> 00:04:50,680
1485ADDS bits, so the role and associated role services that create active directory domain services.
1486496
148700:04:50,781 --> 00:04:55,680
1488If I go through this process and add in all the roles and the role services and necessary features,
1489497
149000:04:55,781 --> 00:05:00,680
1491this will give me everything I need to then in the second step complete the promotion.
1492498
149300:05:00,781 --> 00:05:04,680
1494Now if I choose restart here and yes and then install, that will go through the process
1495499
149600:05:04,781 --> 00:05:09,680
1497of actually installing in the necessary components. Now if I wanted to do this from a command line
1498500
149900:05:09,781 --> 00:05:12,680
1500one of the ways I could do this from the command line is through PowerShell.
1501501
150200:05:12,781 --> 00:05:13,680
1503And if I come up here to run as
1504502
150500:05:13,781 --> 00:05:17,680
1506administrator I can show you just a quick PowerShell command that you've already seen
1507503
150800:05:17,781 --> 00:05:22,680
1509back a couple of courses ago when we were talking about adding and removing roles and role services.
1510504
151100:05:22,781 --> 00:05:29,680
1512The install windows feature command is what I can use against ad-domain-services, that's the role
1513505
151400:05:29,781 --> 00:05:34,680
1515I'm interested in. This command will install the active directory bits onto this machine just
1516506
151700:05:34,781 --> 00:05:39,680
1518like what I've done here in the graphical user interface. There is an additional parameter
1519507
152000:05:39,781 --> 00:05:45,680
1521you may want to use called includemanagementbits or managementtools.
1522508
152300:05:45,781 --> 00:05:49,680
1524That additional parameter will install not only active directory domain services, but all of the
1525509
152600:05:49,781 --> 00:05:54,680
1527other management tools that you would use to manage it. Now we won't run this here because
1528510
152900:05:54,781 --> 00:05:59,680
1530obviously we're already installing the active directory bits onto this machine through the graphical user interface,
1531511
153200:05:59,781 --> 00:06:01,680
1533but we'll keep this open here because I want to show you
1534512
153500:06:01,781 --> 00:06:04,680
1536how you would do the second step of the process both through the graphical user interface
1537513
153800:06:04,781 --> 00:06:09,680
1539as well as through the command line. As you can see back here in the add roles and features wizard
1540514
154100:06:09,781 --> 00:06:13,680
1542we've completed the installation of the bits and now we need to go through the promotion
1543515
154400:06:13,781 --> 00:06:17,680
1545of this server to an active directory domain controller. And it's here where we have a very
1546516
154700:06:17,781 --> 00:06:21,680
1548large number of decisions that we have to make, hopefully you've made these decisions before
1549517
155000:06:21,781 --> 00:06:27,680
1551you get to this point. So one of which is whether or not we're going to be installing a brand new
1552518
155300:06:27,781 --> 00:06:32,680
1554forest, so is this the first domain controller in the first domain in a forest that we're
1555519
155600:06:32,781 --> 00:06:38,680
1557creating brand new from scratch? Or are we adding a new domain to an existing forest?
1558520
155900:06:38,781 --> 00:06:43,680
1560If we're adding a new domain to an existing forest, we are creating another triangle underneath the
1561521
156200:06:43,781 --> 00:06:49,680
1563triangle that we have already created before. Anytime I'm adding a new domain to an existing
1564522
156500:06:49,781 --> 00:06:54,680
1566forest this will be the first DC in that new domain. But in order to establish the connection,
1567523
156800:06:54,781 --> 00:06:59,680
1569the trust between the two, I would need to choose one of the available domain types.
1570524
157100:06:59,781 --> 00:07:05,680
1572That being either a child domain or a tree domain. The biggest difference here is that a tree domain
1573525
157400:07:05,781 --> 00:07:11,680
1575gives you the ability to create a noncontiguous namespace for the domain I'm creating.
1576526
157700:07:11,781 --> 00:07:15,680
1578For example, in a child domain, if I were creating a child domain off of company.pri,
1579527
158000:07:15,781 --> 00:07:20,680
1581the domain name I would be creating would be something.company.pri.
1582528
158300:07:20,781 --> 00:07:25,680
1584Again this is different from a tree domain where I could be really anything that I wanted to.
1585529
158600:07:25,781 --> 00:07:28,680
1587In either case, I'd need to populate the information about what domain name I'm creating down here
1588530
158900:07:28,781 --> 00:07:33,680
1590at the bottom and then obviously provide some credentials down here to perform the action.
1591531
159200:07:33,781 --> 00:07:36,680
1593I do also have a third deployment option up here which is to add a new domain controller
1594532
159500:07:36,781 --> 00:07:42,680
1596to an existing domain, which is of the three the one you'll find yourself doing quite a bit more than the other two.
1597533
159800:07:42,781 --> 00:07:46,680
1599In this case all I need to do is identify which domain I'm interested in and then provide
1600534
160100:07:46,781 --> 00:07:51,680
1602credentials for it down here. We are, however, creating a brand new forest, a brand new forest
1603535
160400:07:51,781 --> 00:07:56,680
1605a brand new domain, and a brand new domain controller. And so, because of that we need to create
1606536
160700:07:56,781 --> 00:08:02,680
1608a new root domain called company.pri. When I do that I'm going to have a variety of different
1609537
161000:08:02,781 --> 00:08:07,680
1611other options and configurations that I need to set for this domain and forest that I'm creating.
1612538
161300:08:07,781 --> 00:08:13,680
1614The first of which is determining what the forest and domain functional level will need to be for the domain.
1615539
161600:08:13,781 --> 00:08:16,680
1617Now you'll notice down here that there are a couple of different options for forest and domain
1618540
161900:08:16,781 --> 00:08:21,680
1620and in fact I think there's a couple for forest here and just a single one here for domain.
1621541
162200:08:21,781 --> 00:08:26,680
1623These functional levels define a set of capabilities that existed at the time that that version
1624542
162500:08:26,781 --> 00:08:33,680
1626of the operating system was released. So back in the year 2008 when Windows Server 2008 was released
1627543
162800:08:33,780 --> 00:08:38,680
1629there were certain types of activities at the forest level that that forest could accomplish.
1630544
163100:08:38,780 --> 00:08:43,680
1632Microsoft then later wrote additional functionality and added it into the operating system
1633545
163400:08:43,780 --> 00:08:49,680
1635with the release of server 2008 R2, and again in 2012 and again in 2012 R2.
1636546
163700:08:49,780 --> 00:08:53,680
1638In most cases, when you're creating a brand new domain and a brand new forest,
1639547
164000:08:53,780 --> 00:08:57,680
1641you'll want to create that forest and domain with the highest functional level available.
1642548
164300:08:57,780 --> 00:09:01,680
1644But occasionally if you have applications that you know will not function with that forest
1645549
164600:09:01,780 --> 00:09:06,680
1647or domain functional level, well you may need to set it down to one level below.
1648550
164900:09:06,780 --> 00:09:10,680
1650More often than not, in the vast majority of cases the highest functional level is indeed the
1651551
165200:09:10,780 --> 00:09:14,680
1653one that you're looking for. Now when you're also creating a new domain controller you have some
1654552
165500:09:14,780 --> 00:09:18,680
1656additional capabilities that you can apply on the domain controller itself.
1657553
165800:09:18,780 --> 00:09:22,680
1659The first of which is whether or not that machine should be a DNS server or not.
1660554
166100:09:22,780 --> 00:09:27,680
1662And whether or not that machine should be a global catalog. Because this is the first domain controller
1663555
166400:09:27,780 --> 00:09:32,680
1665in the domain and the forest, we already have this selection here selected for us for global catalog.
1666556
166700:09:32,780 --> 00:09:37,680
1668We have to have it as a GC. And because we've already installed DNS onto this machine the checkbox here
1669557
167000:09:37,780 --> 00:09:44,680
1671is grayed out as well. It is possible to have the ADDS configuration wizard install DNS server onto
1672558
167300:09:44,780 --> 00:09:52,680
1674this machine as part of the wizard. However, personally I've never seen it function very well.
1675559
167600:09:52,780 --> 00:09:55,680
1677I've always had better luck with getting the DNS server bits installed
1678560
167900:09:55,780 --> 00:10:00,680
1680prior to beginning the ADDS configuration wizard. So it's my recommendation to always start
1681561
168200:10:00,780 --> 00:10:04,680
1683with installing DNS first before you get this far. Down here at the bottom we have what's called
1684562
168500:10:04,780 --> 00:10:11,680
1686the directory services restore mode password, which is a special password that you will enter once
1687563
168800:10:11,780 --> 00:10:15,680
1689and then never need to enter again, except in the situation where you need to perform an
1690564
169100:10:15,780 --> 00:10:21,680
1692authoritative restore of the active directory database. Now this authoritative restore is a bit of
1693565
169400:10:21,780 --> 00:10:26,680
1695a painful activity and because of that there are a lot of tools these days, third-party tools
1696566
169700:10:26,780 --> 00:10:29,680
1698that you can use and even some first party tools with the active directory recycle bin.
1699567
170000:10:29,780 --> 00:10:34,680
1701That ease the process of recovering data out of the active directory database.
1702568
170300:10:34,780 --> 00:10:39,680
1704So recognize that when you set this DSRN password you need to put it in a safe place because until
1705569
170600:10:39,780 --> 00:10:43,680
1707you change it yourself, this password will never be changed again.
1708570
170900:10:43,780 --> 00:10:48,680
1710All too often we find people that have created DSRN passwords with the creation of their domain
1711571
171200:10:48,780 --> 00:10:54,680
1713and forest and that information gets lost until years, many years down the road when an
1714572
171500:10:54,780 --> 00:10:58,680
1716authoritative restore is required. And the last thing that you want is to try to find a
1717573
171800:10:58,780 --> 00:11:02,680
1719DSRN password when you don't have a functioning domain or functioning forest.
1720574
172100:11:02,780 --> 00:11:07,680
1722So pay careful attention to this and probably put it in a safe place somewhere because you
1723575
172400:11:07,780 --> 00:11:10,680
1725may need it at some point in the future. Down here next is
1726576
172700:11:10,780 --> 00:11:15,680
1728where we can specify any DNS delegation options, these will allow us to create the appropriate
1729577
173000:11:15,780 --> 00:11:21,680
1731DNS delegation so that we have the folder structure in DNS to support the SRV records that we'll require.
1732578
173300:11:21,780 --> 00:11:26,680
1734When we do that we can punch in the administrator user name here and the password
1735579
173600:11:26,780 --> 00:11:30,680
1737to create the correct credentials for creating that DNS delegation.
1738580
173900:11:30,780 --> 00:11:34,680
1740Down here under next is where it's going to verify the net bios name that's going to be assigned
1741581
174200:11:34,780 --> 00:11:40,680
1743to the domain. The net bios domain name will be, in most cases, the first set of characters
1744582
174500:11:40,780 --> 00:11:44,680
1746before the first dot, in whatever fully qualified domain name that you create.
1747583
174800:11:44,780 --> 00:11:49,680
1749In our case it was company.pri and so company, all the characters up to that first dot,
1750584
175100:11:49,780 --> 00:11:53,680
1752is what makes that net bios domain name. There are some cases where it will not be those
1753585
175400:11:53,780 --> 00:11:58,680
1755first characters, the net bios domain needs to be, I believe, 15 characters or less.
1756586
175700:11:58,780 --> 00:12:02,680
1758So you might want to take care to ensure that any of the names in your fully qualified domain names
1759587
176000:12:02,780 --> 00:12:08,680
1761for those that you're creating stay under that 15 character limit. If I choose next again
1762588
176300:12:08,780 --> 00:12:14,680
1764I could define what the paths will be for the different components of active directory that are to be installed.
1765589
176600:12:14,780 --> 00:12:19,680
1767The database folder, the log files folder, as well as the SIS file folder here could be determined.
1768590
176900:12:19,780 --> 00:12:23,680
1770Now in a production world you may want to move these off onto a different disc drive,
1771591
177200:12:23,780 --> 00:12:27,680
1773just so that you have them separated out from the operating system.
1774592
177500:12:27,780 --> 00:12:30,680
1776I'll leave them here as C because I only have a single disc drive on this machine,
1777593
177800:12:30,780 --> 00:12:35,680
1779but again in a production world it can be a good idea to move those off onto separate spindles
1780594
178100:12:35,780 --> 00:12:40,680
1782if anything to make the process of recovering this machine a little bit easier.
1783595
178400:12:40,780 --> 00:12:43,680
1785I'll choose Next so that we can go through the review of the options here and I want to
1786596
178700:12:43,780 --> 00:12:47,680
1788direct your attention, down here at the bottom right, this little item called
1789597
179000:12:47,780 --> 00:12:54,680
1791view scripts. This view script item down here is what gives you the abilities to
1792598
179300:12:54,780 --> 00:13:00,680
1794reproduce everything that we've talked about in this wizard, except using the PowerShell tool
1795599
179600:13:00,780 --> 00:13:04,680
1797to do this from the command line. Notice the script that gets created is a .tmp file,
1798600
179900:13:04,780 --> 00:13:08,680
1800which if you end up needing to save this you'd have to put it in the correct format so that the
1801601
180200:13:08,780 --> 00:13:12,680
1803script can be executed by PowerShell. But recognize that what we're doing here is running
1804602
180500:13:12,780 --> 00:13:18,680
1806the import module ADDS deployment command here and then we're running the install ADDS forest command
1807603
180800:13:18,780 --> 00:13:23,680
1809with this long list of parameters that effectively answer all the questions that we've run
1810604
181100:13:23,780 --> 00:13:28,680
1812through here in the wizard. I'm showing you this at this point because it is exactly this piece
1813605
181400:13:28,780 --> 00:13:33,680
1815of code here that would allow you to reproduce this process using the command line
1816606
181700:13:33,780 --> 00:13:39,680
1818if I were to do so here in Windows PowerShell. So this would give you the abilities to
1819607
182000:13:39,780 --> 00:13:44,680
1821stream line the process, to automate the process, to just know how this works using Windows PowerShell. I would
1822608
182300:13:44,780 --> 00:13:50,680
1824know how this is and know that essentially running through this, perhaps even just running through it
1825609
182600:13:50,780 --> 00:13:54,680
1827and pretending to answer all the questions in the way that you would, would give you a really
1828610
182900:13:54,780 --> 00:13:59,680
1830nice piece of code here that you could just punch into the command line to get this machine brought online.
1831611
183200:13:59,780 --> 00:14:04,680
1833This is particularly helpful, not so much when you're creating your first domain controller,
1834612
183500:14:04,780 --> 00:14:07,680
1836but when you're going about creating all those additional domain controllers.
1837613
183800:14:07,780 --> 00:14:12,680
1839Those DCs that will come online after the first DC and the domain are created.
1840614
184100:14:12,780 --> 00:14:15,680
1842It is the creation of those additional domain controllers and the PowerShell commands that are
1843615
184400:14:15,780 --> 00:14:21,680
1845used in creating them, that you can then copy and paste and just adjust in some of the information in here
1846616
184700:14:21,780 --> 00:14:26,680
1848to rapidly deploy those additional domain controllers as you see fit. For our purposes here
1849617
185000:14:26,780 --> 00:14:31,680
1851let's go through and hit the Next button and then allow our prerequisites check to complete.
1852618
185300:14:31,780 --> 00:14:36,680
1854So that we can go about the installation of active directory domain services onto this machine DC.
1855619
185600:14:36,780 --> 00:14:40,680
1857Looks like all of our prerequisite checks completed successfully, so I'll click the install button
1858620
185900:14:40,780 --> 00:14:43,680
1860to begin the installation of active directory.
1861621
186200:14:43,780 --> 00:14:46,680
1863And then finally thanks to the magic of video editing, I can accelerate us to the completion
1864622
186500:14:46,780 --> 00:14:52,180
1866of this installation process. As you can see here after the reboot, we have a machine DC that
1867623
186800:14:52,280 --> 00:14:56,680
1869is currently in the company.pri domain and if I come up here under Tools we have the usual
1870624
187100:14:56,780 --> 00:15:01,680
1872active directory tools that have been installed. So here under active directory users and computers we
1873625
187400:15:01,780 --> 00:00:01,649
1875can see that we indeed now have this domain company.pri.
1876626
187700:00:01,750 --> 00:00:03,258
1878Well, we have one final thing we have to talk about
1879627
188000:00:03,358 --> 00:00:07,759
1881and that is the removal of active directory and removal of domain controllers
1882628
188300:00:07,858 --> 00:00:14,259
1884from an existing domain. It is always a good idea to remove domain controllers using the official
1885629
188600:00:14,358 --> 00:00:18,759
1887procedure as opposed to just ripping them out of the domain. Anytime you go about ripping domain controllers
1888630
188900:00:18,859 --> 00:00:21,759
1890out of a domain without removing the roles and features from
1891631
189200:00:21,859 --> 00:00:25,759
1893those machines, you're going to end up with lingering objects inside of your active directory database,
1894632
189500:00:25,859 --> 00:00:30,759
1896that could cause problems down the road. So as you can see here, I brought up the roles and the remove
1897633
189800:00:30,859 --> 00:00:37,759
1899roles and features wizard here. If I choose Next and then focus it on dc.company.pri,
1900634
190100:00:37,859 --> 00:00:41,759
1902I can choose to unselect active directory domain services. Now there's two things you have to know,
1903635
190400:00:41,859 --> 00:00:45,759
1905the first of which is sort of obvious, and that is that you can't remove a domain until
1906636
190700:00:45,859 --> 00:00:49,759
1908all the domain controllers have been completely removed from that domain.
1909637
191000:00:49,859 --> 00:00:53,759
1911The second of which is that you can't actually remove active directory domain services
1912638
191300:00:53,859 --> 00:00:58,759
1914until you go about demoting the domain controller itself. This demotion
1915639
191600:00:58,859 --> 00:01:05,759
1917process goes through removing all those records out of active directory in the database itself and so on.
1918640
191900:01:05,858 --> 00:01:11,759
1920And ensuring that you end up with a clean domain after this domain controller gets removed.
1921641
192200:01:11,858 --> 00:01:15,759
1923Now occasionally you may end up in the situation where you have a domain controller that for one
1924642
192500:01:15,858 --> 00:01:19,759
1926reason or another cannot be cleanly removed from active directory and when
1927643
192800:01:19,858 --> 00:01:24,759
1929that's the case you may need to go through forcing the removal of the domain controller.
1930644
193100:01:24,858 --> 00:01:27,759
1932And so when that happens there is a whole variety of extra tasks you'll have to go through
1933645
193400:01:27,858 --> 00:01:31,759
1935that are out of scope for our discussion here, but again just recognize that the clean
1936646
193700:01:31,858 --> 00:01:37,759
1938removal is your desired state anytime you're getting rid of these DCs out of an active directory.
1939647
194000:01:37,858 --> 00:01:41,759
1941And then lastly down here is removing this as the last domain controller in the domain.
1942648
194300:01:41,858 --> 00:01:46,759
1944Anytime you're doing that this essentially decommissioned the domain and takes it out of existence.
1945649
194600:01:46,858 --> 00:01:50,759
1947They'll have some warnings here, some removal options, and even a new administrator password,
1948650
194900:01:50,858 --> 00:01:53,759
1950a local password you'll have to configure, but essentially this is the process you'll need
1951651
195200:01:53,858 --> 00:01:58,759
1953to go through to get rid of active directory off of a specific machine.
1954652
195500:01:58,858 --> 00:02:00,759
1956And then finally, just for completeness, I want to show you over here in PowerShell that there
1957653
195800:02:00,858 --> 00:02:05,759
1959is a PowerShell commandlet you should be aware of too that can accomplish the same thing.
1960654
196100:02:05,858 --> 00:02:10,759
1962It is Uninstall-ADDSDomainController. Just like all the PowerShell
1963655
196400:02:10,859 --> 00:02:14,759
1965commands there's a long list of just different parameters that will do more or less the
1966656
196700:02:14,859 --> 00:02:18,759
1968same things that we saw back in the graphical user interface. But this is the mechanism from
1969657
197000:02:18,859 --> 00:02:23,759
1971PowerShell that you would go about removing ADDS or removing this domain controller from the domain
1972658
197300:02:23,859 --> 00:02:27,759
1974and then you would want to go through the remove windows feature commandlet to go about getting rid
1975659
197600:02:27,859 --> 00:00:01,715
1977of the bits off of this machine as well.
1978660
197900:00:01,816 --> 00:00:06,216
1980Now our next topic comes in handy in those rare use cases where you have a machine that you need
1981661
198200:00:06,315 --> 00:00:12,716
1983to build in a location that is perhaps far removed from the rest of your domain because of some latent
1984662
198500:00:12,816 --> 00:00:16,715
1986network condition and you've got a slow connection. Maybe you've got a very full connection
1987663
198800:00:16,815 --> 00:00:20,715
1989that you can't get traffic across within any reasonable amount of time.
1990664
199100:00:20,815 --> 00:00:26,715
1992Now when that's the case it is entirely possible to build a domain controller in that remote location
1993665
199400:00:26,815 --> 00:00:31,715
1995and use now the US Postal Service or whatever your local postal service is in order to transfer
1996666
199700:00:31,815 --> 00:00:35,716
1998the contents of the active directory database perhaps on a flash drive.
1999667
200000:00:35,816 --> 00:00:40,716
2001Because sending it through the mail is faster than sending it through whatever network you have.
2002668
200300:00:40,816 --> 00:00:47,716
2004This is called an install from media installation. And the process to do so starts by creating
2005669
200600:00:47,816 --> 00:00:54,716
2007what is essentially a little mini snapshot of your active directory database on an existing domain controller.
2008670
200900:00:54,816 --> 00:00:55,716
2010Let's go ahead here and
2011671
201200:00:55,816 --> 00:01:00,716
2013bring up an elevated command prompt here that runs as administrator.
2014672
201500:01:00,816 --> 00:01:04,716
2016Because I want to show you the process that you would need to go through to create that initial snapshot.
2017673
201800:01:04,816 --> 00:01:09,716
2019This snapshot will obviously be a little bit behind from the everyday changes in your active directory
2020674
202100:01:09,816 --> 00:01:15,716
2022infrastructure, but will be a great starting point to allow that remote domain controller
2023675
202400:01:15,816 --> 00:01:19,716
2025to at least get the large quantity of your active directory up and operational.
2026676
202700:01:19,816 --> 00:01:22,716
2028So that it only needs to replicate those things that have changed.
2029677
203000:01:22,816 --> 00:01:28,716
2031The way in which we create the snapshot starts by launching the ntdsutil command,
2032678
203300:01:28,816 --> 00:01:36,716
2034which is the or the ntdsutil command, which is the kind of the Swiss army knife for your active directory database.
2035679
203600:01:36,816 --> 00:01:38,716
2037ntdsutil has a large number of commands
2038680
203900:01:38,816 --> 00:01:41,716
2040that you could potentially use here, many of which you'll talk about as you go through the rest of
2041681
204200:01:41,816 --> 00:01:48,716
2043your exploration of the MCSA and MCSE. But the command we're looking for here has to do with
2044682
204500:01:48,816 --> 00:01:55,716
2046creating an IFM instance. Let's start by focusing ntdsutil on the current copy of the active directory
2047683
204800:01:55,816 --> 00:02:03,716
2049database that we're using in production. I will do that with activate instance ntds.
2050684
205100:02:03,816 --> 00:02:08,716
2052That currently focuses us then on the running copy of active directory as opposed to any lightweight directory
2053685
205400:02:08,816 --> 00:02:13,716
2055partitions that might be out there. Once we're done with that we need to type in ifm to get
2056686
205700:02:13,816 --> 00:02:16,716
2058us to the installation from media sub menu. Now this
2059687
206000:02:16,816 --> 00:02:21,716
2061sub menu comes with a variety of different tasks that we could do, the tool that we're interested in here
2062688
206300:02:21,816 --> 00:02:27,716
2064because we need all of these bits to create a new domain controller, would be create full
2065689
206600:02:27,816 --> 00:02:33,716
2067and then a location where we want to store that ifm media. Also available here is the abilities to
2068690
206900:02:33,816 --> 00:02:38,716
2070create an RODC, if I'm creating a read-only domain controller. Or just an output of the
2071691
207200:02:38,816 --> 00:02:45,716
2073sysvol content as well. Let me go ahead and create this full here in c:\users\gshields\desktop
2074692
207500:02:45,816 --> 00:02:52,716
2076and then we'll call this ifm. That creates a snapshot and this process takes just a second or two
2077693
207800:02:52,816 --> 00:02:57,716
2079the larger your database is the longer it will take for it to create that snapshot.
2080694
208100:02:57,816 --> 00:02:58,716
2082And then once we're done we can take a look
2083695
208400:02:58,816 --> 00:03:03,716
2085at the file that we just created, which should be, actually not here apparently, it should be found
2086696
208700:03:03,816 --> 00:03:10,716
2088in C:, Users, and then gshields, and then desktop. There's our ifm folder.
2089697
209000:03:10,816 --> 00:03:15,716
2091In the ifm folder is a copy of the active directory and the registry entries that are important
2092698
209300:03:15,816 --> 00:03:21,716
2094and there is our ntds.dit file. If you've ever wondered where the active directory database exists
2095699
209600:03:21,816 --> 00:03:27,716
2097it actually exists in this file called ntds.dit, that's the database itself.
2098700
209900:03:27,816 --> 00:03:31,716
2100Also here is some registry values that we would need in order to get that other controller
2101701
210200:03:31,816 --> 00:03:34,716
2103that other domain controller configured in the way we need to.
2104702
210500:03:34,816 --> 00:03:39,716
2106Once I have that folder, I can take that folder and drop it onto a USB thumb drive,
2107703
210800:03:39,816 --> 00:03:44,716
2109stick in the mail, receive it at my remote location, and then once I'm at my remote location if I
2110704
211100:03:44,816 --> 00:03:50,716
2112flip over here to an example machine. I can then from that remote location use the information on
2113705
211400:03:50,816 --> 00:03:56,716
2115that thumb drive to go about completing the process of creating a new domain controller.
