· 9 years ago · Jan 04, 2017, 09:06 AM
11
200:00:00,000 --> 00:00:07,900
3For just about every business IT environment these days, active directory has become an almost indivisible
4
52
600:00:08,000 --> 00:00:12,900
7part of the Microsoft Windows experience. And what's curious about that is that active directory
8
93
1000:00:13,000 --> 00:00:15,900
11is by no means a required part of that experience.
12
134
1400:00:16,000 --> 00:00:20,899
15In fact active directory is not necessary in Windows environments, it's completely optional.
16
175
1800:00:21,000 --> 00:00:26,899
19And I've worked with businesses before, even some large organizations that have managed to operate
20
216
2200:00:27,000 --> 00:00:30,899
23without an active directory presence. But those businesses tend to be sort of the one offs,
24
257
2600:00:31,000 --> 00:00:36,899
27they may be very small, they may be the exception to the rule. The reason for that is because
28
298
3000:00:37,000 --> 00:00:41,899
31active directory as a completely free feature in the Windows server operating system, is something
32
339
3400:00:42,000 --> 00:00:46,899
35that most organizations very quickly recognize that they need. You can run a bunch of machines
36
3710
3800:00:47,000 --> 00:00:51,899
39in a work group for a pretty reasonable period of time, but as the number of machines gets
40
4111
4200:00:52,000 --> 00:00:57,899
43much beyond just a handful the need to consolidate them together, their permissioning, their authentication,
44
4512
4600:00:58,000 --> 00:01:02,899
47their authorization. The need to have a central location where all of those things get aggregated
48
4913
5000:01:03,000 --> 00:01:09,900
51becomes very important. And it is for that reason that you see active directory in just about everywhere these days.
52
5314
5400:01:10,000 --> 00:01:13,900
55Well what may surprise you for a technology that is so mission critical that active directory
56
5715
5800:01:14,000 --> 00:01:18,900
59in MCSE generations gone past was quite a bit more heavily tested on than the variety of different tests
60
6116
6200:01:19,000 --> 00:01:23,900
63that you were required to take. These days active directory gets one objective in a long
64
6517
6600:01:24,000 --> 00:01:29,900
67list of those that include other things, like file and file services and installing Windows and so on.
68
6918
7000:01:30,000 --> 00:01:34,900
71And even as you move through to the other tests in your MCSA or MCSC exploration,
72
7319
7400:01:35,000 --> 00:01:39,900
75you'll find that active directory is not the most important thing that you'll be working with.
76
7720
7800:01:40,000 --> 00:01:43,900
79That may be in part to the fact that active directory is already everywhere and so the number of
80
8121
8200:01:44,000 --> 00:01:49,900
83people that have an opportunity to create a production active directory infrastructure from scratch,
84
8522
8600:01:50,000 --> 00:01:54,900
87is just simply getting less and less because those opportunities don't necessarily present itself.
88
8923
9000:01:55,000 --> 00:01:58,900
91As a consequence, what you'll find here in this objective, and then all the other AD related objects
92
9324
9400:01:59,000 --> 00:02:04,900
95that follow in all the tests that follow. That the very foundations of active directory are perhaps
96
9725
9800:02:05,000 --> 00:02:09,900
99a little less important than knowing what to do with it once it's in place.
100
10126
10200:02:10,000 --> 00:02:16,900
103Now if you're just joining us here, this is our learning path for the 70-410, the first in the MCSA curriculum.
104
10527
10600:02:17,000 --> 00:02:19,900
107And this is number four in a long list of seven different courses that we've put together that make
108
10928
11000:02:20,000 --> 00:02:27,900
111up all the different content for that 410 exam. We began first with a look at the MCSA and the 70-410 exam itself
112
11329
11400:02:28,000 --> 00:02:31,900
115and very specifically on the RT version of this exam. And everything we'll be dealing with here
116
11730
11800:02:32,000 --> 00:02:38,900
119in this learning path has to do with that extra content that exists with the release of Windows server 2012 R2.
120
12131
12200:02:39,000 --> 00:02:42,900
123We then took a look at installing and configuring servers, some of the very manual ways in which you can
124
12532
12600:02:43,000 --> 00:02:47,900
127get servers installed and then some of the PowerShell and command line ways in which you can get them configured.
128
12933
13000:02:48,000 --> 00:02:51,900
131And then Jason took a look at the deployment and configuration of core network services,
132
13334
13400:02:52,000 --> 00:02:57,900
135these are things like DNS and DHCP. As well as a fairly extended review of just how you get servers
136
13735
13800:02:58,000 --> 00:03:03,900
139and services on the network, via IPV4 or IPV6. It is that prerequisite that takes us here
140
14136
14200:03:04,000 --> 00:03:08,900
143to our discussion on installing and administering active directory. And it's here where I will freely
144
14537
14600:03:09,000 --> 00:03:13,900
147admit Jason and I had to kind of determine which order these last two courses needed to go in,
148
14938
15000:03:14,000 --> 00:03:17,900
151because in order to have active directory you have to have DNS services.
152
15339
15400:03:18,000 --> 00:03:23,900
155And in some cases in order to have DNS and DHCP services, you had to have active directory.
156
15740
15800:03:24,000 --> 00:03:28,900
159So you'll find Jason back on that last course and then me here in this course, kind of waving our hands
160
16141
16200:03:29,000 --> 00:03:33,900
163in hair when it comes to a couple of the prerequisites that are required in order to get these things up and running.
164
16542
16600:03:34,000 --> 00:03:37,900
167So please bear with us if we seem to be jumping around just a bit. Here in this course
168
16943
17000:03:38,000 --> 00:03:40,900
171we have three different topics we have to talk about, each one mapping to one of the objectives
172
17344
17400:03:41,000 --> 00:03:45,900
175in the 410, the first of which is to install domain controllers. And what's interesting about installing
176
17745
17800:03:46,000 --> 00:03:53,900
179domain controllers is that even today in server 2012 R2 these steps to do so, although are fairly highly automated,
180
18146
18200:03:54,000 --> 00:03:58,900
183still require a couple of prerequisites. There are still of a couple of gotchas you just have to be aware of
184
18547
18600:03:59,000 --> 00:04:02,900
187when it comes time to install your first or may not your first AD/DC.
188
18948
19000:04:03,000 --> 00:04:06,900
191We'll go through what those are, I'll show you the different ways in which you can install a domain controller
192
19349
19400:04:07,000 --> 00:04:10,900
195both using the graphical user interfaces, as well as at the command line.
196
19750
19800:04:11,000 --> 00:04:15,900
199And then from there we'll talk about how you can create and manage your active directory users and computers.
200
20151
20200:04:16,000 --> 00:04:19,899
203Now you might be looking at this and saying, well gosh Greg, are we really going to go through the process
204
20552
20600:04:20,000 --> 00:04:24,899
207to right-click and create a new user or a new computer? Well sort of, I guess.
208
20953
21000:04:25,000 --> 00:04:30,899
211But more importantly these days, and particularly with this current generation of the MCSA and MCSE
212
21354
21400:04:31,000 --> 00:04:34,899
215knowing how to perform these tasks, not only from the user interface, the graphical user interface,
216
21755
21800:04:35,000 --> 00:04:38,899
219but also from the command line, is perhaps a little bit more important.
220
22156
22200:04:39,000 --> 00:04:42,899
223So we'll talk about not only how to create users and computers, but some of the bulk and automated
224
22557
22600:04:43,000 --> 00:04:47,899
227ways in which you can accomplish the same tasks via the command line and via scripting.
228
22958
23000:04:48,000 --> 00:04:51,899
231We will then conclude with a third module and objective here on creating and managing active directory
232
23359
23400:04:52,000 --> 00:04:55,899
235groups and organizational units. In this third module we'll take a look at the different groups
236
23760
23800:04:56,000 --> 00:05:01,899
239that are out there, how they can interrelate, as well as the organizational units, what they're used for
240
24161
24200:05:02,000 --> 00:05:06,899
243and how best to use them. It is this foundation that will get our environment ready to go for the
244
24562
24600:05:07,000 --> 00:05:12,899
247implementation of a variety of different network services that Jason will talk about in the course following.
248
24963
25000:05:13,000 --> 00:05:16,899
251These will be things like file services and print and document services and so on.
252
25364
25400:05:17,000 --> 00:05:20,899
255All of those additional services are ones that make a lot more sense once you have an active directory
256
25765
25800:05:21,000 --> 00:05:28,899
259infrastructure in place and all the users and computers and groups and OUs that populate that active director, but for now
260
26166
26200:05:29,000 --> 00:05:32,899
263let's go ahead and go through the process of getting an active directory on line and getting a couple
264
26567
26600:05:33,000 --> 00:05:37,899
267of servers built into that environment. Coming up next, we begin that process with the installation
268
26968
27000:05:38,000 --> 00:05:42,899
271of a domain controller and the creation of an active directory forest and domain.
272
27369
27400:05:43,000 --> 00:05:46,899
275I will tell you that an active directory, in and amongst all the different components that make it work,
276
27770
27800:05:47,000 --> 00:05:52,899
279has a lot of different pieces that connect together. And whereas the tasks that the exam tests you on,
280
28171
28200:05:53,000 --> 00:05:57,899
283maybe a little disconnected from the academics or the terminology for those components,
284
28572
28600:05:58,000 --> 00:06:02,899
287will start with the foundations. And take a look at those components individually so we can see
288
28973
29000:06:03,000 --> 00:06:08,899
291where they interconnect together to create this experience that is our active directory infrastructure.
292
29374
29400:06:09,000 --> 00:06:12,899
295And then from there we'll go through the click by click and step by step process you'll go through
296
29775
29800:06:13,000 --> 00:06:18,399
299to implement active directory, your very first domain controller and then all the other domain controllers after that.
300
30176
30200:06:18,500 --> 23:59:59,899
303All that and more is the topic for our next module coming up.
304
30577
30600:00:00,000 --> 00:00:06,900
307Sitting back and analyzing the title of this our first objective on installing domain controllers
308
30978
31000:00:07,000 --> 00:00:12,900
311the actual words that Microsoft uses here are very specific in terms of what I believe they want you to know.
312
31379
31400:00:13,000 --> 00:00:17,899
315Notice here that what Microsoft is not talking about is installing active directory or any of the
316
31780
31800:00:18,000 --> 00:00:21,899
319tasks involved with preparing for the installation of active directory.
320
32181
32200:00:22,000 --> 00:00:24,899
323And in that's a really important thing to think about as we're going through the variety
324
32582
32600:00:25,000 --> 00:00:30,899
327of tasks that this module and that objective can cover. Active directory is a very large
328
32983
33000:00:31,000 --> 00:00:34,899
331set of things and all of which have to work together in order to create that experience that we're used to.
332
33384
33400:00:35,000 --> 00:00:42,899
335And so Microsoft kind of punts a bit on a lot of the foundational content that is active directory itself,
336
33785
33800:00:43,000 --> 00:00:48,899
339like forests and domains and what not. And I'm going to focus your attentions down for this objective
340
34186
34200:00:49,000 --> 00:00:52,899
343on just the things you would do with the domain controllers themselves.
344
34587
34600:00:53,000 --> 00:00:56,899
347Here in this module we'll talk about how you can go about adding or removing domain controllers
348
34988
35000:00:57,000 --> 00:01:02,899
351from a domain. And this is a very specific click by click or type by type series of steps that you
352
35389
35400:01:03,000 --> 00:01:07,900
355would go through to add that domain controller from the domain. We'll talk about also the
356
35790
35800:01:08,000 --> 00:01:11,900
359installation of a domain controller using IFM or install from media.
360
36191
36200:01:12,000 --> 00:01:15,900
363Every so often you may have the situation where a domain controller needs to get deployed
364
36592
36600:01:16,000 --> 00:01:21,900
367in some location where the internet connection to that location is really, really poor.
368
36993
37000:01:22,000 --> 00:01:25,900
371And because of that, the replication of that content can take an extremely long period of time.
372
37394
37400:01:26,000 --> 00:01:31,900
375Well the install from media approach allows you to kind of preposition some information on
376
37795
37800:01:32,000 --> 00:01:35,900
379that domain controller to reduce the amount of replication that's required to get the domain controller
380
38196
38200:01:36,000 --> 00:01:41,900
383up and operational. We'll also take everything we've talked about having to do with the installation
384
38597
38600:01:42,000 --> 00:01:47,900
387of ADDS and translate that to the command line having to do with the installation of a domain controller
388
38998
39000:01:48,000 --> 00:01:51,900
391on server core. Just a couple of PowerShell commands you need to be aware of here, as well as a
392
39399
39400:01:52,000 --> 00:01:56,900
395variety of just different switches that go with those PowerShell commands different parameters.
396
397100
39800:01:57,000 --> 00:02:00,900
399We'll talk also about kind of the two ways, the more or less old school way and the new school
400
401101
40200:02:01,000 --> 00:02:04,900
403way involving PowerShell that you can go through in installing the domain controller on server core.
404
405102
40600:02:05,000 --> 00:02:08,900
407And then we'll take everything we've learned and talk a bit about upgrading a domain controller.
408
409103
41000:02:09,000 --> 00:02:12,900
411And in fact I'm going to go just a bit further with this particular task and give you a
412
413104
41400:02:13,000 --> 00:02:18,900
415little bit of additional information that may or may not be on the test, probably isn't on the exam.
416
417105
41800:02:19,000 --> 00:02:24,900
419That has to do not only with upgrading domain controllers, but upgrading domains and upgrading forests.
420
421106
42200:02:25,000 --> 00:02:31,900
423These can be handy when you have the situation where you need to go from a server 2008 R2 active directory domain
424
425107
42600:02:32,000 --> 00:02:36,900
427to one's that server 2012 R2 or so on. And just so knowing the quick five step process to upgrade
428
429108
43000:02:37,000 --> 00:02:42,900
431a domain controller and the domain and forest it resides in, is something you probably should know.
432
433109
43400:02:43,000 --> 00:02:46,900
435Now active directory, the way in which the clients find the servers and services and the way in which
436
437110
43800:02:47,000 --> 00:02:53,900
439each server finds each other, has to do with DNS. And the different kinds of SRV or service records
440
441111
44200:02:54,000 --> 00:02:57,900
443in DNS that are published by each active directory domain controller.
444
445112
44600:02:58,000 --> 00:03:02,900
447Now every so often you can end up with a situation where a record gets removed or corrupted
448
449113
45000:03:03,000 --> 00:03:07,900
451or for some reason or another the domain controller can't update that record or populate that record.
452
453114
45400:03:08,000 --> 00:03:11,900
455Well when that's the case, you need to figure out how to actually go through resolving those
456
457115
45800:03:12,000 --> 00:03:15,900
459record registration issues. And there are a couple, kind of really slick ways in which
460
461116
46200:03:16,000 --> 00:03:19,900
463you can accomplish that, I'll show both of those when we get to this part of our module here.
464
465117
46600:03:20,000 --> 00:03:24,900
467We'll talk also about configuring global catalogs and global catalog servers, there's a checkbox
468
469118
47000:03:25,000 --> 00:03:27,900
471you need to know, there's probably a PowerShell command there too you'll need to know that will
472
473119
47400:03:28,000 --> 00:03:31,900
475enable global catalog on any of the machines that you intend to.
476
477120
47800:03:32,000 --> 00:03:37,900
479Back in the old days, back when our network connections between sites was much, much smaller than it is today,
480
481121
48200:03:38,000 --> 00:03:42,900
483the determination as to where your global catalog should go was much more important.
484
485122
48600:03:43,000 --> 00:03:47,900
487But these days the amount of traffic that occurs between global catalog servers in combination
488
489123
49000:03:48,000 --> 00:03:51,900
491with just the amount of pipeline that we tend to have between our different sites,
492
493124
49400:03:52,000 --> 00:03:55,900
495means that in a lot of environments, at least the ones that I see, you'll find global catalog
496
497125
49800:03:56,000 --> 00:04:02,900
499turned on on every domain controller. Doing so greatly simplifies the planning of your active directory
500
501126
50200:04:03,000 --> 00:04:08,900
503and more importantly it just greatly simplifies knowing where it's at, because every DC is also a GC.
504
505127
50600:04:09,000 --> 00:04:12,900
507And then our final topic here for this module is deploying active directory in Microsoft Azure,
508
509128
51000:04:13,000 --> 00:04:16,899
511which I think you will find is perhaps a little less exciting than it might seem to be.
512
513129
51400:04:17,000 --> 00:04:20,899
515The key reason here why I say that, is that little acronym there in the middle marked IAAS,
516
517130
51800:04:21,000 --> 00:04:25,899
519which is a shorthand for I'm creating active directory on a virtual machine.
520
521131
52200:04:26,000 --> 00:04:28,899
523And so really what we're talking about here in deploying active directory is deploying
524
525132
52600:04:29,000 --> 00:04:33,899
527a domain controller in Microsoft Azure. There are and in the future will be other ways
528
529133
53000:04:34,000 --> 00:04:41,399
531in which active directory can be manifested inside of Azure, more align with a service than a service on a VM.
532
533134
53400:04:41,500 --> 00:04:45,399
535But for our purposes here, I want to spend just a couple of minutes showing you that indeed this is
536
537135
53800:04:45,500 --> 00:04:48,899
539possible and giving you a couple of the things you should be aware of should you decide
540
541136
54200:04:49,000 --> 00:00:01,553
543to deploy active directory and a domain controller into the Microsoft Azure cloud.
544
545137
54600:00:01,653 --> 00:00:05,554
547First up on our list of things to talk about, before we get into the specific tasks that this
548
549138
55000:00:05,653 --> 00:00:09,554
551objective requires, I want to spend just a minute going through some of the foundations
552
553139
55400:00:09,653 --> 00:00:15,554
555the vocabulary, if you will, of active directory. Now this is not directly testable on the exam,
556
557140
55800:00:15,653 --> 00:00:20,553
559at least based off of how the objectives are worded, but you kind of have to know what these things are
560
561141
56200:00:20,653 --> 00:00:23,553
563to appreciate the later things that you're going to be asked to do.
564
565142
56600:00:23,653 --> 00:00:28,553
567The first of which is just recognizing what an active directory domain is and how an active directory
568
569143
57000:00:28,653 --> 00:00:35,554
571domain and an active directory forest are interrelated. This may be entirely review or just
572
573144
57400:00:35,654 --> 00:00:39,554
575completely something that's unnecessary for you, so feel free to click through to the next clip
576
577145
57800:00:39,654 --> 00:00:45,554
579if you find this to be uninteresting or un-useful. But if you're brand new to the notion of active directory
580
581146
58200:00:45,654 --> 00:00:50,554
583or if you've been in an active directory that is a very simple one, this explanation of some very
584
585147
58600:00:50,654 --> 00:00:56,554
587complex ones can be helpful has you begin working through the different questions that this exam may require.
588
589148
59000:00:56,654 --> 00:01:01,554
591Now an active directory domain is something that we are intending to install here onto this our domain controller
592
593149
59400:01:01,654 --> 00:01:05,554
595we'll be dealing with here in just a minute. And in most places an active directory domain,
596
597150
59800:01:05,653 --> 00:01:09,554
599at least in Microsoft parlons, the domain is represented by a triangle, so you're going to see
600
601151
60200:01:09,653 --> 00:01:13,554
603a lot of triangles here coming up. But what I want to show you here is that an active directory
604
605152
60600:01:13,653 --> 00:01:18,554
607domain is sort of the boundary of authentication for a set of users and computers and the different
608
609153
61000:01:18,653 --> 00:01:24,554
611resources that they work with. So when you log into your machine at company.pri you're logging
612
613154
61400:01:24,653 --> 00:01:32,554
615into the domain that is company.pri. Today, these days, most organizations work within
616
617155
61800:01:32,653 --> 00:01:36,554
619what is called a single domain single forest model. And so, the entirety of the workspace
620
621156
62200:01:36,653 --> 00:01:42,554
623that you're dealing with is this thing called company.pri, but what I want to show you here
624
625157
62600:01:42,653 --> 00:01:46,554
627is that it is possible to take multiple domains and connect them together to create
628
629158
63000:01:46,653 --> 00:01:51,554
631a tree of domains or a forest, if you will, of domains. Should you have that need to do so.
632
633159
63400:01:51,653 --> 00:02:00,554
635So, for example, sub to my company.pri domain, it is entirely possible for me to create another domain
636
637160
63800:02:00,653 --> 00:02:06,554
639that sits below. This other domain, Denver.company.pri, is one that perhaps was created for
640
641161
64200:02:06,653 --> 00:02:11,554
643one reason or another. Maybe it's a different company called Denver, maybe it's a different
644
645162
64600:02:11,653 --> 00:02:17,554
647group of people that want to have their own consolidated set of users and computers and resources.
648
649163
65000:02:17,653 --> 00:02:22,554
651They want their own boundary to be different than the root domain there with company.pri.
652
653164
65400:02:22,653 --> 00:02:27,554
655In the 412, 70-412 exam, we'll talk more about the reasons why you would make these decisions,
656
657165
65800:02:27,653 --> 00:02:32,554
659but for now just recognize that it is entirely possible to create these multi-domain structures
660
661166
66200:02:32,653 --> 00:02:37,554
663that are automatically connected together. Now one thing that's important to recognize here
664
665167
66600:02:37,653 --> 00:02:43,554
667with the connection between my company.pri domain and my Denver domain, is that the two name spaces
668
669168
67000:02:43,653 --> 00:02:50,554
671I'm looking at here, the namespace being the words, company.pri, are what we call contiguous.
672
673169
67400:02:50,653 --> 00:02:55,554
675Meaning that Denver.company.pri is effectively a subset of company.pri.
676
677170
67800:02:55,653 --> 00:03:00,554
679Now in the oldest of days, it was necessary for us to maintain a contiguous namespace between
680
681171
68200:03:00,653 --> 00:03:04,554
683any domains that were connected together into a single forest, but these days it's actually
684
685172
68600:03:04,653 --> 00:03:11,554
687possible to create noncontiguous namespaces as well. So, I could have a subdomain of company.pri
688
689173
69000:03:11,653 --> 00:03:18,554
691being taco, for example. Or anything that I want. Now again, when we move the 412 you'll learn
692
693174
69400:03:18,653 --> 00:03:22,554
695more about why I would do that versus why I would not and some of the gotchas and things
696
697175
69800:03:22,653 --> 00:03:27,554
699you have to be aware of should you go down the noncontiguous namespace route.
700
701176
70200:03:27,653 --> 00:03:32,554
703But here in 2012 R2 we do have the ability to create these noncontiguous namespaces.
704
705177
70600:03:32,653 --> 00:03:38,554
707Domains also needn't necessarily be just a single layer deep, we can have multiple layers of different domains.
708
709178
71000:03:38,653 --> 00:03:46,554
711So test.denver.company.pri, and prod.denver.company.pri, and I can even go noncontiguous into my
712
713179
71400:03:46,653 --> 00:03:52,554
715subdomains as well, so taco.pri and burrito.com needn't necessarily be organized with each other
716
717180
71800:03:52,653 --> 00:03:56,554
719except to be in a completely different branch of the tree. Now I'm showing you this not because
720
721181
72200:03:56,653 --> 00:04:02,554
723I'm trying to incent you towards creating this large and complicated multi-domain structure.
724
725182
72600:04:02,653 --> 00:04:09,554
727In fact as I'd mentioned before, in most organizations we have moved to a single domain single forest structure,
728
729183
73000:04:09,653 --> 00:04:13,554
731because trying to figure out where users are and the management of users and computers and resources
732
733184
73400:04:13,653 --> 00:04:19,553
735across the domain boundaries, it gets just really, really complicated.
736
737185
73800:04:19,653 --> 00:04:24,553
739Because of that, the very slight benefits that people get out of multi-domains are in many
740
741186
74200:04:24,653 --> 00:04:30,553
743cases outweighed by the incredible headache that's involved with figuring out where stuff goes
744
745187
74600:04:30,653 --> 00:00:01,583
747and how you can simply address it.
748
749188
75000:00:01,683 --> 00:00:06,584
751Now whereas the multi-domain structure is something that just seems to be getting less and less these days,
752
753189
75400:00:06,684 --> 00:00:10,583
755it's not unlikely for you to occasionally see a multi-forest structure.
756
757190
75800:00:10,683 --> 00:00:13,583
759And again we'll talk more about the different ways in which you can connect forests together
760
761191
76200:00:13,683 --> 00:00:19,583
763in the 412 content, but for now just recognize that one of the ways that you can go about
764
765192
76600:00:19,684 --> 00:00:23,583
767connecting forests together happens through what is called a forest trust.
768
769193
77000:00:23,684 --> 00:00:29,583
771Let's assume here that I have my company.pri domain and forest here, so single forest, single domain,
772
773194
77400:00:29,684 --> 00:00:35,583
775and I need to attach to some other company. So maybe that's the specialized.NET domain and forest.
776
777195
77800:00:35,683 --> 00:00:41,583
779Maybe we acquired them, maybe they've been brought out underneath our organization and we
780
781196
78200:00:41,683 --> 00:00:45,583
783need to take them under our wing for one reason or another. Well it is possible to create what is called
784
785197
78600:00:45,683 --> 00:00:52,583
787a forest trust between the top most level of these two domains that facilitates the communication
788
789198
79000:00:52,683 --> 00:00:57,583
791and the authorization between this domain and that domain. By creating this forest trust
792
793199
79400:00:57,683 --> 00:01:01,583
795and then applying permissions in the appropriate ways, I can sitting here in company.pri,
796
797200
79800:01:01,683 --> 00:01:07,584
799then access resources in specialized.NET. Now the neat part about these forest trusts is that
800
801201
80200:01:07,683 --> 00:01:12,584
803depending on how you configure them, it is entirely possible for all of the different sub domains
804
805202
80600:01:12,683 --> 00:01:19,584
807beneath that main triangle to also have access to the resources in that other forest.
808
809203
81000:01:19,683 --> 00:01:23,584
811Now if you thought that the multi-domain model was complex, you can imagine how the multi-forest
812
813204
81400:01:23,683 --> 00:01:28,584
815multi-domain model gets even more complex. So you tend to see in most organizations
816
817205
81800:01:28,683 --> 00:01:33,584
819when there is a forest trust laid into place. A lot of times that can be done for perhaps
820
821206
82200:01:33,683 --> 00:01:39,584
823a temporary reason until that remote trust can get consumed by the main domain.
824
825207
82600:01:39,683 --> 00:01:44,584
827Or in some cases you'll see it by different partner companies that are working together for one reason or another.
828
829208
83000:01:44,683 --> 00:01:50,584
831In another case, you may have some quasi approved forest that was created by a shadow IT organization
832
833209
83400:01:50,683 --> 00:01:53,584
835that needs to get connected up to the main forest. And so in order to do that you've got to
836
837210
83800:01:53,683 --> 00:01:58,584
839connect them together via a trust, but for whatever reason you're creating it, there is the
840
841211
84200:01:58,683 --> 00:02:03,584
843abilities to bridge from one organization's active directory infrastructure to another
844
845212
84600:02:03,683 --> 00:02:08,584
847by use of what are called trusts. Again we'll learn more about this in 412, the whole concept of trusts
848
849213
85000:02:08,683 --> 00:00:01,655
851and how they get implemented in 412, but at least this gives you an idea of what we're attempting to accomplish.
852
853214
85400:00:01,756 --> 00:00:04,363
855Now in addition to the domains and forests
856
857215
85800:00:04,463 --> 00:00:08,362
859there is also the abilities to create multiple different sites in active directory as well.
860
861216
86200:00:08,462 --> 00:00:14,362
863And it is perhaps the sites that are the least paid attention to in today's modern world
864
865217
86600:00:14,462 --> 00:00:20,362
867in part because it's easy to forget about them and also because the organic constantly growing
868
869218
87000:00:20,463 --> 00:00:26,362
871constantly changing behaviors of our business, sometimes means that the geographic sites
872
873219
87400:00:26,463 --> 00:00:31,362
875that make up our company may not necessarily directly map to the active directory sites that
876
877220
87800:00:31,463 --> 00:00:36,362
879we've configured logically. Now let's assume again that we have this domain company.pri
880
881221
88200:00:36,463 --> 00:00:39,362
883and we're going to deal with a single forest, single domain in this example.
884
885222
88600:00:39,463 --> 00:00:46,362
887In this example I may have three different geographic sites that my domain extends into,
888
889223
89000:00:46,463 --> 00:00:51,362
891Denver, Las Vegas, and Phoenix. These three different geographic sites are just three places
892
893224
89400:00:51,463 --> 00:00:55,362
895where people are working, maybe I have an office in Denver and an office in Las Vegas
896
897225
89800:00:55,463 --> 00:01:01,362
899and an office in Phoenix. Now these three sites correspond with three areas of high network
900
901226
90200:01:01,463 --> 00:01:06,362
903connectivity that happen to be interconnected by probably less powerful network lines, right.
904
905227
90600:01:06,462 --> 00:01:12,362
907You're not going to have 10 megabits or gigabit connections between these different locations, or maybe you will,
908
909228
91000:01:12,462 --> 00:01:18,362
911but the definition of a site is a location of high network connectivity that may connect up to other
912
913229
91400:01:18,462 --> 00:01:25,362
915locations that are similarly configured. Now in this configuration, the Denver, Las Vegas, and Phoenix site,
916
917230
91800:01:25,462 --> 00:01:29,362
919these three sites are defined by the subnet that has been configured on each site.
920
921231
92200:01:29,462 --> 00:01:34,362
923And this is something that you're network team would have done before the implementation of active directory
924
925232
92600:01:34,462 --> 00:01:41,362
927in sites and services and so on. And so the Denver site corresponds with the 192,168.0 net and the
928
929233
93000:01:41,462 --> 00:01:46,362
931Las Vegas site to the 2 net and the Phoenix site to the 3 net. These three different subnets
932
933234
93400:01:46,462 --> 00:01:52,362
935are what allow active directory to define the geographic constraints for this site.
936
937235
93800:01:52,462 --> 00:01:55,362
939Now what's important to recognize is that we're still talking about the same domain,
940
941236
94200:01:55,462 --> 00:02:02,362
943everyone here still logs on to company.pri, but as you can imagine when I've got users that are
944
945237
94600:02:02,462 --> 00:02:08,362
947being added and subtracted and their passwords are changed and they're being given different permission sets.
948
949238
95000:02:08,462 --> 00:02:13,362
951All of this change to the content in the active directory database can occasionally mean that
952
953239
95400:02:13,462 --> 00:02:20,362
955I may need to better control the traffic that is going on in the connections between these independent sites.
956
957240
95800:02:20,462 --> 00:02:26,362
959So for example, if I make a change to a user in Denver, maybe I want to slow down the propagation
960
961241
96200:02:26,462 --> 00:02:34,362
963of that change to Las Vegas and Phoenix, because doing so will consume that precious network bandwidth.
964
965242
96600:02:34,462 --> 00:02:36,362
967Now this makes a lot more sense, maybe not in the three site world,
968
969243
97000:02:36,462 --> 00:02:42,362
971but in a situation where I may have more than three sites. So let's say your organizations got very
972
973244
97400:02:42,462 --> 00:02:47,362
975large now you were, you had Denver and Las Vegas and Phoenix and that was working out well for you.
976
977245
97800:02:47,462 --> 00:02:51,362
979But then suddenly you start buying additional sites, so you open an office in San Francisco and then
980
981246
98200:02:51,462 --> 00:02:57,362
983you open another office in Chicago and there another in Boston and another one in Miami.
984
985247
98600:02:57,462 --> 00:03:03,362
987Well these lines here correspond then with the network connections that pull this single network
988
989248
99000:03:03,462 --> 00:03:07,362
991space together, the actual logical connections that are created with your provider.
992
993249
99400:03:07,462 --> 00:03:15,362
995Well in these cases some of these connections maybe at a lower performance, less bandwidth than the others.
996
997250
99800:03:15,462 --> 00:03:21,362
999And so because of that, you may need to go through and define what the cost of that connection will be.
1000
1001251
100200:03:21,462 --> 00:03:26,362
1003Without getting too much into the details of how we configure these, for connections with a higher cost
1004
1005252
100600:03:26,462 --> 00:03:30,362
1007you may want to throttle down how much active directory content is being replicated.
1008
1009253
101000:03:30,462 --> 00:03:35,362
1011So you don't end up using all the bandwidth so that people have no abilities to use it for other things.
1012
1013254
101400:03:35,462 --> 00:03:39,362
1015Now I don't want to get too much into detail here in terms of how you make these configurations,
1016
1017255
101800:03:39,462 --> 00:03:45,362
1019again, more of this happens in the 412 content. But just recognize that the sites and services
1020
1021256
102200:03:45,462 --> 00:03:50,362
1023active directory sites and services console is the place where much of this ends up being configured.
1024
1025257
102600:03:50,462 --> 00:00:01,988
1027And it has everything to do with how your active directory domain is broken up by geographic location.
1028
1029258
103000:00:02,088 --> 00:00:05,989
1031Now I introduce all of this because, well it's the sites where you need to determine whether or not
1032
1033259
103400:00:06,089 --> 00:00:10,989
1035you need to install a domain controller or not. Or even multiple domain controllers.
1036
1037260
103800:00:11,089 --> 00:00:14,989
1039When we're talking about DCs, the main controllers are the host of the active directory.
1040
1041261
104200:00:15,089 --> 00:00:19,988
1043They're the ones that contain the active directory database. And every active directory domain
1044
1045262
104600:00:20,088 --> 00:00:24,988
1047controller generally has an equal copy of the AD database, as every other domain controller.
1048
1049263
105000:00:25,088 --> 00:00:31,988
1051It's a multi-master model with each one transferring its contents to the other so that everyone
1052
1053264
105400:00:32,088 --> 00:00:38,988
1055has a shared vision of what that database is. Now generally in most configurations, a minimum of
1056
1057265
105800:00:39,088 --> 00:00:42,988
1059two domain controllers is required for a single domain. Those two domain controllers
1060
1061266
106200:00:43,088 --> 00:00:48,988
1063ensure that should you power one off, or reboot one for the purposes of patching or it just dies
1064
1065267
106600:00:49,088 --> 00:00:53,988
1067or what have you. You still have additional services that are out there to support this very mission
1068
1069268
107000:00:54,088 --> 00:00:57,988
1071critical service that is active directory. But things get a little bit more complex when you start
1072
1073269
107400:00:58,088 --> 00:01:04,989
1075moving into the world of multiple sites. So in multiple sites I may need to have multiple domain
1076
1077270
107800:01:05,088 --> 00:01:10,989
1079controllers in my primary location, maybe Denver where most of the users sit.
1080
1081271
108200:01:11,088 --> 00:01:14,989
1083I may also need to have additional domain controllers in another site, like Las Vegas.
1084
1085272
108600:01:15,088 --> 00:01:20,989
1087Maybe I have a lot of users in Las Vegas as well and so putting an additional two DCs in Las Vegas
1088
1089273
109000:01:21,088 --> 00:01:25,989
1091to handle their load can become important as well. Maybe Phoenix is a smaller site and so only
1092
1093274
109400:01:26,088 --> 00:01:31,989
1095a single domain controller is sufficient to service their needs. So when you're thinking about
1096
1097275
109800:01:32,088 --> 00:01:34,989
1099planning your active directory you kind of have to think about how much hardware does each
1100
1101276
110200:01:35,088 --> 00:01:39,989
1103individual site need. And it is the definition of these different sites and services
1104
1105277
110600:01:40,088 --> 00:00:01,977
1107and how they're configured, which ends up driving those decisions.