2116706
211700:03:56,816 --> 00:04:01,716
2118Now I've got here our server file1.company.pri and I'm not going to go through installing active directory
2119707
212000:04:01,816 --> 00:04:06,716
2121onto this machine because we have need for it later on. But I have gone as far as just to get the
2122708
212300:04:06,816 --> 00:04:11,716
2124bits installed so that we can go about attempting to promote this server to a domain controller.
2125709
212600:04:11,816 --> 00:04:14,716
2127Now in this case, again we're not going to go through all the steps here, but I want to show you
2128710
212900:04:14,816 --> 00:04:19,715
2130that when it comes time to add a new domain controller to an existing domain and I provide in
2131711
213200:04:19,815 --> 00:04:24,715
2133all the correct information, the domain and the credentials, and choose next down here.
2134712
213500:04:24,815 --> 00:04:28,715
2136This is the process I would go through in order to create a new domain controller using
2137713
213800:04:28,815 --> 00:04:34,715
2139this ifm media. I will here, just as before, punch in a DSRN password, I'm going to leave it in the
2140714
214100:04:34,815 --> 00:04:40,715
2142existing site, although arguably if I was in a remote site I would need to punch in the remote site name here.
2143715
214400:04:40,815 --> 00:04:45,715
2145Down here under next I would choose DNS options if I needed to, but down here under additional options
2146716
214700:04:45,815 --> 00:04:49,715
2148is where I could go about choosing to install from media. And it's this location where
2149717
215000:04:49,815 --> 00:04:53,715
2151I'd go about pointing it to that appropriate media on that thumb drive to gather and install
2152718
215300:04:53,815 --> 00:04:59,715
2154the snapshot of the active directory database. Now once the snapshot is installed,
2155719
215600:04:59,815 --> 00:05:04,715
2157obviously that's a snapshot from a particular period of time, and so the domain controller that
2158720
215900:05:04,815 --> 00:05:08,715
2160I'm creating is going to need to gather anything that's changed from the time that that snapshot
2161721
216200:05:08,815 --> 00:05:14,715
2163was taken up until this moment in time. In order to get those changes you'll want to point
2164722
216500:05:14,815 --> 00:05:19,715
2166it towards probably the closest domain controller to the DC that you're creating.
2167723
216800:05:19,815 --> 00:05:23,715
2169Now normally it's shows here any domain controller, because in a well-connected environment
2170724
217100:05:23,815 --> 00:05:27,715
2172it doesn't really matter which domain controller you grab that information from.
2173725
217400:05:27,815 --> 00:05:31,715
2175But when I'm dealing with a very slow network connection, I want to come down here and make sure
2176726
217700:05:31,815 --> 00:05:35,715
2178that I do any replication from that machine that is geographically or at least on the network
2179727
218000:05:35,815 --> 00:05:39,915
2181placed the closest to this machine. Once I'm done with that I can go through all the steps that
2182728
218300:05:40,016 --> 00:00:01,924
2184exist here in the wizard and add this as an additional domain controller.
2185729
218600:00:02,024 --> 00:00:05,925
2187Now why we don't actually want to install active directory domain services onto our file server,
2188730
218900:00:06,025 --> 00:00:11,925
2190we do want to get it onto our second DC, number DC2 right here. For us to do that, remember this is
2191731
219200:00:12,025 --> 00:00:17,924
2193a server core machine, we've got that two-step process to get to ADDS first installed onto the machine
2194732
219500:00:18,024 --> 00:00:22,924
2196and then to actually execute the promotion. The first step in the process is our old friend
2197733
219800:00:23,024 --> 00:00:27,924
2199install windows feature, which I need to use PowerShell in order to do that.
2200734
220100:00:28,024 --> 00:00:34,924
2202Install-WindowsFeature with the name of the feature we're interested in being ad-domain-services.
2203735
220400:00:35,024 --> 00:00:40,924
2205If we go through this, this will install the ADDS domain bits onto this machine just like we did before.
2206736
220700:00:41,024 --> 00:00:46,924
2208And then our next step is to use another command, which is install-ADDSDomainController.
2209737
221000:00:47,024 --> 00:00:54,924
2211This command will allow us to connect up this domain controller to our domain, DomainName company.pri.
2212738
221300:00:55,024 --> 00:00:58,924
2214Now one curious thing about this that the process which we're going through this, remember that
2215739
221600:00:59,024 --> 00:01:04,925
2217this machine, DC2, is currently not in the domain. And so for us to be able to facilitate
2218740
221900:01:05,025 --> 00:01:07,925
2220the installation of this as a domain controller and then to add it into the domain,
2221741
222200:01:08,025 --> 00:01:12,925
2223we're going to have to go through a little extra step here involving some credentials
2224742
222500:01:13,025 --> 00:01:18,925
2226that we will apply for the domain we're about to enter into. That process uses the credential,
2227743
222800:01:19,025 --> 00:01:25,925
2229credential parameter, and then we need to pipe in an actual credential, the usable credential here
2230744
223100:01:26,025 --> 00:01:29,925
2232in at the command line. Which we'll do by having PowerShell first resolve the results of
2233745
223400:01:30,025 --> 00:01:34,925
2235a command get credential. This command, get credential, will allow me to get the credential for
2236746
223700:01:35,025 --> 00:01:39,925
2238the company administrator account, if I can type it correctly, so that we can use that information
2239747
224000:01:40,025 --> 00:01:44,925
2241in order to add this machine here into the domain. I'll go ahead and hit the OK button here
2242748
224300:01:45,025 --> 00:01:49,925
2244and then punch in my credential, that's my password there. And as well as the safe mode administrator
2245749
224600:01:50,025 --> 00:01:54,925
2247password, which is our directory services restore mode password we entered in earlier on
2248750
224900:01:55,025 --> 00:01:58,925
2250when we were working with the GUI. I'll punch that in twice to ensure I've got it
2251751
225200:01:59,025 --> 00:02:03,925
2253correctly and choose A to go about configuring this as a domain controller.
2254752
225500:02:04,025 --> 00:02:08,425
2256If everything goes well, as you can see here, we will go about adding this machine as a second domain
2257753
225800:02:08,525 --> 00:00:01,617
2259controller here within our domain.
2260754
226100:00:01,717 --> 00:00:05,618
2262Now building new domain controllers can be a fun activity, until well you've probably done it
2263755
226400:00:05,717 --> 00:00:09,618
2265your 25th or 35th time, but actually upgrading domain controller.
2266756
226700:00:09,717 --> 00:00:13,618
2268And more specifically upgrading domains becomes much more of a project.
2269757
227000:00:13,717 --> 00:00:16,617
2271Remember talking about upgrading domain controllers and upgrading domains
2272758
227300:00:16,717 --> 00:00:21,617
2274we think of this as a project because the move from one operating system to another
2275759
227600:00:21,717 --> 00:00:26,617
2277does more than just change the OS that exists on that domain controller itself.
2278760
227900:00:26,717 --> 00:00:30,617
2280With each new version of the operating system come new features that are baked into active directory
2281761
228200:00:30,717 --> 00:00:35,618
2283as well as a slightly different active directory database itself that's going to require
2284762
228500:00:35,718 --> 00:00:39,618
2286some updating as well. And so the process, not only to upgrade a domain controller,
2287763
228800:00:39,718 --> 00:00:45,618
2289but really a domain or even a forest, typically happens in five different steps.
2290764
229100:00:45,718 --> 00:00:51,618
2292This goes just a little bit further than what I think is going to be required for the exam itself,
2293765
229400:00:51,718 --> 00:00:54,618
2295but I think it's valid for you to understand what these five steps are.
2296766
229700:00:54,718 --> 00:00:58,618
2298Because it's likely that you may be taking this exam to prepare yourself for upgrading your skills
2299767
230000:00:58,718 --> 00:01:03,618
2301and your domain to a newer version of the operating system. The first step in the process
2302768
230300:01:03,718 --> 00:01:08,618
2304is obviously just to get healthy. Making sure that you have a healthy active directory with great
2305769
230600:01:08,718 --> 00:01:14,618
2307replication between machines and no major error messages in any of your domain controller logs
2308770
230900:01:14,718 --> 00:01:19,618
2310is always the best step towards making sure that the garbage you get out is at least as good
2311771
231200:01:19,718 --> 00:01:24,618
2313as the garbage that you had going in. And the 412 content, when we start getting into that exam
2314772
231500:01:24,718 --> 00:01:28,618
2316I'll talk more about some of the tools you can use to make sure that your domain is healthy
2317773
231800:01:28,718 --> 00:01:33,618
2319before you make that jump, but for now just keep it in the back of your mind that there are tools
2320774
232100:01:33,718 --> 00:01:37,618
2322and there are different kinds of command line ways in which you can test and verify whether
2323775
232400:01:37,718 --> 00:01:41,618
2325or not the replication is working and whether or not your active directory database is going
2326776
232700:01:41,718 --> 00:01:46,618
2328to survive that upgrade to the new operating system. And the second step in upgrading a domain
2329777
233000:01:46,718 --> 00:01:51,618
2331controller or a domain has to do with extending the schema. Now as I said, each different version
2332778
233300:01:51,718 --> 00:01:56,618
2334of the operating system tends to come with a slightly different active directory database.
2335779
233600:01:56,718 --> 00:02:01,618
2337This does not have to do with the data in the database, but the structure of the database.
2338780
233900:02:01,718 --> 00:02:06,618
2340And so one process you'll need to go through is to actually extend the schema for your forest
2341781
234200:02:06,718 --> 00:02:12,617
2343before you begin ever adding any of the new domain controllers of that newer version into
2344782
234500:02:12,717 --> 00:02:16,617
2346your active directory infrastructure. Now that command that we're looking for in order to
2347783
234800:02:16,717 --> 00:02:22,617
2349extend the schema, is called AD prep. And the AD prep command is one that's best found
2350784
235100:02:22,717 --> 00:02:23,617
2352on the installation media for Windows
2353785
235400:02:23,717 --> 00:02:30,617
2355Server 2012 R2. Let me come back here to our machine DC and I've brought up a command prompt here
2356786
235700:02:30,717 --> 00:02:36,617
2358an elevated command prompt so that we can take a look at the contents of the attached DVD media.
2359787
236000:02:36,717 --> 00:02:37,617
2361Here if I'm on the D drive
2362788
236300:02:37,717 --> 00:02:41,617
2364if I take a look there's all the stuff that exists on that Windows 2012 R2 DVD media
2365789
236600:02:41,717 --> 00:02:49,617
2367and if I go into the support adprep folder, it's in this folder we'll find
2368790
236900:02:49,717 --> 00:02:56,617
2370the adprep command, right up here at the very top. This adprep.exe command is what goes
2371791
237200:02:56,717 --> 00:03:02,617
2373through the process of extending the schema of making changes to the active directory database
2374792
237500:03:02,717 --> 00:03:04,617
2376to prepare it for all the these new features and functions that come with this
2377793
237800:03:04,717 --> 00:03:10,617
2379new version of the operating system. Now adprep actually executes a long list of what are these
2380794
238100:03:10,717 --> 00:03:17,617
2382ldf files that you can see here. All the way here from 10 or so down to looks like 69 or so.
2383795
238400:03:17,717 --> 00:03:20,617
2385And what's curious about these ldf files is that they're actually human readable.
2386796
238700:03:20,717 --> 00:03:26,617
2388If I go here to the D drive and open it up, and then go to a support and then adprep,
2389797
239000:03:26,717 --> 00:03:31,617
2391I can take a look at any of these ldf files to see, more or less what they look like.
2392798
239300:03:31,717 --> 00:03:36,617
2394Here under notepad you can see that they correspond with the exact text based changes that are
2395799
239600:03:36,717 --> 00:03:40,617
2397going to happen here to the active directory database. And without going into detail as to
2398800
239900:03:40,717 --> 00:03:45,617
2400what it is that we're looking at, just recognize that these are the instructions that the
2401801
240200:03:45,717 --> 00:03:50,617
2403schema extension uses in order to make those changes from old version to new.
2404802
240500:03:50,717 --> 00:03:54,617
2406Now there are actually a couple of different parameters that are associated with adprep
2407803
240800:03:54,717 --> 00:03:57,617
2409that I would at least be aware of. So let me clear the screen here
2410804
241100:03:57,717 --> 00:04:01,617
2412and show you that I would the /?
2413805
241400:04:01,717 --> 00:04:09,617
2415there are, right up here, the forest prep, domain prep, and RODC prep parameters that are of most importance here.
2416806
241700:04:09,717 --> 00:04:14,617
2418There's also a GP prep which you can do that consolidates here with the domain prep.
2419807
242000:04:14,717 --> 00:04:19,617
2421The forest prep command typically happens first and it is a schema extension that deals with
2422808
242300:04:19,718 --> 00:04:27,617
2424forest wide information. The domain prep then needs to happen once in each domain of that forest.
2425809
242600:04:27,718 --> 00:04:31,617
2427You run that and it goes through all the domain wide changes for the different domains that exist
2428810
242900:04:31,718 --> 00:04:37,617
2430in that forest. And then lastly down here, you can choose RODC prep optionally if you plan on
2431811
243200:04:37,718 --> 00:04:43,617
2433installing any RODCs into this forest. These are read-only domain controllers that are used
2434812
243500:04:43,718 --> 00:04:48,617
2436for special circumstances. If you don't have any then you don't have to run this third parameter down here.
2437813
243800:04:48,718 --> 00:04:50,617
2439So these commands here are what are used in order to
2440814
244100:04:50,718 --> 00:04:56,617
2442execute all the schema extensions that are necessary to allow you then to go about upgrading your domain
2443815
244400:04:56,718 --> 00:05:04,617
2445controllers to the new operating system. So you can't start upgrading your DCs until you get your schema extended.
2446816
244700:05:04,718 --> 00:05:08,617
2448You'll then need to go through the process of upgrading all the domain controllers,
2449817
245000:05:08,718 --> 00:05:13,617
2451every single domain controller in the forest and/or domain. Occasionally it migrating around
2452818
245300:05:13,718 --> 00:05:18,617
2454your FSMO roles to ensure that they're always on line. Before you actually get to the final step
2455819
245600:05:18,718 --> 00:05:24,617
2457in the process, which is to go about then taking advantage of all the new features that you get
2458820
245900:05:24,718 --> 00:05:28,617
2460by upgrading your domain or forest functional level to the new version.
2461821
246200:05:28,718 --> 00:05:33,617
2463Now the reason why I call this a project is because you don't actually get any of the benefits
2464822
246500:05:33,718 --> 00:05:37,617
2466of the new domain and forest functional level until you've gone through every step in this process.
2467823
246800:05:37,718 --> 00:05:42,617
2469Including upgrading the operating system of every single domain controller.
2470824
247100:05:42,718 --> 00:05:45,617
2472Now this last step here, raising the domain and forest functional level, is something that you'll find
2473825
247400:05:45,718 --> 00:05:49,617
2475here in the graphical user interface. If I go up here under Tools and take a look at
2476826
247700:05:49,718 --> 00:05:52,617
2478active directory domains and trusts.
2479827
248000:05:52,718 --> 00:05:53,617
2481Out of all the different tools that are
2482828
248300:05:53,718 --> 00:05:57,617
2484associated with active directory, users and computers, sites and services, it's actually
2485829
248600:05:57,718 --> 00:06:02,617
2487domains and trusts that you find yourself inside the least. But it is here where, if I take a look
2488830
248900:06:02,718 --> 00:06:07,617
2490at domains and trusts I can take a look at raising number one, the forest functional level,
2491831
249200:06:07,718 --> 00:06:12,617
2493from one version to another. Now I'm already at the most recent version of the forest functional level,
2494832
249500:06:12,718 --> 00:06:17,617
2496which is server 2012 R2, so there are no options here for me to make any changes.
2497833
249800:06:17,718 --> 00:06:21,617
2499However if I were not and I'd already gone through the adprep activities, well then I'd
2500834
250100:06:21,718 --> 00:06:25,617
2502see this as an option for me to raise that forest functional level.
2503835
250400:06:25,718 --> 00:06:26,617
2505I can do the same thing over here
2506836
250700:06:26,718 --> 00:06:30,617
2508with each individual domain in the forest by clicking here and choosing to raise the domain
2509837
251000:06:30,718 --> 00:06:34,617
2511functional level as well. Most important thing you have to know with this is that the
2512838
251300:06:34,718 --> 00:06:39,617
2514raising of a domain or forest functional level is a one directional activity,
2515839
251600:06:39,718 --> 00:06:43,117
2517you can only go in one direction, you can never go back. But the good news is that once you've
2518840
251900:06:43,218 --> 00:06:47,117
2520done it, you can now begin to take advantage of the new features that you get in active directory
2521841
252200:06:47,218 --> 00:00:01,869
2523out of this new operating system version.
2524842
252500:00:01,969 --> 00:00:05,870
2526Now Jason worked with you back on that course on, among other things, the DNS server,
2527843
252800:00:05,969 --> 00:00:09,970
2529getting DNS services up and operational in an active directory domain.
2530844
253100:00:10,070 --> 00:00:13,370
2532And as I said also here in this course, in order to get active directory running,
2533845
253400:00:13,470 --> 00:00:18,369
2535active directory requires DNS services to be there. This is in part because the installation
2536846
253700:00:18,469 --> 00:00:21,369
2538of active directory creates a number of what are called SRV records,
2539847
254000:00:21,469 --> 00:00:26,369
2541or service records inside of DNS. These SRV records are what allow clients to locate the
2542848
254300:00:26,469 --> 00:00:31,369
2544different active directory services as well as the different servers to find each other.
2545849
254600:00:31,469 --> 00:00:35,369
2547You'll find that these servers, or the records, the SRV records in a domain, are here
2548850
254900:00:35,469 --> 00:00:41,369
2550in these folders that exist below company.pri or whatever your domain name is.
2551851
255200:00:41,469 --> 00:00:46,369
2553And it is this long list of folders that contain all the variety of SRV records and C names
2554852
255500:00:46,469 --> 00:00:48,369
2556that help these different servers and services
2557853
255800:00:48,469 --> 00:00:52,369
2559locate each other and the clients to locate the services themselves.
2560854
256100:00:52,469 --> 00:00:57,369
2562So you can see here if I scroll to the right just a bit, under msdcs, and then dc in sites,
2563855
256400:00:57,469 --> 00:01:02,369
2565and then the site name here, which is by default the default first site name.
2566856
256700:01:02,469 --> 00:01:08,370
2568We have a list of tcp records here that correspond with Kerberos services and ldap services here in the domain.
2569857
257000:01:08,469 --> 00:01:13,370
2571The main idea here is that when a client is looking for Kerberos and ldap services, that in this
2572858
257300:01:13,469 --> 00:01:18,370
2574case exists in the site that is described by default for site name.
2575859
257600:01:18,469 --> 00:01:24,370
2577They then know to go to this location, dc.company.pri, in order to find the ldap server that would
2578860
257900:01:24,469 --> 00:01:29,370
2580be listening for any ldap requests they may be making. Now what gets people confused sometimes
2581861
258200:01:29,469 --> 00:01:33,370
2583is that even in a single domain controller environment there are a large number of records
2584862
258500:01:33,469 --> 00:01:37,370
2586that have to be created for active directory to do what it needs to do.
2587863
258800:01:37,469 --> 00:01:41,370
2589And so being aware of what all these records are and really what they can do is something that can take
2590864
259100:01:41,469 --> 00:01:45,370
2592a little bit of time and you may never understand fully what all these records are intended to
2593865
259400:01:45,469 --> 00:01:52,370
2595point clients towards. But what you are responsible for is ensuring that all of these records are correct.
2596866
259700:01:52,469 --> 00:01:57,370
2598In an environment where I have dynamic updates installed and configured in DNS, this process
2599867
260000:01:57,469 --> 00:02:02,370
2601is relatively easy because each domain controller will automatically enter the correct
2602868
260300:02:02,469 --> 00:02:07,370
2604records into their DNS server as they're appropriate. And if changes are made, two for example
2605869
260600:02:07,469 --> 00:02:13,370
2607add additional domain controllers or turn on or turn off services, or even to change site names,
2608870
260900:02:13,469 --> 00:02:18,370
2610the domain controllers themselves will go about making the necessary changes in DNS.
2611871
261200:02:18,469 --> 00:02:22,370
2613If you should end up in a situation, however, where you do have DNS SRV record registration issues,
2614872
261500:02:22,469 --> 00:02:28,370
2616there are a couple of tools that you can use in order to, kind of, fix the problem.
2617873
261800:02:28,469 --> 00:02:33,370
2619Now the first of these tools works best in an environment that has dynamic updates turned on.
2620874
262100:02:33,469 --> 00:02:34,370
2622Because actually resolving a
2623875
262400:02:34,469 --> 00:02:40,370
2625failed record can be solved very simply by just locating the domain controller where the record
2626876
262700:02:40,469 --> 00:02:47,370
2628is missing and typing in the command ipconf --registerdns. This command will go about registering
2629877
263000:02:47,469 --> 00:02:50,370
2631all the appropriate DNS records that are associated with this machine.
2632878
263300:02:50,469 --> 00:02:54,370
2634You'll need to do it on every domain controller where you're missing records.
2635879
263600:02:54,469 --> 00:02:59,370
2637This includes all the appropriate SRV records as well if this is a domain controller.
2638880
263900:02:59,469 --> 00:03:03,370
2640So if you happen to find yourself in a situation where you go into DNS manager and
2641881
264200:03:03,469 --> 00:03:08,370
2643you're missing some DNS records, well just typing ipconf --registerdns or probably rebooting the server
2644882
264500:03:08,469 --> 00:03:14,370
2646generally will go about fixing those records inside of DNS. However there are some situations
2647883
264800:03:14,469 --> 00:03:17,370
2649some environments where dynamic DNS is just simply not an option.
2650884
265100:03:17,469 --> 00:03:22,370
2652Perhaps the windows team lost the battle many years ago from the Unix team and so the Unix
2653885
265400:03:22,469 --> 00:03:28,370
2655group is now managing DNS and they don't support dynamic DNS for the zones that you're using.
2656886
265700:03:28,469 --> 00:03:33,370
2658First, my sincere condolences for you if that is an environment that you're in, many of those
2659887
266000:03:33,469 --> 00:03:38,370
2661situations have been resolved in recent years as people have recognized the value of dynamic DNS.
2662888
266300:03:38,469 --> 00:03:41,370
2664But if you are still one of those environments, there is a location where you can go to find
2665889
266600:03:41,469 --> 00:03:48,370
2667the long list of records that you'll need in order to get them populated into a non-dynamic DNS server.
2668890
266900:03:48,469 --> 00:04:01,370
2670This is in Windows system 32 and config in that location and if I do Notepad the file name is netlogon.dns.
2671891
267200:04:01,469 --> 00:04:08,370
2673This location here provides the entire list of records that need to get populated into DNS for this server.
2674892
267500:04:08,469 --> 00:04:12,370
2676So this little text file here is something that you can give to, perhaps your Unix people or
2677893
267800:04:12,469 --> 00:04:17,370
2679perhaps your Windows people if you don't have dynamic DNS in Windows, so that
2680894
268100:04:17,470 --> 00:04:23,370
2682they can get entered into the DNS server appropriately for this zone. This list is generated dynamically by
2683895
268400:04:23,470 --> 00:04:27,370
2685active directory domain services so it's a great, it's a handy little guide should you find yourself
2686896
268700:04:27,470 --> 00:00:01,967
2688needing to cross reference the records we are seeing with the records you should have.
2689897
269000:00:02,067 --> 00:00:06,467
2691Now our next task asks us to configure our domain controller as a global catalog server.
2692898
269300:00:06,567 --> 00:00:12,467
2694The first domain controller, if you recall in any domain and forest, is automatically a global catalog.
2695899
269600:00:12,567 --> 00:00:17,466
2697But as we get into production we may need to add additional global catalogs to support the load.
2698900
269900:00:17,567 --> 00:00:20,466
2700I want to show you the process whereby this is done in the graphical user interface,
2701901
270200:00:20,567 --> 00:00:25,466
2703because it's a little difficult to find here within active directory sites and services.
2704902
270500:00:25,567 --> 00:00:30,466
2706So let's poke back here on our server DC really quickly so we can take a look at tools and active directory
2707903
270800:00:30,567 --> 00:00:34,466
2709sites and services. And the other reason why I'm showing you this here is because
2710904
271100:00:34,567 --> 00:00:39,466
2712now we have our server core machine correctly networked, correctly in the domain, heck it's already a domain
2713905
271400:00:39,567 --> 00:00:46,466
2715controller, we can make use of our existing graphically oriented tools to connect remotely to that
2716906
271700:00:46,567 --> 00:00:52,466
2718server to go about different kinds of remote configuration and remote management.
2719907
272000:00:52,567 --> 00:00:55,466
2721And this is one of a great example of where this is just really easy to do here once we have all
2722908
272300:00:55,567 --> 00:01:00,466
2724those connections in place. As you can see here in active directory sites and services
2725909
272600:01:00,567 --> 00:01:03,466
2727we've got a lot of different items that exist here in the tree and these items will only get
2728910
272900:01:03,567 --> 00:01:09,466
2730larger as the number of different subnets and sites that you may create get large.
2731911
273200:01:09,566 --> 00:01:13,466
2733But one thing we do have to pay attention to, even if we don't go about creating additional sites
2734912
273500:01:13,566 --> 00:01:18,466
2736and subnets, are the configuration on each individual domain controller.
2737913
273800:01:18,566 --> 00:01:23,466
2739Down here are the list of servers that exist in our site called default first site name.
2740914
274100:01:23,566 --> 00:01:28,466
2742And remember, sites are a geographic location for domain controllers and all of these
2743915
274400:01:28,566 --> 00:01:32,466
2745being in a single spot, we have no need to create additional sites.
2746916
274700:01:32,566 --> 00:01:35,466
2748For each server, if I view the properties of that server,
2749917
275000:01:35,566 --> 00:01:39,466
2751there is a couple of different items in here, mainly your basic tabs that are generally with all
2752918
275300:01:39,566 --> 00:01:43,466
2754the different items you may choose to view properties on. But the main thing I want to show you
2755919
275600:01:43,566 --> 00:01:46,466
2757is down here, these ntds settings.
2758920
275900:01:46,566 --> 00:01:51,466
2760Which is effectively the settings on the nt database services itself.
2761921
276200:01:51,566 --> 00:01:56,466
2763If I take a look at properties down here, it is this checkbox, next to global catalog,
2764922
276500:01:56,566 --> 00:02:00,466
2766that will turn on global catalog for this machine. And that's all you need to do to turn
2767923
276800:02:00,566 --> 00:02:07,466
2769this domain controller into one that is also a global catalog. Recall that in the old days with more
2770924
277100:02:07,566 --> 00:02:11,467
2772latent network connections, we had to pay more careful attention to which machines were global catalogs.
2773925
277400:02:11,567 --> 00:02:16,467
2775And if you have extremely light network connections between sites, you may need to as well.
2776926
277700:02:16,567 --> 00:02:20,467
2778But for most of us considering the network connections we have these days, it's generally
2779927
278000:02:20,567 --> 00:02:24,867
2781a good practice for many environments outside those that are exceptionally large,
2782928
278300:02:24,967 --> 00:02:29,467
2784to just make all your domain controllers global catalog servers so that they can handle all the
2785929
278600:02:29,567 --> 00:00:01,425
2787necessary requests from incoming clients.
2788930
278900:00:01,526 --> 00:00:06,426
2790And then for our last task here in this module, an objective on installing domain controllers
2791931
279200:00:06,525 --> 00:00:12,426
2793we're asked to deploy active directory in Microsoft Azure. And to be perfectly honest,
2794932
279500:00:12,525 --> 00:00:16,425
2796the inclusion of this additional task here in the R2 version of this content,
2797933
279800:00:16,525 --> 00:00:21,425
2799is a bit strange considering all the extra prerequisite knowledge that's required about Azure itself
2800934
280100:00:21,525 --> 00:00:27,425
2802to appreciate what needs to go into deploying a domain controller inside of Microsoft Azure.
2803935
280400:00:27,525 --> 00:00:33,426
2805Now the process that we're referring to here, the infrastructure as a service process or IAAS process,
2806936
280700:00:33,526 --> 00:00:39,426
2808of getting of a DC up in Azure. What it really relates to is the notion of actually creating
2809937
281000:00:39,526 --> 00:00:44,426
2811a virtual machine inside of Microsoft Azure and then installing active directory on that virtual machine,
2812938
281300:00:44,526 --> 00:00:50,426
2814just like you would inside of a local machine. In fact if I come over here to my other tab first
2815939
281600:00:50,526 --> 00:00:56,426
2817we can take a look at my personal copy of Microsoft Azure. Where if I click down here under New
2818940
281900:00:56,526 --> 00:01:02,426
2820you can take a look at a new virtual machine here, which you can quick create or create from the gallery.
2821941
282200:01:02,526 --> 00:01:06,426
2823When you create that new machine you'll need to associate any additional hard drives or
2824942
282500:01:06,525 --> 00:01:10,426
2826discs with that machine, you'll also need to make a determination about how you want
2827943
282800:01:10,525 --> 00:01:15,426
2829to get that machine connected up into your internal network. Because recall Microsoft Azure
2830944
283100:01:15,525 --> 00:01:21,426
2832and the machines inside of Azure, are available and connectable from the rest of the internet.
2833945
283400:01:21,525 --> 00:01:26,426
2835And so making a connection through some sort of VPN from that Azure location into the rest
2836946
283700:01:26,525 --> 00:01:30,426
2838of your network, is something you'll want to consider when it comes time to building that machine
2839947
284000:01:30,525 --> 00:01:33,426
2841up in the cloud. I want to direct your attention, rather than going into
2842948
284300:01:33,525 --> 00:01:37,426
2844the nitty gritty detail, I want to direct your attention to a specific article here in the
2845949
284600:01:37,525 --> 00:01:43,426
2847Microsoft Azure portion of Microsoft.com, that lists a set of guidelines for deploying
2848950
284900:01:43,525 --> 00:01:48,426
2850Windows Server active directory on Azure virtual machines. This again is the IAAS version.
2851951
285200:01:48,525 --> 00:01:53,426
2853I believe, and this is a gut instinct, but I believe Microsoft's intention that including
2854952
285500:01:53,525 --> 00:01:58,426
2856this here in this version of the 410, is in just helping you recognize that it is now possible
2857953
285800:01:58,525 --> 00:02:04,426
2859to install active directory and a domain controller directly onto a virtual machine.
2860954
286100:02:04,525 --> 00:02:08,426
2862However there are a variety of just different things you have to be aware of in order to do so.
2863955
286400:02:08,526 --> 00:02:13,426
2865And this very long document here provides a great amount of detail really about all the things
2866956
286700:02:13,526 --> 00:02:17,426
2868that are necessary to think about when it comes time to making that provisioning.
2869957
287000:02:17,526 --> 00:02:20,426
2871There is, however, down here way at the bottom, there's one little picture that I want to
2872958
287300:02:20,526 --> 00:02:25,426
2874direct you towards that will help give you an appreciation of the type of network connection
2875959
287600:02:25,526 --> 00:02:29,426
2877that you'll be intending to create when you extend your active directory into Microsoft Azure.
2878960
287900:02:29,526 --> 00:02:34,426
2880And that's this one right here. This third item shows your corporate site, your internal network,
2881961
288200:02:34,526 --> 00:02:39,426
2883and the Windows Azure site that you've created in your account. As well as the domain controllers
2884962
288500:02:39,526 --> 00:02:43,426
2886here in either side that are connected through an Azure virtual network.
2887963
288800:02:43,526 --> 00:02:47,426
2889It is this Azure virtual network that provides a mechanism for these domain controllers
2890964
289100:02:47,526 --> 00:02:51,426
2892to communicate securely across what would otherwise be the internet.
2893965
289400:02:51,526 --> 00:02:55,426
2895Being able to have that domain controller in Azure can be handy when you have organizations
2896966
289700:02:55,526 --> 00:03:00,926
2898and users that are out perhaps anywhere in the world, that need to connect with their domain controller.
2899967
290000:03:01,026 --> 00:03:06,426
2901But there are obviously some risks in making that domain controller directly accessible for the rest of the world.
2902968
290300:03:06,526 --> 00:03:11,426
2904Just again, be aware for the purposes of the 410, that it is possible to do this with some important
2905969
290600:03:11,526 --> 00:00:02,054
2907caveats associated with keeping that information secure.
2908970
290900:00:02,154 --> 00:00:05,555
2910So what is really a surprising amount of content here on installing domain controllers,
2911971
291200:00:05,655 --> 00:00:10,054
2913in part because of that need for some foundations on what active directory really is,
2914972
291500:00:10,154 --> 00:00:14,054
2916as well as its components. What we talked about in this module, we have talked about not only
2917973
291800:00:14,154 --> 00:00:18,054
2919those foundations but a variety of the different click by click things you'll need to go through
2920974
292100:00:18,155 --> 00:00:22,054
2922in order to get domain controllers and an active directory up and operational.
2923975
292400:00:22,155 --> 00:00:26,054
2925We began with adding a domain controller and creating that brand new forest and domain
2926976
292700:00:26,155 --> 00:00:31,054
2928as well a look at removing the domain controller and DC services if you need to.
2929977
293000:00:31,155 --> 00:00:36,054
2931It's always a great idea to remove the domain controller services before removing the domain controller
2932978
293300:00:36,155 --> 00:00:42,054
2934or you'll end up having to go and carefully tease out all those orphan bits out of your active directory database.
2935979
293600:00:42,155 --> 00:00:46,054
2937We then looked at installing domain controllers from install from media as well as how to
2938980
293900:00:46,155 --> 00:00:50,054
2940install ADDS on server core, a bunch of different commands that work on server core
2941981
294200:00:50,155 --> 00:00:55,054
2943and also work on the full version of Windows Server as well. We took a look then at the extended
2944982
294500:00:55,155 --> 00:00:59,054
2946process of upgrading not only a domain controller, but also upgrading a full
2947983
294800:00:59,155 --> 00:01:05,055
2949active directory domain and/or forest. That five step process that involves the adprep tool that
2950984
295100:01:05,155 --> 00:01:11,055
2952upgrades all the domain controllers. And then concludes with upgrading the domain or forest functional level.
2953985
295400:01:11,155 --> 00:01:17,055
2955We took a look at DNS and those SRV records as well as how to resolve some record registration issues.
2956986
295700:01:17,155 --> 00:01:22,055
2958As well as a look also at configuring our global catalog server on any of the domain controllers we may have.
2959987
296000:01:22,155 --> 00:01:26,055
2961And then concluded with a look here at deploying active directory in Microsoft Azure using
2962988
296300:01:26,155 --> 00:01:32,055
2964the IAAS approach. Considering Microsoft's investments in Azure active directory services
2965989
296600:01:32,155 --> 00:01:38,055
2967it's important to differentiate the VM approach from the services approach in building up that Azure
2968990
296900:01:38,155 --> 00:01:43,055
2970active directory presence. Coming up next we will continue this look at active directory focusing
2971991
297200:01:43,155 --> 00:01:48,055
2973in on the users and computers that make up our active directory infrastructure.
2974992
297500:01:48,155 --> 00:01:53,055
2976We'll go through not only the click by click to create users and computers, not terribly an interesting function,
2977993
297800:01:53,155 --> 00:01:58,055
2979but then go into the command line tools that we can use for automating the creation of active directory
2980994
298100:01:58,155 --> 00:02:02,055
2982accounts or performing some interesting bulk active directory operations.
2983995
298400:02:02,155 --> 00:02:06,055
2985We'll talk about the different user rights that can be associated with users as well as how to manage
2986996
298700:02:06,155 --> 00:02:11,055
2988inactive and disabled accounts. We'll take a look at naming our machines and then adding them
2989997
299000:02:11,155 --> 00:02:16,055
2991into the active directory domain and even doing off line domain joins if we have that need as well.
2992998
299300:02:16,155 --> 00:02:21,055
2994Although working with users and computers in active directory might not be the most glamorous job in the world,
2995999
299600:02:21,155 --> 00:02:25,055
2997if we have the right PowerShell command exposure there are ways in which we can make our job
29981000
299900:02:25,155 --> 00:02:30,055
3000that much easier. That discussion on the interesting part of managing users and computers,
30011001
300200:02:30,155 --> 23:59:59,899
3003this is a topic for our next module coming up.
30041002
300500:00:00,000 --> 00:00:06,900
3006You might think that an entire module having to do with creating and managing AD users and computers
30071003
300800:00:07,000 --> 00:00:11,900
3009would be, perhaps, one of the least interesting modules in the entire Pluralsight catalog.
30101004
301100:00:12,000 --> 00:00:17,899
3012And in any other universe you would probably be right. Thankfully the new MCSC, this generation
30131005
301400:00:18,000 --> 00:00:24,899
3015MCSC, gets away from the traditional point and click that we're used to in the graphical user interface.
30161006
301700:00:25,000 --> 00:00:28,899
3018Now for a lot of the content we're talking about, getting away from the graphical user interface
30191007
302000:00:29,000 --> 00:00:33,899
3021means we've got a lot more challenge. But here when we're talking about AD users and computers
30221008
302300:00:34,000 --> 00:00:39,899
3024it actually means that we can go through a whole module of what would ordinarily be really boring stuff
30251009
302600:00:40,000 --> 00:00:44,899
3027and turn it into some really powerful ways in which we can create automations. And in fact
30281010
302900:00:45,000 --> 00:00:49,899
3030here in this module we are going to spend a very small period of time going through the actual in the GUI process
30311011
303200:00:50,000 --> 00:00:54,899
3033of creating and copying and configuring and deleting users and computers in active directory.
30341012
303500:00:55,000 --> 00:01:00,899
3036And I do this purely for completeness I will show you how you can create a new user and/or a
30371013
303800:01:01,000 --> 00:01:06,900
3039new computer in active directory using both the adac and the aduc, the active directory users and
30401014
304100:01:07,000 --> 00:01:12,900
3042computers console and the active directory administrative console, the new version that runs on Windows PowerShell.
30431015
304400:01:13,000 --> 00:01:16,900
3045Now that's not really the reason why we're here, I mean any old person can go about creating
30461016
304700:01:17,000 --> 00:01:22,900
3048users in AD, what we're here more so is in learning how to better automate that process.
30491017
305000:01:23,000 --> 00:01:25,900
3051And there are a lot of ways in which you can accomplish that, the first of which is to just
30521018
305300:01:26,000 --> 00:01:31,900
3054simply set up a template user in active directory and plug in all the default information
30551019
305600:01:32,000 --> 00:01:36,900
3057that you would normally want to consider for a user. And then just simply copy that template to
30581020
305900:01:37,000 --> 00:01:42,900
3060create the new user. This is, in and of itself kind of an automation because you save yourself
30611021
306200:01:43,000 --> 00:01:47,900
3063the extra task of having to reenter information that you would have to do manually when you're
30641022
306500:01:48,000 --> 00:01:52,900
3066creating every new user. Thanks to the use of wild cards in active directory users and computers
30671023
306800:01:53,000 --> 00:01:56,900
3069you can create these templates and just put wildcards in places where you need information
30701024
307100:01:57,000 --> 00:02:02,900
3072to map to perhaps the users logon name. We also have another item here where we're asked to talk
30731025
307400:02:03,000 --> 00:02:06,900
3075about user rights, now we've already gone through user rights, back in that last course
30761026
307700:02:07,000 --> 00:02:12,900
3078when I explained how to set up rights and privileges using user rights assessment on a local machine.
30791027
308000:02:13,000 --> 00:02:18,900
3081What I'd rather do, rather than just repeat that here, is to show you just the introductory bits
30821028
308300:02:19,000 --> 00:02:22,900
3084about how you might deploy user rights using group policy. Now I know that we haven't got
30851029
308600:02:23,000 --> 00:02:26,900
3087into group policy yet and we've got a whole course on group policy that's upcoming.
30881030
308900:02:27,000 --> 00:02:33,900
3090But I just want to show you that baked into group policy is a similar view of the local user rights
30911031
309200:02:34,000 --> 00:02:40,900
3093assessment that you can use for deploying these user rights out globally to multiple machines at once.
30941032
309500:02:41,000 --> 00:02:44,900
3096Now this in no way is intended to take away from the thunder of the course upcoming on group policy
30971033
309800:02:45,000 --> 00:02:50,900
3099but at least it allows us to talk about something slightly different as it relates to user rights.
31001034
310100:02:51,000 --> 00:02:54,900
3102Then once we've done that, let's dig even further into the command line focus for active directory
31031035
310400:02:55,000 --> 00:02:59,900
3105and talk about the PowerShell and even some of the non-PowerShell tools that are out there
31061036
310700:03:00,000 --> 00:03:04,900
3108to perform various tasks in a more automated way. Like, creating active directory accounts,
31091037
311000:03:05,000 --> 00:03:11,900
3111like managing inactive and disabled accounts, and like performing bulk active directory operations.
31121038
311300:03:12,000 --> 00:03:17,900
3114These three tasks here encompass a relatively large set of commands and commandlets in PowerShell
31151039
311600:03:18,000 --> 00:03:24,900
3117that you could potentially bring to bear in order to do a large number of user and computer oriented things.
31181040
311900:03:25,000 --> 00:03:28,900
3120And in fact, some of the commands we'll talk about here are relatively new and actually kind of cool
31211041
312200:03:29,000 --> 00:03:32,900
3123in the types of information that they can surface. There's one in particular that I'll show you here
31241042
312500:03:33,000 --> 00:03:38,900
3126called search AD account, that was even relatively new to me, that is just fantastic for helping you
31271043
312800:03:39,000 --> 00:03:42,900
3129accomplish a task, that in the old days, was extremely hard to do.
31301044
313100:03:43,000 --> 00:03:47,900
3132Then finally we'll conclude with a look here at the offline domain join process, occasionally
31331045
313400:03:48,000 --> 00:03:51,900
3135you have the situation where you have a machine that needs to join your active directory domain,
31361046
313700:03:52,000 --> 00:03:56,900
3138but needs to do so in a way where there is no direct network connectivity between that machine
31391047
314000:03:57,000 --> 00:04:00,900
3141and your domain controller. Now when that happens, in the old days there was no way really to
31421048
314300:04:01,000 --> 00:04:05,900
3144get that machine on your AD domain. These days you can kind of separate the process out
31451049
314600:04:06,000 --> 00:04:11,900
3147into two different steps. The first step being the pre provisioning of that computer account in active directory.
31481050
314900:04:12,000 --> 00:04:17,899
3150The result of which you can transfer to the computer and then use its contents to complete the process
31511051
315200:04:18,000 --> 00:04:22,899
3153in an offline basis with that machine that doesn't happen to be connected to your domain in any way.
31541052
315500:04:23,000 --> 00:04:27,399
3156You may not necessarily find yourself performing this activity very often, but in those rare
31571053
315800:04:27,500 --> 00:04:31,899
3159occasions where you do need to get a machine online, well an offline domain join solves a
31601054
316100:04:32,000 --> 00:00:01,862
3162whole host of problems that would otherwise be insurmountable.
31631055
316400:00:01,963 --> 00:00:07,863
3165So first up on our list is the remarkably uninteresting task of dealing with users and computers
31661056
316700:00:07,963 --> 00:00:12,362
3168inside of the graphical tools that we have here at Windows Server. As you can see I'm back here
31691057
317000:00:12,462 --> 00:00:17,362
3171on my computer dc.company.pri and in a production world you're probably not going to be
31721058
317300:00:17,463 --> 00:00:23,362
3174performing these tasks on the domain controller itself. But I'm going to punch some of the remote
31751059
317600:00:23,463 --> 00:00:28,862
3177uses of these tools until Jason gets an opportunity to talk about the remote management of Windows Server.
31781060
317900:00:28,963 --> 00:00:34,862
3180So let's assume here that I've got my machine dc.company.pri, there are actually a pair of different tools
31811061
318200:00:34,963 --> 00:00:38,862
3183you can use for managing users and computers here in the operating system.
31841062
318500:00:38,963 --> 00:00:45,862
3186The first of which is the old tool, what I like to call the aduc or active directory users and computers.
31871063
318800:00:45,963 --> 00:00:46,862
3189The second of which, which I'll just open up
31901064
319100:00:46,963 --> 00:00:51,862
3192here so we can see it, is the new tool called active directory administrative center.
31931065
319400:00:51,963 --> 00:00:53,862
3195Now these two tools perform
31961066
319700:00:53,963 --> 00:00:58,862
3198many of the same functions, the adac, the newer tool, provides some additional functions that
31991067
320000:00:58,963 --> 00:01:02,862
3201have to do with things like dynamic access controls, some other additional bits that you can
32021068
320300:01:02,963 --> 00:01:08,862
3204add in as well. The biggest difference here is that the adac, different from the aduc,
32051069
320600:01:08,962 --> 00:01:12,862
3207runs on top of Windows PowerShell. And so if you're going about performing many of these tasks
32081070
320900:01:12,962 --> 00:01:14,862
3210when you go in here to click and create users and
32111071
321200:01:14,962 --> 00:01:19,862
3213do the variety of tasks like built, creating new ones, and viewing their properties.
32141072
321500:01:19,962 --> 00:01:25,862
3216Under the covers, what you're actually performing is some PowerShell command to complete the action
32171073
321800:01:25,962 --> 00:01:29,862
3219that you've told this tool to do. Now I'm going to flip back here to the old tool,
32201074
322100:01:29,962 --> 00:01:33,862
3222because I'm old school, and old habits die hard. So that we can take a look
32231075
322400:01:33,962 --> 00:01:37,862
3225at just the users and computers that are here in this active directory domain.
32261076
322700:01:37,962 --> 00:01:41,862
3228Now this is, as you're probably aware, a domain that is right out-of-the-box and we just created it,
32291077
323000:01:41,962 --> 00:01:47,862
3231so the things that you see here are going to be the types of users and groups and computers and whatnot
32321078
323300:01:47,962 --> 00:01:52,862
3234that you would assume exists in a freshly created domain. Here on the left you can see the long
32351079
323600:01:52,962 --> 00:01:57,862
3237list of organizational units and other containers that exist here in our domain company.pri.
32381080
323900:01:57,962 --> 00:02:02,862
3240And over on the right, because we focused here on the list of users, are those users and then the
32411081
324200:02:02,962 --> 00:02:08,862
3243groups that are available right out-of-the-box. For us to create a new user the process to create a
32441082
324500:02:08,962 --> 00:02:13,862
3246new user, I can't believe we're going through this, is to go new, user, and then provide
32471083
324800:02:13,962 --> 00:02:20,862
3249that first name and last name, so this is my name. And then a user logon name for the individual.
32501084
325100:02:20,962 --> 00:02:24,862
3252Over here at the right you can see what we call the upn suffix for that user logon name.
32531085
325400:02:24,962 --> 00:02:29,862
3255Here in Microsoft Windows newer versions of Microsoft Windows, we have the ability to log on
32561086
325700:02:29,962 --> 00:02:34,862
3258via either of these two approaches. The Pre-Windows 2000 approach, which is what many of
32591087
326000:02:34,962 --> 00:02:41,862
3261us still use today, the domain name/a user logon name approach. Or the more new school method
32621088
326300:02:41,962 --> 00:02:46,862
3264which is user name at domain name company.pri. Now later on in the 412 content I'll talk more
32651089
326600:02:46,962 --> 00:02:52,862
3267about how you can go about changing these UPN suffixes if you have a preferred suffix you'd like
32681090
326900:02:52,962 --> 00:02:56,862
3270your users to use that may be different from what your domain name is.
32711091
327200:02:56,962 --> 00:03:00,862
3273There's a little trickery that can do in some of the active directory tools to allow you to
32741092
327500:03:00,962 --> 00:03:05,862
3276support that, but for now right out-of-the-box the way in which a user's going to log in is
32771093
327800:03:05,962 --> 00:03:11,862
3279going to be here username@domain name or domain name/username. For any user that we many
32801094
328100:03:11,962 --> 00:03:15,862
3282enter in; we're going to have to punch in a password that supports whatever our password restrictions are going to be,
32831095
328400:03:15,962 --> 00:03:20,862
3285those rules that we've applied. We'll talk a little more about those password policies in an
32861096
328700:03:20,962 --> 00:03:25,862
3288upcoming course when we're getting into group policy. And then for that user rather than
32891097
329000:03:25,962 --> 00:03:29,862
3291requiring the user to change the password at the next logon, let's just set the user to not change
32921098
329300:03:29,962 --> 00:03:34,862
3294the password and set the password to never expire. Now you wouldn't do that in production,
32951099
329600:03:34,962 --> 00:03:39,862
3297but I tend to do that for my user account in these test and lab environments, just so that I'm not
32981100
329900:03:39,962 --> 00:03:44,862
3300forced to change a password perhaps in the middle of filming one of these different modules.
33011101
330200:03:44,962 --> 00:03:48,862
3303Now once I've created the user then there are a large number of different fields that we could potentially
33041102
330500:03:48,962 --> 00:03:52,862
3306enter in that are associated with the user account. So a description of the user, their office,
33071103
330800:03:52,962 --> 00:03:58,862
3309their telephone number, their email, their physical address information, their account information,
33101104
331100:03:58,962 --> 00:04:03,862
3312any options that we may see down the here. If the account ends up getting locked for one reason
33131105
331400:04:03,962 --> 00:04:08,862
3315or another, perhaps they've entered in their password incorrectly too many times, well I can unlock the
33161106
331700:04:08,962 --> 00:04:14,862
3318account by choosing the checkbox here. I can also set an expire on the account down here at the bottom
33191107
332000:04:14,962 --> 00:04:19,862
3321which is used most often when I have temporary accounts or perhaps consultants, external users
33221108
332300:04:19,963 --> 00:04:24,862
3324that are coming in. That when I create that account I want to make sure that that account
33251109
332600:04:24,963 --> 00:04:30,862
3327doesn't inadvertently stick around past the point that that person should no longer be a part of the organization.
33281110
332900:04:30,963 --> 00:04:34,862
3330I can also choose profile information here, so what they're user profile would be and
33311111
333200:04:34,963 --> 00:04:39,862
3333what their home folder would be. Telephone information any organizational information and a whole host
33341112
333500:04:39,963 --> 00:04:45,862
3336of other tools, like remote control and a remote desktop services profile, the COM+ partition sets
33371113
333800:04:45,963 --> 00:04:50,862
3339that may be associated with. As well as the session information, the environment information,
33401114
334100:04:50,963 --> 00:04:55,862
3342the dial in information, and what groups they're a member of. Now I flip through every single one of these
33431115
334400:04:55,963 --> 00:05:01,862
3345tasks for a reason and it's not just to show you what all the tabs are, but to highlight the
33461116
334700:05:01,963 --> 00:05:06,862
3348notion that it's entirely feasible; Microsoft may want you to know where certain information would
33491117
335000:05:06,963 --> 00:05:12,862
3351need to be entered in when you're creating a new user account. So even though it may seem silly
33521118
335300:05:12,963 --> 00:05:15,862
3354for me to flip through all these tasks, I would at least spend a couple of minutes here with the
33551119
335600:05:15,963 --> 00:05:20,862
3357properties of a user. And again, the properties of a computer so at least you have a good
33581120
335900:05:20,963 --> 00:05:25,862
3360familiarity for where the different types of information may need to be entered.
33611121
336200:05:25,963 --> 00:05:31,862
3363Let's assume that this user, the Greg Shields user, is one that needs to have lots of privileges here in the domain.