1108
1109278
111000:00:02,077 --> 00:00:04,978
1111Now in addition to domain controllers, we have another decision that has to be made as well,
1112
1113279
111400:00:05,078 --> 00:00:10,477
1115and that has to do with global catalogs and the different servers that will serve as a global catalog.
1116
1117280
111800:00:10,577 --> 00:00:15,977
1119You should be aware, at least at this point, that a global catalog provides a subset of the total
1120
1121281
112200:00:16,077 --> 00:00:22,977
1123active directory domain, the database, in order to serve as the logging in the logging out of clients.
1124
1125282
112600:00:23,077 --> 00:00:28,977
1127The general authentication of clients. And as I mentioned before, back in the old days the positioning
1128
1129283
113000:00:29,077 --> 00:00:33,978
1131of global catalogs was much more important when the network connections between our different sites
1132
1133284
113400:00:34,078 --> 00:00:37,978
1135was very small in comparison with the amount of data we were trying to push through them.
1136
1137285
113800:00:38,078 --> 00:00:42,978
1139These days that amount of global catalog traffic or the replication traffic is quite a bit less
1140
1141286
114200:00:43,078 --> 00:00:49,978
1143and so in a lot of environments you find that global catalogs get installed just about everywhere.
1144
1145287
114600:00:50,078 --> 00:00:54,978
1147But a global catalog effectively is another configuration that you apply onto a domain controller.
1148
1149288
115000:00:55,078 --> 00:00:58,978
1151Let's say for example, that this domain controller is the very first one that we've installed in our environment.
1152
1153289
115400:00:59,078 --> 00:01:04,978
1155And so because of that has been configured as a global catalog. You have to have a global catalog
1156
1157290
115800:01:05,078 --> 00:01:09,978
1159in your environment in order to log in clients. And so because of that we've got one sitting here in Denver.
1160
1161291
116200:01:10,078 --> 00:01:14,978
1163Well as you go about configuring your other domain controllers, you may determine to add additional
1164
1165292
116600:01:15,078 --> 00:01:19,978
1167global catalog services at least into each site. So that one of the domain controllers in each site
1168
1169293
117000:01:20,078 --> 00:01:24,978
1171can serve as a global catalog. This can be a good practice to ensure that you have good
1172
1173294
117400:01:25,078 --> 00:01:28,978
1175performing logons as users are going about logging onto their machines.
1176
1177295
117800:01:29,078 --> 00:01:33,978
1179Well catalogs also help you locate objects within the forest as well as providing information about
1180
1181296
118200:01:34,078 --> 00:01:37,978
1183universal groups. Now again, in the old days you'd see these configured in such a way that
1184
1185297
118600:01:38,078 --> 00:01:42,978
1187at least you would have one global catalog probably per site. But the more common practice,
1188
1189298
119000:01:43,078 --> 00:01:47,978
1191whether or not it's an established best practice or not. The more common practice these days
1192
1193299
119400:01:48,078 --> 00:01:52,978
1195is to configure every domain controller as a global catalog. In a world where bandwidth is
1196
1197300
119800:01:53,078 --> 00:01:56,978
1199no longer at the premium it once was, this allows every domain controller to operate with all the
1200
1201301
120200:01:57,078 --> 00:02:01,978
1203functionality required to support the needs of its users. A little later on in this module we'll
1204
1205302
120600:02:02,078 --> 00:02:06,478
1207talk about how you can go about configuring a domain controller as a global catalog server.
1208
1209303
121000:02:06,578 --> 00:00:01,806
1211And it's something you're probably going to want to do.
1212
1213304
121400:00:01,907 --> 00:00:06,307
1215Now another topic worth discussing here in our review of the foundations of active directory,
1216
1217305
121800:00:06,407 --> 00:00:12,807
1219has to do with organizational units. And honestly OUs are routinely misunderstood in terms of
1220
1221306
122200:00:12,907 --> 00:00:18,306
1223what their value is for the organization. I want to show you what an OU is and then show you
1224
1225307
122600:00:18,407 --> 00:00:22,306
1227at least my impression of where you should implement them. Because all too often you find
1228
1229308
123000:00:22,407 --> 00:00:29,806
1231organizations that have implemented OUs in ways that cause them no end of heartache in regular operations.
1232
1233309
123400:00:29,907 --> 00:00:34,906
1235An organizational unit is designed very different from a group, like an active directory group,
1236
1237310
123800:00:35,006 --> 00:00:42,806
1239is designed as a mechanism for the division of user accounts and computer accounts for the purposes
1240
1241311
124200:00:42,906 --> 00:00:48,906
1243of IT and IT alone. So for example, an OU could be created for users and then a sub OU could
1244
1245312
124600:00:49,006 --> 00:00:54,806
1247be created for finance users. On the computer side, we could create an OU for computers and then
1248
1249313
125000:00:54,906 --> 00:01:00,906
1251a sub OU for IT computers or another one for high security computers.
1252
1253314
125400:01:01,006 --> 00:01:04,907
1255Now it is this definition I think that confuses a lot of people, especially when they start
1256
1257315
125800:01:05,007 --> 00:01:09,807
1259working with active directory and see this nifty new thing that is organizational units.
1260
1261316
126200:01:09,906 --> 00:01:16,907
1263The OU is designed for consumption by IT only, it's an administrative function only.
1264
1265317
126600:01:17,007 --> 00:01:22,807
1267And further, the biggest reason for the existence of organizational units is for the separation
1268
1269318
127000:01:22,906 --> 00:01:27,207
1271of active directory group policy and the application of group policy.
1272
1273319
127400:01:27,307 --> 00:01:31,907
1275You can create and manipulate OUs to your hearts content, you can move active directory users
1276
1277320
127800:01:32,007 --> 00:01:38,307
1279and computer groups around into different OUs and really have no fundamental change to how they end up operating.
1280
1281321
128200:01:38,406 --> 00:01:42,307
1283Except when you begin to go through the process of implementing group policy.
1284
1285322
128600:01:42,406 --> 00:01:46,907
1287And I say that because in order to implement group policy you have to tag a group policy
1288
1289323
129000:01:47,007 --> 00:01:52,807
1291object to an organizational unit. Now it's here where I kind want to step away from the exam
1292
1293324
129400:01:52,906 --> 00:01:58,807
1295for just a second and talk a bit about how you might implement things in your actual active directory environment.
1296
1297325
129800:01:58,906 --> 00:02:03,907
1299When you're building your organizational units, if you recognize that the only real use for OUs
1300
1301326
130200:02:04,007 --> 00:02:10,807
1303is for the application of group policy. It is, at least Greg's best practice, to only create
1304
1305327
130600:02:10,907 --> 00:02:16,907
1307organizational units when you need to do so for the application of group policy.
1308
1309328
131000:02:17,007 --> 00:02:21,807
1311Now this sounds like a, kind of a duh moment, but you find all the time out in the world
1312
1313329
131400:02:21,907 --> 00:02:26,307
1315you find organizations that have created dozens or hundreds of different OUs that break down
1316
1317330
131800:02:26,407 --> 00:02:33,807
1319their users and computers into various subcontainers and sub subcontainers, in some cases sub sub subcontainers.
1320
1321331
132200:02:33,907 --> 00:02:39,907
1323But all too often what happens is that the creation of this structure is awesome until the moment
1324
1325332
132600:02:40,007 --> 00:02:47,807
1327that you have to go about ensuring that the proper users and computers are always in the right location.
1328
1329333
133000:02:47,907 --> 00:02:54,807
1331A user account and a computer account can only exist in a single OU at a time.
1332
1333334
133400:02:54,907 --> 00:02:58,907
1335And so on the user side where it may be easy to make sure that Bob in accounting
1336
1337335
133800:02:59,007 --> 00:03:04,807
1339is always in the accounting OU. It's quite a bit more difficult on a day to day basis
1340
1341336
134200:03:04,907 --> 00:03:09,807
1343to know whether or not his computer, which who knows what the name of that computer is,
1344
1345337
134600:03:09,907 --> 00:03:14,907
1347also exists in the appropriate computer oriented organizational unit.
1348
1349338
135000:03:15,007 --> 00:03:20,307
1351If Bob swaps out his laptop for another machine, are you 100% sure that you'll be able to
1352
1353339
135400:03:20,407 --> 00:03:25,807
1355remove that old computer account and add the new one in every time that action happens?
1356
1357340
135800:03:25,907 --> 00:03:30,807
1359In my experience that doesn't happen that often and the more complex the OU structure you find,
1360
1361341
136200:03:30,907 --> 00:03:36,807
1363the less it maps to the real world, shall we say. So Greg's advice, keep your OU structure
1364
1365342
136600:03:36,907 --> 00:00:01,723
1367as simple as possible until you find a group policy oriented reason to separate it out for one reason or another.
1368
1369343
137000:00:01,824 --> 00:00:06,724
1371Now our last of these foundation topics that we have to talk about is also one that I suspect
1372
1373344
137400:00:06,823 --> 00:00:10,724
1375is not tested directly on in the exam, but if something you just have to know because it is
1376
1377345
137800:00:10,823 --> 00:00:16,724
1379one of the basics of active directory. And those are the flexible single master operations roles.
1380
1381346
138200:00:16,824 --> 00:00:21,724
1383Now Microsoft in attempting to create a multi-master model for the active directory database
1384
1385347
138600:00:21,824 --> 00:00:26,724
1387one where every copy of the database was exactly the same. And there was no single master
1388
1389348
139000:00:26,824 --> 00:00:32,723
1391where everyone pulled their content from, realize that a small subset of the activities of active directory
1392
1393349
139400:00:32,823 --> 00:00:38,723
1395could not be made multi-master. Some of these things worked best, or worked at all, when a single
1396
1397350
139800:00:38,823 --> 00:00:43,723
1399computer was responsible for the execution of that task. These created what we now know
1400
1401351
140200:00:43,823 --> 00:00:52,723
1403of as the FSMO roles. These five FSMO roles define a set of activities that have to occur on a specific machine.
1404
1405352
140600:00:52,823 --> 00:00:58,723
1407The first of which is the schema master. Anytime you do any update to the active directory schema,
1408
1409353
141000:00:58,823 --> 00:01:04,724
1411not necessarily changing content in the database, but changing the structure of the database itself.
1412
1413354
141400:01:04,823 --> 00:01:10,724
1415Updates like the AD prep command, Microsoft exchanges updates, any other applications that are going
1416
1417355
141800:01:10,823 --> 00:01:16,724
1419to modify the active directory schema. Those changes have to happen on the domain controller server
1420
1421356
142200:01:16,823 --> 00:01:22,724
1423that has been configured as the schema master. There's only one per forest and generally that's
1424
1425357
142600:01:22,823 --> 00:01:27,724
1427schema master is placed on the forest route PDC. And hold onto that we'll get to the PDC emulator in a minute,
1428
1429358
143000:01:27,823 --> 00:01:35,724
1431but that schema master is generally placed on the PDC emulator role holder in the forest route domain.
1432
1433359
143400:01:35,823 --> 00:01:39,724
1435Most important thing to know here is that in order to do any changes to the schema, you have to have
1436
1437360
143800:01:39,823 --> 00:01:43,724
1439a schema master up and operational. We have another role here called the domain naming master,
1440
1441361
144200:01:43,823 --> 00:01:49,724
1443which is responsible for, you guessed it, the naming of domains. This role was what's responsible
1444
1445362
144600:01:49,823 --> 00:01:53,724
1447for adding a removing domains and application partitions from the active directory forest
1448
1449363
145000:01:53,823 --> 00:01:59,724
1451and has to be online anytime you're doing any of those adds or removes to domains or app partitions.
1452
1453364
145400:01:59,823 --> 00:02:05,724
1455As with the schema master, the domain naming master is generally placed on that forest root PDC.
1456
1457365
145800:02:05,823 --> 00:02:12,724
1459Which is this our third role. Back in the old days, before we had a multi-master model for active directory,
1460
1461366
146200:02:12,824 --> 00:02:17,724
1463we use to have an approach where we had a single machine that served as the primary domain controller.
1464
1465367
146600:02:17,824 --> 00:02:24,724
1467And we had all other machines serving a secondary domain controllers or backup domain controllers, BDCs.
1468
1469368
147000:02:24,824 --> 00:02:33,724
1471These BDCs grabbed their content from the PDC, where a single master authoritative copy of the content always existed.
1472
1473369
147400:02:33,824 --> 00:02:40,724
1475All changes occurred at the PDC. Well with that change to a multi-master replication model for active directory
1476
1477370
147800:02:40,824 --> 00:02:47,724
1479database it still made sense for some of the action, some of the tasks, to occur on a single specified machine.
1480
1481371
148200:02:47,824 --> 00:02:52,724
1483That machine today is known of as the PDC emulator. The PDC emulator handles password changes,
1484
1485372
148600:02:52,824 --> 00:02:57,724
1487so if you're doing computer user accounts on DCs it handles the password changes.
1488
1489373
149000:02:57,824 --> 00:03:01,724
1491It's consulted by your replica domain controllers when you have service authorization requests
1492
1493374
149400:03:01,824 --> 00:03:09,724
1495with mismatched passwords. It is the default target DC anytime you're doing any group policy updates.
1496
1497375
149800:03:09,824 --> 00:03:15,724
1499It is also the default target DC when you have any legacy applications that need to perform writable operations.
1500
1501376
150200:03:15,824 --> 00:03:21,724
1503And some of the old school admin tools still point to the PDC emulators and very old school admin
1504
1505377
150600:03:21,824 --> 00:03:26,724
1507tools in order to accomplish their tasks. And also, not listed here, the PDC emulator tends to
1508
1509378
151000:03:26,824 --> 00:03:33,724
1511also be the time keeper for the domain and forest. Your PDC emulator, because of obviously these things,
1512
1513379
151400:03:33,824 --> 00:03:38,724
1515needs to be online and accessible at all times. And so you generally can't operate for a very
1516
1517380
151800:03:38,824 --> 00:03:44,724
1519long period of time without having a PDC emulator up and running. Many of the other FSMO roles
1520
1521381
152200:03:44,824 --> 00:03:49,724
1523can exist in a state where that domain controller is down for a period of time.
1524
1525382
152600:03:49,824 --> 00:03:54,724
1527I mean you don't often do schema changes, you don't often add and remove domains from your forest,
1528
1529383
153000:03:54,824 --> 00:03:58,724
1531but because of these things the PDC emulator does, it's generally expected to be online and
1532
1533384
153400:03:58,824 --> 00:04:03,724
1535accessible at all times. And it's generally also placed on higher performance hardware
1536
1537385
153800:04:03,824 --> 00:04:11,724
1539in a reliable hub site alongside other domain controllers that can handle your everyday user authentication traffic.
1540
1541386
154200:04:11,824 --> 00:04:16,723
1543When you're in a very large organization, where the emulator is doing a lot of tasks for a very large
1544
1545387
154600:04:16,824 --> 00:04:22,723
1547number of users and computers. Of the five, the PDC emulator is perhaps the most important to
1548
1549388
155000:04:22,824 --> 00:04:27,723
1551keep up and operational. Now the fourth of these is the RID master. And it's the job of the RID
1552
1553389
155400:04:27,824 --> 00:04:33,723
1555master to create what are called relative IDs or the different objects that require permissions or what not
1556
1557390
155800:04:33,824 --> 00:04:39,723
1559to be associated with them. A RID is a string of characters that is used to uniquely identify
1560
1561391
156200:04:39,824 --> 00:04:45,723
1563an object in a domain. The SID, which you're probably more familiar with, is just simply the RID
1564
1565392
156600:04:45,824 --> 00:04:48,723
1567plus an additional series of characters that is its domain identifier.
1568
1569393
157000:04:48,824 --> 00:04:56,723
1571So SID equals RID plus domain ID. The RID master's got to be online, so that any newly promoted DCs
1572
1573394
157400:04:56,824 --> 00:05:03,723
1575can obtain a local RID pool. Generally the RIDs are distributed by the individual DCs
1576
1577395
157800:05:03,824 --> 00:05:08,723
1579and only when they run out of RIDs in their pool do they request another set of them from the RID master.
1580
1581396
158200:05:08,824 --> 00:05:13,723
1583And it generally is also placed on the forest root PDC, as you can see here that PDC has got a lot
1584
1585397
158600:05:13,824 --> 00:05:17,723
1587of different roles that are generally held on it. Again the RID master's not quite as important
1588
1589398
159000:05:17,824 --> 00:05:23,723
1591as the PDC emulator because it's job is to maintain the pools that it distributes out to the domain controllers
1592
1593399
159400:05:23,824 --> 00:05:28,723
1595or actually assigning out those RIDs to individual objects. So you can have it shut down for a period
1596
1597400
159800:05:28,824 --> 00:05:32,723
1599of time, but you tend not to want to keep these things down for very long.
1600
1601401
160200:05:32,824 --> 00:05:38,723
1603The last of these is the infrastructure master and its job is to update references in the local domain
1604
1605402
160600:05:38,824 --> 00:05:44,723
1607for many objects that exist in other domains. So these cross domain references.
1608
1609403
161000:05:44,824 --> 00:05:49,723
1611You've seen this if you have a domain where your domain trusts another domain, either inside of a forest
1612
1613404
161400:05:49,824 --> 00:05:55,723
1615or outside through some forest trust. If you've had that situation where instead of seeing
1616
1617405
161800:05:55,824 --> 00:06:01,723
1619a user name you've seen a long list of numbers in the permissions dialog box and you're trying
1620
1621406
162200:06:01,824 --> 00:06:06,723
1623to assign permissions. It's the job of the infrastructure master to translate that SID into
1624
1625407
162600:06:06,824 --> 00:06:11,723
1627a friendly name. So you actually know what you're looking at. It's also the job of the infrastructure master
1628
1629408
163000:06:11,824 --> 00:06:17,723
1631to manage any phantoms or tombstones out of the global catalog. And these are topics, these are kind of
1632
1633409
163400:06:17,824 --> 00:06:22,723
1635dance topics that have to do with how objects get deleted and preserved and potentially resurrected.
1636
1637410
163800:06:22,824 --> 00:06:28,723
1639But recognize that it's the infrastructure master's job just to maintain those cross domain references.
1640
1641411
164200:06:28,824 --> 00:06:33,723
1643Now a separate infrastructure master is created for each application partition including the
1644
1645412
164600:06:33,824 --> 00:06:38,723
1647default forest wide and domain wide partitions. So it's possible you may see more than one
1648
1649413
165000:06:38,824 --> 00:06:42,723
1651infrastructure master in your domain depending on if you've created additional app partitions.
1652
1653414
165400:06:42,824 --> 00:06:46,723
1655And that's an extremely advanced topic we'll leave for another day.
1656
1657415
165800:06:46,824 --> 00:06:52,723
1659But these five FSMO roles are those that you should be aware of, probably for the exam
1660
1661416
166200:06:52,824 --> 00:06:57,723
1663but more importantly for the implementation in your own active directory domain and forests.
1664
1665417
166600:06:57,824 --> 00:07:02,723
1667Because by default all five roles will get held by the very first machine to come on line.
1668
1669418
167000:07:02,824 --> 00:07:05,723
1671And so it may become necessary for you to transfer those roles to different machines,
1672
1673419
167400:07:05,824 --> 00:07:10,723
1675should you have an outage event or should you need to just distribute the load.
1676
1677420
167800:07:10,824 --> 00:07:13,723
1679Now my last slide here is one that you used to be an awesome test question because
1680
1681421
168200:07:13,824 --> 00:07:18,723
1683it was one of those really ridiculous if/then statements having to do with the infrastructure master
1684
1685422
168600:07:18,824 --> 00:07:22,723
1687and its positioning. But who knows these days if Microsoft still cares.
1688
1689423
169000:07:22,824 --> 00:07:28,723
1691The infrastructure master was a bit of an odd duck in with the other FSMO roles because of how
1692
1693424
169400:07:28,824 --> 00:07:34,723
1695it needed to be placed. So this is that if/then statement, that again I present to you because
1696
1697425
169800:07:34,824 --> 00:07:39,723
1699it's been just one of those wacky ones in the past and who knows if it's still necessary today.
1700
1701426
170200:07:39,824 --> 00:07:45,723
1703In a single domain forest, so you have a single domain, single forest, the infrastructure master
1704
1705427
170600:07:45,824 --> 00:07:49,723
1707could be placed on any domain controller. This is the case because the infrastructure master
1708
1709428
171000:07:49,824 --> 00:07:53,723
1711in a single domain forest that doesn't have any connections or other domains to deal with,
1712
1713429
171400:07:53,824 --> 00:07:59,723
1715it doesn't have that much to do. However in a multi-domain forest, the infrastructure master
1716
1717430
171800:07:59,824 --> 00:08:03,723
1719is generally placed on a domain controller that is not a global catalog.
1720
1721431
172200:08:03,824 --> 00:08:10,723
1723And in fact, shouldn't be placed on a DC that's not a GC, except in the case where all of the
1724
1725432
172600:08:10,824 --> 00:08:15,723
1727DCs are global catalogs. And in that case, it just doesn't matter.
1728
1729433
173000:08:15,824 --> 00:08:19,723
1731So again, I present this to you because those are the roles and this one is a little bit wacky
1732
1733434
173400:08:19,824 --> 00:08:24,723
1735in comparison with the other ones, but in reality whether or not it's important for the exam
1736
1737435
173800:08:24,824 --> 00:08:27,223
1739this is one thing you might take a look at in your own domain to make sure that you've
1740
1741436
174200:08:27,324 --> 00:00:01,680
1743got your infrastructure master placed in the appropriate location.
1744
1745437
174600:00:01,780 --> 00:00:05,681
1747Alright so with the introduction out of the way, the foundations and the vocabulary,
1748
1749438
175000:00:05,780 --> 00:00:10,681
1751let's get into the click by click and command by command mechanisms that we'll go through
1752
1753439
175400:00:10,781 --> 00:00:14,681
1755to implement our active directory infrastructure. Starting first with this first task
1756
1757440
175800:00:14,781 --> 00:00:19,680
1759titled add and remove a domain controller from a domain. We're back here on our machine DC,
1760
1761441
176200:00:19,780 --> 00:00:25,680
1763this is the same machine that you were working with Jason back in that last course on the DNS and DHCP
1764
1765442
176600:00:25,780 --> 00:00:29,680
1767on network services. And this machine is currently still in a work group, I have it here with the
1768
1769443
177000:00:29,780 --> 00:00:36,680
1771address, 192.168.0.100 and I have also have, as you can see here, DNS services installed onto the machine.
1772
1773444
177400:00:36,780 --> 00:00:38,680
1775So, there may be a little
1776
1777445
177800:00:38,780 --> 00:00:42,680
1779misalignment here between what you see here and what you saw back when you were working with Jason,
1780
1781446
178200:00:42,780 --> 00:00:46,680
1783but at the very least we've got the very basics in place so that we can get an active directory
1784
1785447
178600:00:46,780 --> 00:00:51,680
1787infrastructure up and running. I do want to show you here, under DNS manager, that I have a forward
1788
1789448
179000:00:51,780 --> 00:00:58,680
1791lookup zone created for company.pri and I also have a reverse lookup zone created for the 192.168.0 net.
1792
1793449
179400:00:58,780 --> 00:01:05,681
1795And there's not much here, right, I have my DC and I have my DC2 computer currently in this reverse zone.
1796
1797450
179800:01:05,781 --> 00:01:11,681
1799And then over here on the other side I have DC and DC2 both here in company.pri.
1800
1801451
180200:01:11,781 --> 00:01:16,681
1803So, I include this here in this review of DNS because one of the ways in which you can
1804
1805452
180600:01:16,781 --> 00:01:20,681
1807go through a pretty simple test to see if this machine is ready to be promoted into an
1808
1809453
181000:01:20,781 --> 00:01:26,681
1811active directory domain controller. Is to first verify whether or not you can correctly resolve
1812
1813454
181400:01:26,781 --> 00:01:30,681
1815all the possible ways that this machine may need to be resolved. Now I'm going to show you how we can
1816
1817455
181800:01:30,781 --> 00:01:33,681
1819accomplish that, at least one way we can, and that's to bring up
1820
1821456
182200:01:33,781 --> 00:01:37,681
1823the command prompt here. And what I want to show you that here within the command prompt there
1824
1825457
182600:01:37,781 --> 00:01:42,681
1827is the command nslookup, that you probably dealt with back with Jason was talking about DNS.
1828
1829458
183000:01:42,781 --> 00:01:49,681
1831That you can use for checking DNS records or records for a machine in a DNS database.
1832
1833459
183400:01:49,781 --> 00:01:53,681
1835What I'm going to show you is probably not on the exam, but is my own little cheat
1836
1837460
183800:01:53,781 --> 00:01:58,681
1839to make sure that I've got all the DNS bits in place so that I can resolve appropriately
1840
1841461
184200:01:58,781 --> 00:02:04,681
1843and guarantee myself, or almost guarantee myself, a successful promotion of an active directory domain controller.
1844
1845462
184600:02:04,781 --> 00:02:10,681
1847There are three different tests that I use, the first of which is to just the short name for the machine.
1848
1849463
185000:02:10,781 --> 00:02:16,681
1851Here if I type in nslookup dc you'll see the dc.company.pri indeed resolves down here
1852
1853464
185400:02:16,781 --> 00:02:22,681
1855against the same server, which is this server dc.company.pri. If I have exactly this response
1856
1857465
185800:02:22,781 --> 00:02:28,681
1859meaning a successful response without any problems, then that's a success for the first of the three tests.
1860
1861466
186200:02:28,781 --> 00:02:35,681
1863The second test for me, is to then try to do an ns lookup across the entire fully qualified domain name
1864
1865467
186600:02:35,781 --> 00:02:41,681
1867of the DC I'm about to promote. That would be in this case dc.company.pri.
1868
1869468
187000:02:41,781 --> 00:02:44,681
1871And once again you can see here that we have a completely successful test coming back
1872
1873469
187400:02:44,781 --> 00:02:50,681
1875from our DNS server. In some cases, you may end up where the first of these tests
1876
1877470
187800:02:50,781 --> 00:02:56,681
1879resolves correctly, but the second of these tests does not. And this happens most often when
1880
1881471
188200:02:56,781 --> 00:02:59,681
1883back up here when we were taking a look at
1884
1885472
188600:02:59,781 --> 00:03:03,681
1887server manager. When you went about configuring the computer name for this machine
1888
1889473
189000:03:03,781 --> 00:03:08,681
1891one of the things that you can ignore doing in just about every circumstance, except for the
1892
1893474
189400:03:08,781 --> 00:03:12,681
1895case where you're creating a new active directory domain controller.
1896
1897475
189800:03:12,781 --> 00:03:18,681
1899Is in changing not only the full computer name, but down here under the more tab, making sure that
1900
1901476
190200:03:18,781 --> 00:03:23,681
1903you populate the primary DNS suffix for this computer. Again, most of the time we just ignore
1904
1905477
190600:03:23,781 --> 00:03:26,681
1907this step and don't worry about it when we're making a change to a computer name,
1908
1909478
191000:03:26,781 --> 00:03:32,681
1911but in this case, if I don't end up populating this primary DNS suffix for this computer.
1912
1913479
191400:03:32,781 --> 00:03:34,681
1915I'll end up with this second
1916
1917480
191800:03:34,781 --> 00:03:38,681
1919test here ending up with some kind of error messages as opposed to what I'm seeing.
1920
1921481
192200:03:38,781 --> 00:03:44,681
1923The third test then is to do the reverse lookup, which would be 192.168.0.100.
1924
1925482
192600:03:44,781 --> 00:03:48,681
1927And again I get the same response here. So as I said, this has nothing to do with the exam,
1928
1929483
193000:03:48,781 --> 00:03:52,681
1931but I like to use this as just a little test to make sure that I've done
1932
1933484
193400:03:52,781 --> 00:03:58,681
1935everything correctly to prepare myself for adding a new machine as a possible domain controller.
1936
1937485
193800:03:58,781 --> 00:04:02,681
1939We now have to go through that process of doing that addition, so essentially promoting
1940
1941486
194200:04:02,781 --> 00:04:08,681
1943this machine from a member server into a domain controller. And here in Windows Server 2012 and R2
1944
1945487
194600:04:08,781 --> 00:04:13,681
1947the way in which we accomplish that is now two steps as opposed to just one. Let me come back
1948
1949488
195000:04:13,781 --> 00:04:15,681
1951over here to the dashboard and choose to add
1952
1953489
195400:04:15,781 --> 00:04:20,680
1955roles and features. And it's here where I want to show you the first of the two steps.
1956
1957490
195800:04:20,781 --> 00:04:24,680
1959Back in the old days there was a command called DC promo, which you may still need to know here
1960
1961491
196200:04:24,781 --> 00:04:28,680
1963for this exam, but it has been deprecated in this version of the operating system.
1964
1965492
196600:04:28,781 --> 00:04:32,680
1967In the old days DC promo would complete the installation of the necessary bits and then go
1968
1969493
197000:04:32,781 --> 00:04:37,680
1971through the promotion activity to turn a member server into a domain controller.
1972
1973494
197400:04:37,781 --> 00:04:43,680
1975But these days the activity requires you here in Server 2012 and R2 to first install the
1976
1977495
197800:04:43,781 --> 00:04:50,680
1979ADDS bits, so the role and associated role services that create active directory domain services.
1980
1981496
198200:04:50,781 --> 00:04:55,680
1983If I go through this process and add in all the roles and the role services and necessary features,
1984
1985497
198600:04:55,781 --> 00:05:00,680
1987this will give me everything I need to then in the second step complete the promotion.
1988
1989498
199000:05:00,781 --> 00:05:04,680
1991Now if I choose restart here and yes and then install, that will go through the process
1992
1993499
199400:05:04,781 --> 00:05:09,680
1995of actually installing in the necessary components. Now if I wanted to do this from a command line
1996
1997500
199800:05:09,781 --> 00:05:12,680
1999one of the ways I could do this from the command line is through PowerShell.
2000
2001501
200200:05:12,781 --> 00:05:13,680
2003And if I come up here to run as
2004
2005502
200600:05:13,781 --> 00:05:17,680
2007administrator I can show you just a quick PowerShell command that you've already seen
2008
2009503
201000:05:17,781 --> 00:05:22,680
2011back a couple of courses ago when we were talking about adding and removing roles and role services.
2012
2013504
201400:05:22,781 --> 00:05:29,680
2015The install windows feature command is what I can use against ad-domain-services, that's the role
2016
2017505
201800:05:29,781 --> 00:05:34,680
2019I'm interested in. This command will install the active directory bits onto this machine just
2020
2021506
202200:05:34,781 --> 00:05:39,680
2023like what I've done here in the graphical user interface. There is an additional parameter
2024
2025507
202600:05:39,781 --> 00:05:45,680
2027you may want to use called includemanagementbits or managementtools.
2028
2029508
203000:05:45,781 --> 00:05:49,680
2031That additional parameter will install not only active directory domain services, but all of the
2032
2033509
203400:05:49,781 --> 00:05:54,680
2035other management tools that you would use to manage it. Now we won't run this here because
2036
2037510
203800:05:54,781 --> 00:05:59,680
2039obviously we're already installing the active directory bits onto this machine through the graphical user interface,
2040
2041511
204200:05:59,781 --> 00:06:01,680
2043but we'll keep this open here because I want to show you
2044
2045512
204600:06:01,781 --> 00:06:04,680
2047how you would do the second step of the process both through the graphical user interface
2048
2049513
205000:06:04,781 --> 00:06:09,680
2051as well as through the command line. As you can see back here in the add roles and features wizard
2052
2053514
205400:06:09,781 --> 00:06:13,680
2055we've completed the installation of the bits and now we need to go through the promotion
2056
2057515
205800:06:13,781 --> 00:06:17,680
2059of this server to an active directory domain controller. And it's here where we have a very
2060
2061516
206200:06:17,781 --> 00:06:21,680
2063large number of decisions that we have to make, hopefully you've made these decisions before
2064
2065517
206600:06:21,781 --> 00:06:27,680
2067you get to this point. So one of which is whether or not we're going to be installing a brand new
2068
2069518
207000:06:27,781 --> 00:06:32,680
2071forest, so is this the first domain controller in the first domain in a forest that we're
2072
2073519
207400:06:32,781 --> 00:06:38,680
2075creating brand new from scratch? Or are we adding a new domain to an existing forest?
2076
2077520
207800:06:38,781 --> 00:06:43,680
2079If we're adding a new domain to an existing forest, we are creating another triangle underneath the
2080
2081521
208200:06:43,781 --> 00:06:49,680
2083triangle that we have already created before. Anytime I'm adding a new domain to an existing
2084
2085522
208600:06:49,781 --> 00:06:54,680
2087forest this will be the first DC in that new domain. But in order to establish the connection,
2088
2089523
209000:06:54,781 --> 00:06:59,680
2091the trust between the two, I would need to choose one of the available domain types.
2092
2093524
209400:06:59,781 --> 00:07:05,680
2095That being either a child domain or a tree domain. The biggest difference here is that a tree domain
2096
2097525
209800:07:05,781 --> 00:07:11,680
2099gives you the ability to create a noncontiguous namespace for the domain I'm creating.
2100
2101526
210200:07:11,781 --> 00:07:15,680
2103For example, in a child domain, if I were creating a child domain off of company.pri,
2104
2105527
210600:07:15,781 --> 00:07:20,680
2107the domain name I would be creating would be something.company.pri.
2108
2109528
211000:07:20,781 --> 00:07:25,680
2111Again this is different from a tree domain where I could be really anything that I wanted to.
2112
2113529
211400:07:25,781 --> 00:07:28,680
2115In either case, I'd need to populate the information about what domain name I'm creating down here
2116
2117530
211800:07:28,781 --> 00:07:33,680
2119at the bottom and then obviously provide some credentials down here to perform the action.
2120
2121531
212200:07:33,781 --> 00:07:36,680
2123I do also have a third deployment option up here which is to add a new domain controller
2124
2125532
212600:07:36,781 --> 00:07:42,680
2127to an existing domain, which is of the three the one you'll find yourself doing quite a bit more than the other two.
2128
2129533
213000:07:42,781 --> 00:07:46,680
2131In this case all I need to do is identify which domain I'm interested in and then provide
2132
2133534
213400:07:46,781 --> 00:07:51,680
2135credentials for it down here. We are, however, creating a brand new forest, a brand new forest
2136
2137535
213800:07:51,781 --> 00:07:56,680
2139a brand new domain, and a brand new domain controller. And so, because of that we need to create
2140
2141536
214200:07:56,781 --> 00:08:02,680
2143a new root domain called company.pri. When I do that I'm going to have a variety of different
2144
2145537
214600:08:02,781 --> 00:08:07,680
2147other options and configurations that I need to set for this domain and forest that I'm creating.
2148
2149538
215000:08:07,781 --> 00:08:13,680
2151The first of which is determining what the forest and domain functional level will need to be for the domain.
2152
2153539
215400:08:13,781 --> 00:08:16,680
2155Now you'll notice down here that there are a couple of different options for forest and domain
2156
2157540
215800:08:16,781 --> 00:08:21,680
2159and in fact I think there's a couple for forest here and just a single one here for domain.
2160
2161541
216200:08:21,781 --> 00:08:26,680
2163These functional levels define a set of capabilities that existed at the time that that version
2164
2165542
216600:08:26,781 --> 00:08:33,680
2167of the operating system was released. So back in the year 2008 when Windows Server 2008 was released
2168
2169543
217000:08:33,780 --> 00:08:38,680
2171there were certain types of activities at the forest level that that forest could accomplish.
2172
2173544
217400:08:38,780 --> 00:08:43,680
2175Microsoft then later wrote additional functionality and added it into the operating system
2176
2177545
217800:08:43,780 --> 00:08:49,680
2179with the release of server 2008 R2, and again in 2012 and again in 2012 R2.
2180
2181546
218200:08:49,780 --> 00:08:53,680
2183In most cases, when you're creating a brand new domain and a brand new forest,
2184
2185547
218600:08:53,780 --> 00:08:57,680
2187you'll want to create that forest and domain with the highest functional level available.
2188
2189548
219000:08:57,780 --> 00:09:01,680
2191But occasionally if you have applications that you know will not function with that forest
2192
2193549
219400:09:01,780 --> 00:09:06,680
2195or domain functional level, well you may need to set it down to one level below.
2196
2197550
219800:09:06,780 --> 00:09:10,680
2199More often than not, in the vast majority of cases the highest functional level is indeed the
2200
2201551
220200:09:10,780 --> 00:09:14,680
2203one that you're looking for. Now when you're also creating a new domain controller you have some
2204
2205552
220600:09:14,780 --> 00:09:18,680
2207additional capabilities that you can apply on the domain controller itself.
2208
2209553
221000:09:18,780 --> 00:09:22,680
2211The first of which is whether or not that machine should be a DNS server or not.
2212
2213554
221400:09:22,780 --> 00:09:27,680
2215And whether or not that machine should be a global catalog. Because this is the first domain controller
2216
2217555
221800:09:27,780 --> 00:09:32,680
2219in the domain and the forest, we already have this selection here selected for us for global catalog.
2220
2221556
222200:09:32,780 --> 00:09:37,680
2223We have to have it as a GC. And because we've already installed DNS onto this machine the checkbox here
2224
2225557
222600:09:37,780 --> 00:09:44,680
2227is grayed out as well. It is possible to have the ADDS configuration wizard install DNS server onto
2228
2229558
223000:09:44,780 --> 00:09:52,680
2231this machine as part of the wizard. However, personally I've never seen it function very well.
2232
2233559
223400:09:52,780 --> 00:09:55,680
2235I've always had better luck with getting the DNS server bits installed
2236
2237560
223800:09:55,780 --> 00:10:00,680
2239prior to beginning the ADDS configuration wizard. So it's my recommendation to always start
2240
2241561
224200:10:00,780 --> 00:10:04,680
2243with installing DNS first before you get this far. Down here at the bottom we have what's called
2244
2245562
224600:10:04,780 --> 00:10:11,680
2247the directory services restore mode password, which is a special password that you will enter once
2248
2249563
225000:10:11,780 --> 00:10:15,680
2251and then never need to enter again, except in the situation where you need to perform an
2252
2253564
225400:10:15,780 --> 00:10:21,680
2255authoritative restore of the active directory database. Now this authoritative restore is a bit of
2256
2257565
225800:10:21,780 --> 00:10:26,680
2259a painful activity and because of that there are a lot of tools these days, third-party tools
2260
2261566
226200:10:26,780 --> 00:10:29,680
2263that you can use and even some first party tools with the active directory recycle bin.
2264
2265567
226600:10:29,780 --> 00:10:34,680
2267That ease the process of recovering data out of the active directory database.
2268
2269568
227000:10:34,780 --> 00:10:39,680
2271So recognize that when you set this DSRN password you need to put it in a safe place because until
2272
2273569
227400:10:39,780 --> 00:10:43,680
2275you change it yourself, this password will never be changed again.
2276
2277570
227800:10:43,780 --> 00:10:48,680
2279All too often we find people that have created DSRN passwords with the creation of their domain
2280
2281571
228200:10:48,780 --> 00:10:54,680
2283and forest and that information gets lost until years, many years down the road when an
2284
2285572
228600:10:54,780 --> 00:10:58,680
2287authoritative restore is required. And the last thing that you want is to try to find a
2288
2289573
229000:10:58,780 --> 00:11:02,680
2291DSRN password when you don't have a functioning domain or functioning forest.
2292
2293574
229400:11:02,780 --> 00:11:07,680
2295So pay careful attention to this and probably put it in a safe place somewhere because you
2296
2297575
229800:11:07,780 --> 00:11:10,680
2299may need it at some point in the future. Down here next is
2300
2301576
230200:11:10,780 --> 00:11:15,680
2303where we can specify any DNS delegation options, these will allow us to create the appropriate
2304
2305577
230600:11:15,780 --> 00:11:21,680
2307DNS delegation so that we have the folder structure in DNS to support the SRV records that we'll require.
2308
2309578
231000:11:21,780 --> 00:11:26,680
2311When we do that we can punch in the administrator user name here and the password
2312
2313579
231400:11:26,780 --> 00:11:30,680
2315to create the correct credentials for creating that DNS delegation.
2316
2317580
231800:11:30,780 --> 00:11:34,680
2319Down here under next is where it's going to verify the net bios name that's going to be assigned
2320
2321581
232200:11:34,780 --> 00:11:40,680
2323to the domain. The net bios domain name will be, in most cases, the first set of characters
2324
2325582
232600:11:40,780 --> 00:11:44,680
2327before the first dot, in whatever fully qualified domain name that you create.
2328
2329583
233000:11:44,780 --> 00:11:49,680
2331In our case it was company.pri and so company, all the characters up to that first dot,
2332
2333584
233400:11:49,780 --> 00:11:53,680
2335is what makes that net bios domain name. There are some cases where it will not be those
2336
2337585
233800:11:53,780 --> 00:11:58,680
2339first characters, the net bios domain needs to be, I believe, 15 characters or less.
2340
2341586
234200:11:58,780 --> 00:12:02,680
2343So you might want to take care to ensure that any of the names in your fully qualified domain names
2344
2345587
234600:12:02,780 --> 00:12:08,680
2347for those that you're creating stay under that 15 character limit. If I choose next again
2348
2349588
235000:12:08,780 --> 00:12:14,680
2351I could define what the paths will be for the different components of active directory that are to be installed.
2352
2353589
235400:12:14,780 --> 00:12:19,680
2355The database folder, the log files folder, as well as the SIS file folder here could be determined.
2356
2357590
235800:12:19,780 --> 00:12:23,680
2359Now in a production world you may want to move these off onto a different disc drive,
2360
2361591
236200:12:23,780 --> 00:12:27,680
2363just so that you have them separated out from the operating system.
2364
2365592
236600:12:27,780 --> 00:12:30,680
2367I'll leave them here as C because I only have a single disc drive on this machine,
2368
2369593
237000:12:30,780 --> 00:12:35,680
2371but again in a production world it can be a good idea to move those off onto separate spindles
2372
2373594
237400:12:35,780 --> 00:12:40,680
2375if anything to make the process of recovering this machine a little bit easier.
2376
2377595
237800:12:40,780 --> 00:12:43,680
2379I'll choose Next so that we can go through the review of the options here and I want to
2380
2381596
238200:12:43,780 --> 00:12:47,680
2383direct your attention, down here at the bottom right, this little item called
2384
2385597
238600:12:47,780 --> 00:12:54,680
2387view scripts. This view script item down here is what gives you the abilities to
2388
2389598
239000:12:54,780 --> 00:13:00,680
2391reproduce everything that we've talked about in this wizard, except using the PowerShell tool
2392
2393599
239400:13:00,780 --> 00:13:04,680
2395to do this from the command line. Notice the script that gets created is a .tmp file,
2396
2397600
239800:13:04,780 --> 00:13:08,680
2399which if you end up needing to save this you'd have to put it in the correct format so that the
2400
2401601
240200:13:08,780 --> 00:13:12,680
2403script can be executed by PowerShell. But recognize that what we're doing here is running
2404
2405602
240600:13:12,780 --> 00:13:18,680
2407the import module ADDS deployment command here and then we're running the install ADDS forest command
2408
2409603
241000:13:18,780 --> 00:13:23,680
2411with this long list of parameters that effectively answer all the questions that we've run
2412
2413604
241400:13:23,780 --> 00:13:28,680
2415through here in the wizard. I'm showing you this at this point because it is exactly this piece
2416
2417605
241800:13:28,780 --> 00:13:33,680
2419of code here that would allow you to reproduce this process using the command line
2420
2421606
242200:13:33,780 --> 00:13:39,680
2423if I were to do so here in Windows PowerShell. So this would give you the abilities to
2424
2425607
242600:13:39,780 --> 00:13:44,680
2427stream line the process, to automate the process, to just know how this works using Windows PowerShell. I would
2428
2429608
243000:13:44,780 --> 00:13:50,680
2431know how this is and know that essentially running through this, perhaps even just running through it
2432
2433609
243400:13:50,780 --> 00:13:54,680
2435and pretending to answer all the questions in the way that you would, would give you a really
2436
2437610
243800:13:54,780 --> 00:13:59,680
2439nice piece of code here that you could just punch into the command line to get this machine brought online.
2440
2441611
244200:13:59,780 --> 00:14:04,680
2443This is particularly helpful, not so much when you're creating your first domain controller,
2444
2445612
244600:14:04,780 --> 00:14:07,680
2447but when you're going about creating all those additional domain controllers.
2448
2449613
245000:14:07,780 --> 00:14:12,680
2451Those DCs that will come online after the first DC and the domain are created.
2452
2453614
245400:14:12,780 --> 00:14:15,680
2455It is the creation of those additional domain controllers and the PowerShell commands that are
2456
2457615
245800:14:15,780 --> 00:14:21,680
2459used in creating them, that you can then copy and paste and just adjust in some of the information in here
2460
2461616
246200:14:21,780 --> 00:14:26,680
2463to rapidly deploy those additional domain controllers as you see fit. For our purposes here
2464
2465617
246600:14:26,780 --> 00:14:31,680
2467let's go through and hit the Next button and then allow our prerequisites check to complete.
2468
2469618
247000:14:31,780 --> 00:14:36,680
2471So that we can go about the installation of active directory domain services onto this machine DC.
2472
2473619
247400:14:36,780 --> 00:14:40,680
2475Looks like all of our prerequisite checks completed successfully, so I'll click the install button
2476
2477620
247800:14:40,780 --> 00:14:43,680
2479to begin the installation of active directory.
2480
2481621
248200:14:43,780 --> 00:14:46,680
2483And then finally thanks to the magic of video editing, I can accelerate us to the completion
2484
2485622
248600:14:46,780 --> 00:14:52,180
2487of this installation process. As you can see here after the reboot, we have a machine DC that
2488
2489623
249000:14:52,280 --> 00:14:56,680
2491is currently in the company.pri domain and if I come up here under Tools we have the usual
2492
2493624
249400:14:56,780 --> 00:15:01,680
2495active directory tools that have been installed. So here under active directory users and computers we
2496
2497625
249800:15:01,780 --> 00:00:01,649
2499can see that we indeed now have this domain company.pri.
2500
2501626
250200:00:01,750 --> 00:00:03,258
2503Well, we have one final thing we have to talk about
2504
2505627
250600:00:03,358 --> 00:00:07,759
2507and that is the removal of active directory and removal of domain controllers
2508
2509628
251000:00:07,858 --> 00:00:14,259
2511from an existing domain. It is always a good idea to remove domain controllers using the official
2512
2513629
251400:00:14,358 --> 00:00:18,759
2515procedure as opposed to just ripping them out of the domain. Anytime you go about ripping domain controllers
2516
2517630
251800:00:18,859 --> 00:00:21,759
2519out of a domain without removing the roles and features from
2520
2521631
252200:00:21,859 --> 00:00:25,759
2523those machines, you're going to end up with lingering objects inside of your active directory database,
2524
2525632
252600:00:25,859 --> 00:00:30,759
2527that could cause problems down the road. So as you can see here, I brought up the roles and the remove
2528
2529633
253000:00:30,859 --> 00:00:37,759
2531roles and features wizard here. If I choose Next and then focus it on dc.company.pri,
2532
2533634
253400:00:37,859 --> 00:00:41,759
2535I can choose to unselect active directory domain services. Now there's two things you have to know,
2536
2537635
253800:00:41,859 --> 00:00:45,759
2539the first of which is sort of obvious, and that is that you can't remove a domain until
2540
2541636
254200:00:45,859 --> 00:00:49,759
2543all the domain controllers have been completely removed from that domain.
2544
2545637
254600:00:49,859 --> 00:00:53,759
2547The second of which is that you can't actually remove active directory domain services
2548
2549638
255000:00:53,859 --> 00:00:58,759
2551until you go about demoting the domain controller itself. This demotion
2552
2553639
255400:00:58,859 --> 00:01:05,759
2555process goes through removing all those records out of active directory in the database itself and so on.
2556
2557640
255800:01:05,858 --> 00:01:11,759
2559And ensuring that you end up with a clean domain after this domain controller gets removed.
2560
2561641
256200:01:11,858 --> 00:01:15,759
2563Now occasionally you may end up in the situation where you have a domain controller that for one
2564
2565642
256600:01:15,858 --> 00:01:19,759
2567reason or another cannot be cleanly removed from active directory and when
2568
2569643
257000:01:19,858 --> 00:01:24,759
2571that's the case you may need to go through forcing the removal of the domain controller.
2572
2573644
257400:01:24,858 --> 00:01:27,759
2575And so when that happens there is a whole variety of extra tasks you'll have to go through
2576
2577645
257800:01:27,858 --> 00:01:31,759
2579that are out of scope for our discussion here, but again just recognize that the clean
2580
2581646
258200:01:31,858 --> 00:01:37,759
2583removal is your desired state anytime you're getting rid of these DCs out of an active directory.
2584
2585647
258600:01:37,858 --> 00:01:41,759
2587And then lastly down here is removing this as the last domain controller in the domain.
2588
2589648
259000:01:41,858 --> 00:01:46,759
2591Anytime you're doing that this essentially decommissioned the domain and takes it out of existence.
2592
2593649
259400:01:46,858 --> 00:01:50,759
2595They'll have some warnings here, some removal options, and even a new administrator password,
2596
2597650
259800:01:50,858 --> 00:01:53,759
2599a local password you'll have to configure, but essentially this is the process you'll need
2600
2601651
260200:01:53,858 --> 00:01:58,759
2603to go through to get rid of active directory off of a specific machine.
2604
2605652
260600:01:58,858 --> 00:02:00,759
2607And then finally, just for completeness, I want to show you over here in PowerShell that there
2608
2609653
261000:02:00,858 --> 00:02:05,759
2611is a PowerShell commandlet you should be aware of too that can accomplish the same thing.
2612
2613654
261400:02:05,858 --> 00:02:10,759
2615It is Uninstall-ADDSDomainController. Just like all the PowerShell
2616
2617655
261800:02:10,859 --> 00:02:14,759
2619commands there's a long list of just different parameters that will do more or less the
2620
2621656
262200:02:14,859 --> 00:02:18,759
2623same things that we saw back in the graphical user interface. But this is the mechanism from
2624
2625657
262600:02:18,859 --> 00:02:23,759
2627PowerShell that you would go about removing ADDS or removing this domain controller from the domain
2628
2629658
263000:02:23,859 --> 00:02:27,759
2631and then you would want to go through the remove windows feature commandlet to go about getting rid
2632
2633659
263400:02:27,859 --> 00:00:01,715
2635of the bits off of this machine as well.
2636
2637660
263800:00:01,816 --> 00:00:06,216
2639Now our next topic comes in handy in those rare use cases where you have a machine that you need
2640
2641661
264200:00:06,315 --> 00:00:12,716
2643to build in a location that is perhaps far removed from the rest of your domain because of some latent
2644
2645662
264600:00:12,816 --> 00:00:16,715
2647network condition and you've got a slow connection. Maybe you've got a very full connection
2648
2649663
265000:00:16,815 --> 00:00:20,715
2651that you can't get traffic across within any reasonable amount of time.
2652
2653664
265400:00:20,815 --> 00:00:26,715
2655Now when that's the case it is entirely possible to build a domain controller in that remote location
2656
2657665
265800:00:26,815 --> 00:00:31,715
2659and use now the US Postal Service or whatever your local postal service is in order to transfer
2660
2661666
266200:00:31,815 --> 00:00:35,716
2663the contents of the active directory database perhaps on a flash drive.
2664
2665667
266600:00:35,816 --> 00:00:40,716
2667Because sending it through the mail is faster than sending it through whatever network you have.
2668
2669668
267000:00:40,816 --> 00:00:47,716
2671This is called an install from media installation. And the process to do so starts by creating
2672
2673669
267400:00:47,816 --> 00:00:54,716
2675what is essentially a little mini snapshot of your active directory database on an existing domain controller.
2676
2677670
267800:00:54,816 --> 00:00:55,716
2679Let's go ahead here and
2680
2681671
268200:00:55,816 --> 00:01:00,716
2683bring up an elevated command prompt here that runs as administrator.
2684
2685672
268600:01:00,816 --> 00:01:04,716
2687Because I want to show you the process that you would need to go through to create that initial snapshot.
2688
2689673
269000:01:04,816 --> 00:01:09,716
2691This snapshot will obviously be a little bit behind from the everyday changes in your active directory
2692
2693674
269400:01:09,816 --> 00:01:15,716
2695infrastructure, but will be a great starting point to allow that remote domain controller
2696
2697675
269800:01:15,816 --> 00:01:19,716
2699to at least get the large quantity of your active directory up and operational.
2700
2701676
270200:01:19,816 --> 00:01:22,716
2703So that it only needs to replicate those things that have changed.
2704
2705677
270600:01:22,816 --> 00:01:28,716
2707The way in which we create the snapshot starts by launching the ntdsutil command,
2708
2709678
271000:01:28,816 --> 00:01:36,716
2711which is the or the ntdsutil command, which is the kind of the Swiss army knife for your active directory database.
2712
2713679
271400:01:36,816 --> 00:01:38,716
2715ntdsutil has a large number of commands
2716
2717680
271800:01:38,816 --> 00:01:41,716
2719that you could potentially use here, many of which you'll talk about as you go through the rest of
2720
2721681
272200:01:41,816 --> 00:01:48,716
2723your exploration of the MCSA and MCSE. But the command we're looking for here has to do with
2724
2725682
272600:01:48,816 --> 00:01:55,716
2727creating an IFM instance. Let's start by focusing ntdsutil on the current copy of the active directory
2728
2729683
273000:01:55,816 --> 00:02:03,716
2731database that we're using in production. I will do that with activate instance ntds.
2732
2733684
273400:02:03,816 --> 00:02:08,716
2735That currently focuses us then on the running copy of active directory as opposed to any lightweight directory
2736
2737685
273800:02:08,816 --> 00:02:13,716
2739partitions that might be out there. Once we're done with that we need to type in ifm to get
2740
2741686
274200:02:13,816 --> 00:02:16,716
2743us to the installation from media sub menu. Now this
2744
2745687
274600:02:16,816 --> 00:02:21,716
2747sub menu comes with a variety of different tasks that we could do, the tool that we're interested in here
2748
2749688
275000:02:21,816 --> 00:02:27,716
2751because we need all of these bits to create a new domain controller, would be create full
2752
2753689
275400:02:27,816 --> 00:02:33,716
2755and then a location where we want to store that ifm media. Also available here is the abilities to
2756
2757690
275800:02:33,816 --> 00:02:38,716
2759create an RODC, if I'm creating a read-only domain controller. Or just an output of the
2760
2761691
276200:02:38,816 --> 00:02:45,716
2763sysvol content as well. Let me go ahead and create this full here in c:\users\gshields\desktop
2764
2765692
276600:02:45,816 --> 00:02:52,716
2767and then we'll call this ifm. That creates a snapshot and this process takes just a second or two
2768
2769693
277000:02:52,816 --> 00:02:57,716
2771the larger your database is the longer it will take for it to create that snapshot.
2772
2773694
277400:02:57,816 --> 00:02:58,716
2775And then once we're done we can take a look
2776
2777695
277800:02:58,816 --> 00:03:03,716
2779at the file that we just created, which should be, actually not here apparently, it should be found
2780
2781696
278200:03:03,816 --> 00:03:10,716
2783in C:, Users, and then gshields, and then desktop. There's our ifm folder.
2784
2785697
278600:03:10,816 --> 00:03:15,716
2787In the ifm folder is a copy of the active directory and the registry entries that are important
2788
2789698
279000:03:15,816 --> 00:03:21,716
2791and there is our ntds.dit file. If you've ever wondered where the active directory database exists
2792
2793699
279400:03:21,816 --> 00:03:27,716
2795it actually exists in this file called ntds.dit, that's the database itself.
2796
2797700
279800:03:27,816 --> 00:03:31,716
2799Also here is some registry values that we would need in order to get that other controller
2800
2801701
280200:03:31,816 --> 00:03:34,716
2803that other domain controller configured in the way we need to.
2804
2805702
280600:03:34,816 --> 00:03:39,716
2807Once I have that folder, I can take that folder and drop it onto a USB thumb drive,
2808
2809703
281000:03:39,816 --> 00:03:44,716
2811stick in the mail, receive it at my remote location, and then once I'm at my remote location if I
2812
2813704
281400:03:44,816 --> 00:03:50,716
2815flip over here to an example machine. I can then from that remote location use the information on
2816
2817705
281800:03:50,816 --> 00:03:56,716
2819that thumb drive to go about completing the process of creating a new domain controller.
2820
2821706
282200:03:56,816 --> 00:04:01,716
2823Now I've got here our server file1.company.pri and I'm not going to go through installing active directory
2824
2825707
282600:04:01,816 --> 00:04:06,716
2827onto this machine because we have need for it later on. But I have gone as far as just to get the
2828
2829708
283000:04:06,816 --> 00:04:11,716
2831bits installed so that we can go about attempting to promote this server to a domain controller.
2832
2833709
283400:04:11,816 --> 00:04:14,716
2835Now in this case, again we're not going to go through all the steps here, but I want to show you
2836
2837710
283800:04:14,816 --> 00:04:19,715
2839that when it comes time to add a new domain controller to an existing domain and I provide in
2840
2841711
284200:04:19,815 --> 00:04:24,715
2843all the correct information, the domain and the credentials, and choose next down here.
2844
2845712
284600:04:24,815 --> 00:04:28,715
2847This is the process I would go through in order to create a new domain controller using
2848
2849713
285000:04:28,815 --> 00:04:34,715
2851this ifm media. I will here, just as before, punch in a DSRN password, I'm going to leave it in the
2852
2853714
285400:04:34,815 --> 00:04:40,715
2855existing site, although arguably if I was in a remote site I would need to punch in the remote site name here.
2856
2857715
285800:04:40,815 --> 00:04:45,715
2859Down here under next I would choose DNS options if I needed to, but down here under additional options
2860
2861716
286200:04:45,815 --> 00:04:49,715
2863is where I could go about choosing to install from media. And it's this location where
2864
2865717
286600:04:49,815 --> 00:04:53,715
2867I'd go about pointing it to that appropriate media on that thumb drive to gather and install
2868
2869718
287000:04:53,815 --> 00:04:59,715
2871the snapshot of the active directory database. Now once the snapshot is installed,
2872
2873719
287400:04:59,815 --> 00:05:04,715
2875obviously that's a snapshot from a particular period of time, and so the domain controller that
2876
2877720
287800:05:04,815 --> 00:05:08,715
2879I'm creating is going to need to gather anything that's changed from the time that that snapshot
2880
2881721
288200:05:08,815 --> 00:05:14,715
2883was taken up until this moment in time. In order to get those changes you'll want to point
2884
2885722
288600:05:14,815 --> 00:05:19,715
2887it towards probably the closest domain controller to the DC that you're creating.
2888
2889723
289000:05:19,815 --> 00:05:23,715
2891Now normally it's shows here any domain controller, because in a well-connected environment
2892
2893724
289400:05:23,815 --> 00:05:27,715
2895it doesn't really matter which domain controller you grab that information from.
2896
2897725
289800:05:27,815 --> 00:05:31,715
2899But when I'm dealing with a very slow network connection, I want to come down here and make sure
2900
2901726
290200:05:31,815 --> 00:05:35,715
2903that I do any replication from that machine that is geographically or at least on the network
2904
2905727
290600:05:35,815 --> 00:05:39,915
2907placed the closest to this machine. Once I'm done with that I can go through all the steps that
2908
2909728
291000:05:40,016 --> 00:00:01,924
2911exist here in the wizard and add this as an additional domain controller.
2912
2913729
291400:00:02,024 --> 00:00:05,925
2915Now why we don't actually want to install active directory domain services onto our file server,
2916
2917730
291800:00:06,025 --> 00:00:11,925
2919we do want to get it onto our second DC, number DC2 right here. For us to do that, remember this is
2920
2921731
292200:00:12,025 --> 00:00:17,924
2923a server core machine, we've got that two-step process to get to ADDS first installed onto the machine
2924
2925732
292600:00:18,024 --> 00:00:22,924
2927and then to actually execute the promotion. The first step in the process is our old friend
2928
2929733
293000:00:23,024 --> 00:00:27,924
2931install windows feature, which I need to use PowerShell in order to do that.
2932
2933734
293400:00:28,024 --> 00:00:34,924
2935Install-WindowsFeature with the name of the feature we're interested in being ad-domain-services.
2936
2937735
293800:00:35,024 --> 00:00:40,924
2939If we go through this, this will install the ADDS domain bits onto this machine just like we did before.
2940
2941736
294200:00:41,024 --> 00:00:46,924
2943And then our next step is to use another command, which is install-ADDSDomainController.
2944
2945737
294600:00:47,024 --> 00:00:54,924
2947This command will allow us to connect up this domain controller to our domain, DomainName company.pri.
2948
2949738
295000:00:55,024 --> 00:00:58,924
2951Now one curious thing about this that the process which we're going through this, remember that
2952
2953739
295400:00:59,024 --> 00:01:04,925
2955this machine, DC2, is currently not in the domain. And so for us to be able to facilitate
2956
2957740
295800:01:05,025 --> 00:01:07,925
2959the installation of this as a domain controller and then to add it into the domain,
2960
2961741
296200:01:08,025 --> 00:01:12,925
2963we're going to have to go through a little extra step here involving some credentials
2964
2965742
296600:01:13,025 --> 00:01:18,925
2967that we will apply for the domain we're about to enter into. That process uses the credential,
2968
2969743
297000:01:19,025 --> 00:01:25,925
2971credential parameter, and then we need to pipe in an actual credential, the usable credential here
2972
2973744
297400:01:26,025 --> 00:01:29,925
2975in at the command line. Which we'll do by having PowerShell first resolve the results of
2976
2977745
297800:01:30,025 --> 00:01:34,925
2979a command get credential. This command, get credential, will allow me to get the credential for
2980
2981746
298200:01:35,025 --> 00:01:39,925
2983the company administrator account, if I can type it correctly, so that we can use that information
2984
2985747
298600:01:40,025 --> 00:01:44,925
2987in order to add this machine here into the domain. I'll go ahead and hit the OK button here
2988
2989748
299000:01:45,025 --> 00:01:49,925
2991and then punch in my credential, that's my password there. And as well as the safe mode administrator
2992
2993749
299400:01:50,025 --> 00:01:54,925
2995password, which is our directory services restore mode password we entered in earlier on
2996
2997750
299800:01:55,025 --> 00:01:58,925
2999when we were working with the GUI. I'll punch that in twice to ensure I've got it
3000
3001751
300200:01:59,025 --> 00:02:03,925
3003correctly and choose A to go about configuring this as a domain controller.
3004
3005752
300600:02:04,025 --> 00:02:08,425
3007If everything goes well, as you can see here, we will go about adding this machine as a second domain
3008
3009753
301000:02:08,525 --> 00:00:01,617
3011controller here within our domain.
3012
3013754
301400:00:01,717 --> 00:00:05,618
3015Now building new domain controllers can be a fun activity, until well you've probably done it
3016
3017755
301800:00:05,717 --> 00:00:09,618
3019your 25th or 35th time, but actually upgrading domain controller.
3020
3021756
302200:00:09,717 --> 00:00:13,618
3023And more specifically upgrading domains becomes much more of a project.
3024
3025757
302600:00:13,717 --> 00:00:16,617
3027Remember talking about upgrading domain controllers and upgrading domains
3028
3029758
303000:00:16,717 --> 00:00:21,617
3031we think of this as a project because the move from one operating system to another
3032
3033759
303400:00:21,717 --> 00:00:26,617
3035does more than just change the OS that exists on that domain controller itself.
3036
3037760
303800:00:26,717 --> 00:00:30,617
3039With each new version of the operating system come new features that are baked into active directory
3040
3041761
304200:00:30,717 --> 00:00:35,618
3043as well as a slightly different active directory database itself that's going to require
3044
3045762
304600:00:35,718 --> 00:00:39,618
3047some updating as well. And so the process, not only to upgrade a domain controller,
3048
3049763
305000:00:39,718 --> 00:00:45,618
3051but really a domain or even a forest, typically happens in five different steps.
3052
3053764
305400:00:45,718 --> 00:00:51,618
3055This goes just a little bit further than what I think is going to be required for the exam itself,
3056
3057765
305800:00:51,718 --> 00:00:54,618
3059but I think it's valid for you to understand what these five steps are.
3060
3061766
306200:00:54,718 --> 00:00:58,618
3063Because it's likely that you may be taking this exam to prepare yourself for upgrading your skills
3064
3065767
306600:00:58,718 --> 00:01:03,618
3067and your domain to a newer version of the operating system. The first step in the process
3068
3069768
307000:01:03,718 --> 00:01:08,618
3071is obviously just to get healthy. Making sure that you have a healthy active directory with great
3072
3073769
307400:01:08,718 --> 00:01:14,618
3075replication between machines and no major error messages in any of your domain controller logs
3076
3077770
307800:01:14,718 --> 00:01:19,618
3079is always the best step towards making sure that the garbage you get out is at least as good
3080
3081771
308200:01:19,718 --> 00:01:24,618
3083as the garbage that you had going in. And the 412 content, when we start getting into that exam
3084
3085772
308600:01:24,718 --> 00:01:28,618
3087I'll talk more about some of the tools you can use to make sure that your domain is healthy
3088
3089773
309000:01:28,718 --> 00:01:33,618
3091before you make that jump, but for now just keep it in the back of your mind that there are tools
3092
3093774
309400:01:33,718 --> 00:01:37,618
3095and there are different kinds of command line ways in which you can test and verify whether
3096
3097775
309800:01:37,718 --> 00:01:41,618
3099or not the replication is working and whether or not your active directory database is going
3100
3101776
310200:01:41,718 --> 00:01:46,618
3103to survive that upgrade to the new operating system. And the second step in upgrading a domain
3104
3105777
310600:01:46,718 --> 00:01:51,618
3107controller or a domain has to do with extending the schema. Now as I said, each different version
3108
3109778
311000:01:51,718 --> 00:01:56,618
3111of the operating system tends to come with a slightly different active directory database.
3112
3113779
311400:01:56,718 --> 00:02:01,618
3115This does not have to do with the data in the database, but the structure of the database.
3116
3117780
311800:02:01,718 --> 00:02:06,618
3119And so one process you'll need to go through is to actually extend the schema for your forest
3120
3121781
312200:02:06,718 --> 00:02:12,617
3123before you begin ever adding any of the new domain controllers of that newer version into
3124
3125782
312600:02:12,717 --> 00:02:16,617
3127your active directory infrastructure. Now that command that we're looking for in order to
3128
3129783
313000:02:16,717 --> 00:02:22,617
3131extend the schema, is called AD prep. And the AD prep command is one that's best found
3132
3133784
313400:02:22,717 --> 00:02:23,617
3135on the installation media for Windows
3136
3137785
313800:02:23,717 --> 00:02:30,617
3139Server 2012 R2. Let me come back here to our machine DC and I've brought up a command prompt here
3140
3141786
314200:02:30,717 --> 00:02:36,617
3143an elevated command prompt so that we can take a look at the contents of the attached DVD media.
3144
3145787
314600:02:36,717 --> 00:02:37,617
3147Here if I'm on the D drive
3148
3149788
315000:02:37,717 --> 00:02:41,617
3151if I take a look there's all the stuff that exists on that Windows 2012 R2 DVD media
3152
3153789
315400:02:41,717 --> 00:02:49,617
3155and if I go into the support adprep folder, it's in this folder we'll find
3156
3157790
315800:02:49,717 --> 00:02:56,617
3159the adprep command, right up here at the very top. This adprep.exe command is what goes
3160
3161791
316200:02:56,717 --> 00:03:02,617
3163through the process of extending the schema of making changes to the active directory database
3164
3165792
316600:03:02,717 --> 00:03:04,617
3167to prepare it for all the these new features and functions that come with this
3168
3169793
317000:03:04,717 --> 00:03:10,617
3171new version of the operating system. Now adprep actually executes a long list of what are these
3172
3173794
317400:03:10,717 --> 00:03:17,617
3175ldf files that you can see here. All the way here from 10 or so down to looks like 69 or so.
3176
3177795
317800:03:17,717 --> 00:03:20,617
3179And what's curious about these ldf files is that they're actually human readable.
3180
3181796
318200:03:20,717 --> 00:03:26,617
3183If I go here to the D drive and open it up, and then go to a support and then adprep,
3184
3185797
318600:03:26,717 --> 00:03:31,617
3187I can take a look at any of these ldf files to see, more or less what they look like.
3188
3189798
319000:03:31,717 --> 00:03:36,617
3191Here under notepad you can see that they correspond with the exact text based changes that are
3192
3193799
319400:03:36,717 --> 00:03:40,617
3195going to happen here to the active directory database. And without going into detail as to
3196
3197800
319800:03:40,717 --> 00:03:45,617
3199what it is that we're looking at, just recognize that these are the instructions that the
3200
3201801
320200:03:45,717 --> 00:03:50,617
3203schema extension uses in order to make those changes from old version to new.
3204
3205802
320600:03:50,717 --> 00:03:54,617
3207Now there are actually a couple of different parameters that are associated with adprep
3208
3209803
321000:03:54,717 --> 00:03:57,617
3211that I would at least be aware of. So let me clear the screen here
3212
3213804
321400:03:57,717 --> 00:04:01,617
3215and show you that I would the /?
3216
3217805
321800:04:01,717 --> 00:04:09,617
3219there are, right up here, the forest prep, domain prep, and RODC prep parameters that are of most importance here.
3220
3221806
322200:04:09,717 --> 00:04:14,617
3223There's also a GP prep which you can do that consolidates here with the domain prep.
3224
3225807
322600:04:14,717 --> 00:04:19,617
3227The forest prep command typically happens first and it is a schema extension that deals with
3228
3229808
323000:04:19,718 --> 00:04:27,617
3231forest wide information. The domain prep then needs to happen once in each domain of that forest.
3232
3233809
323400:04:27,718 --> 00:04:31,617
3235You run that and it goes through all the domain wide changes for the different domains that exist
3236
3237810
323800:04:31,718 --> 00:04:37,617
3239in that forest. And then lastly down here, you can choose RODC prep optionally if you plan on
3240
3241811
324200:04:37,718 --> 00:04:43,617
3243installing any RODCs into this forest. These are read-only domain controllers that are used
3244
3245812
324600:04:43,718 --> 00:04:48,617
3247for special circumstances. If you don't have any then you don't have to run this third parameter down here.