33641122
336500:05:31,963 --> 00:05:35,862
3366I want to essentially create a user of myself that will give me all the privileges to accomplish
33671123
336800:05:35,963 --> 00:05:38,862
3369the things that we would need to do for all the courses upcoming.
33701124
337100:05:38,963 --> 00:05:43,862
3372So because of that I need to give myself a membership in one or more additional groups that would
33731125
337400:05:43,963 --> 00:05:48,862
3375provide those privileges. Now anytime I create a new user, well that users going to be created
33761126
337700:05:48,963 --> 00:05:53,862
3378with the domain users membership, you have to be in domain users in order to support attaching to
33791127
338000:05:53,963 --> 00:05:57,862
3381and working with any of the objects that make up an active directory domain.
33821128
338300:05:57,963 --> 00:06:01,862
3384Not in every case, but in almost every case. In order to give additional access I would need to
33851129
338600:06:01,963 --> 00:06:06,862
3387add that additional access here. And if I wanted to, I could click the advanced button to
33881130
338900:06:06,963 --> 00:06:11,862
3390take a look at the possible different groups that this user could be added to.
33911131
339200:06:11,963 --> 00:06:15,862
3393If I choose the find now button this will list those groups here.
33941132
339500:06:15,963 --> 00:06:19,862
3396So for this user I'm interested in adding them in as a domain administrator, which would give me
33971133
339800:06:19,963 --> 00:06:24,862
3399access to doing all the things here in the domain, but I also want to give them access
34001134
340100:06:24,963 --> 00:06:29,862
3402to enterprise admins as well as schema admins. So that I can support all the needs that I
34031135
340400:06:29,963 --> 00:06:35,862
3405may potentially require for making changes at the forest level, that's the case in enterprise admins.
34061136
340700:06:35,963 --> 00:06:40,862
3408And also for making changes to the schema, which would be here under schema admins.
34091137
341000:06:40,963 --> 00:06:44,862
3411Now in a production environment it is a best practice for you not to include users in either the
34121138
341300:06:44,963 --> 00:06:49,862
3414enterprise admins or the schema admins group, except in those situations where they actually
34151139
341600:06:49,963 --> 00:06:54,862
3417require the use of those privileges. In higher security environments, it's also a great idea
34181140
341900:06:54,963 --> 00:06:57,862
3420to not include them as a domain admin either, except in those cases where
34211141
342200:06:57,963 --> 00:07:02,862
3423they need to use their domain admins privileges. So you'll see me include these here because this is
34241142
342500:07:02,963 --> 00:07:06,862
3426a lab environment, but in the real world you probably aren't going to see too many people
34271143
342800:07:06,963 --> 00:07:12,862
3429that exist in these additional groups except in those circumstances when they need to use the privileges.
34301144
343100:07:12,963 --> 00:07:17,862
3432Conversely, if you do see users permanently in these groups, you might have an argument there
34331145
343400:07:17,963 --> 00:07:22,862
3435for changing some of the security policies that exist in your organization today.
34361146
343700:07:22,963 --> 00:07:27,862
3438So there's our user, Greg Shields, and this indeed is the excitement of creating and configuring
34391147
344000:07:27,963 --> 00:07:31,862
3441a user here in our active directory domain. Let's go about configuring another user here,
34421148
344300:07:31,963 --> 00:07:37,862
3444this will be another user that is not going to have any privileges; we have no trust in this
34451149
344600:07:37,963 --> 00:07:41,862
3447individual to give them any kind of access here in our domain. So let's create this second user
34481150
344900:07:41,963 --> 00:07:48,862
3450and call them the Jason Helmick user. We'll call him Jason@company.pri and then give him
34511151
345200:07:48,963 --> 00:07:53,862
3453a password as well so that that user has the ability to just log on and perform all the basic stuff
34541152
345500:07:53,963 --> 00:07:56,862
3456that they're used to seeing here in active directory.
34571153
345800:07:56,963 --> 00:08:00,862
3459There's my Jason Helmick very low privileges user that we'll work with a little later on.
34601154
346100:08:00,963 --> 00:08:02,862
3462Now I show you the creation of the Jason Helmick account, because there are a couple other
34631155
346400:08:02,963 --> 00:08:07,862
3465things that we need to know here, which is the copying as well as the deletion of users
34661156
346700:08:07,963 --> 00:08:11,862
3468and also computers here in active directory. And all I want to show you here is that when
34691157
347000:08:11,963 --> 00:08:16,862
3471right-click on a user you can choose to copy that user to create another user account
34721158
347300:08:16,963 --> 00:08:21,862
3474that has most of the same characteristics of the user you're copying.
34751159
347600:08:21,963 --> 00:08:24,862
3477You'll need to go through additional tasks like, you know, changing the user logon name
34781160
347900:08:24,963 --> 00:08:30,862
3480and changing the permissions, but this copy object allows you to create what is effectively the same
34811161
348200:08:30,963 --> 00:08:35,862
3483user as Jason with a different user identity. So if I needed to create a Don Jones account
34841162
348500:08:35,962 --> 00:08:40,862
3486with a similar set of no privileges, I could do so by just copying the object here.
34871163
348800:08:40,962 --> 00:08:45,862
3489And then lastly to delete an account I can right-click and choose the delete item here.
34901164
349100:08:45,962 --> 00:08:48,862
3492Now even though the delete item is pretty self-explanatory, the one thing I do want to
34931165
349400:08:48,962 --> 00:08:53,862
3495point out is that when you go about providing permissions for your different individuals
34961166
349700:08:53,962 --> 00:08:59,862
3498in IT that may go about creating and removing accounts. Just be conscious of how easy it is
34991167
350000:08:59,962 --> 00:09:04,862
3501to go about deleting an account. The deletion of an account can happen with just a couple of
35021168
350300:09:04,962 --> 00:09:09,862
3504inadvertent mouse clicks. As you see here, we have an are you sure prop for deleting that user
35051169
350600:09:09,962 --> 00:09:15,862
3507Jason Helmick, but I could very easily accidently go about removing this user and potentially
35081170
350900:09:15,962 --> 00:09:21,862
3510even multiple users if I wasn't careful. So be conscious of when you're providing those permissions
35111171
351200:09:21,962 --> 00:09:25,862
3513to users to make them aware that the abilities to work with active directory users
35141172
351500:09:25,962 --> 00:09:32,862
3516and computers also comes with the abilities to inadvertently delete active directory users and computers as well.
35171173
351800:09:32,962 --> 00:09:37,862
3519Now this is the user side of the equation. We also have over here the computer side of the equation
35201174
352100:09:37,962 --> 00:09:43,862
3522as well and as you can see here we already have one computer in our active directory domain, that's file1.
35231175
352400:09:43,962 --> 00:09:50,862
3525Now you can actually come in here and right-click to create a new computer object here in your domain.
35261176
352700:09:50,962 --> 00:09:55,862
3528However you don't find yourself doing that all too often, and the reason is that the process
35291177
353000:09:55,962 --> 00:10:00,862
3531to add a computer into the active directory domain automatically creates the computer account
35321178
353300:10:00,962 --> 00:10:05,862
3534as part of that process. It is for this reason why you have to have special privileges in order to
35351179
353600:10:05,962 --> 00:10:11,862
3537add a machine into the domain. Well in certain circumstances you may find the need to
35381180
353900:10:11,962 --> 00:10:16,862
3540preposition computer accounts in active directory to support one reason or another.
35411181
354200:10:16,962 --> 00:10:20,862
3543Later on in this module when we start talking about the offline domain join feature
35441182
354500:10:20,962 --> 00:10:25,862
3546that's one place where actually creating these computer accounts first before you go about
35471183
354800:10:25,962 --> 00:10:27,862
3549adding the machine to the domain is something that has to happen.
35501184
355100:10:27,962 --> 00:10:33,862
3552But again in most circumstances, most of the time you rarely find yourself creating new computer
35531185
355400:10:33,962 --> 00:10:38,862
3555accounts using this interface. Now the only thing I want to show you over in the other interface
35561186
355700:10:38,962 --> 00:10:44,862
3558in the active directory administrative center is the fact that all of the different functions that you see in the aduc
35591187
356000:10:44,962 --> 00:10:48,862
3561are replicated over here in the adac. And one of the main reasons why I didn't show you this
35621188
356300:10:48,962 --> 00:10:55,862
3564first is just really it's pure personal preference. I've used the active directory
35651189
356600:10:55,962 --> 00:10:59,862
3567the aduc, active directory users and computers for far more years than the adac.
35681190
356900:10:59,962 --> 00:11:02,862
3570The other reason too is that personally I tend to find that if we click through here and start
35711191
357200:11:02,962 --> 00:11:08,862
3573looking through the various items that exist in our user, or in our domain, like flipping
35741192
357500:11:08,962 --> 00:11:14,862
3576down here to the users organizational unit. If I locate a user like my Greg Shields user object here
35771193
357800:11:14,962 --> 00:11:18,862
3579and view properties, there's just one long list here of all the possible properties that
35801194
358100:11:18,962 --> 00:11:23,862
3582could be associated with this user account. So instead of having a variety of tabs that
35831195
358400:11:23,962 --> 00:11:27,862
3585you have to flip through in order to enter in all this information, when you're using the
35861196
358700:11:27,962 --> 00:11:32,862
3588adac all of this information is included in one view. Now down here at the bottom you can see
35891197
359000:11:32,962 --> 00:11:37,862
3591a replication of these additional extensions, the other tabs that are part of this user account.
35921198
359300:11:37,962 --> 00:11:42,862
3594So in some places I guess you get rid of the tabs and in other places you have to maintain those tabs.
35951199
359600:11:42,962 --> 00:00:01,707
3597Just personally I prefer the old tool just because of the way it visualizes information.
35981200
359900:00:01,808 --> 00:00:05,508
3600Now back in that last clip we went through a very short explanation of the process to copy
36011201
360200:00:05,607 --> 00:00:10,008
3603an account and we went here over to the Jason Helmick account and attempted to copy Jason Helmick
36041202
360500:00:10,108 --> 00:00:15,008
3606to some other user. And in a world where you may have another user, like the Don Jones person
36071203
360800:00:15,108 --> 00:00:20,007
3609who may be coming in and working in the same group as the Jason Helmick person.
36101204
361100:00:20,108 --> 00:00:24,007
3612Well it makes sense then to just copy the account so that you can very easily replicate
36131205
361400:00:24,108 --> 00:00:28,007
3615all the different configurations that Jason has over to what Don will need.
36161206
361700:00:28,108 --> 00:00:33,007
3618But there comes a time also where when you're creating new accounts you may have a certain
36191207
362000:00:33,107 --> 00:00:39,007
3621minimum baseline set of configurations that every new account may require.
36221208
362300:00:39,107 --> 00:00:43,007
3624Let's say, for example, that you want to set a user profile path or a home drive so that that
36251209
362600:00:43,107 --> 00:00:48,007
3627home drive always corresponds to whatever the user may require. You may also have a set of
36281210
362900:00:48,107 --> 00:00:53,007
3630baseline security groups that the users may need to be added to as well.
36311211
363200:00:53,107 --> 00:00:56,007
3633Well there is a process here in the aduc to create what are called template user accounts,
36341212
363500:00:56,107 --> 00:01:02,007
3636which are honestly less exciting then they might seem. A template user account is essentially
36371213
363800:01:02,107 --> 00:01:07,008
3639a nonfunctioning user account that you create here in active directory users and computers.
36401214
364100:01:07,108 --> 00:01:12,008
3642That you can use as the container for all those baseline configurations.
36431215
364400:01:12,108 --> 00:01:16,008
3645Let's go ahead and create that template account here and I'm going to start it with an underbar
36461216
364700:01:16,108 --> 00:01:21,008
3648for the only reason that when you go about sorting the active directory users and computers interface here
36491217
365000:01:21,108 --> 00:01:25,008
3651that the underbar will force this template account to the top of the list.
36521218
365300:01:25,108 --> 00:01:31,008
3654And if I come down here to the user logon name, I'll do the same thing and create it as underbar template.
36551219
365600:01:31,108 --> 00:01:34,008
3657Let me choose a next button here and I'm going to leave the password as blank.
36581220
365900:01:34,108 --> 00:01:39,008
3660Now here's a really cool trick that you can do when you're creating this template accounts.
36611221
366200:01:39,108 --> 00:01:44,008
3663If I create this password as blank I'm not going to be able to actually create the user.
36641222
366500:01:44,108 --> 00:01:49,008
3666Because in order to create the password as blank well I'm not going to meet the password complexity requirements
36671223
366800:01:49,108 --> 00:01:54,008
3669for my active directory domain. So you can't actually create a blank password on a user,
36701224
367100:01:54,108 --> 00:01:59,008
3672there's a sort of a gut check that's built into AED. But if I do create the password as blank
36731225
367400:01:59,108 --> 00:02:03,008
3675and set the password so it cannot be changed, so the password never expires and so that the
36761226
367700:02:03,108 --> 00:02:09,008
3678account is disabled. I'm then allowed to go about creating this new user.
36791227
368000:02:09,108 --> 00:02:14,008
3681The neat part about this template user is that in no way can I ever enable the account
36821228
368300:02:14,108 --> 00:02:17,008
3684because if I enable the account the blank password is not going to fit
36851229
368600:02:17,108 --> 00:02:22,008
3687within those password complexity requirements. So this creates, as I said, kind of a nonfunctioning
36881230
368900:02:22,108 --> 00:02:26,008
3690account that I can use as the template. Now here inside this template, if I open it up,
36911231
369200:02:26,108 --> 00:02:29,008
3693this gives me the abilities to add in maybe additional membership here.
36941232
369500:02:29,108 --> 00:02:35,008
3696Maybe I want to add in the fact that we have a company users group to add people into to.
36971233
369800:02:35,108 --> 00:02:39,008
3699Maybe I want to configure some dial in permissions or some environment settings or even some
37001234
370100:02:39,108 --> 00:02:43,008
3702sessions settings down here for when I'm connecting up to remote desktop.
37031235
370400:02:43,108 --> 00:02:49,008
3705The other things I can do for this user, for example here under profile, is to configure maybe
37061236
370700:02:49,108 --> 00:02:53,008
3708a roaming profile for the user or a home folder for the user.
37091237
371000:02:53,108 --> 00:02:59,008
3711Now there's one wild card that gets commonly used most often here in the profile tab
37121238
371300:02:59,108 --> 00:03:04,008
3714that you might want to be aware of in case you have need to create a roaming profile or a home folder
37151239
371600:03:04,108 --> 00:03:11,008
3717that is pathed appropriately. And that wild card is the %username& wildcard.
37181240
371900:03:11,108 --> 00:03:16,008
3720This %username% wildcard will translate directly into the username, so the actual logon name
37211241
372200:03:16,108 --> 00:03:21,008
3723of whatever user you copy this template account into. So if you know you want to
37241242
372500:03:21,108 --> 00:03:28,008
3726create a roaming profile to file1\share1\username, when you go about copying this account
37271243
372800:03:28,108 --> 00:03:35,008
3729into an actual user, this will then resolve to whatever username you end up configuring for that individual.
37301244
373100:03:35,108 --> 00:03:36,008
3732If I choose OK down here
37331245
373400:03:36,108 --> 00:03:38,008
3735and then go back here to the copy
37361246
373700:03:38,108 --> 00:03:43,508
3738I can then use this template to go about copying this account, this template, to an actual user.
37391247
374000:03:43,608 --> 00:00:01,535
3741And then they would get all the configurations that I've included in the template.
37421248
374300:00:01,635 --> 00:00:05,036
3744Microsoft seems to insist that you are aware of how to configure user rights,
37451249
374600:00:05,136 --> 00:00:12,035
3747particularly since this task is included I believe in three different locations in this 70-410 learning path.
37481250
374900:00:12,135 --> 00:00:17,035
3750Originally back a couple of courses ago, we talked about how in the local user rights assessment dialog box
37511251
375200:00:17,135 --> 00:00:23,035
3753you could go and configure which users on a single machine should have different privileges
37541252
375500:00:23,135 --> 00:00:27,035
3756to perform tasks on that windows server. But I want to show you at least one other location
37571253
375800:00:27,135 --> 00:00:32,036
3759where those configurations can be made. Before I do that though, I want to just kind of
37601254
376100:00:32,136 --> 00:00:36,036
3762point again to the list of security groups here that exist in this users container
37631255
376400:00:36,136 --> 00:00:41,036
3765in active directory users and computers. These, as I said, are those that exist right out-of-the-box.
37661256
376700:00:41,136 --> 00:00:46,036
3768And so I would have a familiarity of what these groups are, we'll talk more about groups in the
37691257
377000:00:46,136 --> 00:00:51,036
3771next module coming up. I would also have an awareness of these built in groups that exist here,
37721258
377300:00:51,136 --> 00:00:55,036
3774these are the domain local groups that are built into the domain.
37751259
377600:00:55,136 --> 00:01:00,036
3777These provide functionality so that you can provide them that functionality to individual users
37781260
377900:01:00,136 --> 00:01:05,036
3780to be a backup operator or an account operator, for example. Now these groups can come in handy
37811261
378200:01:05,135 --> 00:01:09,036
3783when it comes time to configure the user rights assessment on an individual machine,
37841262
378500:01:09,135 --> 00:01:15,036
3786because you can use them to put users into groups and then assign privileges to those groups
37871263
378800:01:15,135 --> 00:01:17,036
3789as opposed to the individual users.
37901264
379100:01:17,135 --> 00:01:22,036
3792And in fact earlier ago, here under tools, for a specific computer, we took a look at the local security
37931265
379400:01:22,135 --> 00:01:27,036
3795policy on that machine to just see where we might go about configuring the user rights assessment
37961266
379700:01:27,135 --> 00:01:33,036
3798for the various different task and people that should have access to perform those tasks on a computer.
37991267
380000:01:33,135 --> 00:01:37,036
3801But the one thing I want to show you is just a tease of the upcoming course that we'll
38021268
380300:01:37,135 --> 00:01:41,036
3804be talking about when it comes to active directory, because as you can imagine,
38051269
380600:01:41,135 --> 00:01:46,036
3807with the sheer number of groups that are out there and the number of also individual rights
38081270
380900:01:46,135 --> 00:01:49,036
3810that could be configured on a group. This is just a very large list.
38111271
381200:01:49,135 --> 00:01:54,036
3813And the combination of these multiplied by the number of servers you have to manage
38141272
381500:01:54,135 --> 00:01:57,036
3816can make this rather unwieldy over time.
38171273
381800:01:57,135 --> 00:02:00,036
3819The one tool I want to show you, and again this is a tease for our upcoming talk
38201274
382100:02:00,135 --> 00:02:05,036
3822on group policy, is the group policy management console here. Where I'm going to take a look at
38231275
382400:02:05,135 --> 00:02:11,036
3825the default domain policy so that I can just show you here, it is entirely possible
38261276
382700:02:11,135 --> 00:02:16,036
3828in one location to configure the user rights assessment not just for a single machine
38291277
383000:02:16,135 --> 00:02:21,036
3831but in the case of this default domain policy for every machine that attaches to the domain.
38321278
383300:02:21,135 --> 00:02:26,036
3834I could also create additional group policy objects and associate them in the correct locations
38351279
383600:02:26,135 --> 00:02:31,036
3837this is also a topic for later, so that I could configure specific machines with the types
38381280
383900:02:31,135 --> 00:02:36,036
3840of security settings that I may require. Down here under security settings and local policies
38411281
384200:02:36,135 --> 00:02:37,036
3843is this same user
38441282
384500:02:37,135 --> 00:02:40,036
3846rights assessment that we saw before. And right now here with the default domain policy
38471283
384800:02:40,135 --> 00:02:47,036
3849as you can see none of them are defined. So we won't be enforcing any groups or users into these policies at this point,
38501284
385100:02:47,135 --> 00:02:53,036
3852but it's entirely possible for me to make some changes here like to change the time zone.
38531285
385400:02:53,135 --> 00:02:58,036
3855To add in a user or group here that would be then subsequently added in to every server
38561286
385700:02:58,135 --> 00:03:03,036
3858and really every desktop that attaches here into our active directory domain.
38591287
386000:03:03,135 --> 00:03:06,536
3861So if you find yourself getting overwhelmed with all the extra steps that may be required to
38621288
386300:03:06,635 --> 00:03:11,536
3864configure user rights on an individual machine. Well prepare yourself for group policy
38651289
386600:03:11,635 --> 00:00:01,677
3867because it's there where we can do things in a much more cohesive manner.
38681290
386900:00:01,778 --> 00:00:05,677
3870Now as I said, that introduction is kind of the boring part of this particular module because
38711291
387200:00:05,777 --> 00:00:10,178
3873I think a lot of us have at least tooled around in most of these tools at some point or another.
38741292
387500:00:10,278 --> 00:00:16,177
3876But it's the configuration of user accounts, of computer accounts, of all the different other
38771293
387800:00:16,277 --> 00:00:21,177
3879tasks that we need to do from the command line where we can really multiply our efforts
38801294
388100:00:21,277 --> 00:00:25,177
3882in terms of getting the tasks done. And thanks to Microsoft's investment in Windows PowerShell
38831295
388400:00:25,277 --> 00:00:29,177
3885we have a lot of really cool PowerShell commandlets these days that we can use
38861296
388700:00:29,277 --> 00:00:36,177
3888for automating the creation of active directory accounts. In fact in these exams you can almost
38891297
389000:00:36,277 --> 00:00:41,177
3891replace the word automate with the word PowerShell or baring that you can replace it
38921298
389300:00:41,277 --> 00:00:45,177
3894with the word command line. Because when Microsoft uses the term automate, what they really
38951299
389600:00:45,277 --> 00:00:51,177
3897mean is using one or more of a series of commands or commandlets to accomplish the task.
38981300
389900:00:51,277 --> 00:00:57,177
3900Here, as you can see, I've got a variety of commands that exist for dealing with computer accounts.
39011301
390200:00:57,277 --> 00:01:00,177
3903The first of which is, get ad computer, which will provide you all the information,
39041302
390500:01:00,277 --> 00:01:04,178
3906the characteristics of a computer account in active directory.
39071303
390800:01:04,278 --> 00:01:09,178
3909The second set is New-ADComputer and Remove-ADComputer, which allow you to create a computer
39101304
391100:01:09,278 --> 00:01:13,178
3912account and remove a computer account from active directory. I include these here
39131305
391400:01:13,278 --> 00:01:18,178
3915along with the ones here at the bottom Add-Computer and Remove-Computer just to show you
39161306
391700:01:18,278 --> 00:01:23,178
3918that in certain cases they're actually some commandlets in PowerShell that look the same
39191307
392000:01:23,278 --> 00:01:28,178
3921smell the same, and perform many of the same duties, but are in fact slightly different.
39221308
392300:01:28,278 --> 00:01:33,178
3924The bottom of these, Add-Computer and Remove-Computer, are what we term native to PowerShell.
39251309
392600:01:33,278 --> 00:01:39,178
3927As opposed to the middle tier there being those that are part of a specific PowerShell module.
39281310
392900:01:39,278 --> 00:01:43,178
3930The active directory module is one that you'll need to reference if you end up using it here
39311311
393200:01:43,278 --> 00:01:47,178
3933within Windows PowerShell. And although the active directory module is one that's easy to reference
39341312
393500:01:47,278 --> 00:01:51,178
3936I just want to point these two out because you may actually be asked questions about
39371313
393800:01:51,278 --> 00:01:56,178
3939one or the other of these two sets of commandlets when you're taking the exam.
39401314
394100:01:56,278 --> 00:02:01,178
3942In either case, both of these sets of command perform much of the same thing, but perhaps
39431315
394400:02:01,278 --> 00:02:05,178
3945with slight differences. And it is recognizing and appreciating those differences that will come
39461316
394700:02:05,278 --> 00:02:10,177
3948as you become more familiar with Windows PowerShell. Now these are for the computer accounts,
39491317
395000:02:10,277 --> 00:02:14,177
3951but there are a similar set of commandlets we can use for dealing with user accounts as well.
39521318
395300:02:14,277 --> 00:02:20,177
3954There's actually a shorter set here because we don't have the native add computer and remove computer equivalents.
39551319
395600:02:20,277 --> 00:02:26,177
3957These are get aduser, which gets information about a user, and then new aduser, remove aduser
39581320
395900:02:26,277 --> 00:02:30,177
3960that I can use for creating or removing an active directory user. Now at this point the only
39611321
396200:02:30,277 --> 00:02:32,177
3963thing I really want to kind of show you is
39641322
396500:02:32,277 --> 00:02:37,177
3966that for these different commandlets, being aware of how to use them is something you just got to know.
39671323
396800:02:37,277 --> 00:02:46,177
3969So get aduser, if I type that in here, get aduser will provide me a list of information about any
39701324
397100:02:46,277 --> 00:02:51,177
3972particular user that exists in active directory. So get aduser gshields will provide me that
39731325
397400:02:51,277 --> 00:02:56,177
3975long list of information about that user gshields. And, just as with anything, I can format
39761326
397700:02:56,277 --> 00:03:01,177
3978things into a list and provide additional information, I can also here choose to view all
39791327
398000:03:01,277 --> 00:03:05,177
3981of the extended properties for that user. And then view
39821328
398300:03:05,277 --> 00:03:10,177
3984a longer list of everything that happens to be associated with that user account.
39851329
398600:03:10,277 --> 00:03:15,177
3987So being aware of what this is will provide you the abilities to either grab the information
39881330
398900:03:15,277 --> 00:03:20,177
3990or with the set aduser command, change that information. Should you have need to so
39911331
399200:03:20,277 --> 00:03:26,177
3993from the command line. With the new aduser account as well, if I go here to new aduser
39941332
399500:03:26,277 --> 00:03:30,177
3996and then show you the help for new aduser, we can take a look at the long list of parameters
39971333
399800:03:30,277 --> 00:03:36,177
3999that are associated, oops not net aduser, I mean a new aduser. We can take a list, look at the
40001334
400100:03:36,277 --> 00:03:42,177
4002long list of parameters that exist here for creating those new active directory users.
40031335
400400:03:42,277 --> 00:03:45,177
4005So without going into the gory detail of each of the possible parameters here,
40061336
400700:03:45,277 --> 00:03:50,177
4008just take a look at all the things that you can configure when it comes time to create that new user
40091337
401000:03:50,277 --> 00:03:57,177
4011from the command line. So configuring the home directory, the employee Id, the Kerberos encryption type,
40121338
401300:03:57,277 --> 00:04:03,177
4014the home phone, the vast majority of all the different fields we saw in active directory users and computers
40151339
401600:04:03,277 --> 00:04:07,177
4017are represented here as parameters associated with the new aduser command.
40181340
401900:04:07,277 --> 00:04:12,177
4020And that's why this syntax box here includes so much copy, because, well we have to represent all the
40211341
402200:04:12,277 --> 00:04:17,177
4023possible things that we could configure for a specific user. The good news is that pretty much all
40241342
402500:04:17,278 --> 00:04:20,177
4026of these parameters here are optional when you're using the new aduser command.
40271343
402800:04:20,278 --> 00:04:27,177
4029I can create a new user, so new aduser Don Jones, for example, with just identifying what the user
40301344
403100:04:27,278 --> 00:04:32,177
4032name should be for that account that I'm creating. If I do that, as you can see, we would create the djones
40331345
403400:04:32,278 --> 00:04:36,177
4035account up here and if I refresh everything's over here with active directory users and computers,
40361346
403700:04:36,278 --> 00:04:42,177
4038well there is the djones account. So you can add additional parameters if you want, if you want to configure
40391347
404000:04:42,278 --> 00:04:46,177
4041additional pieces in here for your name and your display name and all the other bits that
40421348
404300:04:46,278 --> 00:04:49,677
4044make up that user properties. But those are the commands I would be aware of for
40451349
404600:04:49,778 --> 00:00:01,935
4047automating the creation of active directory accounts.
40481350
404900:00:02,035 --> 00:00:04,935
4050Now I did promise you for this module a couple of really cool things that we could do
40511351
405200:00:05,035 --> 00:00:07,935
4053once we start digging a little further into the PowerShell. And it's here where we can start to do
40541352
405500:00:08,035 --> 00:00:13,935
4056some stuff that I personally is just really exciting. And it's in part because I did actually discover
40571353
405800:00:14,035 --> 00:00:18,934
4059a new PowerShell command that I was unaware of that solves a host of what were otherwise
40601354
406100:00:19,035 --> 00:00:23,934
4062exceptionally difficult problems to figure out way back in the day.
40631355
406400:00:24,035 --> 00:00:26,934
4065But before we get to that command, I want to show you just a couple of the ways
40661356
406700:00:27,035 --> 00:00:31,934
4068in which we can go about managing inactive and disabled accounts here in active directory.
40691357
407000:00:32,034 --> 00:00:36,934
4071I'll start with the old commandlets that we had and then we'll move into this new tool
40721358
407300:00:37,034 --> 00:00:40,934
4074that I think you should be aware of just because it's cool. The first, of which, is let's talk
40751359
407600:00:41,034 --> 00:00:45,934
4077about how I can get information about users that may be inactive or disabled.
40781360
407900:00:46,034 --> 00:00:50,934
4080If you think about users and what users might be inactive, you have to think about okay how
40811361
408200:00:51,034 --> 00:00:57,934
4083can we define a user or a set of users that we consider to be inactive in the domain.
40841362
408500:00:58,034 --> 00:01:00,934
4086Well one way in which we've done for years is by taking a look at the last logon date
40871363
408800:01:01,034 --> 00:01:06,935
4089and the last logon time for when that user would attach to the domain or request the use of resources
40901364
409100:01:07,034 --> 00:01:13,935
4092or even just log onto their machine. Because every logon has to happen through a domain controller
40931365
409400:01:14,034 --> 00:01:18,935
4095it is that last logon date attribute associated with the user account that we can definitively
40961366
409700:01:19,034 --> 00:01:23,935
4098use for determining when they attempted to log onto our domain. Now in times gone past,
40991367
410000:01:24,034 --> 00:01:28,935
4101the only way to get this was through this commandlet get aduser. And a fairly complex series of
41021368
410300:01:29,034 --> 00:01:34,935
4104additional parameters that we have to add. Let's say that we want to use get aduser and then filter
41051369
410600:01:35,034 --> 00:01:42,935
4107it on all the items here so that we can take a look at the property which is the last logon date,
41081370
410900:01:43,034 --> 00:01:51,935
4110oops last logon date. What we're asking here is give us all the users and give us their last logon date.
41111371
411200:01:52,034 --> 00:01:55,935
4113And then once we have that let's filter the results into a nice table that we can use
41141372
411500:01:56,034 --> 00:02:01,935
4116to review the name and indeed the last logon date of that particular user.
41171373
411800:02:02,034 --> 00:02:05,935
4119If I get that I take a look at, well here's my administrator, a user account, and then here's the
41201374
412100:02:06,034 --> 00:02:09,935
4122accounts that I created, the Jason Helmick, the Greg Shields, and the Don Jones account.
41231375
412400:02:10,034 --> 00:02:14,935
4125In a production world, I would have a longer list of different accounts, obviously,
41261376
412700:02:15,034 --> 00:02:18,935
4128and obviously I would also have last logon dates for those users as well.
41291377
413000:02:19,034 --> 00:02:22,935
4131But because we just created these accounts, we're not seeing this additional information in here.
41321378
413300:02:23,034 --> 00:02:26,935
4134I could further look at some additional properties as well, there's another property called
41351379
413600:02:27,034 --> 00:02:31,935
4137password last set that can be useful. This password last set gives me an idea of when the users
41381380
413900:02:32,034 --> 00:02:37,935
4140password was last set. So password last set and then let me grab that then into the table,
41411381
414200:02:38,034 --> 00:02:46,935
4143password last set will provide me the last logon date and then when that password was last set for the account.
41441382
414500:02:47,034 --> 00:02:50,935
4146Now the password last set information gives me a little bit more here for my G Shields,
41471383
414800:02:51,034 --> 00:02:54,935
4149my Jason Helmick, and my Don Jones account, because it tells me when the password was set,
41501384
415100:02:55,034 --> 00:03:00,935
4152which was earlier this morning. The combination of this information, with the appropriate formatting and
41531385
415400:03:01,034 --> 00:03:03,935
4155then ordering by however many days will help you understand,
41561386
415700:03:04,034 --> 00:03:08,935
4158well has this user even attempted to log onto the domain for 30 or 60 or 90 days?
41591387
416000:03:09,034 --> 00:03:12,935
4161With that information, I can go through using the remove commands to get rid of those user
41621388
416300:03:13,034 --> 00:03:17,935
4164accounts out of active directory on a more regularly scheduled basis.
41651389
416600:03:18,034 --> 00:03:21,935
4167Then this helps me for situations when I've got inactive accounts, but what I may also be interested in
41681390
416900:03:22,034 --> 00:03:27,935
4170are disabled accounts. Those that have been specifically disabled in active directory. If I flip back
41711391
417200:03:28,034 --> 00:03:30,935
4173here to my active directory users and computers and take a look at one of the
41741392
417500:03:31,034 --> 00:03:38,935
4176accounts that's available, it is possible for me to go down here and set that an account indeed is disabled here in ad.
41771393
417800:03:39,034 --> 00:03:41,935
4179But the problem is, is having to click through every single user account, then to the account tab,
41801394
418100:03:42,034 --> 00:03:45,935
4182and then to scroll down to account options is kind of a pain in the neck.
41831395
418400:03:46,034 --> 00:03:47,935
4185So I can use PowerShell here in order
41861396
418700:03:48,034 --> 00:03:51,935
4188to speed things up just a little more. And one of the first tools I can use to do that
41891397
419000:03:52,034 --> 00:03:57,935
4191is also the get aduser command, but in this case I'm going to choose a filter on my domain
41921398
419300:03:58,034 --> 00:04:00,935
4194which in this case instead of using a wild card I want to actually create a filter
41951399
419600:04:01,034 --> 00:04:05,935
4197that will define which users may be disabled and which ones aren't.
41981400
419900:04:06,034 --> 00:04:11,935
4200If I do the curly brackets here, I could to the filter on enabled --ne true.
42011401
420200:04:12,034 --> 00:04:16,935
4203So running this will give me the list of users where the account is not enabled.
42041402
420500:04:17,035 --> 00:04:21,935
4206As you can see here I have, looks like the Don Jones account, and obviously my template user account.
42071403
420800:04:22,035 --> 00:04:27,935
4209As well as the other sort of basic out-of-the-box accounts that are also disabled by default.
42101404
421100:04:28,035 --> 00:04:32,935
4212Now that's the old school approach to figuring out this information and by old school I mean
42131405
421400:04:33,035 --> 00:04:37,935
4215an operating system ago or two. But in recent versions of the OS Microsoft has included a new
42161406
421700:04:38,035 --> 00:04:44,935
4218commandlet here that I find to be particularly exciting. That command is search ad account.
42191407
422000:04:45,035 --> 00:04:49,935
4221So search ad account, which, if I run the help on, I think I've spelled that correctly,
42221408
422300:04:50,035 --> 00:04:54,935
4224yes, it will give me the list of possible ways in which I can use this commandlet for finding
42251409
422600:04:55,035 --> 00:05:01,935
4227information about accounts that exist in active directory. So let's take a look here at the possibilities.
42281410
422900:05:02,035 --> 00:05:06,935
4230Those are the abilities to search on whether the account is disabled, whether it's expired,
42311411
423200:05:07,035 --> 00:05:12,935
4233whether it's about to expire or expiring, whether the account is inactive, whether it's locked out,
42341412
423500:05:13,035 --> 00:05:16,935
4236whether the password is configured to never expire. So as you can see this search
42371413
423800:05:17,035 --> 00:05:21,935
4239ad account function has some really cool ways in which I can see without needing to construct
42401414
424100:05:22,035 --> 00:05:27,935
4242a variety of different filters and what not how I can then identify which user accounts
42431415
424400:05:28,035 --> 00:05:34,935
4245are in these various states. So let's do search ad account and then let's start with the disabled accounts.
42461416
424700:05:35,035 --> 00:05:36,935
4248So account disabled.
42491417
425000:05:37,035 --> 00:05:40,935
4251There is my list of users and computers where their accounts are currently disabled,
42521418
425300:05:41,035 --> 00:05:47,935
4254but let's actually go a step further and remove out the computer so I just get the users only for that list.
42551419
425600:05:48,035 --> 00:05:51,935
4257And I'll go one step further still and then format the list so I just get the names of the users
42581420
425900:05:52,035 --> 00:05:57,935
4260that are currently disabled. So search ad account really provides some real nice functionality here
42611421
426200:05:58,035 --> 00:06:01,935
4263for helping my quickly identify the accounts that need to be disabled.
42641422
426500:06:02,035 --> 00:06:05,935
4266The good part is, and you'll learn more about this as you get more familiar with PowerShell,
42671423
426800:06:06,035 --> 00:06:10,935
4269is that the objects that are produced by search ad account could be piped into, for example,
42701424
427100:06:11,035 --> 00:06:14,935
4272the remove ad user command, so that I could just search for the accounts that are disabled
42731425
427400:06:15,035 --> 00:06:22,935
4275and then remove them if need be. I can do another one here, let's do search ad accounts and then
42761426
427700:06:23,035 --> 00:06:29,935
4278accounts inactive, so not disabled or expiring, but inactive. This gives me the ability with the
42791427
428000:06:30,035 --> 00:06:34,935
4281additional parameter of timespan, a set of days or hours that I want to look for potentially
42821428
428300:06:35,035 --> 00:06:42,935
4284inactive accounts. So let's say 30 days for example, so 30 days :00:00.
42851429
428600:06:43,035 --> 00:06:48,935
4287So these are the accounts that have been inactive for 30 days or more that should actually be these accounts.
42881430
428900:06:49,035 --> 00:06:52,935
4290Now as you can see I've got a couple of additional accounts in here like my account and the Jason Helmick account
42911431
429200:06:53,035 --> 00:06:57,935
4293and the Don Jones account that are considered inactive because we haven't actually logged into these accounts yet.
42941432
429500:06:58,035 --> 00:07:01,935
4296They are technically inactive because they don't have any last logon date
42971433
429800:07:02,035 --> 00:07:06,935
4299information populated in with their user record. I've got other functionality I can use
43001434
430100:07:07,035 --> 00:07:12,935
4302like search ad accounts, and then password expired. Which accounts exist in this domain
43031435
430400:07:13,035 --> 00:07:18,935
4305where their passwords have expired. Also which accounts have been configured where the password never expires.
43061436
430700:07:19,035 --> 00:07:22,935
4308So a couple of accounts there that have been setup so the password never expires.
43091437
431000:07:23,035 --> 00:07:28,935
4311And my personal favorite, which is search ad accounts and then locked out.
43121438
431300:07:29,035 --> 00:07:31,935
4314Sometimes you end up with users that have punched in their password incorrectly too many times
43151439
431600:07:32,035 --> 00:07:36,935
4317and they end up locking themselves out. Well identifying the long list of users
43181440
431900:07:37,035 --> 00:07:40,935
4320none of which exist in this domain that have been locked out of their account is great for
43211441
432200:07:41,035 --> 00:07:45,935
4323identifying why that person cannot connect up with the resources that they need.
43241442
432500:07:46,035 --> 00:07:49,935
4326The process by which Windows sets an account to be locked out can sometimes have some really
43271443
432800:07:50,035 --> 00:07:54,935
4329weird effects on how users are connecting up to resources. It's not always cut and dry
43301444
433100:07:55,035 --> 00:07:59,935
4332as in determining why a user cannot log on. And so being able to identify whether or not the
43331445
433400:08:00,035 --> 00:08:04,435
4335account is locked out is handy when the user calls in to try to figure out why they're not able
43361446
433700:08:04,535 --> 00:00:01,795
4338to connect to resources for one reason or another.
43391447
434000:00:01,895 --> 00:00:06,796
4341Now where PowerShell really shines is when it comes time to perform bulk actions on active directory
43421448
434300:00:06,895 --> 00:00:10,796
4344or really against any kind of configuration on a machine or service.
43451449
434600:00:10,896 --> 00:00:14,296
4347And so performing bulk active directory operations is one of the places where we can do some
43481450
434900:00:14,396 --> 00:00:21,295
4350really nifty stuff if we've got the information in a format that can be consumed by one or more of these commands.
43511451
435200:00:21,396 --> 00:00:25,295
4353Now I want to before we get into the PowerShell portion, because there's just one that I want to show you,
43541452
435500:00:25,396 --> 00:00:31,295
4356I want to show you a couple of other commands that have existed in Windows for a very long period of time.
43571453
435800:00:31,396 --> 00:00:36,295
4359These bulk operations commands Microsoft provides in order to either export out information
43601454
436100:00:36,396 --> 00:00:41,295
4362or import in information like to create multiple users at once. The first of which is a command called
43631455
436400:00:41,396 --> 00:00:51,295
4365csvde, which uses CSV files or coma separated values files, to go about performing these bulk operations.
43661456
436700:00:51,396 --> 00:00:56,295
4368Now as you can see here, csvde has a very long list of possible parameters that can it use
43691457
437000:00:56,396 --> 00:01:02,295
4371for exporting or importing information. And in fact the default for csvde is to export
43721458
437300:01:02,396 --> 00:01:06,296
4374information unless you specifically choose to import things, which is a great thing because you don't
43751459
437600:01:06,396 --> 00:01:12,296
4377want to accidently import in a bunch of content. In order to export, just to do a simple export
43781460
437900:01:12,396 --> 00:01:22,296
4380of your domain information you can choose csvde and then --f and then a file name, so output.csv.
43811461
438200:01:22,396 --> 00:01:27,296
4383This command will output a csv file that contains all the information that exists in active directory
43841462
438500:01:27,396 --> 00:01:30,296
4386as it relates to users and computers.
43871463
438800:01:30,396 --> 00:01:35,296
4389So we've actually output this information, so let's go ahead and run Notepad and take a look at
43901464
439100:01:35,396 --> 00:01:39,296
4392that output.csv file that we just created.
43931465
439400:01:39,396 --> 00:01:43,296
4395As you can see it's got a whole lot of stuff baked in here and if I remove the, let's say the
43961466
439700:01:43,396 --> 00:01:50,296
4398word wrap is off, we can take a look at just the kinds of things that are in this coma separated values file.
43991467
440000:01:50,396 --> 00:01:53,296
4401Now because the length of the lines is a little bit long, we're getting some line wrap over here,
44021468
440300:01:53,396 --> 00:01:59,296
4404but as you can see on the top we have the list of column names that are associated with this CSV that we've created.
44051469
440600:01:59,396 --> 00:02:04,296
4407Like distinguished name, the object class, the dn the distinguished name over here, the instance type,
44081470
440900:02:04,396 --> 00:02:09,295
4410when it was created when it was changed. And these are represented down here for each
44111471
441200:02:09,395 --> 00:02:15,295
4413individual account, so the lost and found container, the meetings container, and then all the way
44141472
441500:02:15,395 --> 00:02:19,295
4416down here I believe at the bottom we should actually end up getting to some users and groups.
44171473
441800:02:19,395 --> 00:02:26,295
4419So here's our domain admins group for example and here is our allowed RODC password replication group.
44201474
442100:02:26,395 --> 00:02:31,295
4422Well doing this simple output doesn't really provide us much in the way of useful information
44231475
442400:02:31,395 --> 00:02:37,295
4425because even importing this into Excel to delete out all the uninteresting rows still
44261476
442700:02:37,395 --> 00:02:41,295
4428provides us with us a lot of stuff that's perhaps too much for what we need. Well csvde
44291477
443000:02:41,395 --> 00:02:47,295
4431allows you to kind of tailor what kinds of information you want to get out if you provide
44321478
443300:02:47,395 --> 00:02:55,295
4434the appropriate parameters. Once such parameter, which I'll show you, is csvde-f output2.csv
44351479
443600:02:55,395 --> 00:03:01,295
4437and then here I can use the --d parameter to enter in first the container in active directory
44381480
443900:03:01,395 --> 00:03:06,295
4440that I'm interested in. So the contents of a specific container as opposed to all containers.
44411481
444200:03:06,395 --> 00:03:11,295
4443To do that I'm going to need to provide a path to the container through ldap, which in our case
44441482
444500:03:11,395 --> 00:03:14,295
4446let's choose the users container. This container is what we find over
44471483
444800:03:14,395 --> 00:03:20,295
4449here, right there, the users container in active directory users and computers. The path for that
44501484
445100:03:20,395 --> 00:03:31,295
4452container will be cn=users and then dc=company, dc=pri. This will give me the contents of that's
44531485
445400:03:31,395 --> 00:03:38,295
4455users container. I could also use the --r parameter to identify just an additional filter that
44561486
445700:03:38,395 --> 00:03:41,295
4458I would want to apply for the types of objects I'm interested in.
44591487
446000:03:41,395 --> 00:03:49,295
4461So let's then filter this down just a bit further to just the user objects, so object class = user.
44621488
446300:03:49,395 --> 00:03:50,295
4464And if I run that correctly
44651489
446600:03:50,395 --> 00:03:57,295
4467that should give me just the 7 entries as opposed to the 246 entries that make up the entire domain.
44681490
446900:03:57,395 --> 00:04:02,295
4470Well let's take a look at that new output file that we just created, output2.csv
44711491
447200:04:02,395 --> 00:04:03,295
4473and as you can see there are far
44741492
447500:04:03,395 --> 00:04:08,295
4476fewer records in here that correspond with just the users that exist in that container.
44771493
447800:04:08,395 --> 00:04:14,295
4479The neat part about these is that the creation of these allows you to just drop this into Microsoft Excel
44801494
448100:04:14,395 --> 00:04:19,295
4482make some changes that you may require, perhaps use it as a template to create an additional list of users
44831495
448400:04:19,396 --> 00:04:23,295
4485that you may want to import. And then when it comes time to actually import in this information
44861496
448700:04:23,396 --> 00:04:30,295
4488you could use the same csvde command, csvde, with the --i switch to go ahead and import in an additional file,
44891497
449000:04:30,396 --> 00:04:35,295
4491so output2.csv. Now I'm not going to hit the Enter button here because I don't want to import
44921498
449300:04:35,396 --> 00:04:40,295
4494in additional records that I already have, but this is a process that you could go through using
44951499
449600:04:40,396 --> 00:04:45,295
4497csvde to export and import information in and out of active directory.
44981500
449900:04:45,396 --> 00:04:49,295
4500Now there is one other command that's similar to csvde, I won't go into as much detail with this other
45011501
450200:04:49,396 --> 00:04:53,295
4503command called ldifde.
45041502
450500:04:53,396 --> 00:04:59,295
4506The only main difference here is that ldifde provides many of the same functions as csvde does,
45071503
450800:04:59,396 --> 00:05:07,295
4509except the output format for ldifde will be not in the csv format, but the ldif format.
45101504
451100:05:07,396 --> 00:05:12,295
4512So if I wanted to do a sample export of my current domain so that you could see what the ldif format looks like
45131505
451400:05:12,396 --> 00:05:25,295
4515I do ldifde-f and then output3.ldf. And once I've taken a look at that, let's do a Notepad output3.ldf
45161506
451700:05:25,396 --> 00:05:28,295
4518and we can take a look at just how this differentiates or how this
45191507
452000:05:28,396 --> 00:05:33,295
4521differs from what we saw before in the commerce separated values format.
45221508
452300:05:33,396 --> 00:05:37,295
4524As you can see this is not so much a table but a long list of all the different records and
45251509
452600:05:37,396 --> 00:05:42,295
4527the characteristics associated with those records. And depending on what format you prefer,
45281510
452900:05:42,396 --> 00:05:47,295
4530you can use CSV or ldifde to perform these bulk active directory operations.
45311511
453200:05:47,396 --> 00:05:51,295
4533Now I can't go and show you all the command line tools without delving into the PowerShell a bit
45341512
453500:05:51,396 --> 00:05:56,295
4536because these non-PowerShell tools are, if they're not deprecated, it's likely that they
45371513
453800:05:56,396 --> 00:06:01,295
4539will be deprecated at some point as Microsoft continues its embrace with Windows PowerShell.
45401514
454100:06:01,396 --> 00:06:08,295
4542So I want to show you how I can take the CSV file or a slightly reformatted version of a CSV file
45431515
454400:06:08,396 --> 00:06:15,295
4545and then use that as an input for a PowerShell command so that I can create new users via that mechanism.
45461516
454700:06:15,396 --> 00:06:16,295
4548Let's go ahead and close this output3 here
45491517
455000:06:16,396 --> 00:06:19,295
4551and let me clear the screen so that
45521518
455300:06:19,396 --> 00:06:25,295
4554I can show you just an additional CSV file that I've created. And in fact if I minimize this
45551519
455600:06:25,396 --> 00:06:26,295
4557and minimize this, I can show you
45581520
455900:06:26,396 --> 00:06:32,295
4560that CSV file here. All I've done is taken the variety of different columns names that
45611521
456200:06:32,396 --> 00:06:38,295
4563I'm interested in and populated them here into a CSV file so that I can create three different users.
45641522
456500:06:38,396 --> 00:06:43,295
4566This provides a great example of a situation where, for example, you're Human Resources Department
45671523
456800:06:43,396 --> 00:06:49,295
4569may want to give you a spreadsheet of different users to have you create active directory accounts
45701524
457100:06:49,396 --> 00:06:54,295
4572from that information. That spreadsheet can very easily be converted into a CSV file
45731525
457400:06:54,396 --> 00:06:58,295
4575and as long as you have the appropriate column titles up here, you'll be able to enter
45761526
457700:06:58,396 --> 00:07:03,295
4578them in into active directory as part of this new aduser command.
45791527
458000:07:03,396 --> 00:07:05,295
4581So let me show you here, back here in PowerShell,
45821528
458300:07:05,396 --> 00:07:10,295
4584how we might go about actually accomplishing that. If we take a look again at the new aduser command
45851529
458600:07:10,396 --> 00:07:12,295
4587and I show you the help on it, we can take
45881530
458900:07:12,396 --> 00:07:18,295
4590a look at all the different possible parameters that correspond with the fields for a particular
45911531
459200:07:18,396 --> 00:07:23,295
4593active directory user, like employee Id or certificates or the authentication policy
45941532
459500:07:23,396 --> 00:07:30,295
4596or the auth type or the country. If I have a CSV file that includes the appropriate column titles
45971533
459800:07:30,396 --> 00:07:35,295
4599with the information correctly configured for that column title, I can pipe that information
46001534
460100:07:35,396 --> 00:07:41,295
4602as content into the new aduser account to create multiple accounts in bulk.
46031535
460400:07:41,396 --> 00:07:46,295
4605Let's see how we might do that, let me come back over here and I'm going to
46061536
460700:07:46,396 --> 00:07:51,295
4608import in the CSV file that we just created before. And the CSV file I'm looking for actually
46091537
461000:07:51,396 --> 00:07:57,295
4611is going to be in users administrator desktop, so there's the file I'm looking at.
46121538
461300:07:57,396 --> 00:08:05,295
4614Let's do import csv and then new users.csv, that's the file I'm looking for.
46151539
461600:08:05,396 --> 00:08:10,295
4617And I'm going to pipe that into the new aduser account, new ad, whoops new aduser.