3248
3249813
325000:04:48,718 --> 00:04:50,617
3251So these commands here are what are used in order to
3252
3253814
325400:04:50,718 --> 00:04:56,617
3255execute all the schema extensions that are necessary to allow you then to go about upgrading your domain
3256
3257815
325800:04:56,718 --> 00:05:04,617
3259controllers to the new operating system. So you can't start upgrading your DCs until you get your schema extended.
3260
3261816
326200:05:04,718 --> 00:05:08,617
3263You'll then need to go through the process of upgrading all the domain controllers,
3264
3265817
326600:05:08,718 --> 00:05:13,617
3267every single domain controller in the forest and/or domain. Occasionally it migrating around
3268
3269818
327000:05:13,718 --> 00:05:18,617
3271your FSMO roles to ensure that they're always on line. Before you actually get to the final step
3272
3273819
327400:05:18,718 --> 00:05:24,617
3275in the process, which is to go about then taking advantage of all the new features that you get
3276
3277820
327800:05:24,718 --> 00:05:28,617
3279by upgrading your domain or forest functional level to the new version.
3280
3281821
328200:05:28,718 --> 00:05:33,617
3283Now the reason why I call this a project is because you don't actually get any of the benefits
3284
3285822
328600:05:33,718 --> 00:05:37,617
3287of the new domain and forest functional level until you've gone through every step in this process.
3288
3289823
329000:05:37,718 --> 00:05:42,617
3291Including upgrading the operating system of every single domain controller.
3292
3293824
329400:05:42,718 --> 00:05:45,617
3295Now this last step here, raising the domain and forest functional level, is something that you'll find
3296
3297825
329800:05:45,718 --> 00:05:49,617
3299here in the graphical user interface. If I go up here under Tools and take a look at
3300
3301826
330200:05:49,718 --> 00:05:52,617
3303active directory domains and trusts.
3304
3305827
330600:05:52,718 --> 00:05:53,617
3307Out of all the different tools that are
3308
3309828
331000:05:53,718 --> 00:05:57,617
3311associated with active directory, users and computers, sites and services, it's actually
3312
3313829
331400:05:57,718 --> 00:06:02,617
3315domains and trusts that you find yourself inside the least. But it is here where, if I take a look
3316
3317830
331800:06:02,718 --> 00:06:07,617
3319at domains and trusts I can take a look at raising number one, the forest functional level,
3320
3321831
332200:06:07,718 --> 00:06:12,617
3323from one version to another. Now I'm already at the most recent version of the forest functional level,
3324
3325832
332600:06:12,718 --> 00:06:17,617
3327which is server 2012 R2, so there are no options here for me to make any changes.
3328
3329833
333000:06:17,718 --> 00:06:21,617
3331However if I were not and I'd already gone through the adprep activities, well then I'd
3332
3333834
333400:06:21,718 --> 00:06:25,617
3335see this as an option for me to raise that forest functional level.
3336
3337835
333800:06:25,718 --> 00:06:26,617
3339I can do the same thing over here
3340
3341836
334200:06:26,718 --> 00:06:30,617
3343with each individual domain in the forest by clicking here and choosing to raise the domain
3344
3345837
334600:06:30,718 --> 00:06:34,617
3347functional level as well. Most important thing you have to know with this is that the
3348
3349838
335000:06:34,718 --> 00:06:39,617
3351raising of a domain or forest functional level is a one directional activity,
3352
3353839
335400:06:39,718 --> 00:06:43,117
3355you can only go in one direction, you can never go back. But the good news is that once you've
3356
3357840
335800:06:43,218 --> 00:06:47,117
3359done it, you can now begin to take advantage of the new features that you get in active directory
3360
3361841
336200:06:47,218 --> 00:00:01,869
3363out of this new operating system version.
3364
3365842
336600:00:01,969 --> 00:00:05,870
3367Now Jason worked with you back on that course on, among other things, the DNS server,
3368
3369843
337000:00:05,969 --> 00:00:09,970
3371getting DNS services up and operational in an active directory domain.
3372
3373844
337400:00:10,070 --> 00:00:13,370
3375And as I said also here in this course, in order to get active directory running,
3376
3377845
337800:00:13,470 --> 00:00:18,369
3379active directory requires DNS services to be there. This is in part because the installation
3380
3381846
338200:00:18,469 --> 00:00:21,369
3383of active directory creates a number of what are called SRV records,
3384
3385847
338600:00:21,469 --> 00:00:26,369
3387or service records inside of DNS. These SRV records are what allow clients to locate the
3388
3389848
339000:00:26,469 --> 00:00:31,369
3391different active directory services as well as the different servers to find each other.
3392
3393849
339400:00:31,469 --> 00:00:35,369
3395You'll find that these servers, or the records, the SRV records in a domain, are here
3396
3397850
339800:00:35,469 --> 00:00:41,369
3399in these folders that exist below company.pri or whatever your domain name is.
3400
3401851
340200:00:41,469 --> 00:00:46,369
3403And it is this long list of folders that contain all the variety of SRV records and C names
3404
3405852
340600:00:46,469 --> 00:00:48,369
3407that help these different servers and services
3408
3409853
341000:00:48,469 --> 00:00:52,369
3411locate each other and the clients to locate the services themselves.
3412
3413854
341400:00:52,469 --> 00:00:57,369
3415So you can see here if I scroll to the right just a bit, under msdcs, and then dc in sites,
3416
3417855
341800:00:57,469 --> 00:01:02,369
3419and then the site name here, which is by default the default first site name.
3420
3421856
342200:01:02,469 --> 00:01:08,370
3423We have a list of tcp records here that correspond with Kerberos services and ldap services here in the domain.
3424
3425857
342600:01:08,469 --> 00:01:13,370
3427The main idea here is that when a client is looking for Kerberos and ldap services, that in this
3428
3429858
343000:01:13,469 --> 00:01:18,370
3431case exists in the site that is described by default for site name.
3432
3433859
343400:01:18,469 --> 00:01:24,370
3435They then know to go to this location, dc.company.pri, in order to find the ldap server that would
3436
3437860
343800:01:24,469 --> 00:01:29,370
3439be listening for any ldap requests they may be making. Now what gets people confused sometimes
3440
3441861
344200:01:29,469 --> 00:01:33,370
3443is that even in a single domain controller environment there are a large number of records
3444
3445862
344600:01:33,469 --> 00:01:37,370
3447that have to be created for active directory to do what it needs to do.
3448
3449863
345000:01:37,469 --> 00:01:41,370
3451And so being aware of what all these records are and really what they can do is something that can take
3452
3453864
345400:01:41,469 --> 00:01:45,370
3455a little bit of time and you may never understand fully what all these records are intended to
3456
3457865
345800:01:45,469 --> 00:01:52,370
3459point clients towards. But what you are responsible for is ensuring that all of these records are correct.
3460
3461866
346200:01:52,469 --> 00:01:57,370
3463In an environment where I have dynamic updates installed and configured in DNS, this process
3464
3465867
346600:01:57,469 --> 00:02:02,370
3467is relatively easy because each domain controller will automatically enter the correct
3468
3469868
347000:02:02,469 --> 00:02:07,370
3471records into their DNS server as they're appropriate. And if changes are made, two for example
3472
3473869
347400:02:07,469 --> 00:02:13,370
3475add additional domain controllers or turn on or turn off services, or even to change site names,
3476
3477870
347800:02:13,469 --> 00:02:18,370
3479the domain controllers themselves will go about making the necessary changes in DNS.
3480
3481871
348200:02:18,469 --> 00:02:22,370
3483If you should end up in a situation, however, where you do have DNS SRV record registration issues,
3484
3485872
348600:02:22,469 --> 00:02:28,370
3487there are a couple of tools that you can use in order to, kind of, fix the problem.
3488
3489873
349000:02:28,469 --> 00:02:33,370
3491Now the first of these tools works best in an environment that has dynamic updates turned on.
3492
3493874
349400:02:33,469 --> 00:02:34,370
3495Because actually resolving a
3496
3497875
349800:02:34,469 --> 00:02:40,370
3499failed record can be solved very simply by just locating the domain controller where the record
3500
3501876
350200:02:40,469 --> 00:02:47,370
3503is missing and typing in the command ipconf --registerdns. This command will go about registering
3504
3505877
350600:02:47,469 --> 00:02:50,370
3507all the appropriate DNS records that are associated with this machine.
3508
3509878
351000:02:50,469 --> 00:02:54,370
3511You'll need to do it on every domain controller where you're missing records.
3512
3513879
351400:02:54,469 --> 00:02:59,370
3515This includes all the appropriate SRV records as well if this is a domain controller.
3516
3517880
351800:02:59,469 --> 00:03:03,370
3519So if you happen to find yourself in a situation where you go into DNS manager and
3520
3521881
352200:03:03,469 --> 00:03:08,370
3523you're missing some DNS records, well just typing ipconf --registerdns or probably rebooting the server
3524
3525882
352600:03:08,469 --> 00:03:14,370
3527generally will go about fixing those records inside of DNS. However there are some situations
3528
3529883
353000:03:14,469 --> 00:03:17,370
3531some environments where dynamic DNS is just simply not an option.
3532
3533884
353400:03:17,469 --> 00:03:22,370
3535Perhaps the windows team lost the battle many years ago from the Unix team and so the Unix
3536
3537885
353800:03:22,469 --> 00:03:28,370
3539group is now managing DNS and they don't support dynamic DNS for the zones that you're using.
3540
3541886
354200:03:28,469 --> 00:03:33,370
3543First, my sincere condolences for you if that is an environment that you're in, many of those
3544
3545887
354600:03:33,469 --> 00:03:38,370
3547situations have been resolved in recent years as people have recognized the value of dynamic DNS.
3548
3549888
355000:03:38,469 --> 00:03:41,370
3551But if you are still one of those environments, there is a location where you can go to find
3552
3553889
355400:03:41,469 --> 00:03:48,370
3555the long list of records that you'll need in order to get them populated into a non-dynamic DNS server.
3556
3557890
355800:03:48,469 --> 00:04:01,370
3559This is in Windows system 32 and config in that location and if I do Notepad the file name is netlogon.dns.
3560
3561891
356200:04:01,469 --> 00:04:08,370
3563This location here provides the entire list of records that need to get populated into DNS for this server.
3564
3565892
356600:04:08,469 --> 00:04:12,370
3567So this little text file here is something that you can give to, perhaps your Unix people or
3568
3569893
357000:04:12,469 --> 00:04:17,370
3571perhaps your Windows people if you don't have dynamic DNS in Windows, so that
3572
3573894
357400:04:17,470 --> 00:04:23,370
3575they can get entered into the DNS server appropriately for this zone. This list is generated dynamically by
3576
3577895
357800:04:23,470 --> 00:04:27,370
3579active directory domain services so it's a great, it's a handy little guide should you find yourself
3580
3581896
358200:04:27,470 --> 00:00:01,967
3583needing to cross reference the records we are seeing with the records you should have.
3584
3585897
358600:00:02,067 --> 00:00:06,467
3587Now our next task asks us to configure our domain controller as a global catalog server.
3588
3589898
359000:00:06,567 --> 00:00:12,467
3591The first domain controller, if you recall in any domain and forest, is automatically a global catalog.
3592
3593899
359400:00:12,567 --> 00:00:17,466
3595But as we get into production we may need to add additional global catalogs to support the load.
3596
3597900
359800:00:17,567 --> 00:00:20,466
3599I want to show you the process whereby this is done in the graphical user interface,
3600
3601901
360200:00:20,567 --> 00:00:25,466
3603because it's a little difficult to find here within active directory sites and services.
3604
3605902
360600:00:25,567 --> 00:00:30,466
3607So let's poke back here on our server DC really quickly so we can take a look at tools and active directory
3608
3609903
361000:00:30,567 --> 00:00:34,466
3611sites and services. And the other reason why I'm showing you this here is because
3612
3613904
361400:00:34,567 --> 00:00:39,466
3615now we have our server core machine correctly networked, correctly in the domain, heck it's already a domain
3616
3617905
361800:00:39,567 --> 00:00:46,466
3619controller, we can make use of our existing graphically oriented tools to connect remotely to that
3620
3621906
362200:00:46,567 --> 00:00:52,466
3623server to go about different kinds of remote configuration and remote management.
3624
3625907
362600:00:52,567 --> 00:00:55,466
3627And this is one of a great example of where this is just really easy to do here once we have all
3628
3629908
363000:00:55,567 --> 00:01:00,466
3631those connections in place. As you can see here in active directory sites and services
3632
3633909
363400:01:00,567 --> 00:01:03,466
3635we've got a lot of different items that exist here in the tree and these items will only get
3636
3637910
363800:01:03,567 --> 00:01:09,466
3639larger as the number of different subnets and sites that you may create get large.
3640
3641911
364200:01:09,566 --> 00:01:13,466
3643But one thing we do have to pay attention to, even if we don't go about creating additional sites
3644
3645912
364600:01:13,566 --> 00:01:18,466
3647and subnets, are the configuration on each individual domain controller.
3648
3649913
365000:01:18,566 --> 00:01:23,466
3651Down here are the list of servers that exist in our site called default first site name.
3652
3653914
365400:01:23,566 --> 00:01:28,466
3655And remember, sites are a geographic location for domain controllers and all of these
3656
3657915
365800:01:28,566 --> 00:01:32,466
3659being in a single spot, we have no need to create additional sites.
3660
3661916
366200:01:32,566 --> 00:01:35,466
3663For each server, if I view the properties of that server,
3664
3665917
366600:01:35,566 --> 00:01:39,466
3667there is a couple of different items in here, mainly your basic tabs that are generally with all
3668
3669918
367000:01:39,566 --> 00:01:43,466
3671the different items you may choose to view properties on. But the main thing I want to show you
3672
3673919
367400:01:43,566 --> 00:01:46,466
3675is down here, these ntds settings.
3676
3677920
367800:01:46,566 --> 00:01:51,466
3679Which is effectively the settings on the nt database services itself.
3680
3681921
368200:01:51,566 --> 00:01:56,466
3683If I take a look at properties down here, it is this checkbox, next to global catalog,
3684
3685922
368600:01:56,566 --> 00:02:00,466
3687that will turn on global catalog for this machine. And that's all you need to do to turn
3688
3689923
369000:02:00,566 --> 00:02:07,466
3691this domain controller into one that is also a global catalog. Recall that in the old days with more
3692
3693924
369400:02:07,566 --> 00:02:11,467
3695latent network connections, we had to pay more careful attention to which machines were global catalogs.
3696
3697925
369800:02:11,567 --> 00:02:16,467
3699And if you have extremely light network connections between sites, you may need to as well.
3700
3701926
370200:02:16,567 --> 00:02:20,467
3703But for most of us considering the network connections we have these days, it's generally
3704
3705927
370600:02:20,567 --> 00:02:24,867
3707a good practice for many environments outside those that are exceptionally large,
3708
3709928
371000:02:24,967 --> 00:02:29,467
3711to just make all your domain controllers global catalog servers so that they can handle all the
3712
3713929
371400:02:29,567 --> 00:00:01,425
3715necessary requests from incoming clients.
3716
3717930
371800:00:01,526 --> 00:00:06,426
3719And then for our last task here in this module, an objective on installing domain controllers
3720
3721931
372200:00:06,525 --> 00:00:12,426
3723we're asked to deploy active directory in Microsoft Azure. And to be perfectly honest,
3724
3725932
372600:00:12,525 --> 00:00:16,425
3727the inclusion of this additional task here in the R2 version of this content,
3728
3729933
373000:00:16,525 --> 00:00:21,425
3731is a bit strange considering all the extra prerequisite knowledge that's required about Azure itself
3732
3733934
373400:00:21,525 --> 00:00:27,425
3735to appreciate what needs to go into deploying a domain controller inside of Microsoft Azure.
3736
3737935
373800:00:27,525 --> 00:00:33,426
3739Now the process that we're referring to here, the infrastructure as a service process or IAAS process,
3740
3741936
374200:00:33,526 --> 00:00:39,426
3743of getting of a DC up in Azure. What it really relates to is the notion of actually creating
3744
3745937
374600:00:39,526 --> 00:00:44,426
3747a virtual machine inside of Microsoft Azure and then installing active directory on that virtual machine,
3748
3749938
375000:00:44,526 --> 00:00:50,426
3751just like you would inside of a local machine. In fact if I come over here to my other tab first
3752
3753939
375400:00:50,526 --> 00:00:56,426
3755we can take a look at my personal copy of Microsoft Azure. Where if I click down here under New
3756
3757940
375800:00:56,526 --> 00:01:02,426
3759you can take a look at a new virtual machine here, which you can quick create or create from the gallery.
3760
3761941
376200:01:02,526 --> 00:01:06,426
3763When you create that new machine you'll need to associate any additional hard drives or
3764
3765942
376600:01:06,525 --> 00:01:10,426
3767discs with that machine, you'll also need to make a determination about how you want
3768
3769943
377000:01:10,525 --> 00:01:15,426
3771to get that machine connected up into your internal network. Because recall Microsoft Azure
3772
3773944
377400:01:15,525 --> 00:01:21,426
3775and the machines inside of Azure, are available and connectable from the rest of the internet.
3776
3777945
377800:01:21,525 --> 00:01:26,426
3779And so making a connection through some sort of VPN from that Azure location into the rest
3780
3781946
378200:01:26,525 --> 00:01:30,426
3783of your network, is something you'll want to consider when it comes time to building that machine
3784
3785947
378600:01:30,525 --> 00:01:33,426
3787up in the cloud. I want to direct your attention, rather than going into
3788
3789948
379000:01:33,525 --> 00:01:37,426
3791the nitty gritty detail, I want to direct your attention to a specific article here in the
3792
3793949
379400:01:37,525 --> 00:01:43,426
3795Microsoft Azure portion of Microsoft.com, that lists a set of guidelines for deploying
3796
3797950
379800:01:43,525 --> 00:01:48,426
3799Windows Server active directory on Azure virtual machines. This again is the IAAS version.
3800
3801951
380200:01:48,525 --> 00:01:53,426
3803I believe, and this is a gut instinct, but I believe Microsoft's intention that including
3804
3805952
380600:01:53,525 --> 00:01:58,426
3807this here in this version of the 410, is in just helping you recognize that it is now possible
3808
3809953
381000:01:58,525 --> 00:02:04,426
3811to install active directory and a domain controller directly onto a virtual machine.
3812
3813954
381400:02:04,525 --> 00:02:08,426
3815However there are a variety of just different things you have to be aware of in order to do so.
3816
3817955
381800:02:08,526 --> 00:02:13,426
3819And this very long document here provides a great amount of detail really about all the things
3820
3821956
382200:02:13,526 --> 00:02:17,426
3823that are necessary to think about when it comes time to making that provisioning.
3824
3825957
382600:02:17,526 --> 00:02:20,426
3827There is, however, down here way at the bottom, there's one little picture that I want to
3828
3829958
383000:02:20,526 --> 00:02:25,426
3831direct you towards that will help give you an appreciation of the type of network connection
3832
3833959
383400:02:25,526 --> 00:02:29,426
3835that you'll be intending to create when you extend your active directory into Microsoft Azure.
3836
3837960
383800:02:29,526 --> 00:02:34,426
3839And that's this one right here. This third item shows your corporate site, your internal network,
3840
3841961
384200:02:34,526 --> 00:02:39,426
3843and the Windows Azure site that you've created in your account. As well as the domain controllers
3844
3845962
384600:02:39,526 --> 00:02:43,426
3847here in either side that are connected through an Azure virtual network.
3848
3849963
385000:02:43,526 --> 00:02:47,426
3851It is this Azure virtual network that provides a mechanism for these domain controllers
3852
3853964
385400:02:47,526 --> 00:02:51,426
3855to communicate securely across what would otherwise be the internet.
3856
3857965
385800:02:51,526 --> 00:02:55,426
3859Being able to have that domain controller in Azure can be handy when you have organizations
3860
3861966
386200:02:55,526 --> 00:03:00,926
3863and users that are out perhaps anywhere in the world, that need to connect with their domain controller.
3864
3865967
386600:03:01,026 --> 00:03:06,426
3867But there are obviously some risks in making that domain controller directly accessible for the rest of the world.
3868
3869968
387000:03:06,526 --> 00:03:11,426
3871Just again, be aware for the purposes of the 410, that it is possible to do this with some important
3872
3873969
387400:03:11,526 --> 00:00:02,054
3875caveats associated with keeping that information secure.
3876
3877970
387800:00:02,154 --> 00:00:05,555
3879So what is really a surprising amount of content here on installing domain controllers,
3880
3881971
388200:00:05,655 --> 00:00:10,054
3883in part because of that need for some foundations on what active directory really is,
3884
3885972
388600:00:10,154 --> 00:00:14,054
3887as well as its components. What we talked about in this module, we have talked about not only
3888
3889973
389000:00:14,154 --> 00:00:18,054
3891those foundations but a variety of the different click by click things you'll need to go through
3892
3893974
389400:00:18,155 --> 00:00:22,054
3895in order to get domain controllers and an active directory up and operational.
3896
3897975
389800:00:22,155 --> 00:00:26,054
3899We began with adding a domain controller and creating that brand new forest and domain
3900
3901976
390200:00:26,155 --> 00:00:31,054
3903as well a look at removing the domain controller and DC services if you need to.
3904
3905977
390600:00:31,155 --> 00:00:36,054
3907It's always a great idea to remove the domain controller services before removing the domain controller
3908
3909978
391000:00:36,155 --> 00:00:42,054
3911or you'll end up having to go and carefully tease out all those orphan bits out of your active directory database.
3912
3913979
391400:00:42,155 --> 00:00:46,054
3915We then looked at installing domain controllers from install from media as well as how to
3916
3917980
391800:00:46,155 --> 00:00:50,054
3919install ADDS on server core, a bunch of different commands that work on server core
3920
3921981
392200:00:50,155 --> 00:00:55,054
3923and also work on the full version of Windows Server as well. We took a look then at the extended
3924
3925982
392600:00:55,155 --> 00:00:59,054
3927process of upgrading not only a domain controller, but also upgrading a full
3928
3929983
393000:00:59,155 --> 00:01:05,055
3931active directory domain and/or forest. That five step process that involves the adprep tool that
3932
3933984
393400:01:05,155 --> 00:01:11,055
3935upgrades all the domain controllers. And then concludes with upgrading the domain or forest functional level.
3936
3937985
393800:01:11,155 --> 00:01:17,055
3939We took a look at DNS and those SRV records as well as how to resolve some record registration issues.
3940
3941986
394200:01:17,155 --> 00:01:22,055
3943As well as a look also at configuring our global catalog server on any of the domain controllers we may have.
3944
3945987
394600:01:22,155 --> 00:01:26,055
3947And then concluded with a look here at deploying active directory in Microsoft Azure using
3948
3949988
395000:01:26,155 --> 00:01:32,055
3951the IAAS approach. Considering Microsoft's investments in Azure active directory services
3952
3953989
395400:01:32,155 --> 00:01:38,055
3955it's important to differentiate the VM approach from the services approach in building up that Azure
3956
3957990
395800:01:38,155 --> 00:01:43,055
3959active directory presence. Coming up next we will continue this look at active directory focusing
3960
3961991
396200:01:43,155 --> 00:01:48,055
3963in on the users and computers that make up our active directory infrastructure.
3964
3965992
396600:01:48,155 --> 00:01:53,055
3967We'll go through not only the click by click to create users and computers, not terribly an interesting function,
3968
3969993
397000:01:53,155 --> 00:01:58,055
3971but then go into the command line tools that we can use for automating the creation of active directory
3972
3973994
397400:01:58,155 --> 00:02:02,055
3975accounts or performing some interesting bulk active directory operations.
3976
3977995
397800:02:02,155 --> 00:02:06,055
3979We'll talk about the different user rights that can be associated with users as well as how to manage
3980
3981996
398200:02:06,155 --> 00:02:11,055
3983inactive and disabled accounts. We'll take a look at naming our machines and then adding them
3984
3985997
398600:02:11,155 --> 00:02:16,055
3987into the active directory domain and even doing off line domain joins if we have that need as well.
3988
3989998
399000:02:16,155 --> 00:02:21,055
3991Although working with users and computers in active directory might not be the most glamorous job in the world,
3992
3993999
399400:02:21,155 --> 00:02:25,055
3995if we have the right PowerShell command exposure there are ways in which we can make our job
3996
39971000
399800:02:25,155 --> 00:02:30,055
3999that much easier. That discussion on the interesting part of managing users and computers,
4000
40011001
400200:02:30,155 --> 23:59:59,899
4003this is a topic for our next module coming up.
4004
40051002
400600:00:00,000 --> 00:00:06,900
4007You might think that an entire module having to do with creating and managing AD users and computers
4008
40091003
401000:00:07,000 --> 00:00:11,900
4011would be, perhaps, one of the least interesting modules in the entire Pluralsight catalog.
4012
40131004
401400:00:12,000 --> 00:00:17,899
4015And in any other universe you would probably be right. Thankfully the new MCSC, this generation
4016
40171005
401800:00:18,000 --> 00:00:24,899
4019MCSC, gets away from the traditional point and click that we're used to in the graphical user interface.
4020
40211006
402200:00:25,000 --> 00:00:28,899
4023Now for a lot of the content we're talking about, getting away from the graphical user interface
4024
40251007
402600:00:29,000 --> 00:00:33,899
4027means we've got a lot more challenge. But here when we're talking about AD users and computers
4028
40291008
403000:00:34,000 --> 00:00:39,899
4031it actually means that we can go through a whole module of what would ordinarily be really boring stuff
4032
40331009
403400:00:40,000 --> 00:00:44,899
4035and turn it into some really powerful ways in which we can create automations. And in fact
4036
40371010
403800:00:45,000 --> 00:00:49,899
4039here in this module we are going to spend a very small period of time going through the actual in the GUI process
4040
40411011
404200:00:50,000 --> 00:00:54,899
4043of creating and copying and configuring and deleting users and computers in active directory.
4044
40451012
404600:00:55,000 --> 00:01:00,899
4047And I do this purely for completeness I will show you how you can create a new user and/or a
4048
40491013
405000:01:01,000 --> 00:01:06,900
4051new computer in active directory using both the adac and the aduc, the active directory users and
4052
40531014
405400:01:07,000 --> 00:01:12,900
4055computers console and the active directory administrative console, the new version that runs on Windows PowerShell.
4056
40571015
405800:01:13,000 --> 00:01:16,900
4059Now that's not really the reason why we're here, I mean any old person can go about creating
4060
40611016
406200:01:17,000 --> 00:01:22,900
4063users in AD, what we're here more so is in learning how to better automate that process.
4064
40651017
406600:01:23,000 --> 00:01:25,900
4067And there are a lot of ways in which you can accomplish that, the first of which is to just
4068
40691018
407000:01:26,000 --> 00:01:31,900
4071simply set up a template user in active directory and plug in all the default information
4072
40731019
407400:01:32,000 --> 00:01:36,900
4075that you would normally want to consider for a user. And then just simply copy that template to
4076
40771020
407800:01:37,000 --> 00:01:42,900
4079create the new user. This is, in and of itself kind of an automation because you save yourself
4080
40811021
408200:01:43,000 --> 00:01:47,900
4083the extra task of having to reenter information that you would have to do manually when you're
4084
40851022
408600:01:48,000 --> 00:01:52,900
4087creating every new user. Thanks to the use of wild cards in active directory users and computers
4088
40891023
409000:01:53,000 --> 00:01:56,900
4091you can create these templates and just put wildcards in places where you need information
4092
40931024
409400:01:57,000 --> 00:02:02,900
4095to map to perhaps the users logon name. We also have another item here where we're asked to talk
4096
40971025
409800:02:03,000 --> 00:02:06,900
4099about user rights, now we've already gone through user rights, back in that last course
4100
41011026
410200:02:07,000 --> 00:02:12,900
4103when I explained how to set up rights and privileges using user rights assessment on a local machine.
4104
41051027
410600:02:13,000 --> 00:02:18,900
4107What I'd rather do, rather than just repeat that here, is to show you just the introductory bits
4108
41091028
411000:02:19,000 --> 00:02:22,900
4111about how you might deploy user rights using group policy. Now I know that we haven't got
4112
41131029
411400:02:23,000 --> 00:02:26,900
4115into group policy yet and we've got a whole course on group policy that's upcoming.
4116
41171030
411800:02:27,000 --> 00:02:33,900
4119But I just want to show you that baked into group policy is a similar view of the local user rights
4120
41211031
412200:02:34,000 --> 00:02:40,900
4123assessment that you can use for deploying these user rights out globally to multiple machines at once.
4124
41251032
412600:02:41,000 --> 00:02:44,900
4127Now this in no way is intended to take away from the thunder of the course upcoming on group policy
4128
41291033
413000:02:45,000 --> 00:02:50,900
4131but at least it allows us to talk about something slightly different as it relates to user rights.
4132
41331034
413400:02:51,000 --> 00:02:54,900
4135Then once we've done that, let's dig even further into the command line focus for active directory
4136
41371035
413800:02:55,000 --> 00:02:59,900
4139and talk about the PowerShell and even some of the non-PowerShell tools that are out there
4140
41411036
414200:03:00,000 --> 00:03:04,900
4143to perform various tasks in a more automated way. Like, creating active directory accounts,
4144
41451037
414600:03:05,000 --> 00:03:11,900
4147like managing inactive and disabled accounts, and like performing bulk active directory operations.
4148
41491038
415000:03:12,000 --> 00:03:17,900
4151These three tasks here encompass a relatively large set of commands and commandlets in PowerShell
4152
41531039
415400:03:18,000 --> 00:03:24,900
4155that you could potentially bring to bear in order to do a large number of user and computer oriented things.
4156
41571040
415800:03:25,000 --> 00:03:28,900
4159And in fact, some of the commands we'll talk about here are relatively new and actually kind of cool
4160
41611041
416200:03:29,000 --> 00:03:32,900
4163in the types of information that they can surface. There's one in particular that I'll show you here
4164
41651042
416600:03:33,000 --> 00:03:38,900
4167called search AD account, that was even relatively new to me, that is just fantastic for helping you
4168
41691043
417000:03:39,000 --> 00:03:42,900
4171accomplish a task, that in the old days, was extremely hard to do.
4172
41731044
417400:03:43,000 --> 00:03:47,900
4175Then finally we'll conclude with a look here at the offline domain join process, occasionally
4176
41771045
417800:03:48,000 --> 00:03:51,900
4179you have the situation where you have a machine that needs to join your active directory domain,
4180
41811046
418200:03:52,000 --> 00:03:56,900
4183but needs to do so in a way where there is no direct network connectivity between that machine
4184
41851047
418600:03:57,000 --> 00:04:00,900
4187and your domain controller. Now when that happens, in the old days there was no way really to
4188
41891048
419000:04:01,000 --> 00:04:05,900
4191get that machine on your AD domain. These days you can kind of separate the process out
4192
41931049
419400:04:06,000 --> 00:04:11,900
4195into two different steps. The first step being the pre provisioning of that computer account in active directory.
4196
41971050
419800:04:12,000 --> 00:04:17,899
4199The result of which you can transfer to the computer and then use its contents to complete the process
4200
42011051
420200:04:18,000 --> 00:04:22,899
4203in an offline basis with that machine that doesn't happen to be connected to your domain in any way.
4204
42051052
420600:04:23,000 --> 00:04:27,399
4207You may not necessarily find yourself performing this activity very often, but in those rare
4208
42091053
421000:04:27,500 --> 00:04:31,899
4211occasions where you do need to get a machine online, well an offline domain join solves a
4212
42131054
421400:04:32,000 --> 00:00:01,862
4215whole host of problems that would otherwise be insurmountable.
4216
42171055
421800:00:01,963 --> 00:00:07,863
4219So first up on our list is the remarkably uninteresting task of dealing with users and computers
4220
42211056
422200:00:07,963 --> 00:00:12,362
4223inside of the graphical tools that we have here at Windows Server. As you can see I'm back here
4224
42251057
422600:00:12,462 --> 00:00:17,362
4227on my computer dc.company.pri and in a production world you're probably not going to be
4228
42291058
423000:00:17,463 --> 00:00:23,362
4231performing these tasks on the domain controller itself. But I'm going to punch some of the remote
4232
42331059
423400:00:23,463 --> 00:00:28,862
4235uses of these tools until Jason gets an opportunity to talk about the remote management of Windows Server.
4236
42371060
423800:00:28,963 --> 00:00:34,862
4239So let's assume here that I've got my machine dc.company.pri, there are actually a pair of different tools
4240
42411061
424200:00:34,963 --> 00:00:38,862
4243you can use for managing users and computers here in the operating system.
4244
42451062
424600:00:38,963 --> 00:00:45,862
4247The first of which is the old tool, what I like to call the aduc or active directory users and computers.
4248
42491063
425000:00:45,963 --> 00:00:46,862
4251The second of which, which I'll just open up
4252
42531064
425400:00:46,963 --> 00:00:51,862
4255here so we can see it, is the new tool called active directory administrative center.
4256
42571065
425800:00:51,963 --> 00:00:53,862
4259Now these two tools perform
4260
42611066
426200:00:53,963 --> 00:00:58,862
4263many of the same functions, the adac, the newer tool, provides some additional functions that
4264
42651067
426600:00:58,963 --> 00:01:02,862
4267have to do with things like dynamic access controls, some other additional bits that you can
4268
42691068
427000:01:02,963 --> 00:01:08,862
4271add in as well. The biggest difference here is that the adac, different from the aduc,
4272
42731069
427400:01:08,962 --> 00:01:12,862
4275runs on top of Windows PowerShell. And so if you're going about performing many of these tasks
4276
42771070
427800:01:12,962 --> 00:01:14,862
4279when you go in here to click and create users and
4280
42811071
428200:01:14,962 --> 00:01:19,862
4283do the variety of tasks like built, creating new ones, and viewing their properties.
4284
42851072
428600:01:19,962 --> 00:01:25,862
4287Under the covers, what you're actually performing is some PowerShell command to complete the action
4288
42891073
429000:01:25,962 --> 00:01:29,862
4291that you've told this tool to do. Now I'm going to flip back here to the old tool,
4292
42931074
429400:01:29,962 --> 00:01:33,862
4295because I'm old school, and old habits die hard. So that we can take a look
4296
42971075
429800:01:33,962 --> 00:01:37,862
4299at just the users and computers that are here in this active directory domain.
4300
43011076
430200:01:37,962 --> 00:01:41,862
4303Now this is, as you're probably aware, a domain that is right out-of-the-box and we just created it,
4304
43051077
430600:01:41,962 --> 00:01:47,862
4307so the things that you see here are going to be the types of users and groups and computers and whatnot
4308
43091078
431000:01:47,962 --> 00:01:52,862
4311that you would assume exists in a freshly created domain. Here on the left you can see the long
4312
43131079
431400:01:52,962 --> 00:01:57,862
4315list of organizational units and other containers that exist here in our domain company.pri.
4316
43171080
431800:01:57,962 --> 00:02:02,862
4319And over on the right, because we focused here on the list of users, are those users and then the
4320
43211081
432200:02:02,962 --> 00:02:08,862
4323groups that are available right out-of-the-box. For us to create a new user the process to create a
4324
43251082
432600:02:08,962 --> 00:02:13,862
4327new user, I can't believe we're going through this, is to go new, user, and then provide
4328
43291083
433000:02:13,962 --> 00:02:20,862
4331that first name and last name, so this is my name. And then a user logon name for the individual.
4332
43331084
433400:02:20,962 --> 00:02:24,862
4335Over here at the right you can see what we call the upn suffix for that user logon name.