46181540
461900:08:10,396 --> 00:08:15,295
4620If everything's been done correctly this should automatically create those three users
46211541
462200:08:15,396 --> 00:08:19,295
4623in active directory with all the characteristics, the field values populated that I
46241542
462500:08:19,396 --> 00:08:23,295
4626included in that CSV. If I come over here to
46271543
462800:08:23,396 --> 00:08:26,295
4629active directory users and computers and you'll see I've created an organizational unit here
46301544
463100:08:26,396 --> 00:08:31,295
4632called bulk users just a place to store these accounts. And I hit the F5 to refresh things,
46331545
463400:08:31,396 --> 00:08:38,295
4635yep there are my three users that I just created, user test1, user test2, and user test3.
46361546
463700:08:38,395 --> 00:08:42,295
4638Now they're going to be some caveats here in doing this, there's some types of things that you
46391547
464000:08:42,395 --> 00:08:47,295
4641just can't pipe in, passwords are one that require a little extra effort.
46421548
464300:08:47,395 --> 00:08:51,295
4644There can be some other complex object types that may require extra effort as well.
46451549
464600:08:51,395 --> 00:08:56,295
4647You also need to create an organizational unit here as opposed to just a container in active directory
46481550
464900:08:56,395 --> 00:09:01,295
4650to support where these things need to get targeted too, but I wanted to show you this just to
46511551
465200:09:01,395 --> 00:09:06,295
4653give you a feel for how you might be able to construct the kinds of bulk active directory
46541552
465500:09:06,395 --> 00:09:10,295
4656operations that you might need with a little more than an Excel spreadsheet and
46571553
465800:09:10,395 --> 00:00:01,746
4659a really well-crafted PowerShell command.
46601554
466100:00:01,846 --> 00:00:05,747
4662And then on to our final task here in this module on users and computers, we want to talk about
46631555
466400:00:05,847 --> 00:00:10,746
4665doing an offline domain join for servers that for some reason cannot connect directly up
46661556
466700:00:10,846 --> 00:00:16,246
4668into the rest of our active directory infrastructure. Now as I said in the introduction to this module
46691557
467000:00:16,347 --> 00:00:19,246
4671this is a step that you probably won't find yourself doing all that often.
46721558
467300:00:19,347 --> 00:00:25,246
4674In most cases the creation of a new computer probably happens perhaps in the IT location
46751559
467600:00:25,347 --> 00:00:29,246
4677where you're building those new laptops or desktops. But sometimes you may have a situation
46781560
467900:00:29,347 --> 00:00:34,246
4680where you've got a user in some remote location that doesn't have direct connectivity with
46811561
468200:00:34,347 --> 00:00:40,246
4683the rest of your network and so can't attach their computer directly to your domain.
46841562
468500:00:40,347 --> 00:00:43,246
4686In the old days there was no real good way to fix this, but these days we have this tool
46871563
468800:00:43,347 --> 00:00:51,246
4689called djoin, a little command line tool called djoin, that presents an ability, if I do djoin question mark here,
46901564
469100:00:51,347 --> 00:00:57,246
4692which presents the ability to preprovision an active directory computer account and then generate
46931565
469400:00:57,347 --> 00:01:02,246
4695a little file once that's done. Which we can then copy over to the computer, install it to the
46961566
469700:01:02,347 --> 00:01:09,246
4698correct location, and use that file as the mechanism to complete the joining of that machine into active directory.
46991567
470000:01:09,346 --> 00:01:13,246
4701We're effectively accomplishing the same series of steps that we would do with a traditional active directory
47021568
470300:01:13,346 --> 00:01:17,246
4704join, we're just separating it out with the use of this file and the content in that file
47051569
470600:01:17,346 --> 00:01:21,246
4707to complete the authentication. So let's go through
47081570
470900:01:21,346 --> 00:01:27,246
4710just the couple of steps that we need to do to first create that computer account in active directory.
47111571
471200:01:27,346 --> 00:01:33,246
4713In order to do that we'll use the djoin command and then a couple of, really a long series of parameters here.
47141572
471500:01:33,346 --> 00:01:42,246
4716So here's provision and then domain company.pri, then the machine we're looking for is going to be server1,
47171573
471800:01:42,346 --> 00:01:49,246
4719the save file that we'll be creating will be server1.txt. This will go about creating
47201574
472100:01:49,346 --> 00:01:51,246
4722that computer account there in active directory and if I take a look
47231575
472400:01:51,346 --> 00:01:56,246
4725here at the computers OU, I should here see, there's my server1 computer account
47261576
472700:01:56,346 --> 00:02:00,246
4728that's been added into active directory. What I can also see, if we take a look
47291577
473000:02:00,346 --> 00:02:06,246
4731then here at the root of C, is this server1.txt file, which includes a very long series
47321578
473300:02:06,346 --> 00:02:11,247
4734of letters and numbers, which is effectively the shared secret that you would use on the remote machine
47351579
473600:02:11,347 --> 00:02:15,247
4737to complete the addition to the domain. I should mention that you should be very careful
47381580
473900:02:15,347 --> 00:02:20,247
4740with these txt files once they're created because you're active directory is anticipating
47411581
474200:02:20,347 --> 00:02:23,247
4743a connection from a machine that has actually processed this file.
47441582
474500:02:23,347 --> 00:02:30,247
4746So once you create these files keep them close at hand until you complete getting them onto that remote computer.
47471583
474800:02:30,347 --> 00:02:32,247
4749Let me then flip back over to our
47501584
475100:02:32,347 --> 00:02:33,247
4752computer server1 here.
47531585
475400:02:33,347 --> 00:02:35,247
4755And I'm going to logon just a local administrator
47561586
475700:02:35,347 --> 00:02:40,247
4758onto this machine so that we can take a look at this final step in the process.
47591587
476000:02:40,347 --> 00:02:42,247
4761I want to show you that this is one of the computers that we were
47621588
476300:02:42,347 --> 00:02:48,247
4764dealing with back a couple of courses ago that was named that win-long series of letters and numbers.
47651589
476600:02:48,347 --> 00:02:52,247
4767I've gone through here to rename the computer as server1 so that we can change it from
47681590
476900:02:52,347 --> 00:02:56,247
4770it's work group mode over into a full active directory connected mode.
47711591
477200:02:56,347 --> 00:03:00,247
4773Let's begin that process here on this machine by copying the file that we just created over
47741592
477500:03:00,347 --> 00:03:06,247
4776on our DC machine here locally so that we can make use of it. I've mapped a drive here, the Z drive
47771593
477800:03:06,347 --> 00:03:12,247
4779to the DC computer, so that on the root of C I can grab our server1.txt file.
47801594
478100:03:12,347 --> 00:03:13,247
4782And I'll just throw that file here
47831595
478400:03:13,347 --> 00:03:16,247
4785onto the desktop so that we can make use of it.
47861596
478700:03:16,347 --> 00:03:19,247
4788With that done let's go ahead and open up a traditional command prompt here and we'll set
47891597
479000:03:19,347 --> 00:03:22,247
4791it as an elevated command prompt.
47921598
479300:03:22,347 --> 00:03:26,247
4794So that we can work with it for the purposes of actually completing this domain join.
47951599
479600:03:26,347 --> 00:03:30,247
4797Let me make sure that I've got the file there, there's my server1.txt file.
47981600
479900:03:30,347 --> 00:03:37,247
4800And so the second use of the djoin command that I need is djoin /requestodj, then I need to
48011601
480200:03:37,347 --> 00:03:48,247
4803load the file, that file is server1.txt. And then I need to do windowspath%systemroots and that the
48041602
480500:03:48,347 --> 00:03:54,247
4806path for windows and then configure this as a local OS. This should allow me to go about actually
48071603
480800:03:54,347 --> 00:03:59,247
4809completing this join of this machine server1 into my active directory domain.
48101604
481100:03:59,347 --> 00:04:02,247
4812As you can see here we've loaded the provisioning data from that file server1 and the
48131605
481400:04:02,347 --> 00:04:08,247
4815request is completed successfully, but we are going to need to reboot for those changes to be applied.
48161606
481700:04:08,347 --> 00:04:12,247
4818Let me go ahead and reboot this machine so that we can take a look at what happens
48191607
482000:04:12,347 --> 00:04:17,246
4821now that we've added this machine server1 here into our active directory domain.
48221608
482300:04:17,346 --> 00:04:19,246
4824With the reboot complete, let me see if I can log
48251609
482600:04:19,346 --> 00:04:24,246
4827in here and yep there we go. I can now log in as my user name into the company domain
48281610
482900:04:24,346 --> 00:04:26,746
4830which I couldn't do before because it was only in a work group.
48311611
483200:04:26,846 --> 00:04:30,246
4833This gives you that ability again to offline domain join machines when
48341612
483500:04:30,346 --> 00:00:01,895
4836they're not directly connected up to the rest of your active directory environment.
48371613
483800:00:01,995 --> 00:00:07,395
4839So equal parts nifty and perhaps not so nifty here in this module on users and computers.
48401614
484100:00:07,495 --> 00:00:11,394
4842We have talked about some pretty cool things, you know, ways in which you can use the command line
48431615
484400:00:11,494 --> 00:00:15,394
4845and PowerShell to automate a variety of otherwise really boring tasks and wrap them up
48461616
484700:00:15,494 --> 00:00:21,394
4848into what used to be a very risk killing activity clicking around in active directory users and computers.
48491617
485000:00:21,495 --> 00:00:25,394
4851So what have we talked about in this module? We have talked about creating, copying, configuring,
48521618
485300:00:25,495 --> 00:00:30,394
4854and deleting users and computers using both the aduc and adac. We configured some templates there
48551619
485600:00:30,495 --> 00:00:34,394
4857in active directory users and computers so that we could ensure a common baseline across the
48581620
485900:00:34,494 --> 00:00:38,394
4860users that we would create. We took a quick look at user rights and how you can apply them
48611621
486200:00:38,494 --> 00:00:43,394
4863now through group policy as well as the automation of creating active directory accounts,
48641622
486500:00:43,494 --> 00:00:47,394
4866managing those that are inactive and disabled, and even some really cool ways that we can
48671623
486800:00:47,494 --> 00:00:51,394
4869perform bulk active directory operations. Once we have the right commands under our belt.
48701624
487100:00:51,494 --> 00:00:56,394
4872We then concluded with a look at offline domain join and how for those machines that aren't connected
48731625
487400:00:56,494 --> 00:01:02,394
4875to our network, we can get them added into active directory with a pair of commands and a very important file.
48761626
487700:01:02,494 --> 00:01:07,395
4878Coming up next, we will take a look now at active directory groups and organizational units.
48791627
488000:01:07,495 --> 00:01:11,395
4881In comparison with users and computers, dealing with active directory groups is one of those
48821628
488300:01:11,495 --> 00:01:15,395
4884required activities for any IT professional. And making sure that you apply them in ways
48851629
488600:01:15,495 --> 00:01:20,395
4887that are intelligent is something that admittedly you don't find in a lot of organizations.
48881630
488900:01:20,495 --> 00:01:24,395
4890Part of the reason for that is that there are just so many ways in which groups can get configured
48911631
489200:01:24,495 --> 00:01:29,395
4893together and nested inside of each other. Do so correctly, and it's very easy for you to go
48941632
489500:01:29,495 --> 00:01:33,395
4896about adding and removing users from the resources that they require.
48971633
489800:01:33,495 --> 00:01:37,395
4899Do so incorrectly and you could inadvertently expose inappropriate information to people that
49001634
490100:01:37,495 --> 00:01:42,395
4902shouldn't have access. So in that module we'll talk about group nesting, the different kinds of
49031635
490400:01:42,495 --> 00:01:46,395
4905groups that active directory provides. How to manage group membership using group policy
49061636
490700:01:46,495 --> 00:01:51,395
4908and enumerate group membership. I'll talk about delegation of control and how you might
49091637
491000:01:51,495 --> 00:01:55,395
4911go about configuring your organizational units to support the needs of your users and
49121638
491300:01:55,495 --> 00:02:00,395
4914ultimately the needs of your group policy application. A discussion on groups and organizational
49151639
491600:02:00,495 --> 23:59:59,899
4917units as a topic for our next module coming up.
49181640
491900:00:00,000 --> 00:00:05,900
4920You can argue that managing active directory users is a relatively straightforward process.
49211641
492200:00:06,000 --> 00:00:11,900
4923I mean user has an account or they don't and if they don't they don't have access to anything.
49241642
492500:00:12,000 --> 00:00:15,900
4926Well whereas those users may be relatively straightforward, dealing with the groups that that
49271643
492800:00:16,000 --> 00:00:20,899
4929user may be a member of is quite another thing entirely. Managing your active directory groups
49301644
493100:00:21,000 --> 00:00:26,899
4932can at first blush seem like a really a simple thing to do, but these groups and the sheer number
49331645
493400:00:27,000 --> 00:00:30,899
4935of groups you will likely have and the nesting of one group into another.
49361646
493700:00:31,000 --> 00:00:36,899
4938Can very quickly turn what would seem a simple active directory infrastructure into one
49391647
494000:00:37,000 --> 00:00:40,899
4941that is far more complicated than you would ever expect. And so for that reason here in this module
49421648
494300:00:41,000 --> 00:00:44,899
4944on creating and managing active directory groups and organizational units,
49451649
494600:00:45,000 --> 00:00:48,899
4947we're going to spend our time talking not just about how to put users in groups,
49481650
494900:00:49,000 --> 00:00:50,899
4950but more specifically on the other
49511651
495200:00:51,000 --> 00:00:54,899
4953things that you have to deal with when you're talking about managing the groups themselves.
49541652
495500:00:55,000 --> 00:00:59,899
4956I mean the reason why we have groups is to ensure that the right people have access to the right resources.
49571653
495800:01:00,000 --> 00:01:05,900
4959And conversely that the wrong people don't have access to the resources they shouldn't have access too.
49601654
496100:01:06,000 --> 00:01:10,900
4962And so dealing with your groups requires a bit of strategy in ensuring that you create them
49631655
496400:01:11,000 --> 00:01:14,900
4965and manage them correctly. We'll talk here in this module about how to create and copy, configure,
49661656
496700:01:15,000 --> 00:01:20,900
4968and delete groups and organizational units both from the graphical user interface and using Windows PowerShell.
49691657
497000:01:21,000 --> 00:01:24,900
4971Similar to what we were talking about in the last module on users, they were just a small set
49721658
497300:01:25,000 --> 00:01:28,900
4974of Windows PowerShell commands that you just got to know. These give you the abilities to create
49751659
497600:01:29,000 --> 00:01:33,900
4977new groups and organizational units and to change their membership and to perform all the usual
49781660
497900:01:34,000 --> 00:01:37,900
4980tasks that you would consider as part of group management. We'll also talk about group nesting
49811661
498200:01:38,000 --> 00:01:42,900
4983and it's here where groups can get a little insidious because it is possible to take one group
49841662
498500:01:43,000 --> 00:01:46,900
4986and in some cases stick it inside another group. And in fact when you look at some of the best
49871663
498800:01:47,000 --> 00:01:52,900
4989practices for how to do group nesting, the best way to actually configure your groups involves
49901664
499100:01:53,000 --> 00:01:56,900
4992always using some form of group nesting. I will show you what that best practice is and
49931665
499400:01:57,000 --> 00:02:01,900
4995a little acronym that you could potentially use for memorizing which groups go into which groups.
49961666
499700:02:02,000 --> 00:02:07,900
4998But pay careful attention to the strategy you use in setting up the nesting of your groups.
49991667
500000:02:08,000 --> 00:02:11,900
5001Because without being careful here, it's entirely possible for you to inadvertently give the
50021668
500300:02:12,000 --> 00:02:15,900
5004wrong person access to something they shouldn't have. We'll also talk about some of the
50051669
500600:02:16,000 --> 00:02:20,900
5007PowerShell commands you can use for enumerating group membership and I'll go actually a little
50081670
500900:02:21,000 --> 00:02:25,900
5010deeper here than just the one command you need to know for which users are in which group.
50111671
501200:02:26,000 --> 00:02:31,900
5013I want to talk about three use cases for membership and how we can use PowerShell to greatly enhance
50141672
501500:02:32,000 --> 00:02:36,900
5016the vision that you'll have in understanding which users may have access to which groups.
50171673
501800:02:37,000 --> 00:02:40,900
5019Particularly when you combine this with the groups that may be nested in each other.
50201674
502100:02:41,000 --> 00:02:43,900
5022We'll talk very quickly about how to convert groups; there are just a couple of commands
50231675
502400:02:44,000 --> 00:02:47,900
5025you would do for converting, for example, security to distribution groups.
50261676
502700:02:48,000 --> 00:02:51,900
5028Or from global groups to universal groups. There are also some kinds of conversions you just
50291677
503000:02:52,000 --> 00:02:56,900
5031simply can't do, so we'll talk about the options that you have in converting one type of group into another.
50321678
503300:02:57,000 --> 00:03:02,900
5034It is also possible to manage your group membership using group policy as well.
50351679
503600:03:03,000 --> 00:03:05,900
5037And once again I don't want to steal the thunder from our entire course on group policy,
50381680
503900:03:06,000 --> 00:03:09,900
5040but I do want to show you one area inside of the group policy management console
50411681
504200:03:10,000 --> 00:03:13,900
5043where you can configure a group and then configure the membership for that group
50441682
504500:03:14,000 --> 00:03:19,900
5046so that it will be universally applied across all the machines where that group policy applies.
50471683
504800:03:20,000 --> 00:03:23,900
5049As with our user rights assessment back in that last module, this functionality presents a
50501684
505100:03:24,000 --> 00:03:29,900
5052really awesome way to ensure that the right people get in the right groups on every machine all at once.
50531685
505400:03:30,000 --> 00:03:32,900
5055We will also talk about the delegation of control wizard and when you're dealing with active directory
50561686
505700:03:33,000 --> 00:03:38,900
5058objects it is this delegation of control wizard where you can identify which users should have the
50591687
506000:03:39,000 --> 00:03:42,900
5061abilities to perform administrative tasks on groups and other objects, like being able to
50621688
506300:03:43,000 --> 00:03:47,900
5064change the membership. Well the delegation of control wizard is great for being able to do things,
50651689
506600:03:48,000 --> 00:03:52,900
5067but we also have to be kind of cautious with its use because once you start popping into the delegation
50681690
506900:03:53,000 --> 00:03:58,900
5070of control wizard you can begin to make changes that are very difficult to locate later on
50711691
507200:03:59,000 --> 00:04:02,900
5073and even harder to rip out. So I'll show you where the delegation of control wizard is
50741692
507500:04:03,000 --> 00:04:06,900
5076but be careful when you use it in production. And then lastly is a single command here called
50771693
507800:04:07,000 --> 00:04:10,900
5079redircmp that you should be aware of. Because it will do the very handy action of changing
50801694
508100:04:11,000 --> 00:04:17,899
5082the default active directory container from the computers OU to some other organizational unit
50831695
508400:04:18,000 --> 00:04:21,899
5085for new computers that are coming into your active directory. So every time you add a
50861696
508700:04:22,000 --> 00:04:25,899
5088new computer in active directory, if you want that computer to go somewhere else as opposed
50891697
509000:04:26,000 --> 00:04:28,649
5091to the default container, well you can do so with this single command.
50921698
509300:04:28,750 --> 00:00:01,927
5094And I'll show you what the command is and how to use it here in our final task.
50951699
509600:00:02,028 --> 00:00:05,653
5097For our first task here on creating, copying, configuring, and deleting groups in OUs I think
50981700
509900:00:05,753 --> 00:00:11,928
5100it's worthwhile for us to spend just a second or two talking about the academics of groups in active directory.
51011701
510200:00:12,028 --> 00:00:15,927
5103Groups have multiple different types and they also have multiple different scopes so you'll be
51041702
510500:00:16,027 --> 00:00:20,927
5106creating different kinds of groups depending on what you actually need to use that group for.
51071703
510800:00:21,027 --> 00:00:24,927
5109First up are the two different types of groups in active directory, security groups on one side
51101704
511100:00:25,027 --> 00:00:31,927
5112and distribution groups on the other. In every case if you're attempting to use a group for the
51131705
511400:00:32,027 --> 00:00:35,927
5115dissemination of permission or in other words to apply permissions to some folder or other object.
51161706
511700:00:36,027 --> 00:00:39,927
5118You're going to use a security group to do that. The only case where you find yourself using
51191707
512000:00:40,027 --> 00:00:43,927
5121distribution groups is when you're dealing with email and the need to send out the email to a
51221708
512300:00:44,027 --> 00:00:49,927
5124group of users for one reason or another. This differentiation is very simple, so anytime
51251709
512600:00:50,027 --> 00:00:52,927
5127you're dealing with security, you deal with security groups. And anytime you're dealing with email
51281710
512900:00:53,027 --> 00:00:56,927
5130and Microsoft exchange, generally, you're going to deal with distribution groups.
51311711
513200:00:57,027 --> 00:01:00,927
5133Now when it comes to scopes this is where things get a little bit more challenging because the scopes
51341712
513500:01:01,027 --> 00:01:05,928
5136can be a little confusing when you first start out. On the left hand side down here we have
51371713
513800:01:06,028 --> 00:01:11,928
5139global groups and groups can include users, computers, global groups can include other global groups
51401714
514100:01:12,028 --> 00:01:17,928
5142from the same domain. Most often you use global groups to organize users who have similar functions,
51431715
514400:01:18,028 --> 00:01:22,928
5145so your finance group, your IT group, and so on. And so because of that these users will
51461716
514700:01:23,028 --> 00:01:27,928
5148have similar requirements on the network. When you're thinking about the best practice approach
51491717
515000:01:28,028 --> 00:01:32,928
5151for using global groups, you most often assign these to functions in the organization,
51521718
515300:01:33,028 --> 00:01:37,928
5154again, the finance, IT, sales, what have you. This is differentiated from domain local groups,
51551719
515600:01:38,028 --> 00:01:43,928
5157which can also include users, computers, and groups from any domain in the forest.
51581720
515900:01:44,028 --> 00:01:47,928
5160These groups are most often utilized to give permissions to resources and to provide access
51611721
516200:01:48,028 --> 00:01:52,928
5163to resources in the domain where they're located. In most cases you find that domain local groups
51641722
516500:01:53,028 --> 00:01:57,928
5166actually contain global groups so that you organize the users by global groups and you'd
51671723
516800:01:58,028 --> 00:02:01,928
5169organize the resources by domain local groups. I'll talk more about how this works when we
51701724
517100:02:02,028 --> 00:02:07,927
5172get into group nesting here in just a minute. The third group over here on the right is a universal group.
51731725
517400:02:08,027 --> 00:02:11,927
5175So these are kind of a special group that you have to pay careful attention too, because the
51761726
517700:02:12,027 --> 00:02:16,927
5178universal groups and the membership of universal groups is something that's taken care of
51791727
518000:02:17,027 --> 00:02:22,927
5181by any domain controllers that are also global catalogs. And so because of that any change to the
51821728
518300:02:23,027 --> 00:02:26,927
5184membership of a universal group is going to require that membership to be replicated around
51851729
518600:02:27,027 --> 00:02:32,927
5187every global catalog server in your active directory forest. A universal group can include users
51881730
518900:02:33,027 --> 00:02:39,927
5190and groups from any domain in the forest and can be used to grant permissions to any resource in the forest.
51911731
519200:02:40,027 --> 00:02:44,927
5193Now this may automatically make you think that, okay well if I can put in a user or object or what have you
51941732
519500:02:45,027 --> 00:02:49,927
5196in a universal group anywhere in the forest, then I can assign it for any permission anywhere in the forest.
51971733
519800:02:50,027 --> 00:02:52,927
5199Well a universal group would be the thing I should use for everything.
52001734
520100:02:53,027 --> 00:02:57,927
5202But you have to be cautious with these because again the ultimate power that a universal group comes
52031735
520400:02:58,027 --> 00:03:02,927
5205with a cost and that being the replication of the membership of that group.
52061736
520700:03:03,027 --> 00:03:07,927
5208If you find yourself using a lot of universal groups you could find yourself also requiring a lot of
52091737
521000:03:08,027 --> 00:03:12,927
5211replication from domain controller to domain controller. So take care with the use of universal groups
52121738
521300:03:13,027 --> 00:03:17,927
5214and use them in those special circumstances where you'd have multiple domains in the forest
52151739
521600:03:18,027 --> 00:00:01,790
5217and multiple users in those domains or multiple resources that need to integrate together.
52181740
521900:00:01,891 --> 00:00:05,291
5220Now in addition to the groups that you'll be creating as you go through the day to day operations
52211741
522200:00:05,391 --> 00:00:08,791
5223of your active directory infrastructure, they're also a number of built in groups,
52241742
522500:00:08,891 --> 00:00:13,291
5226there are a number of those that are available out-of-the-box. These we've already talked about
52271743
522800:00:13,391 --> 00:00:17,790
5229back in that last module when we're looking at the active directory users and computers console.
52301744
523100:00:17,890 --> 00:00:23,290
5232But I want to show you here back in our machine dc.company.pri, just once again the location
52331745
523400:00:23,390 --> 00:00:27,290
5235where we can take a look at the different groups that exist in active directory.
52361746
523700:00:27,390 --> 00:00:31,290
5238I'm going to pop up here and open up my old favorite ad.console here, active directory users and computers.
52391747
524000:00:31,390 --> 00:00:37,290
5241Although you could use the adac, the active directory administrative center if you preferred to.
52421748
524300:00:37,390 --> 00:00:38,290
5244And if I come down here to our users
52451749
524600:00:38,390 --> 00:00:44,290
5247OU we can take a look again at some of the groups that are available, and in this case mostly right out-of-the-box.
52481750
524900:00:44,390 --> 00:00:50,290
5250Here you can see these groups that are configured as universal groups, as global groups, and as domain local groups.
52511751
525200:00:50,390 --> 00:00:53,290
5253And if we pick any particular one of these, like domain admins for example
52541752
525500:00:53,390 --> 00:00:56,290
5256we can take a look at just some of the characteristics that are associated with these groups.
52571753
525800:00:56,390 --> 00:01:03,290
5259So the group name, the description, any email addresses, the scope of the group, the type of the group,
52601754
526100:01:03,390 --> 00:01:09,291
5262any notes, as well as up here the members of that group and where this group is a member of somewhere else.
52631755
526400:01:09,391 --> 00:01:14,291
5265And then lastly is the ability for us to assign a user or other object that is determined to be
52661756
526700:01:14,391 --> 00:01:19,291
5268the manager of the group. So here for this domain admins group I can click the Change button
52691757
527000:01:19,391 --> 00:01:23,291
5271and identify some user or other security principle that would be the manager of that group
52721758
527300:01:23,391 --> 00:01:28,291
5274with all of the associated information down here. You don't see this happen too terribly often
52751759
527600:01:28,391 --> 00:01:32,291
5277in production environments, but this can be nice if you've got certain groups that you just want
52781760
527900:01:32,391 --> 00:01:37,291
5280to set yourself or a particular user as the person responsible for dealing with this group.
52811761
528200:01:37,391 --> 00:01:40,291
5283Notice how if I click the Change button here and identify myself
52841762
528500:01:40,391 --> 00:01:44,291
5286as a potential manager for the group, one of the other things that I can do is identify
52871763
528800:01:44,391 --> 00:01:49,291
5289whether or not this manager has the privileges of updating the group membership list or not.
52901764
529100:01:49,391 --> 00:01:55,291
5292Now this says that I may be able to give a user, a particular user, that privilege so that they
52931765
529400:01:55,391 --> 00:02:00,291
5295can add and remove members from this group. This is obviously a fairly powerful privilege
52961766
529700:02:00,391 --> 00:02:04,291
5298so you'll want to be careful when you check this box to make sure you only do so in situations
52991767
530000:02:04,391 --> 00:02:10,290
5301where you trust the individual that would be managing the group. I will clear the G Shields user from this list
53021768
530300:02:10,390 --> 00:02:14,290
5304now just to keep our domain admins group relatively pristine at this point.
53051769
530600:02:14,390 --> 00:02:19,290
5307Because while we're here I want to show you also some of the organizational units that exist here in our domain as well.
53081770
530900:02:19,390 --> 00:02:24,290
5310And very specifically I want to show you one difference between what we think of as an organizational
53111771
531200:02:24,390 --> 00:02:29,290
5313unit and what we think of a just an active directory container. And everything about that has to do
53141772
531500:02:29,390 --> 00:02:35,290
5316with these little icons right here on the left. Notice how some of the icons here have a little
53171773
531800:02:35,390 --> 00:02:40,290
5319what is that a box there in the little folder and some of them do not.
53201774
532100:02:40,390 --> 00:02:43,290
5322Those here that have a box next to the folder are different from those that do not
53231775
532400:02:43,390 --> 00:02:49,290
5325because these are technically organizational units as opposed to being active directory containers,
53261776
532700:02:49,390 --> 00:02:54,290
5328just purely containers. Now an organizational unit is a container, but there are some functions
53291777
533000:02:54,390 --> 00:03:01,290
5331you can perform on an organizational unit that you cannot perform on one that is just purely a container.
53321778
533300:03:01,390 --> 00:03:06,290
5334Now it is for that reason that most organizations create a special organizational unit
53351779
533600:03:06,390 --> 00:03:13,290
5337to become the location where users and computers ultimately reside as opposed to the default containers here.
53381780
533900:03:13,390 --> 00:03:18,290
5340Let's say, for example, I wanted to create a new organizational unit I could do so by choosing New OU.
53411781
534200:03:18,390 --> 00:03:24,290
5343And then I could create this organizational unit as, for example, company computers.
53441782
534500:03:24,390 --> 00:03:28,290
5346When I create that OU I have the abilities to protect the container from accidental deletion,
53471783
534800:03:28,390 --> 00:03:33,290
5349this sets a flag on the permissions for that OU that eliminates the abilities to accidently
53501784
535100:03:33,390 --> 00:03:38,290
5352click and delete the entire organizational unit at once. But when I create that OU,
53531785
535400:03:38,390 --> 00:03:42,290
5355notice how this company computers OU now has the little box next to it.
53561786
535700:03:42,390 --> 00:03:46,290
5358And I can then take my servers, if I wanted to, from the default computers container and
53591787
536000:03:46,390 --> 00:03:49,290
5361then move them over here into the company computers organizational unit.
53621788
536300:03:49,390 --> 00:03:54,290
5364So that I then could enjoy all the extra features and benefits that I get out of being a
53651789
536600:03:54,390 --> 00:03:59,290
5367full organizational unit as opposed to a container. Now you may be asking, okay well what are those extra things?
53681790
536900:03:59,390 --> 00:04:04,290
5370The biggest of which is the abilities to assign group policy to this container.
53711791
537200:04:04,390 --> 00:04:08,290
5373Later on when we talk about group policy you'll see how I can create a group policy object and then
53741792
537500:04:08,390 --> 00:04:13,290
5376assign it to a container like this group of company computers. And in fact, we'll be doing that
53771793
537800:04:13,390 --> 00:04:17,290
5379as we start creating those GPOs a little later on. Now that's the process we would go through
53801794
538100:04:17,391 --> 00:04:20,290
5382in order to do all of this work here inside of the graphical user interface.
53831795
538400:04:20,391 --> 00:04:25,290
5385If I needed to create, for example, groups I can do the same thing just like I did before,
53861796
538700:04:25,391 --> 00:04:30,290
5388it's using new group, assigning a name, and then the scope and the type associated with that group.
53891797
539000:04:30,391 --> 00:04:34,290
5391But it's really the PowerShell pieces here that I think are just as important, if not more important,
53921798
539300:04:34,391 --> 00:04:39,290
5394particularly for the exam. So, let's actually flip back over here into our PowerShell console
53951799
539600:04:39,391 --> 00:04:44,290
5397and take a look at the process by which we would accomplish these tasks inside of PowerShell.
53981800
539900:04:44,391 --> 00:04:47,290
5400And in fact before we get into actually typing in commands into our PowerShell prompt
54011801
540200:04:47,391 --> 00:04:52,290
5403let's take a look at just some of the basic commandlets that you got to know here
54041802
540500:04:52,391 --> 00:04:56,290
5406that are associated with group and organizational unit management.
54071803
540800:04:56,391 --> 00:04:59,290
5409I want to bring up first this slide that we took a look at back in that last module
54101804
541100:04:59,391 --> 00:05:03,290
5412which had to do with automating the creation of active directory accounts.
54131805
541400:05:03,391 --> 00:05:07,290
5415And we already looked at all these commandlets that relate to creating computer and user accounts
54161806
541700:05:07,391 --> 00:05:12,290
5418in our domain. And I bring this up because they very much mirror the same kinds of commands
54191807
542000:05:12,391 --> 00:05:17,290
5421that we would use for automating the creation and removal of active directory groups.
54221808
542300:05:17,391 --> 00:05:21,290
5424So on the group side we could use the get ADGroup command to get information about a particular group.
54251809
542600:05:21,391 --> 00:05:26,290
5427And then new and remove ADGroup to create a group and remove a group.
54281810
542900:05:26,391 --> 00:05:31,290
5430We could use the add and remove ADGroup Member commandlet to add and remove members from
54311811
543200:05:31,391 --> 00:05:35,290
5433that group that we just created. Over on the organizational unit side we can use
54341812
543500:05:35,391 --> 00:05:40,290
5436Get-ADOrganizationalUnit to get information about an OU and then new and remove
54371813
543800:05:40,391 --> 00:05:46,290
5439to create or remove an OU from our domain. Fairly basic stuff here obviously,
54401814
544100:05:46,391 --> 00:05:50,290
5442but I wanted to bring this up to give you an idea of the mapping between how the commandlets
54431815
544400:05:50,391 --> 00:05:56,290
5445look on the group side and the OU side in comparison with how they look on the user side and the computer side.
54461816
544700:05:56,391 --> 00:05:59,290
5448So let's flip back here into Windows PowerShell and actually go through creating some
54491817
545000:05:59,391 --> 00:06:04,290
5451objects here in our active directory domain. Let's start with a new organizational unit
54521818
545300:06:04,391 --> 00:06:10,290
5454similar to the company computers OU that we created, but in this case we will do company users.
54551819
545600:06:10,391 --> 00:06:17,290
5457So I'll choose New-ADOrganizationalUnit and let's call this company users as the new OU that we'll be creating.
54581820
545900:06:17,391 --> 00:06:22,290
5460In this OU we'll need to go about moving our active directory user accounts into the new location.
54611821
546200:06:22,391 --> 00:06:26,290
5463We also perhaps want to create new groups in that location as well, which we could do
54641822
546500:06:26,391 --> 00:06:34,290
5466with New-ADGroup. Let's create a new group here for the individuals in our organization
54671823
546800:06:34,391 --> 00:06:39,290
5469who are extremely untrusted people. We were joking about this back in the last module
54701824
547100:06:39,391 --> 00:06:44,290
5472about our Jason account and our Don Jones account, as being extremely untrusted users
54731825
547400:06:44,391 --> 00:06:51,290
5475in our active directory domain. So let's create that group and we'll call it extremely untrusted users,
54761826
547700:06:51,391 --> 00:06:56,290
5478if I can spell it correctly. That group, extremely untrusted users, we then need to set the
54791827
548000:06:56,391 --> 00:07:03,290
5481groups scope here as a global group, as opposed to a domain local group or universal group.
54821828
548300:07:03,391 --> 00:07:08,290
5484And then I want to set the path also on the group to the correct location here in active directory
54851829
548600:07:08,391 --> 00:07:12,290
5487where we want to create the group. This path needs to be setup using ldap language,
54881830
548900:07:12,391 --> 00:07:22,290
5490so I do I ou=Company, oops, Company Users, and then dc=Company and then dc=pri
54911831
549200:07:22,391 --> 00:07:28,290
5493that should path this group into the company users organizational unit that we created just a second ago.
54941832
549500:07:28,391 --> 00:07:32,290
5496It looks like I created everything correctly there and let's go ahead and verify that everything
54971833
549800:07:32,391 --> 00:07:36,290
5499is correct up here in our active directory users and computers console.
55001834
550100:07:36,391 --> 00:07:40,290
5502I'll refresh things here in company.pri and there is our company users OU that
55031835
550400:07:40,391 --> 00:07:46,290
5505we created and our extremely untrusted users security group that we also just created.
55061836
550700:07:46,391 --> 00:07:47,290
5508Let's complete the process by adding
55091837
551000:07:47,391 --> 00:07:52,290
5511in those terrible users into this extremely untrusted users group.
55121838
551300:07:52,391 --> 00:08:01,290
5514So Add-ADGroupMember and then Extremely Untrusted Users as the group name.
55151839
551600:08:01,391 --> 00:08:07,290
5517And then the two people that we want to add into this group would be our Jason user and our Don Jones user.
55181840
551900:08:07,391 --> 00:08:08,290
5520If everything's been done correctly here
55211841
552200:08:08,391 --> 00:08:15,290
5523I can come back to the group and verify that the group members of this group are indeed Jason and Don.
55241842
552500:08:15,391 --> 00:08:19,290
5526So this gives you an idea of really the simplicity of using the PowerShell commandlets here
55271843
552800:08:19,391 --> 00:08:25,290
5529for adding and removing users from groups. And if you had to deal with the risk torture activity
55301844
553100:08:25,391 --> 00:08:27,290
5532that is dealing around and clicking around here
55331845
553400:08:27,391 --> 00:08:32,290
5535in the active directory users and computers console, you'll definitely appreciate using PowerShell
55361846
553700:08:32,390 --> 00:00:01,579
5538and your fingers to accomplish the task as opposed to your wrists.
55391847
554000:00:01,679 --> 00:00:05,580
5541Everything about dealing with groups seems relatively easy until you start to realize just
55421848
554300:00:05,679 --> 00:00:09,580
5544how many possible groups you could potentially create in your organization.
55451849
554600:00:09,679 --> 00:00:13,580
5547I mean if you think about just the different, I don't know, the different departments that exist
55481850
554900:00:13,679 --> 00:00:19,579
5550in your prototypical company, your sales and your finance and your executives, those are, at least, the start.
55511851
555200:00:19,679 --> 00:00:23,579
5553But then as you start moving into ever more complex structures, you start needing to
55541852
555500:00:23,679 --> 00:00:29,579
5556do things for individual, perhaps, groups within those groups. Maybe inside of sales there's
55571853
555800:00:29,679 --> 00:00:33,579
5559inside sales and outside sales and even inside of inside of sales there's the inside sales team
55601854
556100:00:33,679 --> 00:00:39,579
5562that has to do with project X and the inside sales team that has to deal with project Y.
55631855
556400:00:39,679 --> 00:00:42,579
5565And so because of that you can almost tell the age of an active directory infrastructure
55661856
556700:00:42,679 --> 00:00:48,579
5568by the sheer number of groups that exist. It is rare that you ever find yourself removing groups.
55691857
557000:00:48,679 --> 00:00:52,579
5571Instead all too often, you just create new groups for every new need.
55721858
557300:00:52,679 --> 00:00:57,579
5574Now Microsoft actually has, kind of, best practice approach for configuring the nesting of
55751859
557600:00:57,679 --> 00:01:02,579
5577one type of group into another, but however, when you start poking around in different organizations
55781860
557900:01:02,679 --> 00:01:06,580
5580you find that not a lot of organizations actually use this group nesting.
55811861
558200:01:06,680 --> 00:01:10,580
5583So I'm going to show you the best practices approach and then I'm going to tell what I've
55841862
558500:01:10,680 --> 00:01:14,580
5586seen in the world and you can choose to do it via the best practices approach or via the
55871863
558800:01:14,680 --> 00:01:20,580
5589not entirely great, but what seems to be the in practice approach just about everywhere.
55901864
559100:01:20,680 --> 00:01:24,580
5592If you follow Microsoft's recommendation, your users go in global groups.
55931865
559400:01:24,680 --> 00:01:29,580
5595And so global groups define the different types of functions that users may participate in,
55961866
559700:01:29,680 --> 00:01:36,580
5598so finance, sales, IT, inside sales, and what have you. Those global groups are then supposed
55991867
560000:01:36,680 --> 00:01:41,580
5601to go into domain local groups. And it is the domain local groups that constrain
56021868
560300:01:41,680 --> 00:01:46,580
5604the types of accesses that people should have access to. For that reason you assign
56051869
560600:01:46,680 --> 00:01:51,580
5607permissions then to the domain local groups. This separation of who you are, the global group,
56081870
560900:01:51,680 --> 00:01:56,580
5610from what you should access, the domain local group, helps ensure that you don't end up giving
56111871
561200:01:56,680 --> 00:02:02,580
5613the right group the wrong access. Now you might be thinking, why in the world would I do this?
56141872
561500:02:02,680 --> 00:02:07,580
5616If you think about the group, the only real way you have to determine what that group is
56171873
561800:02:07,680 --> 00:02:13,580
5619has to do with the name. And then identifying where those groups are actually applied
56201874
562100:02:13,680 --> 00:02:17,580
5622can get very difficult, as your number of servers goes up and the number of possible places
56231875
562400:02:17,680 --> 00:02:23,580
5625where permissions can get assigned goes up. And so separating out the functions, who a person is
56261876
562700:02:23,680 --> 00:02:28,580
5628from the locations, where they need access, can help ensure that you don't end up putting the
56291877
563000:02:28,680 --> 00:02:33,580
5631right person in the wrong place. Particularly when the only thing you have to go on
56321878
563300:02:33,680 --> 00:02:38,580
5634is the name of the group itself. The acronym that I learned a thousand years ago for this
56351879
563600:02:38,680 --> 00:02:44,580
5637was UGLA or users going to global groups, global groups go into local groups, and local groups
56381880
563900:02:44,680 --> 00:02:48,580
5640get assigned permissions. There are other acronyms out there that essentially say the same thing,
56411881
564200:02:48,680 --> 00:02:54,580
5643but it's the UGLA acronym that I remember from the earliest days of studying for my first MCSE.
56441882
564500:02:54,680 --> 00:03:00,580
5646Now I told you that in the real world you don't often see the UGLA approach implemented in its entirety.
56471883
564800:03:00,680 --> 00:03:05,580
5649And that is as we've moved towards more of a single domain, single forest model for a lot of
56501884
565100:03:05,680 --> 00:03:10,580
5652organizations, the difference between global groups and domain local groups become less relevant.
56531885
565400:03:10,680 --> 00:03:16,580
5655Remember that a global group can only include objects from the same domain, whereas a domain object
56561886
565700:03:16,680 --> 00:03:21,580
5658can include objects from any domain in the forest. And so when you get into that single domain,
56591887
566000:03:21,680 --> 00:03:26,580
5661single forest infrastructure, the domain local group and the global group are kind of
56621888
566300:03:26,680 --> 00:03:30,580
5664almost sort of the same thing, because there are no other domains in the forest.
56651889
566600:03:30,680 --> 00:03:35,580
5667And so in production, sometimes you will see just the exclusive use of global groups
56681890
566900:03:35,680 --> 00:03:40,580
5670as the mechanism for defining permissions and categorizing users. I am by no means suggesting that this
56711891
567200:03:40,680 --> 00:03:45,580
5673is the best approach, but it is one that you see commonly in a lot of organizations.
56741892
567500:03:45,680 --> 00:03:46,580
5676Now let me show you an example of where this can
56771893
567800:03:46,680 --> 00:03:52,580
5679actually make things go awry. Let's talk about just different global groups existing in other groups.
56801894
568100:03:52,680 --> 00:03:55,580
5682So back here in our list of users we have that domain
56831895
568400:03:55,680 --> 00:04:01,580
5685admin security group, this is the global group. And we also have back here under company users
56861896
568700:04:01,680 --> 00:04:06,580
5688the extremely untrusted users that we created. Let's say that you don't implement
56891897
569000:04:06,680 --> 00:04:11,580
5691things using a best practice approach and you use your global groups for a variety of different purposes.
56921898
569300:04:11,680 --> 00:04:15,580
5694And when you do that, let's say that someone for one reason or another
56951899
569600:04:15,680 --> 00:04:19,579
5697gets a request to add in to the domain admins group another group.
56981900
569900:04:19,680 --> 00:04:23,579
5700Somebody calls into the help desk and says, hey you know what I need to get access to the
57011901
570200:04:23,680 --> 00:04:27,579
5703domain admins group and can you just add in this other group as a member of domain admins,
57041902
570500:04:27,680 --> 00:04:34,579
5706the extremely untrusted users group here. Now this is an obvious example of something
57071903
570800:04:34,680 --> 00:04:37,579
5709you wouldn't want to do, but I'm guessing in your active directory domain you don't
57101904
571100:04:37,680 --> 00:04:45,579
5712have a group called extremely untrusted users. That might be the inside sales admin team,
57131905
571400:04:45,680 --> 00:04:50,079
5715or something else that may not be very well worded. So I want to just kind of show you
57161906
571700:04:50,180 --> 00:04:54,079
5718how remarkably easy it can be based off of group nesting for the
57191907
572000:04:54,180 --> 00:05:00,079
5721wrong group to end up a member of the wrong group. When this happens it can be phenomenally
57221908
572300:05:00,180 --> 00:00:01,568
5724difficult to figure out what went wrong and why people have access to the wrong resources.
57251909
572600:00:01,669 --> 00:00:05,869
5727Now thankfully PowerShell comes riding to the rescue when it comes time to actually enumerate
57281910
572900:00:05,969 --> 00:00:10,868
5730users in these variety of groups that we've created. Back in the oldest of days trying to figure
57311911
573200:00:10,968 --> 00:00:15,868
5733out which users were in which groups could involve some complex coculus with commands like
57341912
573500:00:15,968 --> 00:00:21,868
5736DSGet and DSQuery, the old net group command as well. There were even some relatively complex
57371913
573800:00:21,969 --> 00:00:26,868
5739VB scripts that you could create or even using the iCacls command or the Xcacls command
57401914
574100:00:26,969 --> 00:00:31,868
5742to try to figure out where groups and permissions were assigned and who was in what group.
57431915
574400:00:31,969 --> 00:00:35,868
5745Thankfully PowerShell these days does a better job of centralizing all these different tools
57461916
574700:00:35,969 --> 00:00:39,868
5748into a single framework that we can use for enumerating group membership.
57491917
575000:00:39,969 --> 00:00:43,868
5751Let's assume we have a couple of different questions that we need to answer based partially
57521918
575300:00:43,969 --> 00:00:48,868
5754on that accidental group addition that we just did back on that last clip.
57551919
575600:00:48,969 --> 00:00:54,868
5757So what kinds of questions would we need to ask? Maybe what users are members of the domain admins group?
57581920
575900:00:54,969 --> 00:00:58,868
5760So maybe I need to know, alright well who's in domain admins? Or I need to know membership
57611921
576200:00:58,969 --> 00:01:03,868
5763for a particular user in which groups is Jason Helmick a member?
57641922
576500:01:03,969 --> 00:01:09,868
5766Or even more importantly, is Jason Helmick accidently or purposefully a nested member of
57671923
576800:01:09,968 --> 00:01:14,868
5769a certain group, like domain admins? Remember that when we created that extremely untrusted users
57701924
577100:01:14,968 --> 00:01:18,868
5772group we added Jason to that group because we don't trust the guy.
57731925
577400:01:18,968 --> 00:01:24,868
5775And we don't want him a member of domain admins not by direct membership,
57761926
577700:01:24,968 --> 00:01:29,868
5778but by indirect membership through his membership in the extremely untrusted users group.
57791927
578000:01:29,968 --> 00:01:32,868
5781So these are the different kinds of questions you may have to think about when it comes
57821928
578300:01:32,968 --> 00:01:36,868
5784time to really think about your group membership in your domain.
57851929
578600:01:36,968 --> 00:01:40,868
5787Let's talk about some of the ways using PowerShell that we can go through answering these
57881930
578900:01:40,968 --> 00:01:45,868
5790questions and ensuring that the wrong person stays out of the domain admins group.
57911931
579200:01:45,968 --> 00:01:47,868
5793Let me go ahead and minimize this and we'll
57941932
579500:01:47,968 --> 00:01:51,868
5796come back here to our active directory users and computers console, in fact let me instead go here
57971933
579800:01:51,968 --> 00:01:57,868
5799over directly to PowerShell. So that we can run a couple of these commands and see, number one
58001934
580100:01:57,968 --> 00:02:04,868
5802who is a member of the domain admins group. The command I'm going to show you here is Get-AdGroupMember.
58031935
580400:02:04,968 --> 00:02:09,868
5805And the Get-ADGroupMember command will allow me to see the membership of domain admins.
58061936
580700:02:09,968 --> 00:02:13,868
5808Now I'm going to pipe this to a table and just show the names here so we can see who is
58091937
581000:02:13,968 --> 00:02:18,868
5811a member of the domain admins group. Looks like administrator is, Greg Shields is, and this
58121938
581300:02:18,968 --> 00:02:24,868
5814interesting one here called extremely untrusted users. Now this can be perhaps not as
58151939
581600:02:24,968 --> 00:02:29,868
5817obvious as it might seem, remember it's none the likely that you would have an extremely untrusted users
58181940
581900:02:29,968 --> 00:02:34,868
5820group in your active directory domain, it might say something else.
58211941
582200:02:34,968 --> 00:02:39,868
5823So the direct membership of the domain admins group using just this command may be insufficient
58241942
582500:02:39,968 --> 00:02:44,868
5826for helping us ensure the wrong person's not in this group. Let's go a different route,
58271943
582800:02:44,968 --> 00:02:48,868
5829let's go from the completely opposite direction. We know that Jason's a really bad guy
58301944
583100:02:48,968 --> 00:02:53,868
5832and so we want to see what kinds of groups he is a member of. Let's take a look at that,
58331945
583400:02:53,968 --> 00:03:00,868
5835so Get-ADPrincipalGroupMembership for the Jason user and then let me do that into a table also,
58361946
583700:03:00,968 --> 00:03:06,868
5838so that we can see which groups Jason is a direct member of. According to this,
58391947
584000:03:06,968 --> 00:03:12,868
5841Jason is a member of the domain users and the extremely untrusted users group.
58421948
584300:03:12,968 --> 00:03:16,868
5844Which is handy for helping us understand what groups Jason is a member of, at least directly,
58451949
584600:03:16,968 --> 00:03:21,868
5847but doesn't necessarily give us all the information to trigger that red flag in the back of
58481950
584900:03:21,968 --> 00:03:25,868
5850our mind that, oops Jason might be a domain admin by accident.
58511951
585200:03:25,968 --> 00:03:29,868
5853And so there's a third command here that I want to show you that's a little bit more complicated
58541952
585500:03:29,968 --> 00:03:36,868
5856using Get-ADUser where we can do a recursive match for a particular group and then trace
58571953
585800:03:36,968 --> 00:03:41,868
5859backwards for the users who are members of groups who are members of the group I'm interested in.
58601954
586100:03:41,968 --> 00:03:46,868
5862This would be the indirect membership of a group, like domain admins.
58631955
586400:03:46,968 --> 00:03:53,868
5865So let me do Get-, Get-ADUser and then I'm going to do a filter for this on a member of.
58661956
586700:03:53,968 --> 00:04:05,868
5868I'm going to do a recursive match, recursive match, against cn=domainadmins, cn=users,
58691957
587000:04:05,968 --> 00:04:12,868
5871and then dc=company, and then dc=pri and then I'll take the results of that and then
58721958
587300:04:12,968 --> 00:04:17,868
5874pipe that also into a table against the user name. So it's this filter which will allow me
58751959
587600:04:17,968 --> 00:04:21,868
5877to then do that recursive match against the domain admins and then all the membership
58781960
587900:04:21,968 --> 00:04:25,868
5880of all the groups that happen to be in the domain admins group, so that I can find out,
58811961
588200:04:25,968 --> 00:04:32,868
5883ah oh, Jason Helmick and also even Don Jones are a member of domain admins through indirect membership.