4336
43371085
433800:02:24,962 --> 00:02:29,862
4339Here in Microsoft Windows newer versions of Microsoft Windows, we have the ability to log on
4340
43411086
434200:02:29,962 --> 00:02:34,862
4343via either of these two approaches. The Pre-Windows 2000 approach, which is what many of
4344
43451087
434600:02:34,962 --> 00:02:41,862
4347us still use today, the domain name/a user logon name approach. Or the more new school method
4348
43491088
435000:02:41,962 --> 00:02:46,862
4351which is user name at domain name company.pri. Now later on in the 412 content I'll talk more
4352
43531089
435400:02:46,962 --> 00:02:52,862
4355about how you can go about changing these UPN suffixes if you have a preferred suffix you'd like
4356
43571090
435800:02:52,962 --> 00:02:56,862
4359your users to use that may be different from what your domain name is.
4360
43611091
436200:02:56,962 --> 00:03:00,862
4363There's a little trickery that can do in some of the active directory tools to allow you to
4364
43651092
436600:03:00,962 --> 00:03:05,862
4367support that, but for now right out-of-the-box the way in which a user's going to log in is
4368
43691093
437000:03:05,962 --> 00:03:11,862
4371going to be here username@domain name or domain name/username. For any user that we many
4372
43731094
437400:03:11,962 --> 00:03:15,862
4375enter in; we're going to have to punch in a password that supports whatever our password restrictions are going to be,
4376
43771095
437800:03:15,962 --> 00:03:20,862
4379those rules that we've applied. We'll talk a little more about those password policies in an
4380
43811096
438200:03:20,962 --> 00:03:25,862
4383upcoming course when we're getting into group policy. And then for that user rather than
4384
43851097
438600:03:25,962 --> 00:03:29,862
4387requiring the user to change the password at the next logon, let's just set the user to not change
4388
43891098
439000:03:29,962 --> 00:03:34,862
4391the password and set the password to never expire. Now you wouldn't do that in production,
4392
43931099
439400:03:34,962 --> 00:03:39,862
4395but I tend to do that for my user account in these test and lab environments, just so that I'm not
4396
43971100
439800:03:39,962 --> 00:03:44,862
4399forced to change a password perhaps in the middle of filming one of these different modules.
4400
44011101
440200:03:44,962 --> 00:03:48,862
4403Now once I've created the user then there are a large number of different fields that we could potentially
4404
44051102
440600:03:48,962 --> 00:03:52,862
4407enter in that are associated with the user account. So a description of the user, their office,
4408
44091103
441000:03:52,962 --> 00:03:58,862
4411their telephone number, their email, their physical address information, their account information,
4412
44131104
441400:03:58,962 --> 00:04:03,862
4415any options that we may see down the here. If the account ends up getting locked for one reason
4416
44171105
441800:04:03,962 --> 00:04:08,862
4419or another, perhaps they've entered in their password incorrectly too many times, well I can unlock the
4420
44211106
442200:04:08,962 --> 00:04:14,862
4423account by choosing the checkbox here. I can also set an expire on the account down here at the bottom
4424
44251107
442600:04:14,962 --> 00:04:19,862
4427which is used most often when I have temporary accounts or perhaps consultants, external users
4428
44291108
443000:04:19,963 --> 00:04:24,862
4431that are coming in. That when I create that account I want to make sure that that account
4432
44331109
443400:04:24,963 --> 00:04:30,862
4435doesn't inadvertently stick around past the point that that person should no longer be a part of the organization.
4436
44371110
443800:04:30,963 --> 00:04:34,862
4439I can also choose profile information here, so what they're user profile would be and
4440
44411111
444200:04:34,963 --> 00:04:39,862
4443what their home folder would be. Telephone information any organizational information and a whole host
4444
44451112
444600:04:39,963 --> 00:04:45,862
4447of other tools, like remote control and a remote desktop services profile, the COM+ partition sets
4448
44491113
445000:04:45,963 --> 00:04:50,862
4451that may be associated with. As well as the session information, the environment information,
4452
44531114
445400:04:50,963 --> 00:04:55,862
4455the dial in information, and what groups they're a member of. Now I flip through every single one of these
4456
44571115
445800:04:55,963 --> 00:05:01,862
4459tasks for a reason and it's not just to show you what all the tabs are, but to highlight the
4460
44611116
446200:05:01,963 --> 00:05:06,862
4463notion that it's entirely feasible; Microsoft may want you to know where certain information would
4464
44651117
446600:05:06,963 --> 00:05:12,862
4467need to be entered in when you're creating a new user account. So even though it may seem silly
4468
44691118
447000:05:12,963 --> 00:05:15,862
4471for me to flip through all these tasks, I would at least spend a couple of minutes here with the
4472
44731119
447400:05:15,963 --> 00:05:20,862
4475properties of a user. And again, the properties of a computer so at least you have a good
4476
44771120
447800:05:20,963 --> 00:05:25,862
4479familiarity for where the different types of information may need to be entered.
4480
44811121
448200:05:25,963 --> 00:05:31,862
4483Let's assume that this user, the Greg Shields user, is one that needs to have lots of privileges here in the domain.
4484
44851122
448600:05:31,963 --> 00:05:35,862
4487I want to essentially create a user of myself that will give me all the privileges to accomplish
4488
44891123
449000:05:35,963 --> 00:05:38,862
4491the things that we would need to do for all the courses upcoming.
4492
44931124
449400:05:38,963 --> 00:05:43,862
4495So because of that I need to give myself a membership in one or more additional groups that would
4496
44971125
449800:05:43,963 --> 00:05:48,862
4499provide those privileges. Now anytime I create a new user, well that users going to be created
4500
45011126
450200:05:48,963 --> 00:05:53,862
4503with the domain users membership, you have to be in domain users in order to support attaching to
4504
45051127
450600:05:53,963 --> 00:05:57,862
4507and working with any of the objects that make up an active directory domain.
4508
45091128
451000:05:57,963 --> 00:06:01,862
4511Not in every case, but in almost every case. In order to give additional access I would need to
4512
45131129
451400:06:01,963 --> 00:06:06,862
4515add that additional access here. And if I wanted to, I could click the advanced button to
4516
45171130
451800:06:06,963 --> 00:06:11,862
4519take a look at the possible different groups that this user could be added to.
4520
45211131
452200:06:11,963 --> 00:06:15,862
4523If I choose the find now button this will list those groups here.
4524
45251132
452600:06:15,963 --> 00:06:19,862
4527So for this user I'm interested in adding them in as a domain administrator, which would give me
4528
45291133
453000:06:19,963 --> 00:06:24,862
4531access to doing all the things here in the domain, but I also want to give them access
4532
45331134
453400:06:24,963 --> 00:06:29,862
4535to enterprise admins as well as schema admins. So that I can support all the needs that I
4536
45371135
453800:06:29,963 --> 00:06:35,862
4539may potentially require for making changes at the forest level, that's the case in enterprise admins.
4540
45411136
454200:06:35,963 --> 00:06:40,862
4543And also for making changes to the schema, which would be here under schema admins.
4544
45451137
454600:06:40,963 --> 00:06:44,862
4547Now in a production environment it is a best practice for you not to include users in either the
4548
45491138
455000:06:44,963 --> 00:06:49,862
4551enterprise admins or the schema admins group, except in those situations where they actually
4552
45531139
455400:06:49,963 --> 00:06:54,862
4555require the use of those privileges. In higher security environments, it's also a great idea
4556
45571140
455800:06:54,963 --> 00:06:57,862
4559to not include them as a domain admin either, except in those cases where
4560
45611141
456200:06:57,963 --> 00:07:02,862
4563they need to use their domain admins privileges. So you'll see me include these here because this is
4564
45651142
456600:07:02,963 --> 00:07:06,862
4567a lab environment, but in the real world you probably aren't going to see too many people
4568
45691143
457000:07:06,963 --> 00:07:12,862
4571that exist in these additional groups except in those circumstances when they need to use the privileges.
4572
45731144
457400:07:12,963 --> 00:07:17,862
4575Conversely, if you do see users permanently in these groups, you might have an argument there
4576
45771145
457800:07:17,963 --> 00:07:22,862
4579for changing some of the security policies that exist in your organization today.
4580
45811146
458200:07:22,963 --> 00:07:27,862
4583So there's our user, Greg Shields, and this indeed is the excitement of creating and configuring
4584
45851147
458600:07:27,963 --> 00:07:31,862
4587a user here in our active directory domain. Let's go about configuring another user here,
4588
45891148
459000:07:31,963 --> 00:07:37,862
4591this will be another user that is not going to have any privileges; we have no trust in this
4592
45931149
459400:07:37,963 --> 00:07:41,862
4595individual to give them any kind of access here in our domain. So let's create this second user
4596
45971150
459800:07:41,963 --> 00:07:48,862
4599and call them the Jason Helmick user. We'll call him Jason@company.pri and then give him
4600
46011151
460200:07:48,963 --> 00:07:53,862
4603a password as well so that that user has the ability to just log on and perform all the basic stuff
4604
46051152
460600:07:53,963 --> 00:07:56,862
4607that they're used to seeing here in active directory.
4608
46091153
461000:07:56,963 --> 00:08:00,862
4611There's my Jason Helmick very low privileges user that we'll work with a little later on.
4612
46131154
461400:08:00,963 --> 00:08:02,862
4615Now I show you the creation of the Jason Helmick account, because there are a couple other
4616
46171155
461800:08:02,963 --> 00:08:07,862
4619things that we need to know here, which is the copying as well as the deletion of users
4620
46211156
462200:08:07,963 --> 00:08:11,862
4623and also computers here in active directory. And all I want to show you here is that when
4624
46251157
462600:08:11,963 --> 00:08:16,862
4627right-click on a user you can choose to copy that user to create another user account
4628
46291158
463000:08:16,963 --> 00:08:21,862
4631that has most of the same characteristics of the user you're copying.
4632
46331159
463400:08:21,963 --> 00:08:24,862
4635You'll need to go through additional tasks like, you know, changing the user logon name
4636
46371160
463800:08:24,963 --> 00:08:30,862
4639and changing the permissions, but this copy object allows you to create what is effectively the same
4640
46411161
464200:08:30,963 --> 00:08:35,862
4643user as Jason with a different user identity. So if I needed to create a Don Jones account
4644
46451162
464600:08:35,962 --> 00:08:40,862
4647with a similar set of no privileges, I could do so by just copying the object here.
4648
46491163
465000:08:40,962 --> 00:08:45,862
4651And then lastly to delete an account I can right-click and choose the delete item here.
4652
46531164
465400:08:45,962 --> 00:08:48,862
4655Now even though the delete item is pretty self-explanatory, the one thing I do want to
4656
46571165
465800:08:48,962 --> 00:08:53,862
4659point out is that when you go about providing permissions for your different individuals
4660
46611166
466200:08:53,962 --> 00:08:59,862
4663in IT that may go about creating and removing accounts. Just be conscious of how easy it is
4664
46651167
466600:08:59,962 --> 00:09:04,862
4667to go about deleting an account. The deletion of an account can happen with just a couple of
4668
46691168
467000:09:04,962 --> 00:09:09,862
4671inadvertent mouse clicks. As you see here, we have an are you sure prop for deleting that user
4672
46731169
467400:09:09,962 --> 00:09:15,862
4675Jason Helmick, but I could very easily accidently go about removing this user and potentially
4676
46771170
467800:09:15,962 --> 00:09:21,862
4679even multiple users if I wasn't careful. So be conscious of when you're providing those permissions
4680
46811171
468200:09:21,962 --> 00:09:25,862
4683to users to make them aware that the abilities to work with active directory users
4684
46851172
468600:09:25,962 --> 00:09:32,862
4687and computers also comes with the abilities to inadvertently delete active directory users and computers as well.
4688
46891173
469000:09:32,962 --> 00:09:37,862
4691Now this is the user side of the equation. We also have over here the computer side of the equation
4692
46931174
469400:09:37,962 --> 00:09:43,862
4695as well and as you can see here we already have one computer in our active directory domain, that's file1.
4696
46971175
469800:09:43,962 --> 00:09:50,862
4699Now you can actually come in here and right-click to create a new computer object here in your domain.
4700
47011176
470200:09:50,962 --> 00:09:55,862
4703However you don't find yourself doing that all too often, and the reason is that the process
4704
47051177
470600:09:55,962 --> 00:10:00,862
4707to add a computer into the active directory domain automatically creates the computer account
4708
47091178
471000:10:00,962 --> 00:10:05,862
4711as part of that process. It is for this reason why you have to have special privileges in order to
4712
47131179
471400:10:05,962 --> 00:10:11,862
4715add a machine into the domain. Well in certain circumstances you may find the need to
4716
47171180
471800:10:11,962 --> 00:10:16,862
4719preposition computer accounts in active directory to support one reason or another.
4720
47211181
472200:10:16,962 --> 00:10:20,862
4723Later on in this module when we start talking about the offline domain join feature
4724
47251182
472600:10:20,962 --> 00:10:25,862
4727that's one place where actually creating these computer accounts first before you go about
4728
47291183
473000:10:25,962 --> 00:10:27,862
4731adding the machine to the domain is something that has to happen.
4732
47331184
473400:10:27,962 --> 00:10:33,862
4735But again in most circumstances, most of the time you rarely find yourself creating new computer
4736
47371185
473800:10:33,962 --> 00:10:38,862
4739accounts using this interface. Now the only thing I want to show you over in the other interface
4740
47411186
474200:10:38,962 --> 00:10:44,862
4743in the active directory administrative center is the fact that all of the different functions that you see in the aduc
4744
47451187
474600:10:44,962 --> 00:10:48,862
4747are replicated over here in the adac. And one of the main reasons why I didn't show you this
4748
47491188
475000:10:48,962 --> 00:10:55,862
4751first is just really it's pure personal preference. I've used the active directory
4752
47531189
475400:10:55,962 --> 00:10:59,862
4755the aduc, active directory users and computers for far more years than the adac.
4756
47571190
475800:10:59,962 --> 00:11:02,862
4759The other reason too is that personally I tend to find that if we click through here and start
4760
47611191
476200:11:02,962 --> 00:11:08,862
4763looking through the various items that exist in our user, or in our domain, like flipping
4764
47651192
476600:11:08,962 --> 00:11:14,862
4767down here to the users organizational unit. If I locate a user like my Greg Shields user object here
4768
47691193
477000:11:14,962 --> 00:11:18,862
4771and view properties, there's just one long list here of all the possible properties that
4772
47731194
477400:11:18,962 --> 00:11:23,862
4775could be associated with this user account. So instead of having a variety of tabs that
4776
47771195
477800:11:23,962 --> 00:11:27,862
4779you have to flip through in order to enter in all this information, when you're using the
4780
47811196
478200:11:27,962 --> 00:11:32,862
4783adac all of this information is included in one view. Now down here at the bottom you can see
4784
47851197
478600:11:32,962 --> 00:11:37,862
4787a replication of these additional extensions, the other tabs that are part of this user account.
4788
47891198
479000:11:37,962 --> 00:11:42,862
4791So in some places I guess you get rid of the tabs and in other places you have to maintain those tabs.
4792
47931199
479400:11:42,962 --> 00:00:01,707
4795Just personally I prefer the old tool just because of the way it visualizes information.
4796
47971200
479800:00:01,808 --> 00:00:05,508
4799Now back in that last clip we went through a very short explanation of the process to copy
4800
48011201
480200:00:05,607 --> 00:00:10,008
4803an account and we went here over to the Jason Helmick account and attempted to copy Jason Helmick
4804
48051202
480600:00:10,108 --> 00:00:15,008
4807to some other user. And in a world where you may have another user, like the Don Jones person
4808
48091203
481000:00:15,108 --> 00:00:20,007
4811who may be coming in and working in the same group as the Jason Helmick person.
4812
48131204
481400:00:20,108 --> 00:00:24,007
4815Well it makes sense then to just copy the account so that you can very easily replicate
4816
48171205
481800:00:24,108 --> 00:00:28,007
4819all the different configurations that Jason has over to what Don will need.
4820
48211206
482200:00:28,108 --> 00:00:33,007
4823But there comes a time also where when you're creating new accounts you may have a certain
4824
48251207
482600:00:33,107 --> 00:00:39,007
4827minimum baseline set of configurations that every new account may require.
4828
48291208
483000:00:39,107 --> 00:00:43,007
4831Let's say, for example, that you want to set a user profile path or a home drive so that that
4832
48331209
483400:00:43,107 --> 00:00:48,007
4835home drive always corresponds to whatever the user may require. You may also have a set of
4836
48371210
483800:00:48,107 --> 00:00:53,007
4839baseline security groups that the users may need to be added to as well.
4840
48411211
484200:00:53,107 --> 00:00:56,007
4843Well there is a process here in the aduc to create what are called template user accounts,
4844
48451212
484600:00:56,107 --> 00:01:02,007
4847which are honestly less exciting then they might seem. A template user account is essentially
4848
48491213
485000:01:02,107 --> 00:01:07,008
4851a nonfunctioning user account that you create here in active directory users and computers.
4852
48531214
485400:01:07,108 --> 00:01:12,008
4855That you can use as the container for all those baseline configurations.
4856
48571215
485800:01:12,108 --> 00:01:16,008
4859Let's go ahead and create that template account here and I'm going to start it with an underbar
4860
48611216
486200:01:16,108 --> 00:01:21,008
4863for the only reason that when you go about sorting the active directory users and computers interface here
4864
48651217
486600:01:21,108 --> 00:01:25,008
4867that the underbar will force this template account to the top of the list.
4868
48691218
487000:01:25,108 --> 00:01:31,008
4871And if I come down here to the user logon name, I'll do the same thing and create it as underbar template.
4872
48731219
487400:01:31,108 --> 00:01:34,008
4875Let me choose a next button here and I'm going to leave the password as blank.
4876
48771220
487800:01:34,108 --> 00:01:39,008
4879Now here's a really cool trick that you can do when you're creating this template accounts.
4880
48811221
488200:01:39,108 --> 00:01:44,008
4883If I create this password as blank I'm not going to be able to actually create the user.
4884
48851222
488600:01:44,108 --> 00:01:49,008
4887Because in order to create the password as blank well I'm not going to meet the password complexity requirements
4888
48891223
489000:01:49,108 --> 00:01:54,008
4891for my active directory domain. So you can't actually create a blank password on a user,
4892
48931224
489400:01:54,108 --> 00:01:59,008
4895there's a sort of a gut check that's built into AED. But if I do create the password as blank
4896
48971225
489800:01:59,108 --> 00:02:03,008
4899and set the password so it cannot be changed, so the password never expires and so that the
4900
49011226
490200:02:03,108 --> 00:02:09,008
4903account is disabled. I'm then allowed to go about creating this new user.
4904
49051227
490600:02:09,108 --> 00:02:14,008
4907The neat part about this template user is that in no way can I ever enable the account
4908
49091228
491000:02:14,108 --> 00:02:17,008
4911because if I enable the account the blank password is not going to fit
4912
49131229
491400:02:17,108 --> 00:02:22,008
4915within those password complexity requirements. So this creates, as I said, kind of a nonfunctioning
4916
49171230
491800:02:22,108 --> 00:02:26,008
4919account that I can use as the template. Now here inside this template, if I open it up,
4920
49211231
492200:02:26,108 --> 00:02:29,008
4923this gives me the abilities to add in maybe additional membership here.
4924
49251232
492600:02:29,108 --> 00:02:35,008
4927Maybe I want to add in the fact that we have a company users group to add people into to.
4928
49291233
493000:02:35,108 --> 00:02:39,008
4931Maybe I want to configure some dial in permissions or some environment settings or even some
4932
49331234
493400:02:39,108 --> 00:02:43,008
4935sessions settings down here for when I'm connecting up to remote desktop.
4936
49371235
493800:02:43,108 --> 00:02:49,008
4939The other things I can do for this user, for example here under profile, is to configure maybe
4940
49411236
494200:02:49,108 --> 00:02:53,008
4943a roaming profile for the user or a home folder for the user.
4944
49451237
494600:02:53,108 --> 00:02:59,008
4947Now there's one wild card that gets commonly used most often here in the profile tab
4948
49491238
495000:02:59,108 --> 00:03:04,008
4951that you might want to be aware of in case you have need to create a roaming profile or a home folder
4952
49531239
495400:03:04,108 --> 00:03:11,008
4955that is pathed appropriately. And that wild card is the %username& wildcard.
4956
49571240
495800:03:11,108 --> 00:03:16,008
4959This %username% wildcard will translate directly into the username, so the actual logon name
4960
49611241
496200:03:16,108 --> 00:03:21,008
4963of whatever user you copy this template account into. So if you know you want to
4964
49651242
496600:03:21,108 --> 00:03:28,008
4967create a roaming profile to file1\share1\username, when you go about copying this account
4968
49691243
497000:03:28,108 --> 00:03:35,008
4971into an actual user, this will then resolve to whatever username you end up configuring for that individual.
4972
49731244
497400:03:35,108 --> 00:03:36,008
4975If I choose OK down here
4976
49771245
497800:03:36,108 --> 00:03:38,008
4979and then go back here to the copy
4980
49811246
498200:03:38,108 --> 00:03:43,508
4983I can then use this template to go about copying this account, this template, to an actual user.
4984
49851247
498600:03:43,608 --> 00:00:01,535
4987And then they would get all the configurations that I've included in the template.
4988
49891248
499000:00:01,635 --> 00:00:05,036
4991Microsoft seems to insist that you are aware of how to configure user rights,
4992
49931249
499400:00:05,136 --> 00:00:12,035
4995particularly since this task is included I believe in three different locations in this 70-410 learning path.
4996
49971250
499800:00:12,135 --> 00:00:17,035
4999Originally back a couple of courses ago, we talked about how in the local user rights assessment dialog box
5000
50011251
500200:00:17,135 --> 00:00:23,035
5003you could go and configure which users on a single machine should have different privileges
5004
50051252
500600:00:23,135 --> 00:00:27,035
5007to perform tasks on that windows server. But I want to show you at least one other location
5008
50091253
501000:00:27,135 --> 00:00:32,036
5011where those configurations can be made. Before I do that though, I want to just kind of
5012
50131254
501400:00:32,136 --> 00:00:36,036
5015point again to the list of security groups here that exist in this users container
5016
50171255
501800:00:36,136 --> 00:00:41,036
5019in active directory users and computers. These, as I said, are those that exist right out-of-the-box.
5020
50211256
502200:00:41,136 --> 00:00:46,036
5023And so I would have a familiarity of what these groups are, we'll talk more about groups in the
5024
50251257
502600:00:46,136 --> 00:00:51,036
5027next module coming up. I would also have an awareness of these built in groups that exist here,
5028
50291258
503000:00:51,136 --> 00:00:55,036
5031these are the domain local groups that are built into the domain.
5032
50331259
503400:00:55,136 --> 00:01:00,036
5035These provide functionality so that you can provide them that functionality to individual users
5036
50371260
503800:01:00,136 --> 00:01:05,036
5039to be a backup operator or an account operator, for example. Now these groups can come in handy
5040
50411261
504200:01:05,135 --> 00:01:09,036
5043when it comes time to configure the user rights assessment on an individual machine,
5044
50451262
504600:01:09,135 --> 00:01:15,036
5047because you can use them to put users into groups and then assign privileges to those groups
5048
50491263
505000:01:15,135 --> 00:01:17,036
5051as opposed to the individual users.
5052
50531264
505400:01:17,135 --> 00:01:22,036
5055And in fact earlier ago, here under tools, for a specific computer, we took a look at the local security
5056
50571265
505800:01:22,135 --> 00:01:27,036
5059policy on that machine to just see where we might go about configuring the user rights assessment
5060
50611266
506200:01:27,135 --> 00:01:33,036
5063for the various different task and people that should have access to perform those tasks on a computer.
5064
50651267
506600:01:33,135 --> 00:01:37,036
5067But the one thing I want to show you is just a tease of the upcoming course that we'll
5068
50691268
507000:01:37,135 --> 00:01:41,036
5071be talking about when it comes to active directory, because as you can imagine,
5072
50731269
507400:01:41,135 --> 00:01:46,036
5075with the sheer number of groups that are out there and the number of also individual rights
5076
50771270
507800:01:46,135 --> 00:01:49,036
5079that could be configured on a group. This is just a very large list.
5080
50811271
508200:01:49,135 --> 00:01:54,036
5083And the combination of these multiplied by the number of servers you have to manage
5084
50851272
508600:01:54,135 --> 00:01:57,036
5087can make this rather unwieldy over time.
5088
50891273
509000:01:57,135 --> 00:02:00,036
5091The one tool I want to show you, and again this is a tease for our upcoming talk
5092
50931274
509400:02:00,135 --> 00:02:05,036
5095on group policy, is the group policy management console here. Where I'm going to take a look at
5096
50971275
509800:02:05,135 --> 00:02:11,036
5099the default domain policy so that I can just show you here, it is entirely possible
5100
51011276
510200:02:11,135 --> 00:02:16,036
5103in one location to configure the user rights assessment not just for a single machine
5104
51051277
510600:02:16,135 --> 00:02:21,036
5107but in the case of this default domain policy for every machine that attaches to the domain.
5108
51091278
511000:02:21,135 --> 00:02:26,036
5111I could also create additional group policy objects and associate them in the correct locations
5112
51131279
511400:02:26,135 --> 00:02:31,036
5115this is also a topic for later, so that I could configure specific machines with the types
5116
51171280
511800:02:31,135 --> 00:02:36,036
5119of security settings that I may require. Down here under security settings and local policies
5120
51211281
512200:02:36,135 --> 00:02:37,036
5123is this same user
5124
51251282
512600:02:37,135 --> 00:02:40,036
5127rights assessment that we saw before. And right now here with the default domain policy
5128
51291283
513000:02:40,135 --> 00:02:47,036
5131as you can see none of them are defined. So we won't be enforcing any groups or users into these policies at this point,
5132
51331284
513400:02:47,135 --> 00:02:53,036
5135but it's entirely possible for me to make some changes here like to change the time zone.
5136
51371285
513800:02:53,135 --> 00:02:58,036
5139To add in a user or group here that would be then subsequently added in to every server
5140
51411286
514200:02:58,135 --> 00:03:03,036
5143and really every desktop that attaches here into our active directory domain.
5144
51451287
514600:03:03,135 --> 00:03:06,536
5147So if you find yourself getting overwhelmed with all the extra steps that may be required to
5148
51491288
515000:03:06,635 --> 00:03:11,536
5151configure user rights on an individual machine. Well prepare yourself for group policy
5152
51531289
515400:03:11,635 --> 00:00:01,677
5155because it's there where we can do things in a much more cohesive manner.
5156
51571290
515800:00:01,778 --> 00:00:05,677
5159Now as I said, that introduction is kind of the boring part of this particular module because
5160
51611291
516200:00:05,777 --> 00:00:10,178
5163I think a lot of us have at least tooled around in most of these tools at some point or another.
5164
51651292
516600:00:10,278 --> 00:00:16,177
5167But it's the configuration of user accounts, of computer accounts, of all the different other
5168
51691293
517000:00:16,277 --> 00:00:21,177
5171tasks that we need to do from the command line where we can really multiply our efforts
5172
51731294
517400:00:21,277 --> 00:00:25,177
5175in terms of getting the tasks done. And thanks to Microsoft's investment in Windows PowerShell
5176
51771295
517800:00:25,277 --> 00:00:29,177
5179we have a lot of really cool PowerShell commandlets these days that we can use
5180
51811296
518200:00:29,277 --> 00:00:36,177
5183for automating the creation of active directory accounts. In fact in these exams you can almost
5184
51851297
518600:00:36,277 --> 00:00:41,177
5187replace the word automate with the word PowerShell or baring that you can replace it
5188
51891298
519000:00:41,277 --> 00:00:45,177
5191with the word command line. Because when Microsoft uses the term automate, what they really
5192
51931299
519400:00:45,277 --> 00:00:51,177
5195mean is using one or more of a series of commands or commandlets to accomplish the task.
5196
51971300
519800:00:51,277 --> 00:00:57,177
5199Here, as you can see, I've got a variety of commands that exist for dealing with computer accounts.
5200
52011301
520200:00:57,277 --> 00:01:00,177
5203The first of which is, get ad computer, which will provide you all the information,
5204
52051302
520600:01:00,277 --> 00:01:04,178
5207the characteristics of a computer account in active directory.
5208
52091303
521000:01:04,278 --> 00:01:09,178
5211The second set is New-ADComputer and Remove-ADComputer, which allow you to create a computer
5212
52131304
521400:01:09,278 --> 00:01:13,178
5215account and remove a computer account from active directory. I include these here
5216
52171305
521800:01:13,278 --> 00:01:18,178
5219along with the ones here at the bottom Add-Computer and Remove-Computer just to show you
5220
52211306
522200:01:18,278 --> 00:01:23,178
5223that in certain cases they're actually some commandlets in PowerShell that look the same
5224
52251307
522600:01:23,278 --> 00:01:28,178
5227smell the same, and perform many of the same duties, but are in fact slightly different.
5228
52291308
523000:01:28,278 --> 00:01:33,178
5231The bottom of these, Add-Computer and Remove-Computer, are what we term native to PowerShell.
5232
52331309
523400:01:33,278 --> 00:01:39,178
5235As opposed to the middle tier there being those that are part of a specific PowerShell module.
5236
52371310
523800:01:39,278 --> 00:01:43,178
5239The active directory module is one that you'll need to reference if you end up using it here
5240
52411311
524200:01:43,278 --> 00:01:47,178
5243within Windows PowerShell. And although the active directory module is one that's easy to reference
5244
52451312
524600:01:47,278 --> 00:01:51,178
5247I just want to point these two out because you may actually be asked questions about
5248
52491313
525000:01:51,278 --> 00:01:56,178
5251one or the other of these two sets of commandlets when you're taking the exam.
5252
52531314
525400:01:56,278 --> 00:02:01,178
5255In either case, both of these sets of command perform much of the same thing, but perhaps
5256
52571315
525800:02:01,278 --> 00:02:05,178
5259with slight differences. And it is recognizing and appreciating those differences that will come
5260
52611316
526200:02:05,278 --> 00:02:10,177
5263as you become more familiar with Windows PowerShell. Now these are for the computer accounts,
5264
52651317
526600:02:10,277 --> 00:02:14,177
5267but there are a similar set of commandlets we can use for dealing with user accounts as well.
5268
52691318
527000:02:14,277 --> 00:02:20,177
5271There's actually a shorter set here because we don't have the native add computer and remove computer equivalents.
5272
52731319
527400:02:20,277 --> 00:02:26,177
5275These are get aduser, which gets information about a user, and then new aduser, remove aduser
5276
52771320
527800:02:26,277 --> 00:02:30,177
5279that I can use for creating or removing an active directory user. Now at this point the only
5280
52811321
528200:02:30,277 --> 00:02:32,177
5283thing I really want to kind of show you is
5284
52851322
528600:02:32,277 --> 00:02:37,177
5287that for these different commandlets, being aware of how to use them is something you just got to know.
5288
52891323
529000:02:37,277 --> 00:02:46,177
5291So get aduser, if I type that in here, get aduser will provide me a list of information about any
5292
52931324
529400:02:46,277 --> 00:02:51,177
5295particular user that exists in active directory. So get aduser gshields will provide me that
5296
52971325
529800:02:51,277 --> 00:02:56,177
5299long list of information about that user gshields. And, just as with anything, I can format
5300
53011326
530200:02:56,277 --> 00:03:01,177
5303things into a list and provide additional information, I can also here choose to view all
5304
53051327
530600:03:01,277 --> 00:03:05,177
5307of the extended properties for that user. And then view
5308
53091328
531000:03:05,277 --> 00:03:10,177
5311a longer list of everything that happens to be associated with that user account.
5312
53131329
531400:03:10,277 --> 00:03:15,177
5315So being aware of what this is will provide you the abilities to either grab the information
5316
53171330
531800:03:15,277 --> 00:03:20,177
5319or with the set aduser command, change that information. Should you have need to so
5320
53211331
532200:03:20,277 --> 00:03:26,177
5323from the command line. With the new aduser account as well, if I go here to new aduser
5324
53251332
532600:03:26,277 --> 00:03:30,177
5327and then show you the help for new aduser, we can take a look at the long list of parameters
5328
53291333
533000:03:30,277 --> 00:03:36,177
5331that are associated, oops not net aduser, I mean a new aduser. We can take a list, look at the
5332
53331334
533400:03:36,277 --> 00:03:42,177
5335long list of parameters that exist here for creating those new active directory users.
5336
53371335
533800:03:42,277 --> 00:03:45,177
5339So without going into the gory detail of each of the possible parameters here,
5340
53411336
534200:03:45,277 --> 00:03:50,177
5343just take a look at all the things that you can configure when it comes time to create that new user
5344
53451337
534600:03:50,277 --> 00:03:57,177
5347from the command line. So configuring the home directory, the employee Id, the Kerberos encryption type,
5348
53491338
535000:03:57,277 --> 00:04:03,177
5351the home phone, the vast majority of all the different fields we saw in active directory users and computers
5352
53531339
535400:04:03,277 --> 00:04:07,177
5355are represented here as parameters associated with the new aduser command.
5356
53571340
535800:04:07,277 --> 00:04:12,177
5359And that's why this syntax box here includes so much copy, because, well we have to represent all the
5360
53611341
536200:04:12,277 --> 00:04:17,177
5363possible things that we could configure for a specific user. The good news is that pretty much all
5364
53651342
536600:04:17,278 --> 00:04:20,177
5367of these parameters here are optional when you're using the new aduser command.
5368
53691343
537000:04:20,278 --> 00:04:27,177
5371I can create a new user, so new aduser Don Jones, for example, with just identifying what the user
5372
53731344
537400:04:27,278 --> 00:04:32,177
5375name should be for that account that I'm creating. If I do that, as you can see, we would create the djones
5376
53771345
537800:04:32,278 --> 00:04:36,177
5379account up here and if I refresh everything's over here with active directory users and computers,
5380
53811346
538200:04:36,278 --> 00:04:42,177
5383well there is the djones account. So you can add additional parameters if you want, if you want to configure
5384
53851347
538600:04:42,278 --> 00:04:46,177
5387additional pieces in here for your name and your display name and all the other bits that
5388
53891348
539000:04:46,278 --> 00:04:49,677
5391make up that user properties. But those are the commands I would be aware of for
5392
53931349
539400:04:49,778 --> 00:00:01,935
5395automating the creation of active directory accounts.
5396
53971350
539800:00:02,035 --> 00:00:04,935
5399Now I did promise you for this module a couple of really cool things that we could do
5400
54011351
540200:00:05,035 --> 00:00:07,935
5403once we start digging a little further into the PowerShell. And it's here where we can start to do
5404
54051352
540600:00:08,035 --> 00:00:13,935
5407some stuff that I personally is just really exciting. And it's in part because I did actually discover
5408
54091353
541000:00:14,035 --> 00:00:18,934
5411a new PowerShell command that I was unaware of that solves a host of what were otherwise
5412
54131354
541400:00:19,035 --> 00:00:23,934
5415exceptionally difficult problems to figure out way back in the day.
5416
54171355
541800:00:24,035 --> 00:00:26,934
5419But before we get to that command, I want to show you just a couple of the ways
5420
54211356
542200:00:27,035 --> 00:00:31,934
5423in which we can go about managing inactive and disabled accounts here in active directory.