58841962
588500:04:32,968 --> 00:04:35,868
5886So these different commands here can be really helpful in ensuring that the right people
58871963
588800:04:35,968 --> 00:04:40,868
5889end up in the right group. And rather than just show them to you, I wanted to give you an example
58901964
589100:04:40,968 --> 00:00:01,721
5892of where you might actually use these to ensure that the wrong person doesn't end up in the wrong location.
58931965
589400:00:01,822 --> 00:00:05,222
5895Now while you won't find yourself doing this all too often, occasionally you create groups
58961966
589700:00:05,322 --> 00:00:09,721
5898in a way that was not really the way you intended to and you might find yourself needing to
58991967
590000:00:09,821 --> 00:00:13,922
5901convert a group from one type to another or from one scope to another.
59021968
590300:00:14,022 --> 00:00:17,221
5904Well thankfully in later versions of the operating system, actually very later versions of the
59051969
590600:00:17,321 --> 00:00:22,221
5907operating system, you have the ability to convert certain types of groups into other
59081970
590900:00:22,321 --> 00:00:27,221
5910certain types of groups. But, and this is a caveat, other types you can't.
59111971
591200:00:27,321 --> 00:00:30,221
5913Let's take a look at those you can as opposed to those you can't.
59141972
591500:00:30,321 --> 00:00:34,222
5916For our first possibility it is possible to take domain local groups and global groups
59171973
591800:00:34,322 --> 00:00:40,222
5919and convert them into universal groups. It is similarly possible to take a universal group
59201974
592100:00:40,322 --> 00:00:45,222
5922and convert it into a domain local or a global group. However it is not possible to take
59231975
592400:00:45,322 --> 00:00:51,222
5925a domain local group and convert it to a global or to take a global and convert it to a domain local.
59261976
592700:00:51,322 --> 00:00:54,222
5928So they're a couple things you can do and a couple of things you can't do when it comes
59291977
593000:00:54,322 --> 00:00:58,222
5931to converting these groups from one type to another. Now I want to show you just here
59321978
593300:00:58,322 --> 00:01:03,222
5934back in our active directory users and computers console, just the fact that when I create a group
59351979
593600:01:03,322 --> 00:01:05,222
5937so back up here under company users
59381980
593900:01:05,322 --> 00:01:06,222
5940here's our extremely untrusted users
59411981
594200:01:06,322 --> 00:01:11,222
5943group. I could, down here, just check the box to switch between global and universal
59441982
594500:01:11,322 --> 00:01:16,222
5946or security to distribution. Doing so would change the structure of the group and the functionality
59471983
594800:01:16,322 --> 00:01:20,222
5949of the group. Switching from global to universal would then populate all this information
59501984
595100:01:20,322 --> 00:01:25,222
5952into my global catalog servers and the membership into my global catalog servers.
59531985
595400:01:25,322 --> 00:01:30,222
5955Over here changing from security to distribution would facilitate this being an email group
59561986
595700:01:30,322 --> 00:01:34,222
5958as opposed to a security group. Now there are a couple of ways here in PowerShell, because we got to
59591987
596000:01:34,322 --> 00:01:35,222
5961talk about all the
59621988
596300:01:35,322 --> 00:01:39,222
5964PowerShell here, there are a couple of ways in which you can use PowerShell to go about doing
59651989
596600:01:39,322 --> 00:01:46,222
5967this conversion as well. Let's say, for example, that I'm going about happily creating new groups
59681990
596900:01:46,322 --> 00:01:54,222
5970here using Windows PowerShell, so My Universal Distribution Group, there, there's a new group that I created.
59711991
597200:01:54,322 --> 00:01:58,222
5973And the group scope for this, I'm going to create it as a global group, whoops, by accident.
59741992
597500:01:58,322 --> 00:02:00,222
5976Gosh wait a minute, I just created that group and now
59771993
597800:02:00,322 --> 00:02:02,222
5979if I take a look down here
59801994
598100:02:02,322 --> 00:02:07,222
5982under users and then refresh things, I've created my universal distribution group
59831995
598400:02:07,322 --> 00:02:10,222
5985as a global security group. Let's go back here
59861996
598700:02:10,322 --> 00:02:16,222
5988to PowerShell and then fix the problem that we just created. Let me instead of New-ADGroup,
59891997
599000:02:16,322 --> 00:02:22,222
5991let me instead get the adgroup that I just created, so Get-ADGroup.
59921998
599300:02:22,322 --> 00:02:25,222
5994If we take a look at that, well there's the information about the group and I can see here
59951999
599600:02:25,322 --> 00:02:29,222
5997that the scope is set to global and the category is set to security.
59982000
599900:02:29,322 --> 00:02:35,222
6000Let's make some changes. Let me do Set-ADGroup and then I'm going to set the groups scope
60012001
600200:02:35,322 --> 00:02:40,222
6003there's my group scope, over to universal, okay that should fix that.
60042002
600500:02:40,322 --> 00:02:45,222
6006And then I'll set my group category from a security group here to a distribution group
60072003
600800:02:45,322 --> 00:02:50,222
6009which I would do by entering a zero in here to set it over to a distribution group.
60102004
601100:02:50,322 --> 00:02:55,222
6012Once I'm done with that, let's go back up here to get the group then, so Get-ADGroup
60132005
601400:02:55,322 --> 00:02:58,222
6015and as you can see now we have a universal distribution group exactly the one
60162006
601700:02:58,322 --> 00:03:01,722
6018that we were looking for when we initially created the group the first time.
60192007
602000:03:01,822 --> 00:03:05,722
6021And back over here, in fact yep there's the group scope and there's the group type,
60222008
602300:03:05,822 --> 00:00:01,550
6024now as a universal distribution group.
60252009
602600:00:01,651 --> 00:00:06,551
6027Now everything we've talked about up to this point has to do with groups that exist on the domain controller.
60282010
602900:00:06,650 --> 00:00:10,551
6030We're dealing with global groups on that dc, we're dealing with domain local groups
60312011
603200:00:10,650 --> 00:00:16,050
6033that also exist on that domain controller. But we haven't really talked much about local groups.
60342012
603500:00:16,150 --> 00:00:20,050
6036We discussed them earlier back when we were talking about users and we also took a look
60372013
603800:00:20,150 --> 00:00:24,050
6039here on a particular server like this machine file1, just to see the local groups,
60402014
604100:00:24,150 --> 00:00:29,050
6042not domain local, but local groups that exist on every Windows server that we may have.
60432015
604400:00:29,150 --> 00:00:34,051
6045What I want to show you here is that if on this machine file1, if we come here to tools and to
60462016
604700:00:34,151 --> 00:00:36,051
6048computer management,
60492017
605000:00:36,151 --> 00:00:38,051
6051we can take a look at that list of local users
60522018
605300:00:38,151 --> 00:00:42,051
6054and groups that exists on a machine. Here under the list of groups are all those
60552019
605600:00:42,151 --> 00:00:48,051
6057that exist for this machine and I would then potentially take a global group from my domain
60582020
605900:00:48,151 --> 00:00:53,051
6060or even a domain local group, and add it in here into my local group on this machine
60612021
606200:00:53,151 --> 00:00:59,051
6063to provide a group of active directory users, the permissions to accomplish one of these variety of tasks.
60642022
606500:00:59,151 --> 00:01:04,051
6066Now as you can imagine, this gets somewhat cumbersome over time. If you think about the
60672023
606800:01:04,150 --> 00:01:08,051
606920 or 30 or 40 servers that you may need to control, well making sure that the right
60702024
607100:01:08,150 --> 00:01:10,051
6072people get in the administrators group or the backup
60732025
607400:01:10,150 --> 00:01:16,051
6075operators group, is something that can be overwhelming when you start having to do it on every single machine
60762026
607700:01:16,150 --> 00:01:23,051
6078using the manual approach. And so for that reason, Microsoft provides with group policy
60792027
608000:01:23,150 --> 00:01:27,051
6081the abilities to define which user should go in which groups via a group policy object,
60822028
608300:01:27,150 --> 00:01:32,051
6084as opposed to having to do this the manual way. Let's flip back over here to my machine
60852029
608600:01:32,150 --> 00:01:36,051
6087dc because on this machine I have an access to the group policy management
60882030
608900:01:36,150 --> 00:01:40,051
6090console. And I'm going to just edit here the default domain policy, but I would not do this
60912031
609200:01:40,150 --> 00:01:45,051
6093again in production unless you're sure you want this to go to every single machine in your domain.
60942032
609500:01:45,150 --> 00:01:49,051
6096What I want to show you here is that under the default domain policy, if I go down here to policies
60972033
609800:01:49,150 --> 00:01:53,051
6099in Windows settings, and then if I take a look at security settings, there's an item down
61002034
610100:01:53,150 --> 00:02:00,051
6102here called restricted groups. Which allows me to enter in one or more groups that I may wish to control.
61032035
610400:02:00,150 --> 00:02:05,051
6105Let's say that the group I'm interested in controlling is the administrators group.
61062036
610700:02:05,150 --> 00:02:07,051
6108If I enter that in,
61092037
611000:02:07,150 --> 00:02:12,051
6111this will give me the abilities to define the members of this group, up here at the top,
61122038
611300:02:12,151 --> 00:02:16,051
6114and the fact that this group is a member of other groups down here at the bottom.
61152039
611600:02:16,151 --> 00:02:20,051
6117So, for example, if I wanted to define the members of a group, I could define the members of the group
61182040
611900:02:20,151 --> 00:02:28,051
6120as being the domain admins group. Setting domains admins here to the administrators group
61212041
612200:02:28,151 --> 00:02:34,051
6123will ensure that the domain admins global group ends up as a member of the administrators
61242042
612500:02:34,151 --> 00:02:39,051
6126local group on each machine where this active directory group policy object applies.
61272043
612800:02:39,151 --> 00:02:43,051
6129You see this commonly done to ensure that the IT group ends up being an administrator so that
61302044
613100:02:43,151 --> 00:02:47,051
6132the backup operators group gets put in the proper location on local machines.
61332045
613400:02:47,151 --> 00:02:52,051
6135But anytime you've got those custom groups that may not necessarily be domain admins
61362046
613700:02:52,151 --> 00:02:57,051
6138that are, you know, any of the default groups out-of-the-box, this tool here with group policy
61392047
614000:02:57,151 --> 00:03:01,551
6141allows you to then deploy out all of your custom groups. Out to all the servers and potentially
61422048
614300:03:01,651 --> 00:00:01,979
6144desktops that exist in your active directory domain.
61452049
614600:00:02,079 --> 00:00:05,979
6147I find it funny sometimes when walking into different organizations and taking a look at their
61482050
614900:00:06,078 --> 00:00:12,979
6150active directory structure and finding every person in the IT department a member of the domain admins group.
61512051
615200:00:13,079 --> 00:00:17,978
6153Well you see that happen in a lot of places, you see also users that just use the administrator
61542052
615500:00:18,079 --> 00:00:20,978
6156account anytime they're trying to do something with advanced privileges.
61572053
615800:00:21,079 --> 00:00:25,978
6159And all of these are examples of terrible security and terrible auditing ability
61602054
616100:00:26,079 --> 00:00:30,978
6162for any of the users that might be doing things. In a well-run organization,
61632055
616400:00:31,079 --> 00:00:35,978
6165it's better to create separate groups that users are a member of so that you can
61662056
616700:00:36,079 --> 00:00:41,478
6168discreetly identify the tasks that a person should do. As opposed to giving every single
61692057
617000:00:41,579 --> 00:00:45,478
6171person complete keys to the kingdom. This is an example of delegation of control,
61722058
617300:00:45,579 --> 00:00:49,478
6174so being able to define specifically what a group of users should be able to do,
61752059
617600:00:49,579 --> 00:00:54,478
6177whether or not they're a member of IT or not. So let's say, for example, in this example
61782060
617900:00:54,579 --> 00:00:58,478
6180of delegation of control that we're taking a look at this company users organizational unit
61812061
618200:00:58,579 --> 00:01:03,478
6183that we created earlier. And the idea here being that this company users OU
61842062
618500:01:03,579 --> 00:01:06,478
6186should be the location where all of our regular users end up being located.
61872063
618800:01:06,578 --> 00:01:11,478
6189So the Jason account, the Don account, and the Greg Shields account.
61902064
619100:01:11,578 --> 00:01:15,478
6192I move these over here and then complete this process, now I've got what
61932065
619400:01:15,578 --> 00:01:21,478
6195is effectively an organization full of users, also user groups.
61962066
619700:01:21,578 --> 00:01:26,478
6198Let's say also that I've created a group here called IT and rather than giving just
61992067
620000:01:26,578 --> 00:01:32,478
6201domain admins privileges to create users in this organizational unit and to change the membership of
62022068
620300:01:32,578 --> 00:01:38,478
6204things in this OU. I really want to dial it down so that I have a subset of people
62052069
620600:01:38,578 --> 00:01:42,478
6207that are perhaps not extremely untrusted, but that are partially trusted.
62082070
620900:01:42,578 --> 00:01:46,478
6210Not so much at the domain admin level, but at a level that is commensurate with the
62112071
621200:01:46,578 --> 00:01:51,478
6213types of things that they need to do. Maybe this is the help desk, you know the IT help desk
62142072
621500:01:51,578 --> 00:01:54,478
6216that needs to add and remove people from groups and just create accounts.
62172073
621800:01:54,578 --> 00:01:58,478
6219When this is the case, and it really should be the case in every situation,
62202074
622100:01:58,578 --> 00:02:01,478
6222one of the ways in which I can provide that access is by running what is called
62232075
622400:02:01,578 --> 00:02:06,478
6225the delegation of control wizard. Now earlier, when we introduced this whole module,
62262076
622700:02:06,578 --> 00:02:09,479
6228I mentioned that you have to be very careful with this delegation of control wizard.
62292077
623000:02:09,579 --> 00:02:14,479
6231Because it can be very difficult to locate and then rip out any of the delegation of control
62322078
623300:02:14,579 --> 00:02:19,479
6234that you create using the wizard. So I'm going to show you how this works, but be very careful
62352079
623600:02:19,579 --> 00:02:24,479
6237anytime you go about making any changes here, because locating what you've changed
62382080
623900:02:24,579 --> 00:02:28,479
6240can be really challenging and I'll show you why here in a just second.
62412081
624200:02:28,579 --> 00:02:30,479
6243Let me choose the next button, because what I want to do here
62442082
624500:02:30,579 --> 00:02:38,479
6246is for the company users organizational unit, I want to give my IT group access to perform various tasks.
62472083
624800:02:38,579 --> 00:02:44,479
6249So let me add in here the IT group, that's my group. And then the tasks that I want that IT
62502084
625100:02:44,579 --> 00:02:49,479
6252group to perform are these following common tasks, like creating, deleting, and managing user accounts
62532085
625400:02:49,579 --> 00:02:55,479
6255resetting the passwords, reading the user information. And then managing the groups that are
62562086
625700:02:55,579 --> 00:03:01,479
6258also existing here inside of this organizational unit. I could further come down here
62592087
626000:03:01,579 --> 00:03:05,479
6261and create custom tasks to delegate as well, however, this gets really complex and
62622088
626300:03:05,579 --> 00:03:09,479
6264just the sheer number of possible tasks that you can enable or disable.
62652089
626600:03:09,579 --> 00:03:13,479
6267So we'll keep things relatively easy here with just the common tasks that I would want to give
62682090
626900:03:13,579 --> 00:03:18,479
6270that subset of users that are not domain admin caliber, but still need to be able to work
62712091
627200:03:18,579 --> 00:03:22,479
6273within this organizational unit. If I choose Next and choose
62742092
627500:03:22,579 --> 00:03:28,479
6276Finish I've now gone through and provided the delegation of control to that IT group.
62772093
627800:03:28,579 --> 00:03:31,479
6279Now as I said, the hard part is finding this stuff after you've applied it.
62802094
628100:03:31,579 --> 00:03:35,479
6282And so let me show you here if I bring up the advanced view, the advanced features
62832095
628400:03:35,579 --> 00:03:40,479
6285here in active directory users and computers. So that we can take a look at more or less
62862096
628700:03:40,579 --> 00:03:45,479
6288what we've just done. Once I turn on the advance features here and go back to view properties,
62892097
629000:03:45,579 --> 00:03:50,479
6291there are a number of additional tabs that appear here in the list for my organizational unit.
62922098
629300:03:50,579 --> 00:03:56,479
6294And again over for any groups that I may create. The important one here is the security tab.
62952099
629600:03:56,579 --> 00:04:00,479
6297Which you can see here we now have a group called IT that has some special permissions that have
62982100
629900:04:00,579 --> 00:04:04,479
6300been assigned down here at the bottom. Those special
63012101
630200:04:04,579 --> 00:04:09,479
6303permissions, relatively difficult to find because as you look down here it's create/delete group objects,
63042102
630500:04:09,579 --> 00:04:15,479
6306create/delete user objects, full control on the various items that we've configured for this group.
63072103
630800:04:15,579 --> 00:04:19,478
6309So pay careful attention anytime you're using that delegation of control wizard because it will
63102104
631100:04:19,579 --> 00:04:24,478
6312go about creating a variety of additional permissions that exist here in the list.
63132105
631400:04:24,579 --> 00:04:26,478
6315But also recognize that trying to figure out
63162106
631700:04:26,579 --> 00:04:30,478
6318exactly what you've done is something you might want to document as you're going through the process.
63192107
632000:04:30,579 --> 00:04:32,478
6321I do also want to show you
63222108
632300:04:32,579 --> 00:04:36,478
6324that for an individual group I can also take a look at, with advanced featured turned on,
63252109
632600:04:36,579 --> 00:04:41,478
6327some additional tabs that appear here in the list of properties for that group.
63282110
632900:04:41,579 --> 00:04:43,478
6330Not the least of which is the security tab.
63312111
633200:04:43,579 --> 00:04:48,478
6333Which allows me to provide additional discrete permissions for users or groups that are on
63342112
633500:04:48,579 --> 00:04:55,478
6336the group object itself. This is not the membership of the group, but actually the things the
63372113
633800:04:55,579 --> 00:04:59,478
6339actions that you could apply on that group. Many of these are not entirely obvious,
63402114
634100:04:59,579 --> 00:05:03,478
6342so you'll have to kind of poke around to see which ones you're interested in.
63432115
634400:05:03,579 --> 00:05:07,478
6345But at least this is the location where you would go to modify permissions in order to
63462116
634700:05:07,579 --> 00:05:12,478
6348for example, get a user the abilities to add and remove membership from this group.
63492117
635000:05:12,579 --> 00:05:16,478
6351So I would be aware that the delegation of control wizard exists, that it is something
63522118
635300:05:16,579 --> 00:05:19,478
6354that you would apply to, for example, an organizational unit of users.
63552119
635600:05:19,579 --> 00:00:02,028
6357And then I would be very careful anytime I'm trying to use it in production.
63582120
635900:00:02,129 --> 00:00:07,028
6360And then onto our final topic in this our module here on groups and organizational units.
63612121
636200:00:07,128 --> 00:00:12,028
6363In this topic we're asked to manage the default active directory containers, and very specifically
63642122
636500:00:12,128 --> 00:00:19,028
6366what we're asked to is to create a way to reset that default container when new computers get added
63672123
636800:00:19,129 --> 00:00:24,028
6369into our active directory domain. Now here we've created our company computers organizational unit
63702124
637100:00:24,129 --> 00:00:31,028
6372here and I manually moved over file1, server1, and servercore1 into the company computers OU.
63732125
637400:00:31,129 --> 00:00:36,028
6375But this was a manual process, the next time I add a new computer into the organizational unit
63762126
637700:00:36,128 --> 00:00:40,028
6378it's going to end up appearing here in our list of computers down here.
63792127
638000:00:40,128 --> 00:00:48,028
6381I would prefer these new computers to end up in a different location than the default computers container.
63822128
638300:00:48,128 --> 00:00:53,028
6384Microsoft provides a way in order to do that, that is the redircmp command, that is not a PowerShell command,
63852129
638600:00:53,128 --> 00:00:55,028
6387but is one that we can execute inside
63882130
638900:00:55,128 --> 00:01:03,028
6390of the PowerShell shell itself. A redircmp if I do /? here provides a way for me to just
63912131
639200:01:03,128 --> 00:01:07,029
6393change the default location for any newly created computer objects.
63942132
639500:01:07,129 --> 00:01:11,029
6396And so if I wanted to change that to my company computers organizational unit,
63972133
639800:01:11,129 --> 00:01:25,029
6399it would be as simple as redircmp and the OU= or OU= company computers then dc=company and then dc=pir.
64002134
640100:01:25,129 --> 00:01:30,029
6402At that point every new computer that comes into the domain will be automatically added into the
64032135
640400:01:30,129 --> 00:01:34,529
6405company computers organizational unit as opposed to the computers container.
64062136
640700:01:34,629 --> 00:01:40,529
6408This becomes particularly handy when I start applying group policy to that company computers OU.
64092137
641000:01:40,629 --> 00:00:01,845
6411And it helps me ensure that every new computer is going to end up getting that group policy that I've applied.
64122138
641300:00:01,945 --> 00:00:05,346
6414And so some kind of fun stuff here as it relates to managing groups and OUs,
64152139
641600:00:05,445 --> 00:00:09,846
6417both from the graphical user interface as well as from the command line here in our module.
64182140
641900:00:09,945 --> 00:00:12,846
6420And in fact what have we talked about in this module? We've talked about that process of
64212141
642200:00:12,945 --> 00:00:18,846
6423creating, copying, configuring, and deleting groups and OUs. The process in the graphical user
64242142
642500:00:18,946 --> 00:00:23,846
6426interface is fundamentally the same and really even in PowerShell it's fundamentally the same
64272143
642800:00:23,946 --> 00:00:27,846
6429as what you were doing with users. A couple of the PowerShell nouns are different and where
64302144
643100:00:27,946 --> 00:00:31,846
6432exactly you would click in the interface to create or delete these items is slightly different.
64332145
643400:00:31,946 --> 00:00:37,845
6435But for the most part dealing with groups and OUs is very much the same as dealing with users.
64362146
643700:00:37,945 --> 00:00:41,845
6438However things get a little different when we start talking about nesting of groups.
64392147
644000:00:41,945 --> 00:00:45,845
6441Active directory groups at face value provide a great way to consolidate users and consolidate
64422148
644300:00:45,945 --> 00:00:50,845
6444resources that users need to access. But it's the connection of those users to those
64452149
644600:00:50,945 --> 00:00:54,845
6447resources and the nesting of one kind of group into another, where things can get a little complicated.
64482150
644900:00:54,945 --> 00:00:59,845
6450And so having a good strategy for your group nesting will ensure that the wrong person doesn't
64512151
645200:00:59,945 --> 00:01:04,846
6453get access to the wrong information. To that end, we took a look at some of the tools you
64542152
645500:01:04,945 --> 00:01:08,846
6456can use to enumerate group membership. Should you end up in a situation where that person gets
64572153
645800:01:08,945 --> 00:01:12,846
6459added to the wrong group, well you can use some of these nice PowerShell tools with
64602154
646100:01:12,945 --> 00:01:17,846
6462recursion to identify their direct and indirect group membership. We took a look at the rules
64632155
646400:01:17,945 --> 00:01:23,846
6465for converting groups across security, distribution, universal, domain local, and domain global groups,
64662156
646700:01:23,945 --> 00:01:27,846
6468where you can and where you can't go about converting groups should you create them in one format
64692157
647000:01:27,945 --> 00:01:32,846
6471and need them in another. We took a look at group policy and how you can use group policy
64722158
647300:01:32,945 --> 00:01:37,846
6474to define the local group membership using domain global groups. So that once you create those
64752159
647600:01:37,945 --> 00:01:42,846
6477servers in your domain you can automatically grant the right people the correct permissions.
64782160
647900:01:42,945 --> 00:01:46,846
6480We took a look at delegation of control and how you can delegate the creation and management
64812161
648200:01:46,945 --> 00:01:51,846
6483of active directory objects, very specifically organizational units right within the a.console.
64842162
648500:01:51,945 --> 00:01:55,846
6486And then concluded with a look at one little command here that allows you to change the default
64872163
648800:01:55,945 --> 00:02:00,846
6489active directory container where new computers get entered when their added into the domain.
64902164
649100:02:00,945 --> 00:02:03,846
6492Very handy for getting computers in the right location and even more so when group policies
64932165
649400:02:03,945 --> 00:02:09,846
6495need to be applied. Coming up next, with our active directory now created and our servers a member
64962166
649700:02:09,945 --> 00:02:13,846
6498of that active directory, it's time for us to begin dealing with the different kinds of
64992167
650000:02:13,945 --> 00:02:17,846
6501servers and services that we would put in that AD infrastructure.
65022168
650300:02:17,945 --> 00:02:22,846
6504These are things like file and share access, the file server that contain documents users need.
65052169
650600:02:22,945 --> 00:02:26,846
6507These are things like print and document services that allow users to print out hard copies
65082170
650900:02:26,945 --> 00:02:31,846
6510of whatever documents they may need. As well as configuring servers for remote management,
65112171
651200:02:31,945 --> 00:02:35,846
6513a topic that Jason will lead off with and give you all the necessary information that you need
65142172
651500:02:35,945 --> 00:02:39,846
6516so that the variety of tasks that we've been accomplishing thus far and as well as to the
65172173
651800:02:39,945 --> 00:02:44,846
6519rest of this learning path. You can do so from the comfort of your administrative desktop
65202174
652100:02:44,945 --> 00:02:50,346
6522without having to remote desktop into the servers directly or walk into that server data center.
65232175
652400:02:50,445 --> 00:02:54,846
6525These days performing tasks directly on the console of servers is no longer the best practice.
65262176
652700:02:54,945 --> 00:03:00,346
6528And so being able to do multi-server management remotely is something that you really have to know.
65292177
653000:03:00,445 --> 00:03:03,445
6531That entire conversation on server roles and features is the topic for our next course coming up.