5424
54251357
542600:00:32,034 --> 00:00:36,934
5427I'll start with the old commandlets that we had and then we'll move into this new tool
5428
54291358
543000:00:37,034 --> 00:00:40,934
5431that I think you should be aware of just because it's cool. The first, of which, is let's talk
5432
54331359
543400:00:41,034 --> 00:00:45,934
5435about how I can get information about users that may be inactive or disabled.
5436
54371360
543800:00:46,034 --> 00:00:50,934
5439If you think about users and what users might be inactive, you have to think about okay how
5440
54411361
544200:00:51,034 --> 00:00:57,934
5443can we define a user or a set of users that we consider to be inactive in the domain.
5444
54451362
544600:00:58,034 --> 00:01:00,934
5447Well one way in which we've done for years is by taking a look at the last logon date
5448
54491363
545000:01:01,034 --> 00:01:06,935
5451and the last logon time for when that user would attach to the domain or request the use of resources
5452
54531364
545400:01:07,034 --> 00:01:13,935
5455or even just log onto their machine. Because every logon has to happen through a domain controller
5456
54571365
545800:01:14,034 --> 00:01:18,935
5459it is that last logon date attribute associated with the user account that we can definitively
5460
54611366
546200:01:19,034 --> 00:01:23,935
5463use for determining when they attempted to log onto our domain. Now in times gone past,
5464
54651367
546600:01:24,034 --> 00:01:28,935
5467the only way to get this was through this commandlet get aduser. And a fairly complex series of
5468
54691368
547000:01:29,034 --> 00:01:34,935
5471additional parameters that we have to add. Let's say that we want to use get aduser and then filter
5472
54731369
547400:01:35,034 --> 00:01:42,935
5475it on all the items here so that we can take a look at the property which is the last logon date,
5476
54771370
547800:01:43,034 --> 00:01:51,935
5479oops last logon date. What we're asking here is give us all the users and give us their last logon date.
5480
54811371
548200:01:52,034 --> 00:01:55,935
5483And then once we have that let's filter the results into a nice table that we can use
5484
54851372
548600:01:56,034 --> 00:02:01,935
5487to review the name and indeed the last logon date of that particular user.
5488
54891373
549000:02:02,034 --> 00:02:05,935
5491If I get that I take a look at, well here's my administrator, a user account, and then here's the
5492
54931374
549400:02:06,034 --> 00:02:09,935
5495accounts that I created, the Jason Helmick, the Greg Shields, and the Don Jones account.
5496
54971375
549800:02:10,034 --> 00:02:14,935
5499In a production world, I would have a longer list of different accounts, obviously,
5500
55011376
550200:02:15,034 --> 00:02:18,935
5503and obviously I would also have last logon dates for those users as well.
5504
55051377
550600:02:19,034 --> 00:02:22,935
5507But because we just created these accounts, we're not seeing this additional information in here.
5508
55091378
551000:02:23,034 --> 00:02:26,935
5511I could further look at some additional properties as well, there's another property called
5512
55131379
551400:02:27,034 --> 00:02:31,935
5515password last set that can be useful. This password last set gives me an idea of when the users
5516
55171380
551800:02:32,034 --> 00:02:37,935
5519password was last set. So password last set and then let me grab that then into the table,
5520
55211381
552200:02:38,034 --> 00:02:46,935
5523password last set will provide me the last logon date and then when that password was last set for the account.
5524
55251382
552600:02:47,034 --> 00:02:50,935
5527Now the password last set information gives me a little bit more here for my G Shields,
5528
55291383
553000:02:51,034 --> 00:02:54,935
5531my Jason Helmick, and my Don Jones account, because it tells me when the password was set,
5532
55331384
553400:02:55,034 --> 00:03:00,935
5535which was earlier this morning. The combination of this information, with the appropriate formatting and
5536
55371385
553800:03:01,034 --> 00:03:03,935
5539then ordering by however many days will help you understand,
5540
55411386
554200:03:04,034 --> 00:03:08,935
5543well has this user even attempted to log onto the domain for 30 or 60 or 90 days?
5544
55451387
554600:03:09,034 --> 00:03:12,935
5547With that information, I can go through using the remove commands to get rid of those user
5548
55491388
555000:03:13,034 --> 00:03:17,935
5551accounts out of active directory on a more regularly scheduled basis.
5552
55531389
555400:03:18,034 --> 00:03:21,935
5555Then this helps me for situations when I've got inactive accounts, but what I may also be interested in
5556
55571390
555800:03:22,034 --> 00:03:27,935
5559are disabled accounts. Those that have been specifically disabled in active directory. If I flip back
5560
55611391
556200:03:28,034 --> 00:03:30,935
5563here to my active directory users and computers and take a look at one of the
5564
55651392
556600:03:31,034 --> 00:03:38,935
5567accounts that's available, it is possible for me to go down here and set that an account indeed is disabled here in ad.
5568
55691393
557000:03:39,034 --> 00:03:41,935
5571But the problem is, is having to click through every single user account, then to the account tab,
5572
55731394
557400:03:42,034 --> 00:03:45,935
5575and then to scroll down to account options is kind of a pain in the neck.
5576
55771395
557800:03:46,034 --> 00:03:47,935
5579So I can use PowerShell here in order
5580
55811396
558200:03:48,034 --> 00:03:51,935
5583to speed things up just a little more. And one of the first tools I can use to do that
5584
55851397
558600:03:52,034 --> 00:03:57,935
5587is also the get aduser command, but in this case I'm going to choose a filter on my domain
5588
55891398
559000:03:58,034 --> 00:04:00,935
5591which in this case instead of using a wild card I want to actually create a filter
5592
55931399
559400:04:01,034 --> 00:04:05,935
5595that will define which users may be disabled and which ones aren't.
5596
55971400
559800:04:06,034 --> 00:04:11,935
5599If I do the curly brackets here, I could to the filter on enabled --ne true.
5600
56011401
560200:04:12,034 --> 00:04:16,935
5603So running this will give me the list of users where the account is not enabled.
5604
56051402
560600:04:17,035 --> 00:04:21,935
5607As you can see here I have, looks like the Don Jones account, and obviously my template user account.
5608
56091403
561000:04:22,035 --> 00:04:27,935
5611As well as the other sort of basic out-of-the-box accounts that are also disabled by default.
5612
56131404
561400:04:28,035 --> 00:04:32,935
5615Now that's the old school approach to figuring out this information and by old school I mean
5616
56171405
561800:04:33,035 --> 00:04:37,935
5619an operating system ago or two. But in recent versions of the OS Microsoft has included a new
5620
56211406
562200:04:38,035 --> 00:04:44,935
5623commandlet here that I find to be particularly exciting. That command is search ad account.
5624
56251407
562600:04:45,035 --> 00:04:49,935
5627So search ad account, which, if I run the help on, I think I've spelled that correctly,
5628
56291408
563000:04:50,035 --> 00:04:54,935
5631yes, it will give me the list of possible ways in which I can use this commandlet for finding
5632
56331409
563400:04:55,035 --> 00:05:01,935
5635information about accounts that exist in active directory. So let's take a look here at the possibilities.
5636
56371410
563800:05:02,035 --> 00:05:06,935
5639Those are the abilities to search on whether the account is disabled, whether it's expired,
5640
56411411
564200:05:07,035 --> 00:05:12,935
5643whether it's about to expire or expiring, whether the account is inactive, whether it's locked out,
5644
56451412
564600:05:13,035 --> 00:05:16,935
5647whether the password is configured to never expire. So as you can see this search
5648
56491413
565000:05:17,035 --> 00:05:21,935
5651ad account function has some really cool ways in which I can see without needing to construct
5652
56531414
565400:05:22,035 --> 00:05:27,935
5655a variety of different filters and what not how I can then identify which user accounts
5656
56571415
565800:05:28,035 --> 00:05:34,935
5659are in these various states. So let's do search ad account and then let's start with the disabled accounts.
5660
56611416
566200:05:35,035 --> 00:05:36,935
5663So account disabled.
5664
56651417
566600:05:37,035 --> 00:05:40,935
5667There is my list of users and computers where their accounts are currently disabled,
5668
56691418
567000:05:41,035 --> 00:05:47,935
5671but let's actually go a step further and remove out the computer so I just get the users only for that list.
5672
56731419
567400:05:48,035 --> 00:05:51,935
5675And I'll go one step further still and then format the list so I just get the names of the users
5676
56771420
567800:05:52,035 --> 00:05:57,935
5679that are currently disabled. So search ad account really provides some real nice functionality here
5680
56811421
568200:05:58,035 --> 00:06:01,935
5683for helping my quickly identify the accounts that need to be disabled.
5684
56851422
568600:06:02,035 --> 00:06:05,935
5687The good part is, and you'll learn more about this as you get more familiar with PowerShell,
5688
56891423
569000:06:06,035 --> 00:06:10,935
5691is that the objects that are produced by search ad account could be piped into, for example,
5692
56931424
569400:06:11,035 --> 00:06:14,935
5695the remove ad user command, so that I could just search for the accounts that are disabled
5696
56971425
569800:06:15,035 --> 00:06:22,935
5699and then remove them if need be. I can do another one here, let's do search ad accounts and then
5700
57011426
570200:06:23,035 --> 00:06:29,935
5703accounts inactive, so not disabled or expiring, but inactive. This gives me the ability with the
5704
57051427
570600:06:30,035 --> 00:06:34,935
5707additional parameter of timespan, a set of days or hours that I want to look for potentially
5708
57091428
571000:06:35,035 --> 00:06:42,935
5711inactive accounts. So let's say 30 days for example, so 30 days :00:00.
5712
57131429
571400:06:43,035 --> 00:06:48,935
5715So these are the accounts that have been inactive for 30 days or more that should actually be these accounts.
5716
57171430
571800:06:49,035 --> 00:06:52,935
5719Now as you can see I've got a couple of additional accounts in here like my account and the Jason Helmick account
5720
57211431
572200:06:53,035 --> 00:06:57,935
5723and the Don Jones account that are considered inactive because we haven't actually logged into these accounts yet.
5724
57251432
572600:06:58,035 --> 00:07:01,935
5727They are technically inactive because they don't have any last logon date
5728
57291433
573000:07:02,035 --> 00:07:06,935
5731information populated in with their user record. I've got other functionality I can use
5732
57331434
573400:07:07,035 --> 00:07:12,935
5735like search ad accounts, and then password expired. Which accounts exist in this domain
5736
57371435
573800:07:13,035 --> 00:07:18,935
5739where their passwords have expired. Also which accounts have been configured where the password never expires.
5740
57411436
574200:07:19,035 --> 00:07:22,935
5743So a couple of accounts there that have been setup so the password never expires.
5744
57451437
574600:07:23,035 --> 00:07:28,935
5747And my personal favorite, which is search ad accounts and then locked out.
5748
57491438
575000:07:29,035 --> 00:07:31,935
5751Sometimes you end up with users that have punched in their password incorrectly too many times
5752
57531439
575400:07:32,035 --> 00:07:36,935
5755and they end up locking themselves out. Well identifying the long list of users
5756
57571440
575800:07:37,035 --> 00:07:40,935
5759none of which exist in this domain that have been locked out of their account is great for
5760
57611441
576200:07:41,035 --> 00:07:45,935
5763identifying why that person cannot connect up with the resources that they need.
5764
57651442
576600:07:46,035 --> 00:07:49,935
5767The process by which Windows sets an account to be locked out can sometimes have some really
5768
57691443
577000:07:50,035 --> 00:07:54,935
5771weird effects on how users are connecting up to resources. It's not always cut and dry
5772
57731444
577400:07:55,035 --> 00:07:59,935
5775as in determining why a user cannot log on. And so being able to identify whether or not the
5776
57771445
577800:08:00,035 --> 00:08:04,435
5779account is locked out is handy when the user calls in to try to figure out why they're not able
5780
57811446
578200:08:04,535 --> 00:00:01,795
5783to connect to resources for one reason or another.
5784
57851447
578600:00:01,895 --> 00:00:06,796
5787Now where PowerShell really shines is when it comes time to perform bulk actions on active directory
5788
57891448
579000:00:06,895 --> 00:00:10,796
5791or really against any kind of configuration on a machine or service.
5792
57931449
579400:00:10,896 --> 00:00:14,296
5795And so performing bulk active directory operations is one of the places where we can do some
5796
57971450
579800:00:14,396 --> 00:00:21,295
5799really nifty stuff if we've got the information in a format that can be consumed by one or more of these commands.
5800
58011451
580200:00:21,396 --> 00:00:25,295
5803Now I want to before we get into the PowerShell portion, because there's just one that I want to show you,
5804
58051452
580600:00:25,396 --> 00:00:31,295
5807I want to show you a couple of other commands that have existed in Windows for a very long period of time.
5808
58091453
581000:00:31,396 --> 00:00:36,295
5811These bulk operations commands Microsoft provides in order to either export out information
5812
58131454
581400:00:36,396 --> 00:00:41,295
5815or import in information like to create multiple users at once. The first of which is a command called
5816
58171455
581800:00:41,396 --> 00:00:51,295
5819csvde, which uses CSV files or coma separated values files, to go about performing these bulk operations.
5820
58211456
582200:00:51,396 --> 00:00:56,295
5823Now as you can see here, csvde has a very long list of possible parameters that can it use
5824
58251457
582600:00:56,396 --> 00:01:02,295
5827for exporting or importing information. And in fact the default for csvde is to export
5828
58291458
583000:01:02,396 --> 00:01:06,296
5831information unless you specifically choose to import things, which is a great thing because you don't
5832
58331459
583400:01:06,396 --> 00:01:12,296
5835want to accidently import in a bunch of content. In order to export, just to do a simple export
5836
58371460
583800:01:12,396 --> 00:01:22,296
5839of your domain information you can choose csvde and then --f and then a file name, so output.csv.
5840
58411461
584200:01:22,396 --> 00:01:27,296
5843This command will output a csv file that contains all the information that exists in active directory
5844
58451462
584600:01:27,396 --> 00:01:30,296
5847as it relates to users and computers.
5848
58491463
585000:01:30,396 --> 00:01:35,296
5851So we've actually output this information, so let's go ahead and run Notepad and take a look at
5852
58531464
585400:01:35,396 --> 00:01:39,296
5855that output.csv file that we just created.
5856
58571465
585800:01:39,396 --> 00:01:43,296
5859As you can see it's got a whole lot of stuff baked in here and if I remove the, let's say the
5860
58611466
586200:01:43,396 --> 00:01:50,296
5863word wrap is off, we can take a look at just the kinds of things that are in this coma separated values file.
5864
58651467
586600:01:50,396 --> 00:01:53,296
5867Now because the length of the lines is a little bit long, we're getting some line wrap over here,
5868
58691468
587000:01:53,396 --> 00:01:59,296
5871but as you can see on the top we have the list of column names that are associated with this CSV that we've created.
5872
58731469
587400:01:59,396 --> 00:02:04,296
5875Like distinguished name, the object class, the dn the distinguished name over here, the instance type,
5876
58771470
587800:02:04,396 --> 00:02:09,295
5879when it was created when it was changed. And these are represented down here for each
5880
58811471
588200:02:09,395 --> 00:02:15,295
5883individual account, so the lost and found container, the meetings container, and then all the way
5884
58851472
588600:02:15,395 --> 00:02:19,295
5887down here I believe at the bottom we should actually end up getting to some users and groups.
5888
58891473
589000:02:19,395 --> 00:02:26,295
5891So here's our domain admins group for example and here is our allowed RODC password replication group.
5892
58931474
589400:02:26,395 --> 00:02:31,295
5895Well doing this simple output doesn't really provide us much in the way of useful information
5896
58971475
589800:02:31,395 --> 00:02:37,295
5899because even importing this into Excel to delete out all the uninteresting rows still
5900
59011476
590200:02:37,395 --> 00:02:41,295
5903provides us with us a lot of stuff that's perhaps too much for what we need. Well csvde
5904
59051477
590600:02:41,395 --> 00:02:47,295
5907allows you to kind of tailor what kinds of information you want to get out if you provide
5908
59091478
591000:02:47,395 --> 00:02:55,295
5911the appropriate parameters. Once such parameter, which I'll show you, is csvde-f output2.csv
5912
59131479
591400:02:55,395 --> 00:03:01,295
5915and then here I can use the --d parameter to enter in first the container in active directory
5916
59171480
591800:03:01,395 --> 00:03:06,295
5919that I'm interested in. So the contents of a specific container as opposed to all containers.
5920
59211481
592200:03:06,395 --> 00:03:11,295
5923To do that I'm going to need to provide a path to the container through ldap, which in our case
5924
59251482
592600:03:11,395 --> 00:03:14,295
5927let's choose the users container. This container is what we find over
5928
59291483
593000:03:14,395 --> 00:03:20,295
5931here, right there, the users container in active directory users and computers. The path for that
5932
59331484
593400:03:20,395 --> 00:03:31,295
5935container will be cn=users and then dc=company, dc=pri. This will give me the contents of that's
5936
59371485
593800:03:31,395 --> 00:03:38,295
5939users container. I could also use the --r parameter to identify just an additional filter that
5940
59411486
594200:03:38,395 --> 00:03:41,295
5943I would want to apply for the types of objects I'm interested in.
5944
59451487
594600:03:41,395 --> 00:03:49,295
5947So let's then filter this down just a bit further to just the user objects, so object class = user.
5948
59491488
595000:03:49,395 --> 00:03:50,295
5951And if I run that correctly
5952
59531489
595400:03:50,395 --> 00:03:57,295
5955that should give me just the 7 entries as opposed to the 246 entries that make up the entire domain.
5956
59571490
595800:03:57,395 --> 00:04:02,295
5959Well let's take a look at that new output file that we just created, output2.csv
5960
59611491
596200:04:02,395 --> 00:04:03,295
5963and as you can see there are far
5964
59651492
596600:04:03,395 --> 00:04:08,295
5967fewer records in here that correspond with just the users that exist in that container.
5968
59691493
597000:04:08,395 --> 00:04:14,295
5971The neat part about these is that the creation of these allows you to just drop this into Microsoft Excel
5972
59731494
597400:04:14,395 --> 00:04:19,295
5975make some changes that you may require, perhaps use it as a template to create an additional list of users
5976
59771495
597800:04:19,396 --> 00:04:23,295
5979that you may want to import. And then when it comes time to actually import in this information
5980
59811496
598200:04:23,396 --> 00:04:30,295
5983you could use the same csvde command, csvde, with the --i switch to go ahead and import in an additional file,
5984
59851497
598600:04:30,396 --> 00:04:35,295
5987so output2.csv. Now I'm not going to hit the Enter button here because I don't want to import
5988
59891498
599000:04:35,396 --> 00:04:40,295
5991in additional records that I already have, but this is a process that you could go through using
5992
59931499
599400:04:40,396 --> 00:04:45,295
5995csvde to export and import information in and out of active directory.
5996
59971500
599800:04:45,396 --> 00:04:49,295
5999Now there is one other command that's similar to csvde, I won't go into as much detail with this other
6000
60011501
600200:04:49,396 --> 00:04:53,295
6003command called ldifde.
6004
60051502
600600:04:53,396 --> 00:04:59,295
6007The only main difference here is that ldifde provides many of the same functions as csvde does,
6008
60091503
601000:04:59,396 --> 00:05:07,295
6011except the output format for ldifde will be not in the csv format, but the ldif format.
6012
60131504
601400:05:07,396 --> 00:05:12,295
6015So if I wanted to do a sample export of my current domain so that you could see what the ldif format looks like
6016
60171505
601800:05:12,396 --> 00:05:25,295
6019I do ldifde-f and then output3.ldf. And once I've taken a look at that, let's do a Notepad output3.ldf
6020
60211506
602200:05:25,396 --> 00:05:28,295
6023and we can take a look at just how this differentiates or how this
6024
60251507
602600:05:28,396 --> 00:05:33,295
6027differs from what we saw before in the commerce separated values format.
6028
60291508
603000:05:33,396 --> 00:05:37,295
6031As you can see this is not so much a table but a long list of all the different records and
6032
60331509
603400:05:37,396 --> 00:05:42,295
6035the characteristics associated with those records. And depending on what format you prefer,
6036
60371510
603800:05:42,396 --> 00:05:47,295
6039you can use CSV or ldifde to perform these bulk active directory operations.
6040
60411511
604200:05:47,396 --> 00:05:51,295
6043Now I can't go and show you all the command line tools without delving into the PowerShell a bit
6044
60451512
604600:05:51,396 --> 00:05:56,295
6047because these non-PowerShell tools are, if they're not deprecated, it's likely that they
6048
60491513
605000:05:56,396 --> 00:06:01,295
6051will be deprecated at some point as Microsoft continues its embrace with Windows PowerShell.
6052
60531514
605400:06:01,396 --> 00:06:08,295
6055So I want to show you how I can take the CSV file or a slightly reformatted version of a CSV file
6056
60571515
605800:06:08,396 --> 00:06:15,295
6059and then use that as an input for a PowerShell command so that I can create new users via that mechanism.
6060
60611516
606200:06:15,396 --> 00:06:16,295
6063Let's go ahead and close this output3 here
6064
60651517
606600:06:16,396 --> 00:06:19,295
6067and let me clear the screen so that
6068
60691518
607000:06:19,396 --> 00:06:25,295
6071I can show you just an additional CSV file that I've created. And in fact if I minimize this
6072
60731519
607400:06:25,396 --> 00:06:26,295
6075and minimize this, I can show you
6076
60771520
607800:06:26,396 --> 00:06:32,295
6079that CSV file here. All I've done is taken the variety of different columns names that
6080
60811521
608200:06:32,396 --> 00:06:38,295
6083I'm interested in and populated them here into a CSV file so that I can create three different users.
6084
60851522
608600:06:38,396 --> 00:06:43,295
6087This provides a great example of a situation where, for example, you're Human Resources Department
6088
60891523
609000:06:43,396 --> 00:06:49,295
6091may want to give you a spreadsheet of different users to have you create active directory accounts
6092
60931524
609400:06:49,396 --> 00:06:54,295
6095from that information. That spreadsheet can very easily be converted into a CSV file
6096
60971525
609800:06:54,396 --> 00:06:58,295
6099and as long as you have the appropriate column titles up here, you'll be able to enter
6100
61011526
610200:06:58,396 --> 00:07:03,295
6103them in into active directory as part of this new aduser command.
6104
61051527
610600:07:03,396 --> 00:07:05,295
6107So let me show you here, back here in PowerShell,
6108
61091528
611000:07:05,396 --> 00:07:10,295
6111how we might go about actually accomplishing that. If we take a look again at the new aduser command
6112
61131529
611400:07:10,396 --> 00:07:12,295
6115and I show you the help on it, we can take
6116
61171530
611800:07:12,396 --> 00:07:18,295
6119a look at all the different possible parameters that correspond with the fields for a particular
6120
61211531
612200:07:18,396 --> 00:07:23,295
6123active directory user, like employee Id or certificates or the authentication policy
6124
61251532
612600:07:23,396 --> 00:07:30,295
6127or the auth type or the country. If I have a CSV file that includes the appropriate column titles
6128
61291533
613000:07:30,396 --> 00:07:35,295
6131with the information correctly configured for that column title, I can pipe that information
6132
61331534
613400:07:35,396 --> 00:07:41,295
6135as content into the new aduser account to create multiple accounts in bulk.
6136
61371535
613800:07:41,396 --> 00:07:46,295
6139Let's see how we might do that, let me come back over here and I'm going to
6140
61411536
614200:07:46,396 --> 00:07:51,295
6143import in the CSV file that we just created before. And the CSV file I'm looking for actually
6144
61451537
614600:07:51,396 --> 00:07:57,295
6147is going to be in users administrator desktop, so there's the file I'm looking at.
6148
61491538
615000:07:57,396 --> 00:08:05,295
6151Let's do import csv and then new users.csv, that's the file I'm looking for.
6152
61531539
615400:08:05,396 --> 00:08:10,295
6155And I'm going to pipe that into the new aduser account, new ad, whoops new aduser.
6156
61571540
615800:08:10,396 --> 00:08:15,295
6159If everything's been done correctly this should automatically create those three users
6160
61611541
616200:08:15,396 --> 00:08:19,295
6163in active directory with all the characteristics, the field values populated that I
6164
61651542
616600:08:19,396 --> 00:08:23,295
6167included in that CSV. If I come over here to
6168
61691543
617000:08:23,396 --> 00:08:26,295
6171active directory users and computers and you'll see I've created an organizational unit here
6172
61731544
617400:08:26,396 --> 00:08:31,295
6175called bulk users just a place to store these accounts. And I hit the F5 to refresh things,
6176
61771545
617800:08:31,396 --> 00:08:38,295
6179yep there are my three users that I just created, user test1, user test2, and user test3.
6180
61811546
618200:08:38,395 --> 00:08:42,295
6183Now they're going to be some caveats here in doing this, there's some types of things that you
6184
61851547
618600:08:42,395 --> 00:08:47,295
6187just can't pipe in, passwords are one that require a little extra effort.
6188
61891548
619000:08:47,395 --> 00:08:51,295
6191There can be some other complex object types that may require extra effort as well.
6192
61931549
619400:08:51,395 --> 00:08:56,295
6195You also need to create an organizational unit here as opposed to just a container in active directory
6196
61971550
619800:08:56,395 --> 00:09:01,295
6199to support where these things need to get targeted too, but I wanted to show you this just to
6200
62011551
620200:09:01,395 --> 00:09:06,295
6203give you a feel for how you might be able to construct the kinds of bulk active directory
6204
62051552
620600:09:06,395 --> 00:09:10,295
6207operations that you might need with a little more than an Excel spreadsheet and
6208
62091553
621000:09:10,395 --> 00:00:01,746
6211a really well-crafted PowerShell command.
6212
62131554
621400:00:01,846 --> 00:00:05,747
6215And then on to our final task here in this module on users and computers, we want to talk about
6216
62171555
621800:00:05,847 --> 00:00:10,746
6219doing an offline domain join for servers that for some reason cannot connect directly up
6220
62211556
622200:00:10,846 --> 00:00:16,246
6223into the rest of our active directory infrastructure. Now as I said in the introduction to this module
6224
62251557
622600:00:16,347 --> 00:00:19,246
6227this is a step that you probably won't find yourself doing all that often.
6228
62291558
623000:00:19,347 --> 00:00:25,246
6231In most cases the creation of a new computer probably happens perhaps in the IT location
6232
62331559
623400:00:25,347 --> 00:00:29,246
6235where you're building those new laptops or desktops. But sometimes you may have a situation
6236
62371560
623800:00:29,347 --> 00:00:34,246
6239where you've got a user in some remote location that doesn't have direct connectivity with
6240
62411561
624200:00:34,347 --> 00:00:40,246
6243the rest of your network and so can't attach their computer directly to your domain.
6244
62451562
624600:00:40,347 --> 00:00:43,246
6247In the old days there was no real good way to fix this, but these days we have this tool
6248
62491563
625000:00:43,347 --> 00:00:51,246
6251called djoin, a little command line tool called djoin, that presents an ability, if I do djoin question mark here,
6252
62531564
625400:00:51,347 --> 00:00:57,246
6255which presents the ability to preprovision an active directory computer account and then generate
6256
62571565
625800:00:57,347 --> 00:01:02,246
6259a little file once that's done. Which we can then copy over to the computer, install it to the
6260
62611566
626200:01:02,347 --> 00:01:09,246
6263correct location, and use that file as the mechanism to complete the joining of that machine into active directory.
6264
62651567
626600:01:09,346 --> 00:01:13,246
6267We're effectively accomplishing the same series of steps that we would do with a traditional active directory
6268
62691568
627000:01:13,346 --> 00:01:17,246
6271join, we're just separating it out with the use of this file and the content in that file
6272
62731569
627400:01:17,346 --> 00:01:21,246
6275to complete the authentication. So let's go through
6276
62771570
627800:01:21,346 --> 00:01:27,246
6279just the couple of steps that we need to do to first create that computer account in active directory.
6280
62811571
628200:01:27,346 --> 00:01:33,246
6283In order to do that we'll use the djoin command and then a couple of, really a long series of parameters here.
6284
62851572
628600:01:33,346 --> 00:01:42,246
6287So here's provision and then domain company.pri, then the machine we're looking for is going to be server1,
6288
62891573
629000:01:42,346 --> 00:01:49,246
6291the save file that we'll be creating will be server1.txt. This will go about creating
6292
62931574
629400:01:49,346 --> 00:01:51,246
6295that computer account there in active directory and if I take a look
6296
62971575
629800:01:51,346 --> 00:01:56,246
6299here at the computers OU, I should here see, there's my server1 computer account
6300
63011576
630200:01:56,346 --> 00:02:00,246
6303that's been added into active directory. What I can also see, if we take a look
6304
63051577
630600:02:00,346 --> 00:02:06,246
6307then here at the root of C, is this server1.txt file, which includes a very long series
6308
63091578
631000:02:06,346 --> 00:02:11,247
6311of letters and numbers, which is effectively the shared secret that you would use on the remote machine
6312
63131579
631400:02:11,347 --> 00:02:15,247
6315to complete the addition to the domain. I should mention that you should be very careful
6316
63171580
631800:02:15,347 --> 00:02:20,247
6319with these txt files once they're created because you're active directory is anticipating
6320
63211581
632200:02:20,347 --> 00:02:23,247
6323a connection from a machine that has actually processed this file.
6324
63251582
632600:02:23,347 --> 00:02:30,247
6327So once you create these files keep them close at hand until you complete getting them onto that remote computer.
6328
63291583
633000:02:30,347 --> 00:02:32,247
6331Let me then flip back over to our
6332
63331584
633400:02:32,347 --> 00:02:33,247
6335computer server1 here.
6336
63371585
633800:02:33,347 --> 00:02:35,247
6339And I'm going to logon just a local administrator
6340
63411586
634200:02:35,347 --> 00:02:40,247
6343onto this machine so that we can take a look at this final step in the process.
6344
63451587
634600:02:40,347 --> 00:02:42,247
6347I want to show you that this is one of the computers that we were
6348
63491588
635000:02:42,347 --> 00:02:48,247
6351dealing with back a couple of courses ago that was named that win-long series of letters and numbers.
6352
63531589
635400:02:48,347 --> 00:02:52,247
6355I've gone through here to rename the computer as server1 so that we can change it from
6356
63571590
635800:02:52,347 --> 00:02:56,247
6359it's work group mode over into a full active directory connected mode.
6360
63611591
636200:02:56,347 --> 00:03:00,247
6363Let's begin that process here on this machine by copying the file that we just created over
6364
63651592
636600:03:00,347 --> 00:03:06,247
6367on our DC machine here locally so that we can make use of it. I've mapped a drive here, the Z drive
6368
63691593
637000:03:06,347 --> 00:03:12,247
6371to the DC computer, so that on the root of C I can grab our server1.txt file.
6372
63731594
637400:03:12,347 --> 00:03:13,247
6375And I'll just throw that file here
6376
63771595
637800:03:13,347 --> 00:03:16,247
6379onto the desktop so that we can make use of it.
6380
63811596
638200:03:16,347 --> 00:03:19,247
6383With that done let's go ahead and open up a traditional command prompt here and we'll set
6384
63851597
638600:03:19,347 --> 00:03:22,247
6387it as an elevated command prompt.
6388
63891598
639000:03:22,347 --> 00:03:26,247
6391So that we can work with it for the purposes of actually completing this domain join.
6392
63931599
639400:03:26,347 --> 00:03:30,247
6395Let me make sure that I've got the file there, there's my server1.txt file.
6396
63971600
639800:03:30,347 --> 00:03:37,247
6399And so the second use of the djoin command that I need is djoin /requestodj, then I need to
6400
64011601
640200:03:37,347 --> 00:03:48,247
6403load the file, that file is server1.txt. And then I need to do windowspath%systemroots and that the
6404
64051602
640600:03:48,347 --> 00:03:54,247
6407path for windows and then configure this as a local OS. This should allow me to go about actually
6408
64091603
641000:03:54,347 --> 00:03:59,247
6411completing this join of this machine server1 into my active directory domain.
6412
64131604
641400:03:59,347 --> 00:04:02,247
6415As you can see here we've loaded the provisioning data from that file server1 and the
6416
64171605
641800:04:02,347 --> 00:04:08,247
6419request is completed successfully, but we are going to need to reboot for those changes to be applied.
6420
64211606
642200:04:08,347 --> 00:04:12,247
6423Let me go ahead and reboot this machine so that we can take a look at what happens
6424
64251607
642600:04:12,347 --> 00:04:17,246
6427now that we've added this machine server1 here into our active directory domain.
6428
64291608
643000:04:17,346 --> 00:04:19,246
6431With the reboot complete, let me see if I can log
6432
64331609
643400:04:19,346 --> 00:04:24,246
6435in here and yep there we go. I can now log in as my user name into the company domain
6436
64371610
643800:04:24,346 --> 00:04:26,746
6439which I couldn't do before because it was only in a work group.
6440
64411611
644200:04:26,846 --> 00:04:30,246
6443This gives you that ability again to offline domain join machines when
6444
64451612
644600:04:30,346 --> 00:00:01,895
6447they're not directly connected up to the rest of your active directory environment.
6448
64491613
645000:00:01,995 --> 00:00:07,395
6451So equal parts nifty and perhaps not so nifty here in this module on users and computers.
6452
64531614
645400:00:07,495 --> 00:00:11,394
6455We have talked about some pretty cool things, you know, ways in which you can use the command line
6456
64571615
645800:00:11,494 --> 00:00:15,394
6459and PowerShell to automate a variety of otherwise really boring tasks and wrap them up
6460
64611616
646200:00:15,494 --> 00:00:21,394
6463into what used to be a very risk killing activity clicking around in active directory users and computers.
6464
64651617
646600:00:21,495 --> 00:00:25,394
6467So what have we talked about in this module? We have talked about creating, copying, configuring,
6468
64691618
647000:00:25,495 --> 00:00:30,394
6471and deleting users and computers using both the aduc and adac. We configured some templates there
6472
64731619
647400:00:30,495 --> 00:00:34,394
6475in active directory users and computers so that we could ensure a common baseline across the
6476
64771620
647800:00:34,494 --> 00:00:38,394
6479users that we would create. We took a quick look at user rights and how you can apply them
6480
64811621
648200:00:38,494 --> 00:00:43,394
6483now through group policy as well as the automation of creating active directory accounts,
6484
64851622
648600:00:43,494 --> 00:00:47,394
6487managing those that are inactive and disabled, and even some really cool ways that we can
6488
64891623
649000:00:47,494 --> 00:00:51,394
6491perform bulk active directory operations. Once we have the right commands under our belt.
6492
64931624
649400:00:51,494 --> 00:00:56,394
6495We then concluded with a look at offline domain join and how for those machines that aren't connected
6496
64971625
649800:00:56,494 --> 00:01:02,394
6499to our network, we can get them added into active directory with a pair of commands and a very important file.
6500
65011626
650200:01:02,494 --> 00:01:07,395
6503Coming up next, we will take a look now at active directory groups and organizational units.
6504
65051627
650600:01:07,495 --> 00:01:11,395
6507In comparison with users and computers, dealing with active directory groups is one of those
6508
65091628
651000:01:11,495 --> 00:01:15,395
6511required activities for any IT professional. And making sure that you apply them in ways
6512
65131629
651400:01:15,495 --> 00:01:20,395
6515that are intelligent is something that admittedly you don't find in a lot of organizations.
6516
65171630
651800:01:20,495 --> 00:01:24,395
6519Part of the reason for that is that there are just so many ways in which groups can get configured
6520
65211631
652200:01:24,495 --> 00:01:29,395
6523together and nested inside of each other. Do so correctly, and it's very easy for you to go
6524
65251632
652600:01:29,495 --> 00:01:33,395
6527about adding and removing users from the resources that they require.
6528
65291633
653000:01:33,495 --> 00:01:37,395
6531Do so incorrectly and you could inadvertently expose inappropriate information to people that
6532
65331634
653400:01:37,495 --> 00:01:42,395
6535shouldn't have access. So in that module we'll talk about group nesting, the different kinds of
6536
65371635
653800:01:42,495 --> 00:01:46,395
6539groups that active directory provides. How to manage group membership using group policy
6540
65411636
654200:01:46,495 --> 00:01:51,395
6543and enumerate group membership. I'll talk about delegation of control and how you might
6544
65451637
654600:01:51,495 --> 00:01:55,395
6547go about configuring your organizational units to support the needs of your users and
6548
65491638
655000:01:55,495 --> 00:02:00,395
6551ultimately the needs of your group policy application. A discussion on groups and organizational
6552
65531639
655400:02:00,495 --> 23:59:59,899
6555units as a topic for our next module coming up.
6556
65571640
655800:00:00,000 --> 00:00:05,900
6559You can argue that managing active directory users is a relatively straightforward process.
6560
65611641
656200:00:06,000 --> 00:00:11,900
6563I mean user has an account or they don't and if they don't they don't have access to anything.
6564
65651642
656600:00:12,000 --> 00:00:15,900
6567Well whereas those users may be relatively straightforward, dealing with the groups that that
6568
65691643
657000:00:16,000 --> 00:00:20,899
6571user may be a member of is quite another thing entirely. Managing your active directory groups
6572
65731644
657400:00:21,000 --> 00:00:26,899
6575can at first blush seem like a really a simple thing to do, but these groups and the sheer number
6576
65771645
657800:00:27,000 --> 00:00:30,899
6579of groups you will likely have and the nesting of one group into another.
6580
65811646
658200:00:31,000 --> 00:00:36,899
6583Can very quickly turn what would seem a simple active directory infrastructure into one
6584
65851647
658600:00:37,000 --> 00:00:40,899
6587that is far more complicated than you would ever expect. And so for that reason here in this module
6588
65891648
659000:00:41,000 --> 00:00:44,899
6591on creating and managing active directory groups and organizational units,
6592
65931649
659400:00:45,000 --> 00:00:48,899
6595we're going to spend our time talking not just about how to put users in groups,
6596
65971650
659800:00:49,000 --> 00:00:50,899
6599but more specifically on the other
6600
66011651
660200:00:51,000 --> 00:00:54,899
6603things that you have to deal with when you're talking about managing the groups themselves.
6604
66051652
660600:00:55,000 --> 00:00:59,899
6607I mean the reason why we have groups is to ensure that the right people have access to the right resources.
6608
66091653
661000:01:00,000 --> 00:01:05,900
6611And conversely that the wrong people don't have access to the resources they shouldn't have access too.
6612
66131654
661400:01:06,000 --> 00:01:10,900
6615And so dealing with your groups requires a bit of strategy in ensuring that you create them
6616
66171655
661800:01:11,000 --> 00:01:14,900
6619and manage them correctly. We'll talk here in this module about how to create and copy, configure,
6620
66211656
662200:01:15,000 --> 00:01:20,900
6623and delete groups and organizational units both from the graphical user interface and using Windows PowerShell.
6624
66251657
662600:01:21,000 --> 00:01:24,900
6627Similar to what we were talking about in the last module on users, they were just a small set
6628
66291658
663000:01:25,000 --> 00:01:28,900
6631of Windows PowerShell commands that you just got to know. These give you the abilities to create
6632
66331659
663400:01:29,000 --> 00:01:33,900
6635new groups and organizational units and to change their membership and to perform all the usual
6636
66371660
663800:01:34,000 --> 00:01:37,900
6639tasks that you would consider as part of group management. We'll also talk about group nesting
6640
66411661
664200:01:38,000 --> 00:01:42,900
6643and it's here where groups can get a little insidious because it is possible to take one group
6644
66451662
664600:01:43,000 --> 00:01:46,900
6647and in some cases stick it inside another group. And in fact when you look at some of the best
6648
66491663
665000:01:47,000 --> 00:01:52,900
6651practices for how to do group nesting, the best way to actually configure your groups involves
6652
66531664
665400:01:53,000 --> 00:01:56,900
6655always using some form of group nesting. I will show you what that best practice is and
6656
66571665
665800:01:57,000 --> 00:02:01,900
6659a little acronym that you could potentially use for memorizing which groups go into which groups.
6660
66611666
666200:02:02,000 --> 00:02:07,900
6663But pay careful attention to the strategy you use in setting up the nesting of your groups.
6664
66651667
666600:02:08,000 --> 00:02:11,900
6667Because without being careful here, it's entirely possible for you to inadvertently give the
6668
66691668
667000:02:12,000 --> 00:02:15,900
6671wrong person access to something they shouldn't have. We'll also talk about some of the
6672
66731669
667400:02:16,000 --> 00:02:20,900
6675PowerShell commands you can use for enumerating group membership and I'll go actually a little
6676
66771670
667800:02:21,000 --> 00:02:25,900
6679deeper here than just the one command you need to know for which users are in which group.
6680
66811671
668200:02:26,000 --> 00:02:31,900
6683I want to talk about three use cases for membership and how we can use PowerShell to greatly enhance
6684
66851672
668600:02:32,000 --> 00:02:36,900
6687the vision that you'll have in understanding which users may have access to which groups.
6688
66891673
669000:02:37,000 --> 00:02:40,900
6691Particularly when you combine this with the groups that may be nested in each other.
6692
66931674
669400:02:41,000 --> 00:02:43,900
6695We'll talk very quickly about how to convert groups; there are just a couple of commands
6696
66971675
669800:02:44,000 --> 00:02:47,900
6699you would do for converting, for example, security to distribution groups.
6700
67011676
670200:02:48,000 --> 00:02:51,900
6703Or from global groups to universal groups. There are also some kinds of conversions you just
6704
67051677
670600:02:52,000 --> 00:02:56,900
6707simply can't do, so we'll talk about the options that you have in converting one type of group into another.
6708
67091678
671000:02:57,000 --> 00:03:02,900
6711It is also possible to manage your group membership using group policy as well.
6712
67131679
671400:03:03,000 --> 00:03:05,900
6715And once again I don't want to steal the thunder from our entire course on group policy,
6716
67171680
671800:03:06,000 --> 00:03:09,900
6719but I do want to show you one area inside of the group policy management console
6720
67211681
672200:03:10,000 --> 00:03:13,900
6723where you can configure a group and then configure the membership for that group
6724
67251682
672600:03:14,000 --> 00:03:19,900
6727so that it will be universally applied across all the machines where that group policy applies.
6728
67291683
673000:03:20,000 --> 00:03:23,900
6731As with our user rights assessment back in that last module, this functionality presents a
6732
67331684
673400:03:24,000 --> 00:03:29,900
6735really awesome way to ensure that the right people get in the right groups on every machine all at once.
6736
67371685
673800:03:30,000 --> 00:03:32,900
6739We will also talk about the delegation of control wizard and when you're dealing with active directory
6740
67411686
674200:03:33,000 --> 00:03:38,900
6743objects it is this delegation of control wizard where you can identify which users should have the
6744
67451687
674600:03:39,000 --> 00:03:42,900
6747abilities to perform administrative tasks on groups and other objects, like being able to
6748
67491688
675000:03:43,000 --> 00:03:47,900
6751change the membership. Well the delegation of control wizard is great for being able to do things,
6752
67531689
675400:03:48,000 --> 00:03:52,900
6755but we also have to be kind of cautious with its use because once you start popping into the delegation
6756
67571690
675800:03:53,000 --> 00:03:58,900
6759of control wizard you can begin to make changes that are very difficult to locate later on
6760
67611691
676200:03:59,000 --> 00:04:02,900
6763and even harder to rip out. So I'll show you where the delegation of control wizard is
6764
67651692
676600:04:03,000 --> 00:04:06,900
6767but be careful when you use it in production. And then lastly is a single command here called
6768
67691693
677000:04:07,000 --> 00:04:10,900
6771redircmp that you should be aware of. Because it will do the very handy action of changing
6772
67731694
677400:04:11,000 --> 00:04:17,899
6775the default active directory container from the computers OU to some other organizational unit
6776
67771695
677800:04:18,000 --> 00:04:21,899
6779for new computers that are coming into your active directory. So every time you add a
6780
67811696
678200:04:22,000 --> 00:04:25,899
6783new computer in active directory, if you want that computer to go somewhere else as opposed
6784
67851697
678600:04:26,000 --> 00:04:28,649
6787to the default container, well you can do so with this single command.
6788
67891698
679000:04:28,750 --> 00:00:01,927
6791And I'll show you what the command is and how to use it here in our final task.
6792
67931699
679400:00:02,028 --> 00:00:05,653
6795For our first task here on creating, copying, configuring, and deleting groups in OUs I think
6796
67971700
679800:00:05,753 --> 00:00:11,928
6799it's worthwhile for us to spend just a second or two talking about the academics of groups in active directory.
6800
68011701
680200:00:12,028 --> 00:00:15,927
6803Groups have multiple different types and they also have multiple different scopes so you'll be
6804
68051702
680600:00:16,027 --> 00:00:20,927
6807creating different kinds of groups depending on what you actually need to use that group for.
6808
68091703
681000:00:21,027 --> 00:00:24,927
6811First up are the two different types of groups in active directory, security groups on one side
6812
68131704
681400:00:25,027 --> 00:00:31,927
6815and distribution groups on the other. In every case if you're attempting to use a group for the
6816
68171705
681800:00:32,027 --> 00:00:35,927
6819dissemination of permission or in other words to apply permissions to some folder or other object.
6820
68211706
682200:00:36,027 --> 00:00:39,927
6823You're going to use a security group to do that. The only case where you find yourself using
6824
68251707
682600:00:40,027 --> 00:00:43,927
6827distribution groups is when you're dealing with email and the need to send out the email to a
6828
68291708
683000:00:44,027 --> 00:00:49,927
6831group of users for one reason or another. This differentiation is very simple, so anytime
6832
68331709
683400:00:50,027 --> 00:00:52,927
6835you're dealing with security, you deal with security groups. And anytime you're dealing with email
6836
68371710
683800:00:53,027 --> 00:00:56,927
6839and Microsoft exchange, generally, you're going to deal with distribution groups.
6840
68411711
684200:00:57,027 --> 00:01:00,927
6843Now when it comes to scopes this is where things get a little bit more challenging because the scopes
6844
68451712
684600:01:01,027 --> 00:01:05,928
6847can be a little confusing when you first start out. On the left hand side down here we have
6848
68491713
685000:01:06,028 --> 00:01:11,928
6851global groups and groups can include users, computers, global groups can include other global groups
6852
68531714
685400:01:12,028 --> 00:01:17,928
6855from the same domain. Most often you use global groups to organize users who have similar functions,
6856
68571715
685800:01:18,028 --> 00:01:22,928
6859so your finance group, your IT group, and so on. And so because of that these users will
6860
68611716
686200:01:23,028 --> 00:01:27,928
6863have similar requirements on the network. When you're thinking about the best practice approach
6864
68651717
686600:01:28,028 --> 00:01:32,928
6867for using global groups, you most often assign these to functions in the organization,
6868
68691718
687000:01:33,028 --> 00:01:37,928
6871again, the finance, IT, sales, what have you. This is differentiated from domain local groups,
6872
68731719
687400:01:38,028 --> 00:01:43,928
6875which can also include users, computers, and groups from any domain in the forest.
6876
68771720
687800:01:44,028 --> 00:01:47,928
6879These groups are most often utilized to give permissions to resources and to provide access
6880
68811721
688200:01:48,028 --> 00:01:52,928
6883to resources in the domain where they're located. In most cases you find that domain local groups
6884
68851722
688600:01:53,028 --> 00:01:57,928
6887actually contain global groups so that you organize the users by global groups and you'd
6888
68891723
689000:01:58,028 --> 00:02:01,928
6891organize the resources by domain local groups. I'll talk more about how this works when we
6892
68931724
689400:02:02,028 --> 00:02:07,927
6895get into group nesting here in just a minute. The third group over here on the right is a universal group.
6896
68971725
689800:02:08,027 --> 00:02:11,927
6899So these are kind of a special group that you have to pay careful attention too, because the
6900
69011726
690200:02:12,027 --> 00:02:16,927
6903universal groups and the membership of universal groups is something that's taken care of
6904
69051727
690600:02:17,027 --> 00:02:22,927
6907by any domain controllers that are also global catalogs. And so because of that any change to the
6908
69091728
691000:02:23,027 --> 00:02:26,927
6911membership of a universal group is going to require that membership to be replicated around
6912
69131729
691400:02:27,027 --> 00:02:32,927
6915every global catalog server in your active directory forest. A universal group can include users
6916
69171730
691800:02:33,027 --> 00:02:39,927
6919and groups from any domain in the forest and can be used to grant permissions to any resource in the forest.
6920
69211731
692200:02:40,027 --> 00:02:44,927
6923Now this may automatically make you think that, okay well if I can put in a user or object or what have you
6924
69251732
692600:02:45,027 --> 00:02:49,927
6927in a universal group anywhere in the forest, then I can assign it for any permission anywhere in the forest.
6928
69291733
693000:02:50,027 --> 00:02:52,927
6931Well a universal group would be the thing I should use for everything.
6932
69331734
693400:02:53,027 --> 00:02:57,927
6935But you have to be cautious with these because again the ultimate power that a universal group comes
6936
69371735
693800:02:58,027 --> 00:03:02,927
6939with a cost and that being the replication of the membership of that group.
6940
69411736
694200:03:03,027 --> 00:03:07,927
6943If you find yourself using a lot of universal groups you could find yourself also requiring a lot of
6944
69451737
694600:03:08,027 --> 00:03:12,927
6947replication from domain controller to domain controller. So take care with the use of universal groups
6948
69491738
695000:03:13,027 --> 00:03:17,927
6951and use them in those special circumstances where you'd have multiple domains in the forest
6952
69531739
695400:03:18,027 --> 00:00:01,790
6955and multiple users in those domains or multiple resources that need to integrate together.
6956
69571740
695800:00:01,891 --> 00:00:05,291
6959Now in addition to the groups that you'll be creating as you go through the day to day operations
6960
69611741
696200:00:05,391 --> 00:00:08,791
6963of your active directory infrastructure, they're also a number of built in groups,
6964
69651742
696600:00:08,891 --> 00:00:13,291
6967there are a number of those that are available out-of-the-box. These we've already talked about
6968
69691743
697000:00:13,391 --> 00:00:17,790
6971back in that last module when we're looking at the active directory users and computers console.
6972
69731744
697400:00:17,890 --> 00:00:23,290
6975But I want to show you here back in our machine dc.company.pri, just once again the location
6976
69771745
697800:00:23,390 --> 00:00:27,290
6979where we can take a look at the different groups that exist in active directory.
6980
69811746
698200:00:27,390 --> 00:00:31,290
6983I'm going to pop up here and open up my old favorite ad.console here, active directory users and computers.
6984
69851747
698600:00:31,390 --> 00:00:37,290
6987Although you could use the adac, the active directory administrative center if you preferred to.
6988
69891748
699000:00:37,390 --> 00:00:38,290
6991And if I come down here to our users
6992
69931749
699400:00:38,390 --> 00:00:44,290
6995OU we can take a look again at some of the groups that are available, and in this case mostly right out-of-the-box.
6996
69971750
699800:00:44,390 --> 00:00:50,290
6999Here you can see these groups that are configured as universal groups, as global groups, and as domain local groups.
7000
70011751
700200:00:50,390 --> 00:00:53,290
7003And if we pick any particular one of these, like domain admins for example
7004
70051752
700600:00:53,390 --> 00:00:56,290
7007we can take a look at just some of the characteristics that are associated with these groups.
7008
70091753
701000:00:56,390 --> 00:01:03,290
7011So the group name, the description, any email addresses, the scope of the group, the type of the group,
7012
70131754
701400:01:03,390 --> 00:01:09,291
7015any notes, as well as up here the members of that group and where this group is a member of somewhere else.
7016
70171755
701800:01:09,391 --> 00:01:14,291
7019And then lastly is the ability for us to assign a user or other object that is determined to be
7020
70211756
702200:01:14,391 --> 00:01:19,291
7023the manager of the group. So here for this domain admins group I can click the Change button
7024
70251757
702600:01:19,391 --> 00:01:23,291
7027and identify some user or other security principle that would be the manager of that group
7028
70291758
703000:01:23,391 --> 00:01:28,291
7031with all of the associated information down here. You don't see this happen too terribly often
7032
70331759
703400:01:28,391 --> 00:01:32,291
7035in production environments, but this can be nice if you've got certain groups that you just want
7036
70371760
703800:01:32,391 --> 00:01:37,291
7039to set yourself or a particular user as the person responsible for dealing with this group.
7040
70411761
704200:01:37,391 --> 00:01:40,291
7043Notice how if I click the Change button here and identify myself
7044
70451762
704600:01:40,391 --> 00:01:44,291
7047as a potential manager for the group, one of the other things that I can do is identify
7048
70491763
705000:01:44,391 --> 00:01:49,291
7051whether or not this manager has the privileges of updating the group membership list or not.
7052
70531764
705400:01:49,391 --> 00:01:55,291
7055Now this says that I may be able to give a user, a particular user, that privilege so that they
7056
70571765
705800:01:55,391 --> 00:02:00,291
7059can add and remove members from this group. This is obviously a fairly powerful privilege
7060
70611766
706200:02:00,391 --> 00:02:04,291
7063so you'll want to be careful when you check this box to make sure you only do so in situations
7064
70651767
706600:02:04,391 --> 00:02:10,290
7067where you trust the individual that would be managing the group. I will clear the G Shields user from this list
7068
70691768
707000:02:10,390 --> 00:02:14,290
7071now just to keep our domain admins group relatively pristine at this point.
7072
70731769
707400:02:14,390 --> 00:02:19,290
7075Because while we're here I want to show you also some of the organizational units that exist here in our domain as well.
7076
70771770
707800:02:19,390 --> 00:02:24,290
7079And very specifically I want to show you one difference between what we think of as an organizational
7080
70811771
708200:02:24,390 --> 00:02:29,290
7083unit and what we think of a just an active directory container. And everything about that has to do
7084
70851772
708600:02:29,390 --> 00:02:35,290
7087with these little icons right here on the left. Notice how some of the icons here have a little
7088
70891773
709000:02:35,390 --> 00:02:40,290
7091what is that a box there in the little folder and some of them do not.
7092
70931774
709400:02:40,390 --> 00:02:43,290
7095Those here that have a box next to the folder are different from those that do not
7096
70971775
709800:02:43,390 --> 00:02:49,290
7099because these are technically organizational units as opposed to being active directory containers,
7100
71011776
710200:02:49,390 --> 00:02:54,290
7103just purely containers. Now an organizational unit is a container, but there are some functions
7104
71051777
710600:02:54,390 --> 00:03:01,290
7107you can perform on an organizational unit that you cannot perform on one that is just purely a container.
7108
71091778
711000:03:01,390 --> 00:03:06,290
7111Now it is for that reason that most organizations create a special organizational unit
7112
71131779
711400:03:06,390 --> 00:03:13,290
7115to become the location where users and computers ultimately reside as opposed to the default containers here.
7116
71171780
711800:03:13,390 --> 00:03:18,290
7119Let's say, for example, I wanted to create a new organizational unit I could do so by choosing New OU.
7120
71211781
712200:03:18,390 --> 00:03:24,290
7123And then I could create this organizational unit as, for example, company computers.
7124
71251782
712600:03:24,390 --> 00:03:28,290
7127When I create that OU I have the abilities to protect the container from accidental deletion,
7128
71291783
713000:03:28,390 --> 00:03:33,290
7131this sets a flag on the permissions for that OU that eliminates the abilities to accidently
7132
71331784
713400:03:33,390 --> 00:03:38,290
7135click and delete the entire organizational unit at once. But when I create that OU,
7136
71371785
713800:03:38,390 --> 00:03:42,290
7139notice how this company computers OU now has the little box next to it.
7140
71411786
714200:03:42,390 --> 00:03:46,290
7143And I can then take my servers, if I wanted to, from the default computers container and
7144
71451787
714600:03:46,390 --> 00:03:49,290
7147then move them over here into the company computers organizational unit.
7148
71491788
715000:03:49,390 --> 00:03:54,290
7151So that I then could enjoy all the extra features and benefits that I get out of being a
7152
71531789
715400:03:54,390 --> 00:03:59,290
7155full organizational unit as opposed to a container. Now you may be asking, okay well what are those extra things?
7156
71571790
715800:03:59,390 --> 00:04:04,290
7159The biggest of which is the abilities to assign group policy to this container.
7160
71611791
716200:04:04,390 --> 00:04:08,290
7163Later on when we talk about group policy you'll see how I can create a group policy object and then
7164
71651792
716600:04:08,390 --> 00:04:13,290
7167assign it to a container like this group of company computers. And in fact, we'll be doing that
7168
71691793
717000:04:13,390 --> 00:04:17,290
7171as we start creating those GPOs a little later on. Now that's the process we would go through
7172
71731794
717400:04:17,391 --> 00:04:20,290
7175in order to do all of this work here inside of the graphical user interface.
7176
71771795
717800:04:20,391 --> 00:04:25,290
7179If I needed to create, for example, groups I can do the same thing just like I did before,
7180
71811796
718200:04:25,391 --> 00:04:30,290
7183it's using new group, assigning a name, and then the scope and the type associated with that group.
7184
71851797
718600:04:30,391 --> 00:04:34,290
7187But it's really the PowerShell pieces here that I think are just as important, if not more important,
7188
71891798
719000:04:34,391 --> 00:04:39,290
7191particularly for the exam. So, let's actually flip back over here into our PowerShell console
7192
71931799
719400:04:39,391 --> 00:04:44,290
7195and take a look at the process by which we would accomplish these tasks inside of PowerShell.
7196
71971800
719800:04:44,391 --> 00:04:47,290
7199And in fact before we get into actually typing in commands into our PowerShell prompt
7200
72011801
720200:04:47,391 --> 00:04:52,290
7203let's take a look at just some of the basic commandlets that you got to know here
7204
72051802
720600:04:52,391 --> 00:04:56,290
7207that are associated with group and organizational unit management.
7208
72091803
721000:04:56,391 --> 00:04:59,290
7211I want to bring up first this slide that we took a look at back in that last module
7212
72131804
721400:04:59,391 --> 00:05:03,290
7215which had to do with automating the creation of active directory accounts.
7216
72171805
721800:05:03,391 --> 00:05:07,290
7219And we already looked at all these commandlets that relate to creating computer and user accounts
7220
72211806
722200:05:07,391 --> 00:05:12,290
7223in our domain. And I bring this up because they very much mirror the same kinds of commands
7224
72251807
722600:05:12,391 --> 00:05:17,290
7227that we would use for automating the creation and removal of active directory groups.
7228
72291808
723000:05:17,391 --> 00:05:21,290
7231So on the group side we could use the get ADGroup command to get information about a particular group.
7232
72331809
723400:05:21,391 --> 00:05:26,290
7235And then new and remove ADGroup to create a group and remove a group.
7236
72371810
723800:05:26,391 --> 00:05:31,290
7239We could use the add and remove ADGroup Member commandlet to add and remove members from
7240
72411811
724200:05:31,391 --> 00:05:35,290
7243that group that we just created. Over on the organizational unit side we can use
7244
72451812
724600:05:35,391 --> 00:05:40,290
7247Get-ADOrganizationalUnit to get information about an OU and then new and remove
7248
72491813
725000:05:40,391 --> 00:05:46,290
7251to create or remove an OU from our domain. Fairly basic stuff here obviously,
7252
72531814
725400:05:46,391 --> 00:05:50,290
7255but I wanted to bring this up to give you an idea of the mapping between how the commandlets
7256
72571815
725800:05:50,391 --> 00:05:56,290
7259look on the group side and the OU side in comparison with how they look on the user side and the computer side.
7260
72611816
726200:05:56,391 --> 00:05:59,290
7263So let's flip back here into Windows PowerShell and actually go through creating some
7264
72651817
726600:05:59,391 --> 00:06:04,290
7267objects here in our active directory domain. Let's start with a new organizational unit
7268
72691818
727000:06:04,391 --> 00:06:10,290
7271similar to the company computers OU that we created, but in this case we will do company users.
7272
72731819
727400:06:10,391 --> 00:06:17,290
7275So I'll choose New-ADOrganizationalUnit and let's call this company users as the new OU that we'll be creating.
7276
72771820
727800:06:17,391 --> 00:06:22,290
7279In this OU we'll need to go about moving our active directory user accounts into the new location.
7280
72811821
728200:06:22,391 --> 00:06:26,290
7283We also perhaps want to create new groups in that location as well, which we could do
7284
72851822
728600:06:26,391 --> 00:06:34,290
7287with New-ADGroup. Let's create a new group here for the individuals in our organization
7288
72891823
729000:06:34,391 --> 00:06:39,290
7291who are extremely untrusted people. We were joking about this back in the last module
7292
72931824
729400:06:39,391 --> 00:06:44,290
7295about our Jason account and our Don Jones account, as being extremely untrusted users
7296
72971825
729800:06:44,391 --> 00:06:51,290
7299in our active directory domain. So let's create that group and we'll call it extremely untrusted users,
7300
73011826
730200:06:51,391 --> 00:06:56,290
7303if I can spell it correctly. That group, extremely untrusted users, we then need to set the
7304
73051827
730600:06:56,391 --> 00:07:03,290
7307groups scope here as a global group, as opposed to a domain local group or universal group.
7308
73091828
731000:07:03,391 --> 00:07:08,290
7311And then I want to set the path also on the group to the correct location here in active directory
7312
73131829
731400:07:08,391 --> 00:07:12,290
7315where we want to create the group. This path needs to be setup using ldap language,
7316
73171830
731800:07:12,391 --> 00:07:22,290
7319so I do I ou=Company, oops, Company Users, and then dc=Company and then dc=pri
7320
73211831
732200:07:22,391 --> 00:07:28,290
7323that should path this group into the company users organizational unit that we created just a second ago.
7324
73251832
732600:07:28,391 --> 00:07:32,290
7327It looks like I created everything correctly there and let's go ahead and verify that everything
7328
73291833
733000:07:32,391 --> 00:07:36,290
7331is correct up here in our active directory users and computers console.
7332
73331834
733400:07:36,391 --> 00:07:40,290
7335I'll refresh things here in company.pri and there is our company users OU that
7336
73371835
733800:07:40,391 --> 00:07:46,290
7339we created and our extremely untrusted users security group that we also just created.
7340
73411836
734200:07:46,391 --> 00:07:47,290
7343Let's complete the process by adding
7344
73451837
734600:07:47,391 --> 00:07:52,290
7347in those terrible users into this extremely untrusted users group.
7348
73491838
735000:07:52,391 --> 00:08:01,290
7351So Add-ADGroupMember and then Extremely Untrusted Users as the group name.
7352
73531839
735400:08:01,391 --> 00:08:07,290
7355And then the two people that we want to add into this group would be our Jason user and our Don Jones user.
7356
73571840
735800:08:07,391 --> 00:08:08,290
7359If everything's been done correctly here
7360
73611841
736200:08:08,391 --> 00:08:15,290
7363I can come back to the group and verify that the group members of this group are indeed Jason and Don.
7364
73651842
736600:08:15,391 --> 00:08:19,290
7367So this gives you an idea of really the simplicity of using the PowerShell commandlets here
7368
73691843
737000:08:19,391 --> 00:08:25,290
7371for adding and removing users from groups. And if you had to deal with the risk torture activity
7372
73731844
737400:08:25,391 --> 00:08:27,290
7375that is dealing around and clicking around here
7376
73771845
737800:08:27,391 --> 00:08:32,290
7379in the active directory users and computers console, you'll definitely appreciate using PowerShell
7380
73811846
738200:08:32,390 --> 00:00:01,579
7383and your fingers to accomplish the task as opposed to your wrists.
7384
73851847
738600:00:01,679 --> 00:00:05,580
7387Everything about dealing with groups seems relatively easy until you start to realize just
7388
73891848
739000:00:05,679 --> 00:00:09,580
7391how many possible groups you could potentially create in your organization.
7392
73931849
739400:00:09,679 --> 00:00:13,580
7395I mean if you think about just the different, I don't know, the different departments that exist
7396
73971850
739800:00:13,679 --> 00:00:19,579
7399in your prototypical company, your sales and your finance and your executives, those are, at least, the start.
7400
74011851
740200:00:19,679 --> 00:00:23,579
7403But then as you start moving into ever more complex structures, you start needing to
7404
74051852
740600:00:23,679 --> 00:00:29,579
7407do things for individual, perhaps, groups within those groups. Maybe inside of sales there's
7408
74091853
741000:00:29,679 --> 00:00:33,579
7411inside sales and outside sales and even inside of inside of sales there's the inside sales team
7412
74131854
741400:00:33,679 --> 00:00:39,579
7415that has to do with project X and the inside sales team that has to deal with project Y.
7416
74171855
741800:00:39,679 --> 00:00:42,579
7419And so because of that you can almost tell the age of an active directory infrastructure
7420
74211856
742200:00:42,679 --> 00:00:48,579
7423by the sheer number of groups that exist. It is rare that you ever find yourself removing groups.
7424
74251857
742600:00:48,679 --> 00:00:52,579
7427Instead all too often, you just create new groups for every new need.
7428
74291858
743000:00:52,679 --> 00:00:57,579
7431Now Microsoft actually has, kind of, best practice approach for configuring the nesting of
7432
74331859
743400:00:57,679 --> 00:01:02,579
7435one type of group into another, but however, when you start poking around in different organizations
7436
74371860
743800:01:02,679 --> 00:01:06,580
7439you find that not a lot of organizations actually use this group nesting.
7440
74411861
744200:01:06,680 --> 00:01:10,580
7443So I'm going to show you the best practices approach and then I'm going to tell what I've
7444
74451862
744600:01:10,680 --> 00:01:14,580
7447seen in the world and you can choose to do it via the best practices approach or via the
7448
74491863
745000:01:14,680 --> 00:01:20,580
7451not entirely great, but what seems to be the in practice approach just about everywhere.
7452
74531864
745400:01:20,680 --> 00:01:24,580
7455If you follow Microsoft's recommendation, your users go in global groups.
7456
74571865
745800:01:24,680 --> 00:01:29,580
7459And so global groups define the different types of functions that users may participate in,
7460
74611866
746200:01:29,680 --> 00:01:36,580
7463so finance, sales, IT, inside sales, and what have you. Those global groups are then supposed
7464
74651867
746600:01:36,680 --> 00:01:41,580
7467to go into domain local groups. And it is the domain local groups that constrain
7468
74691868
747000:01:41,680 --> 00:01:46,580
7471the types of accesses that people should have access to. For that reason you assign
7472
74731869
747400:01:46,680 --> 00:01:51,580
7475permissions then to the domain local groups. This separation of who you are, the global group,
7476
74771870
747800:01:51,680 --> 00:01:56,580
7479from what you should access, the domain local group, helps ensure that you don't end up giving
7480
74811871
748200:01:56,680 --> 00:02:02,580
7483the right group the wrong access. Now you might be thinking, why in the world would I do this?
7484
74851872
748600:02:02,680 --> 00:02:07,580
7487If you think about the group, the only real way you have to determine what that group is
7488
74891873
749000:02:07,680 --> 00:02:13,580
7491has to do with the name. And then identifying where those groups are actually applied
7492
74931874
749400:02:13,680 --> 00:02:17,580
7495can get very difficult, as your number of servers goes up and the number of possible places
7496
74971875
749800:02:17,680 --> 00:02:23,580
7499where permissions can get assigned goes up. And so separating out the functions, who a person is
7500
75011876
750200:02:23,680 --> 00:02:28,580
7503from the locations, where they need access, can help ensure that you don't end up putting the
7504
75051877
750600:02:28,680 --> 00:02:33,580
7507right person in the wrong place. Particularly when the only thing you have to go on
7508
75091878
751000:02:33,680 --> 00:02:38,580
7511is the name of the group itself. The acronym that I learned a thousand years ago for this
7512
75131879
751400:02:38,680 --> 00:02:44,580
7515was UGLA or users going to global groups, global groups go into local groups, and local groups
7516
75171880
751800:02:44,680 --> 00:02:48,580
7519get assigned permissions. There are other acronyms out there that essentially say the same thing,
7520
75211881
752200:02:48,680 --> 00:02:54,580
7523but it's the UGLA acronym that I remember from the earliest days of studying for my first MCSE.
7524
75251882
752600:02:54,680 --> 00:03:00,580
7527Now I told you that in the real world you don't often see the UGLA approach implemented in its entirety.
7528
75291883
753000:03:00,680 --> 00:03:05,580
7531And that is as we've moved towards more of a single domain, single forest model for a lot of
7532
75331884
753400:03:05,680 --> 00:03:10,580
7535organizations, the difference between global groups and domain local groups become less relevant.
7536
75371885
753800:03:10,680 --> 00:03:16,580
7539Remember that a global group can only include objects from the same domain, whereas a domain object
7540
75411886
754200:03:16,680 --> 00:03:21,580
7543can include objects from any domain in the forest. And so when you get into that single domain,
7544
75451887
754600:03:21,680 --> 00:03:26,580
7547single forest infrastructure, the domain local group and the global group are kind of
7548
75491888
755000:03:26,680 --> 00:03:30,580
7551almost sort of the same thing, because there are no other domains in the forest.
7552
75531889
755400:03:30,680 --> 00:03:35,580
7555And so in production, sometimes you will see just the exclusive use of global groups
7556
75571890
755800:03:35,680 --> 00:03:40,580
7559as the mechanism for defining permissions and categorizing users. I am by no means suggesting that this
7560
75611891
756200:03:40,680 --> 00:03:45,580
7563is the best approach, but it is one that you see commonly in a lot of organizations.
7564
75651892
756600:03:45,680 --> 00:03:46,580
7567Now let me show you an example of where this can
7568
75691893
757000:03:46,680 --> 00:03:52,580
7571actually make things go awry. Let's talk about just different global groups existing in other groups.
7572
75731894
757400:03:52,680 --> 00:03:55,580
7575So back here in our list of users we have that domain
7576
75771895
757800:03:55,680 --> 00:04:01,580
7579admin security group, this is the global group. And we also have back here under company users
7580
75811896
758200:04:01,680 --> 00:04:06,580
7583the extremely untrusted users that we created. Let's say that you don't implement
7584
75851897
758600:04:06,680 --> 00:04:11,580
7587things using a best practice approach and you use your global groups for a variety of different purposes.
7588
75891898
759000:04:11,680 --> 00:04:15,580
7591And when you do that, let's say that someone for one reason or another
7592
75931899
759400:04:15,680 --> 00:04:19,579
7595gets a request to add in to the domain admins group another group.
7596
75971900
759800:04:19,680 --> 00:04:23,579
7599Somebody calls into the help desk and says, hey you know what I need to get access to the
7600
76011901
760200:04:23,680 --> 00:04:27,579
7603domain admins group and can you just add in this other group as a member of domain admins,
7604
76051902
760600:04:27,680 --> 00:04:34,579
7607the extremely untrusted users group here. Now this is an obvious example of something
7608
76091903
761000:04:34,680 --> 00:04:37,579
7611you wouldn't want to do, but I'm guessing in your active directory domain you don't
7612
76131904
761400:04:37,680 --> 00:04:45,579
7615have a group called extremely untrusted users. That might be the inside sales admin team,
7616
76171905
761800:04:45,680 --> 00:04:50,079
7619or something else that may not be very well worded. So I want to just kind of show you
7620
76211906
762200:04:50,180 --> 00:04:54,079
7623how remarkably easy it can be based off of group nesting for the
7624
76251907
762600:04:54,180 --> 00:05:00,079
7627wrong group to end up a member of the wrong group. When this happens it can be phenomenally
7628
76291908
763000:05:00,180 --> 00:00:01,568
7631difficult to figure out what went wrong and why people have access to the wrong resources.
7632
76331909
763400:00:01,669 --> 00:00:05,869
7635Now thankfully PowerShell comes riding to the rescue when it comes time to actually enumerate
7636
76371910
763800:00:05,969 --> 00:00:10,868
7639users in these variety of groups that we've created. Back in the oldest of days trying to figure
7640
76411911
764200:00:10,968 --> 00:00:15,868
7643out which users were in which groups could involve some complex coculus with commands like
7644
76451912
764600:00:15,968 --> 00:00:21,868
7647DSGet and DSQuery, the old net group command as well. There were even some relatively complex
7648
76491913
765000:00:21,969 --> 00:00:26,868
7651VB scripts that you could create or even using the iCacls command or the Xcacls command
7652
76531914
765400:00:26,969 --> 00:00:31,868
7655to try to figure out where groups and permissions were assigned and who was in what group.
7656
76571915
765800:00:31,969 --> 00:00:35,868
7659Thankfully PowerShell these days does a better job of centralizing all these different tools
7660
76611916
766200:00:35,969 --> 00:00:39,868
7663into a single framework that we can use for enumerating group membership.
7664
76651917
766600:00:39,969 --> 00:00:43,868
7667Let's assume we have a couple of different questions that we need to answer based partially
7668
76691918
767000:00:43,969 --> 00:00:48,868
7671on that accidental group addition that we just did back on that last clip.
7672
76731919
767400:00:48,969 --> 00:00:54,868
7675So what kinds of questions would we need to ask? Maybe what users are members of the domain admins group?
7676
76771920
767800:00:54,969 --> 00:00:58,868
7679So maybe I need to know, alright well who's in domain admins? Or I need to know membership
7680
76811921
768200:00:58,969 --> 00:01:03,868
7683for a particular user in which groups is Jason Helmick a member?
7684
76851922
768600:01:03,969 --> 00:01:09,868
7687Or even more importantly, is Jason Helmick accidently or purposefully a nested member of
7688
76891923
769000:01:09,968 --> 00:01:14,868
7691a certain group, like domain admins? Remember that when we created that extremely untrusted users
7692
76931924
769400:01:14,968 --> 00:01:18,868
7695group we added Jason to that group because we don't trust the guy.
7696
76971925
769800:01:18,968 --> 00:01:24,868
7699And we don't want him a member of domain admins not by direct membership,
7700
77011926
770200:01:24,968 --> 00:01:29,868
7703but by indirect membership through his membership in the extremely untrusted users group.
7704
77051927
770600:01:29,968 --> 00:01:32,868
7707So these are the different kinds of questions you may have to think about when it comes
7708
77091928
771000:01:32,968 --> 00:01:36,868
7711time to really think about your group membership in your domain.
7712
77131929
771400:01:36,968 --> 00:01:40,868
7715Let's talk about some of the ways using PowerShell that we can go through answering these
7716
77171930
771800:01:40,968 --> 00:01:45,868
7719questions and ensuring that the wrong person stays out of the domain admins group.
7720
77211931
772200:01:45,968 --> 00:01:47,868
7723Let me go ahead and minimize this and we'll
7724
77251932
772600:01:47,968 --> 00:01:51,868
7727come back here to our active directory users and computers console, in fact let me instead go here
7728
77291933
773000:01:51,968 --> 00:01:57,868
7731over directly to PowerShell. So that we can run a couple of these commands and see, number one
7732
77331934
773400:01:57,968 --> 00:02:04,868
7735who is a member of the domain admins group. The command I'm going to show you here is Get-AdGroupMember.
7736
77371935
773800:02:04,968 --> 00:02:09,868
7739And the Get-ADGroupMember command will allow me to see the membership of domain admins.
7740
77411936
774200:02:09,968 --> 00:02:13,868
7743Now I'm going to pipe this to a table and just show the names here so we can see who is
7744
77451937
774600:02:13,968 --> 00:02:18,868
7747a member of the domain admins group. Looks like administrator is, Greg Shields is, and this
7748
77491938
775000:02:18,968 --> 00:02:24,868
7751interesting one here called extremely untrusted users. Now this can be perhaps not as
7752
77531939
775400:02:24,968 --> 00:02:29,868
7755obvious as it might seem, remember it's none the likely that you would have an extremely untrusted users
7756
77571940
775800:02:29,968 --> 00:02:34,868
7759group in your active directory domain, it might say something else.
7760
77611941
776200:02:34,968 --> 00:02:39,868
7763So the direct membership of the domain admins group using just this command may be insufficient
7764
77651942
776600:02:39,968 --> 00:02:44,868
7767for helping us ensure the wrong person's not in this group. Let's go a different route,
7768
77691943
777000:02:44,968 --> 00:02:48,868
7771let's go from the completely opposite direction. We know that Jason's a really bad guy
7772
77731944
777400:02:48,968 --> 00:02:53,868
7775and so we want to see what kinds of groups he is a member of. Let's take a look at that,
7776
77771945
777800:02:53,968 --> 00:03:00,868
7779so Get-ADPrincipalGroupMembership for the Jason user and then let me do that into a table also,
7780
77811946
778200:03:00,968 --> 00:03:06,868
7783so that we can see which groups Jason is a direct member of. According to this,
7784
77851947
778600:03:06,968 --> 00:03:12,868
7787Jason is a member of the domain users and the extremely untrusted users group.
7788
77891948
779000:03:12,968 --> 00:03:16,868
7791Which is handy for helping us understand what groups Jason is a member of, at least directly,
7792
77931949
779400:03:16,968 --> 00:03:21,868
7795but doesn't necessarily give us all the information to trigger that red flag in the back of
7796
77971950
779800:03:21,968 --> 00:03:25,868
7799our mind that, oops Jason might be a domain admin by accident.
7800
78011951
780200:03:25,968 --> 00:03:29,868
7803And so there's a third command here that I want to show you that's a little bit more complicated
7804
78051952
780600:03:29,968 --> 00:03:36,868
7807using Get-ADUser where we can do a recursive match for a particular group and then trace
7808
78091953
781000:03:36,968 --> 00:03:41,868
7811backwards for the users who are members of groups who are members of the group I'm interested in.
7812
78131954
781400:03:41,968 --> 00:03:46,868
7815This would be the indirect membership of a group, like domain admins.
7816
78171955
781800:03:46,968 --> 00:03:53,868
7819So let me do Get-, Get-ADUser and then I'm going to do a filter for this on a member of.
7820
78211956
782200:03:53,968 --> 00:04:05,868
7823I'm going to do a recursive match, recursive match, against cn=domainadmins, cn=users,
7824
78251957
782600:04:05,968 --> 00:04:12,868
7827and then dc=company, and then dc=pri and then I'll take the results of that and then
7828
78291958
783000:04:12,968 --> 00:04:17,868
7831pipe that also into a table against the user name. So it's this filter which will allow me
7832
78331959
783400:04:17,968 --> 00:04:21,868
7835to then do that recursive match against the domain admins and then all the membership
7836
78371960
783800:04:21,968 --> 00:04:25,868
7839of all the groups that happen to be in the domain admins group, so that I can find out,
7840
78411961
784200:04:25,968 --> 00:04:32,868
7843ah oh, Jason Helmick and also even Don Jones are a member of domain admins through indirect membership.
7844
78451962
784600:04:32,968 --> 00:04:35,868
7847So these different commands here can be really helpful in ensuring that the right people
7848
78491963
785000:04:35,968 --> 00:04:40,868
7851end up in the right group. And rather than just show them to you, I wanted to give you an example
7852
78531964
785400:04:40,968 --> 00:00:01,721
7855of where you might actually use these to ensure that the wrong person doesn't end up in the wrong location.
7856
78571965
785800:00:01,822 --> 00:00:05,222
7859Now while you won't find yourself doing this all too often, occasionally you create groups
7860
78611966
786200:00:05,322 --> 00:00:09,721
7863in a way that was not really the way you intended to and you might find yourself needing to
7864
78651967
786600:00:09,821 --> 00:00:13,922
7867convert a group from one type to another or from one scope to another.
7868
78691968
787000:00:14,022 --> 00:00:17,221
7871Well thankfully in later versions of the operating system, actually very later versions of the
7872
78731969
787400:00:17,321 --> 00:00:22,221
7875operating system, you have the ability to convert certain types of groups into other
7876
78771970
787800:00:22,321 --> 00:00:27,221
7879certain types of groups. But, and this is a caveat, other types you can't.
7880
78811971
788200:00:27,321 --> 00:00:30,221
7883Let's take a look at those you can as opposed to those you can't.
7884
78851972
788600:00:30,321 --> 00:00:34,222
7887For our first possibility it is possible to take domain local groups and global groups
7888
78891973
789000:00:34,322 --> 00:00:40,222
7891and convert them into universal groups. It is similarly possible to take a universal group
7892
78931974
789400:00:40,322 --> 00:00:45,222
7895and convert it into a domain local or a global group. However it is not possible to take
7896
78971975
789800:00:45,322 --> 00:00:51,222
7899a domain local group and convert it to a global or to take a global and convert it to a domain local.
7900
79011976
790200:00:51,322 --> 00:00:54,222
7903So they're a couple things you can do and a couple of things you can't do when it comes
7904
79051977
790600:00:54,322 --> 00:00:58,222
7907to converting these groups from one type to another. Now I want to show you just here
7908
79091978
791000:00:58,322 --> 00:01:03,222
7911back in our active directory users and computers console, just the fact that when I create a group
7912
79131979
791400:01:03,322 --> 00:01:05,222
7915so back up here under company users
7916
79171980
791800:01:05,322 --> 00:01:06,222
7919here's our extremely untrusted users
7920
79211981
792200:01:06,322 --> 00:01:11,222
7923group. I could, down here, just check the box to switch between global and universal
7924
79251982
792600:01:11,322 --> 00:01:16,222
7927or security to distribution. Doing so would change the structure of the group and the functionality
7928
79291983
793000:01:16,322 --> 00:01:20,222
7931of the group. Switching from global to universal would then populate all this information
7932
79331984
793400:01:20,322 --> 00:01:25,222
7935into my global catalog servers and the membership into my global catalog servers.
7936
79371985
793800:01:25,322 --> 00:01:30,222
7939Over here changing from security to distribution would facilitate this being an email group
7940
79411986
794200:01:30,322 --> 00:01:34,222
7943as opposed to a security group. Now there are a couple of ways here in PowerShell, because we got to
7944
79451987
794600:01:34,322 --> 00:01:35,222
7947talk about all the
7948
79491988
795000:01:35,322 --> 00:01:39,222
7951PowerShell here, there are a couple of ways in which you can use PowerShell to go about doing
7952
79531989
795400:01:39,322 --> 00:01:46,222
7955this conversion as well. Let's say, for example, that I'm going about happily creating new groups
7956
79571990
795800:01:46,322 --> 00:01:54,222
7959here using Windows PowerShell, so My Universal Distribution Group, there, there's a new group that I created.
7960
79611991
796200:01:54,322 --> 00:01:58,222
7963And the group scope for this, I'm going to create it as a global group, whoops, by accident.
7964
79651992
796600:01:58,322 --> 00:02:00,222
7967Gosh wait a minute, I just created that group and now
7968
79691993
797000:02:00,322 --> 00:02:02,222
7971if I take a look down here
7972
79731994
797400:02:02,322 --> 00:02:07,222
7975under users and then refresh things, I've created my universal distribution group
7976
79771995
797800:02:07,322 --> 00:02:10,222
7979as a global security group. Let's go back here
7980
79811996
798200:02:10,322 --> 00:02:16,222
7983to PowerShell and then fix the problem that we just created. Let me instead of New-ADGroup,
7984
79851997
798600:02:16,322 --> 00:02:22,222
7987let me instead get the adgroup that I just created, so Get-ADGroup.
7988
79891998
799000:02:22,322 --> 00:02:25,222
7991If we take a look at that, well there's the information about the group and I can see here
7992
79931999
799400:02:25,322 --> 00:02:29,222
7995that the scope is set to global and the category is set to security.
7996
79972000
799800:02:29,322 --> 00:02:35,222
7999Let's make some changes. Let me do Set-ADGroup and then I'm going to set the groups scope
8000
80012001
800200:02:35,322 --> 00:02:40,222
8003there's my group scope, over to universal, okay that should fix that.
8004
80052002
800600:02:40,322 --> 00:02:45,222
8007And then I'll set my group category from a security group here to a distribution group
8008
80092003
801000:02:45,322 --> 00:02:50,222
8011which I would do by entering a zero in here to set it over to a distribution group.
8012
80132004
801400:02:50,322 --> 00:02:55,222
8015Once I'm done with that, let's go back up here to get the group then, so Get-ADGroup
8016
80172005
801800:02:55,322 --> 00:02:58,222
8019and as you can see now we have a universal distribution group exactly the one
8020
80212006
802200:02:58,322 --> 00:03:01,722
8023that we were looking for when we initially created the group the first time.
8024
80252007
802600:03:01,822 --> 00:03:05,722
8027And back over here, in fact yep there's the group scope and there's the group type,
8028
80292008
803000:03:05,822 --> 00:00:01,550
8031now as a universal distribution group.
8032
80332009
803400:00:01,651 --> 00:00:06,551
8035Now everything we've talked about up to this point has to do with groups that exist on the domain controller.
8036
80372010
803800:00:06,650 --> 00:00:10,551
8039We're dealing with global groups on that dc, we're dealing with domain local groups
8040
80412011
804200:00:10,650 --> 00:00:16,050
8043that also exist on that domain controller. But we haven't really talked much about local groups.
8044
80452012
804600:00:16,150 --> 00:00:20,050
8047We discussed them earlier back when we were talking about users and we also took a look
8048
80492013
805000:00:20,150 --> 00:00:24,050
8051here on a particular server like this machine file1, just to see the local groups,
8052
80532014
805400:00:24,150 --> 00:00:29,050
8055not domain local, but local groups that exist on every Windows server that we may have.
8056
80572015
805800:00:29,150 --> 00:00:34,051
8059What I want to show you here is that if on this machine file1, if we come here to tools and to
8060
80612016
806200:00:34,151 --> 00:00:36,051
8063computer management,
8064
80652017
806600:00:36,151 --> 00:00:38,051
8067we can take a look at that list of local users
8068
80692018
807000:00:38,151 --> 00:00:42,051
8071and groups that exists on a machine. Here under the list of groups are all those
8072
80732019
807400:00:42,151 --> 00:00:48,051
8075that exist for this machine and I would then potentially take a global group from my domain
8076
80772020
807800:00:48,151 --> 00:00:53,051
8079or even a domain local group, and add it in here into my local group on this machine
8080
80812021
808200:00:53,151 --> 00:00:59,051
8083to provide a group of active directory users, the permissions to accomplish one of these variety of tasks.
8084
80852022
808600:00:59,151 --> 00:01:04,051
8087Now as you can imagine, this gets somewhat cumbersome over time. If you think about the
8088
80892023
809000:01:04,150 --> 00:01:08,051
809120 or 30 or 40 servers that you may need to control, well making sure that the right
8092
80932024
809400:01:08,150 --> 00:01:10,051
8095people get in the administrators group or the backup
8096
80972025
809800:01:10,150 --> 00:01:16,051
8099operators group, is something that can be overwhelming when you start having to do it on every single machine
8100
81012026
810200:01:16,150 --> 00:01:23,051
8103using the manual approach. And so for that reason, Microsoft provides with group policy
8104
81052027
810600:01:23,150 --> 00:01:27,051
8107the abilities to define which user should go in which groups via a group policy object,
8108
81092028
811000:01:27,150 --> 00:01:32,051
8111as opposed to having to do this the manual way. Let's flip back over here to my machine
8112
81132029
811400:01:32,150 --> 00:01:36,051
8115dc because on this machine I have an access to the group policy management
8116
81172030
811800:01:36,150 --> 00:01:40,051
8119console. And I'm going to just edit here the default domain policy, but I would not do this
8120
81212031
812200:01:40,150 --> 00:01:45,051
8123again in production unless you're sure you want this to go to every single machine in your domain.
8124
81252032
812600:01:45,150 --> 00:01:49,051
8127What I want to show you here is that under the default domain policy, if I go down here to policies
8128
81292033
813000:01:49,150 --> 00:01:53,051
8131in Windows settings, and then if I take a look at security settings, there's an item down
8132
81332034
813400:01:53,150 --> 00:02:00,051
8135here called restricted groups. Which allows me to enter in one or more groups that I may wish to control.
8136
81372035
813800:02:00,150 --> 00:02:05,051
8139Let's say that the group I'm interested in controlling is the administrators group.
8140
81412036
814200:02:05,150 --> 00:02:07,051
8143If I enter that in,
8144
81452037
814600:02:07,150 --> 00:02:12,051
8147this will give me the abilities to define the members of this group, up here at the top,
8148
81492038
815000:02:12,151 --> 00:02:16,051
8151and the fact that this group is a member of other groups down here at the bottom.
8152
81532039
815400:02:16,151 --> 00:02:20,051
8155So, for example, if I wanted to define the members of a group, I could define the members of the group
8156
81572040
815800:02:20,151 --> 00:02:28,051
8159as being the domain admins group. Setting domains admins here to the administrators group
8160
81612041
816200:02:28,151 --> 00:02:34,051
8163will ensure that the domain admins global group ends up as a member of the administrators
8164
81652042
816600:02:34,151 --> 00:02:39,051
8167local group on each machine where this active directory group policy object applies.
8168
81692043
817000:02:39,151 --> 00:02:43,051
8171You see this commonly done to ensure that the IT group ends up being an administrator so that
8172
81732044
817400:02:43,151 --> 00:02:47,051
8175the backup operators group gets put in the proper location on local machines.
8176
81772045
817800:02:47,151 --> 00:02:52,051
8179But anytime you've got those custom groups that may not necessarily be domain admins
8180
81812046
818200:02:52,151 --> 00:02:57,051
8183that are, you know, any of the default groups out-of-the-box, this tool here with group policy
8184
81852047
818600:02:57,151 --> 00:03:01,551
8187allows you to then deploy out all of your custom groups. Out to all the servers and potentially
8188
81892048
819000:03:01,651 --> 00:00:01,979
8191desktops that exist in your active directory domain.
8192
81932049
819400:00:02,079 --> 00:00:05,979
8195I find it funny sometimes when walking into different organizations and taking a look at their
8196
81972050
819800:00:06,078 --> 00:00:12,979
8199active directory structure and finding every person in the IT department a member of the domain admins group.
8200
82012051
820200:00:13,079 --> 00:00:17,978
8203Well you see that happen in a lot of places, you see also users that just use the administrator
8204
82052052
820600:00:18,079 --> 00:00:20,978
8207account anytime they're trying to do something with advanced privileges.
8208
82092053
821000:00:21,079 --> 00:00:25,978
8211And all of these are examples of terrible security and terrible auditing ability
8212
82132054
821400:00:26,079 --> 00:00:30,978
8215for any of the users that might be doing things. In a well-run organization,
8216
82172055
821800:00:31,079 --> 00:00:35,978
8219it's better to create separate groups that users are a member of so that you can
8220
82212056
822200:00:36,079 --> 00:00:41,478
8223discreetly identify the tasks that a person should do. As opposed to giving every single
8224
82252057
822600:00:41,579 --> 00:00:45,478
8227person complete keys to the kingdom. This is an example of delegation of control,
8228
82292058
823000:00:45,579 --> 00:00:49,478
8231so being able to define specifically what a group of users should be able to do,
8232
82332059
823400:00:49,579 --> 00:00:54,478
8235whether or not they're a member of IT or not. So let's say, for example, in this example
8236
82372060
823800:00:54,579 --> 00:00:58,478
8239of delegation of control that we're taking a look at this company users organizational unit
8240
82412061
824200:00:58,579 --> 00:01:03,478
8243that we created earlier. And the idea here being that this company users OU
8244
82452062
824600:01:03,579 --> 00:01:06,478
8247should be the location where all of our regular users end up being located.
8248
82492063
825000:01:06,578 --> 00:01:11,478
8251So the Jason account, the Don account, and the Greg Shields account.
8252
82532064
825400:01:11,578 --> 00:01:15,478
8255I move these over here and then complete this process, now I've got what
8256
82572065
825800:01:15,578 --> 00:01:21,478
8259is effectively an organization full of users, also user groups.
8260
82612066
826200:01:21,578 --> 00:01:26,478
8263Let's say also that I've created a group here called IT and rather than giving just
8264
82652067
826600:01:26,578 --> 00:01:32,478
8267domain admins privileges to create users in this organizational unit and to change the membership of
8268
82692068
827000:01:32,578 --> 00:01:38,478
8271things in this OU. I really want to dial it down so that I have a subset of people
8272
82732069
827400:01:38,578 --> 00:01:42,478
8275that are perhaps not extremely untrusted, but that are partially trusted.
8276
82772070
827800:01:42,578 --> 00:01:46,478
8279Not so much at the domain admin level, but at a level that is commensurate with the
8280
82812071
828200:01:46,578 --> 00:01:51,478
8283types of things that they need to do. Maybe this is the help desk, you know the IT help desk
8284
82852072
828600:01:51,578 --> 00:01:54,478
8287that needs to add and remove people from groups and just create accounts.
8288
82892073
829000:01:54,578 --> 00:01:58,478
8291When this is the case, and it really should be the case in every situation,
8292
82932074
829400:01:58,578 --> 00:02:01,478
8295one of the ways in which I can provide that access is by running what is called
8296
82972075
829800:02:01,578 --> 00:02:06,478
8299the delegation of control wizard. Now earlier, when we introduced this whole module,
8300
83012076
830200:02:06,578 --> 00:02:09,479
8303I mentioned that you have to be very careful with this delegation of control wizard.
8304
83052077
830600:02:09,579 --> 00:02:14,479
8307Because it can be very difficult to locate and then rip out any of the delegation of control
8308
83092078
831000:02:14,579 --> 00:02:19,479
8311that you create using the wizard. So I'm going to show you how this works, but be very careful
8312
83132079
831400:02:19,579 --> 00:02:24,479
8315anytime you go about making any changes here, because locating what you've changed
8316
83172080
831800:02:24,579 --> 00:02:28,479
8319can be really challenging and I'll show you why here in a just second.
8320
83212081
832200:02:28,579 --> 00:02:30,479
8323Let me choose the next button, because what I want to do here
8324
83252082
832600:02:30,579 --> 00:02:38,479
8327is for the company users organizational unit, I want to give my IT group access to perform various tasks.
8328
83292083
833000:02:38,579 --> 00:02:44,479
8331So let me add in here the IT group, that's my group. And then the tasks that I want that IT
8332
83332084
833400:02:44,579 --> 00:02:49,479
8335group to perform are these following common tasks, like creating, deleting, and managing user accounts
8336
83372085
833800:02:49,579 --> 00:02:55,479
8339resetting the passwords, reading the user information. And then managing the groups that are
8340
83412086
834200:02:55,579 --> 00:03:01,479
8343also existing here inside of this organizational unit. I could further come down here
8344
83452087
834600:03:01,579 --> 00:03:05,479
8347and create custom tasks to delegate as well, however, this gets really complex and
8348
83492088
835000:03:05,579 --> 00:03:09,479
8351just the sheer number of possible tasks that you can enable or disable.
8352
83532089
835400:03:09,579 --> 00:03:13,479
8355So we'll keep things relatively easy here with just the common tasks that I would want to give
8356
83572090
835800:03:13,579 --> 00:03:18,479
8359that subset of users that are not domain admin caliber, but still need to be able to work
8360
83612091
836200:03:18,579 --> 00:03:22,479
8363within this organizational unit. If I choose Next and choose
8364
83652092
836600:03:22,579 --> 00:03:28,479
8367Finish I've now gone through and provided the delegation of control to that IT group.
8368
83692093
837000:03:28,579 --> 00:03:31,479
8371Now as I said, the hard part is finding this stuff after you've applied it.
8372
83732094
837400:03:31,579 --> 00:03:35,479
8375And so let me show you here if I bring up the advanced view, the advanced features
8376
83772095
837800:03:35,579 --> 00:03:40,479
8379here in active directory users and computers. So that we can take a look at more or less
8380
83812096
838200:03:40,579 --> 00:03:45,479
8383what we've just done. Once I turn on the advance features here and go back to view properties,
8384
83852097
838600:03:45,579 --> 00:03:50,479
8387there are a number of additional tabs that appear here in the list for my organizational unit.
8388
83892098
839000:03:50,579 --> 00:03:56,479
8391And again over for any groups that I may create. The important one here is the security tab.
8392
83932099
839400:03:56,579 --> 00:04:00,479
8395Which you can see here we now have a group called IT that has some special permissions that have
8396
83972100
839800:04:00,579 --> 00:04:04,479
8399been assigned down here at the bottom. Those special
8400
84012101
840200:04:04,579 --> 00:04:09,479
8403permissions, relatively difficult to find because as you look down here it's create/delete group objects,
8404
84052102
840600:04:09,579 --> 00:04:15,479
8407create/delete user objects, full control on the various items that we've configured for this group.
8408
84092103
841000:04:15,579 --> 00:04:19,478
8411So pay careful attention anytime you're using that delegation of control wizard because it will
8412
84132104
841400:04:19,579 --> 00:04:24,478
8415go about creating a variety of additional permissions that exist here in the list.
8416
84172105
841800:04:24,579 --> 00:04:26,478
8419But also recognize that trying to figure out
8420
84212106
842200:04:26,579 --> 00:04:30,478
8423exactly what you've done is something you might want to document as you're going through the process.
8424
84252107
842600:04:30,579 --> 00:04:32,478
8427I do also want to show you
8428
84292108
843000:04:32,579 --> 00:04:36,478
8431that for an individual group I can also take a look at, with advanced featured turned on,
8432
84332109
843400:04:36,579 --> 00:04:41,478
8435some additional tabs that appear here in the list of properties for that group.
8436
84372110
843800:04:41,579 --> 00:04:43,478
8439Not the least of which is the security tab.
8440
84412111
844200:04:43,579 --> 00:04:48,478
8443Which allows me to provide additional discrete permissions for users or groups that are on
8444
84452112
844600:04:48,579 --> 00:04:55,478
8447the group object itself. This is not the membership of the group, but actually the things the
8448
84492113
845000:04:55,579 --> 00:04:59,478
8451actions that you could apply on that group. Many of these are not entirely obvious,
8452
84532114
845400:04:59,579 --> 00:05:03,478
8455so you'll have to kind of poke around to see which ones you're interested in.
8456
84572115
845800:05:03,579 --> 00:05:07,478
8459But at least this is the location where you would go to modify permissions in order to
8460
84612116
846200:05:07,579 --> 00:05:12,478
8463for example, get a user the abilities to add and remove membership from this group.
8464
84652117
846600:05:12,579 --> 00:05:16,478
8467So I would be aware that the delegation of control wizard exists, that it is something
8468
84692118
847000:05:16,579 --> 00:05:19,478
8471that you would apply to, for example, an organizational unit of users.
8472
84732119
847400:05:19,579 --> 00:00:02,028
8475And then I would be very careful anytime I'm trying to use it in production.
8476
84772120
847800:00:02,129 --> 00:00:07,028
8479And then onto our final topic in this our module here on groups and organizational units.
8480
84812121
848200:00:07,128 --> 00:00:12,028
8483In this topic we're asked to manage the default active directory containers, and very specifically
8484
84852122
848600:00:12,128 --> 00:00:19,028
8487what we're asked to is to create a way to reset that default container when new computers get added
8488
84892123
849000:00:19,129 --> 00:00:24,028
8491into our active directory domain. Now here we've created our company computers organizational unit
8492
84932124
849400:00:24,129 --> 00:00:31,028
8495here and I manually moved over file1, server1, and servercore1 into the company computers OU.
8496
84972125
849800:00:31,129 --> 00:00:36,028
8499But this was a manual process, the next time I add a new computer into the organizational unit
8500
85012126
850200:00:36,128 --> 00:00:40,028
8503it's going to end up appearing here in our list of computers down here.
8504
85052127
850600:00:40,128 --> 00:00:48,028
8507I would prefer these new computers to end up in a different location than the default computers container.
8508
85092128
851000:00:48,128 --> 00:00:53,028
8511Microsoft provides a way in order to do that, that is the redircmp command, that is not a PowerShell command,
8512
85132129
851400:00:53,128 --> 00:00:55,028
8515but is one that we can execute inside
8516
85172130
851800:00:55,128 --> 00:01:03,028
8519of the PowerShell shell itself. A redircmp if I do /? here provides a way for me to just
8520
85212131
852200:01:03,128 --> 00:01:07,029
8523change the default location for any newly created computer objects.
8524
85252132
852600:01:07,129 --> 00:01:11,029
8527And so if I wanted to change that to my company computers organizational unit,
8528
85292133
853000:01:11,129 --> 00:01:25,029
8531it would be as simple as redircmp and the OU= or OU= company computers then dc=company and then dc=pir.
8532
85332134
853400:01:25,129 --> 00:01:30,029
8535At that point every new computer that comes into the domain will be automatically added into the
8536
85372135
853800:01:30,129 --> 00:01:34,529
8539company computers organizational unit as opposed to the computers container.
8540
85412136
854200:01:34,629 --> 00:01:40,529
8543This becomes particularly handy when I start applying group policy to that company computers OU.
8544
85452137
854600:01:40,629 --> 00:00:01,845
8547And it helps me ensure that every new computer is going to end up getting that group policy that I've applied.
8548
85492138
855000:00:01,945 --> 00:00:05,346
8551And so some kind of fun stuff here as it relates to managing groups and OUs,
8552
85532139
855400:00:05,445 --> 00:00:09,846
8555both from the graphical user interface as well as from the command line here in our module.
8556
85572140
855800:00:09,945 --> 00:00:12,846
8559And in fact what have we talked about in this module? We've talked about that process of
8560
85612141
856200:00:12,945 --> 00:00:18,846
8563creating, copying, configuring, and deleting groups and OUs. The process in the graphical user
8564
85652142
856600:00:18,946 --> 00:00:23,846
8567interface is fundamentally the same and really even in PowerShell it's fundamentally the same
8568
85692143
857000:00:23,946 --> 00:00:27,846
8571as what you were doing with users. A couple of the PowerShell nouns are different and where
8572
85732144
857400:00:27,946 --> 00:00:31,846
8575exactly you would click in the interface to create or delete these items is slightly different.
8576
85772145
857800:00:31,946 --> 00:00:37,845
8579But for the most part dealing with groups and OUs is very much the same as dealing with users.
8580
85812146
858200:00:37,945 --> 00:00:41,845
8583However things get a little different when we start talking about nesting of groups.
8584
85852147
858600:00:41,945 --> 00:00:45,845
8587Active directory groups at face value provide a great way to consolidate users and consolidate
8588
85892148
859000:00:45,945 --> 00:00:50,845
8591resources that users need to access. But it's the connection of those users to those
8592
85932149
859400:00:50,945 --> 00:00:54,845
8595resources and the nesting of one kind of group into another, where things can get a little complicated.
8596
85972150
859800:00:54,945 --> 00:00:59,845
8599And so having a good strategy for your group nesting will ensure that the wrong person doesn't
8600
86012151
860200:00:59,945 --> 00:01:04,846
8603get access to the wrong information. To that end, we took a look at some of the tools you
8604
86052152
860600:01:04,945 --> 00:01:08,846
8607can use to enumerate group membership. Should you end up in a situation where that person gets
8608
86092153
861000:01:08,945 --> 00:01:12,846
8611added to the wrong group, well you can use some of these nice PowerShell tools with
8612
86132154
861400:01:12,945 --> 00:01:17,846
8615recursion to identify their direct and indirect group membership. We took a look at the rules
8616
86172155
861800:01:17,945 --> 00:01:23,846
8619for converting groups across security, distribution, universal, domain local, and domain global groups,
8620
86212156
862200:01:23,945 --> 00:01:27,846
8623where you can and where you can't go about converting groups should you create them in one format
8624
86252157
862600:01:27,945 --> 00:01:32,846
8627and need them in another. We took a look at group policy and how you can use group policy
8628
86292158
863000:01:32,945 --> 00:01:37,846
8631to define the local group membership using domain global groups. So that once you create those
8632
86332159
863400:01:37,945 --> 00:01:42,846
8635servers in your domain you can automatically grant the right people the correct permissions.
8636
86372160
863800:01:42,945 --> 00:01:46,846
8639We took a look at delegation of control and how you can delegate the creation and management
8640
86412161
864200:01:46,945 --> 00:01:51,846
8643of active directory objects, very specifically organizational units right within the a.console.
8644
86452162
864600:01:51,945 --> 00:01:55,846
8647And then concluded with a look at one little command here that allows you to change the default
8648
86492163
865000:01:55,945 --> 00:02:00,846
8651active directory container where new computers get entered when their added into the domain.
8652
86532164
865400:02:00,945 --> 00:02:03,846
8655Very handy for getting computers in the right location and even more so when group policies
8656
86572165
865800:02:03,945 --> 00:02:09,846
8659need to be applied. Coming up next, with our active directory now created and our servers a member
8660
86612166
866200:02:09,945 --> 00:02:13,846
8663of that active directory, it's time for us to begin dealing with the different kinds of
8664
86652167
866600:02:13,945 --> 00:02:17,846
8667servers and services that we would put in that AD infrastructure.
8668
86692168
867000:02:17,945 --> 00:02:22,846
8671These are things like file and share access, the file server that contain documents users need.
8672
86732169
867400:02:22,945 --> 00:02:26,846
8675These are things like print and document services that allow users to print out hard copies
8676
86772170
867800:02:26,945 --> 00:02:31,846
8679of whatever documents they may need. As well as configuring servers for remote management,
8680
86812171
868200:02:31,945 --> 00:02:35,846
8683a topic that Jason will lead off with and give you all the necessary information that you need
8684
86852172
868600:02:35,945 --> 00:02:39,846
8687so that the variety of tasks that we've been accomplishing thus far and as well as to the
8688
86892173
869000:02:39,945 --> 00:02:44,846
8691rest of this learning path. You can do so from the comfort of your administrative desktop
8692
86932174
869400:02:44,945 --> 00:02:50,346
8695without having to remote desktop into the servers directly or walk into that server data center.
8696
86972175
869800:02:50,445 --> 00:02:54,846
8699These days performing tasks directly on the console of servers is no longer the best practice.
8700
87012176
870200:02:54,945 --> 00:03:00,346
8703And so being able to do multi-server management remotely is something that you really have to know.
8704
87052177
870600:03:00,445 --> 00:03:03,445
8707That entire conversation on server roles and features is the topic for our next course coming up.