Posts

Showing posts with the label Active Directory Stuff

Check Phonetic attributes in Active Directory

Sometimes you come across a user account or maybe a resource that is named in a way that is not common to your native language.  When users search for this resource they may have some difficulty.  In Active Directory there is now several phonetic attributes to help your users out. ms-DS-Phonetic-First-Name Contains the phonetic given name or first name of the person. ms-DS-Phonetic-Last-Name Contains the phonetic last name of the person. ms-DS-Phonetic-Department Contains the phonetic department name where the person works. ms-DS-Phonetic-Company-Name Contains the phonetic company name where the person works. ms-DS-Phonetic-Display-Name The phonetic display name of an object. In the absence of a phonetic display name the existing display name is used. To test this I manually populated the ms-DS-Phonetic-First-Name attribute with Bbrraadd for the user named Brad.  In Active Directory Users and computers, I did a search for the name Bbrr . ...

What SYSVOL Folder Contains & Structure | About SYSVOL Folder Structure

Image
About each folder under the SYSVOL share in Domain Controller SYSVOL folder used to store a copy of the domain’s public files like system policies, Group Policy settings and logon/logoff scripts, which are replicated to all other domain controllers in the Active Directory domain through File Replication Services (FRS), You can find many folders inside the SYSVOL share, I would like to explore and explain each folder by how it’s used in the process of SYSVOL replication. SYSVOL Folder Structure \Sysvol |____ | |____Policies | |____Scripts | |____ DO_NOT_REMOVE_NtFrs_PreInstall_Directory | |____ NtFrs_PreExisting___See EventLog | |____Enterprise | |____Policies | |____Scripts | |____Staging | |____Domain | |____Enterprise | |____Staging Areas | |____Enterprise (junction> = Sysvol\Staging\Enterprise) | |____Your Domain Name (junction> = Sysvol\Staging\Domain) | |____Sysvol | |____Enterprise (junctio...

Transferring FSMO Roles Step by Step Guide - Command Line & GUI Mode

Transfer of FSMO Roles We can transfer the roles for some temporary maintenance issues on to ADC and again we can transfer back the roles onto DC. We can transfer the roles in two ways 1. Command mode 2. Graphical mode Transfer of roles through command: On DC Go to command prompt and type ntdsutil Type  roles Connections Connect to server (name of ADC ex.sys2) Q Transfer schema master Transfer RID master Transfer infrastructure master Transfer PDCQ Q Exit Transferring roles using GUI: On DC Register the Schema For registering Schema Start --> Run --> regsvr32 schmmgmt.dll Transferring schema master On DC Start --> Run --> mmc --> click on file --> select add/remove snap in Select A.D.Schema --> add --> close --> ok From console root Expand console root Right click AD Schema Change domain controller Specify name Ok Right click AD schema Select operations master Click on change Yes --> ok --> file --> e...

Active Directory Partitions List in Windows 2003 and 2008 Servers

Active Directory data is logically partitioned so that each domain controller does not store all objects in the directory. Each directory partition, also called a naming context, contains objects of a particular scope and purpose. Below are the three major Active Directory partitions described:- ·          Schema Partition defines the object classes and their attributes for the entire directory. The configuration is replicated to every domain controller in the forest. ·          Domain Partition contains all the objects stored in a domain, including users, groups, computers, and Group Policy containers (GPCs). This partition information is replicated to all domain controllers within a domain, but not to domain controllers in other domains. ·          Configuration Partition contains objects that represent the logical structure of the forest, domains, ...

10 Tips for Effective Active Directory Design

Active Directory design is a science, and it’s far too complex to cover all the nuances within the confines of one article. But I wanted to share with you 10 quick tips that will help make your AD design more efficient and easier to troubleshoot and manage. 1: Keep it simple The first bit of advice is to keep things as simple as you can. Active Directory is designed to be flexible, and if offers numerous types of objects and components. But just because you can use something doesn’t mean you should. Keeping your Active Directory as simple as possible will help improve overall efficiency, and it will make the troubleshooting process easier whenever problems arise. 2: Use the appropriate site topology Although there is definitely something to be said for simplicity, you shouldn’t shy away from creating more complex structures when it is appropriate. Larger networks will almost always require multiple Active Directory sites. The site topology should mirror your network top...

Types of Trust Relation Ships in Windows 2003 | Windows Trust Relation Ships - A Brief Description

Windows 2003 supports six types of trusts (although the OS doesn't support all types for all forest modes): * Tree-root trust-- Windows 2003 automatically creates a transitive, two-way trust when you add a new tree-root domain to an existing forest. Tree-root trusts let every domain in different trees in the same forest implicitly trust one another. * Parent-child trust-- Windows 2003 automatically creates a transitive, two-way trust when you add a child domain to an existing domain. This trust lets every domain in a particular tree implicitly trust one another. * Shortcut trust-- When domains that authenticate users are logically distant from one another, the process of logging on to the network can take a long time. You can manually add a shortcut trust between two domains in the same forest to speed authentication. Shortcut trusts are transitive and can either be one way or two way. * External trust-- Administrators can manually create an external trust between domains i...

Understanding Forests and Domains

Image
An Overview of Forests and Domains A domain is a collection of computers and resources that share a common security database, in this case, the Active Directory database. Computers in the domain also have a common namespace. A namespace is the hierarchical grouping of service and object names that are stored in Active Directory and DNS. Active Directory and DNS namespaces have to be the same. This is a Microsoft requirement. A domain can also be considered a security boundary because you can create and manage related resources within a domain and then exercise administrative control and implement security. You define security policies such as account lockout policy and password policy on a domain basis. Administrative rights granted in one domain are therefore only valid within that particular domain. Active Directory domains contain a logical partition of users, groups, computers and other objects within the environment. All network objects exist in a domain. Each doma...

Understanding Group Types and Scopes

Image
An Introduction to Groups A group can be defined as a collection of accounts that are grouped together so that Administrators can assign permissions and rights to the group as a single entity. This removes the need for an Administrator to individually assign permissions and rights to each account. Therefore, while a user account is associated with an individual, or one entity; a group account or a group, is created to simplify the administration of multiple user accounts (users). When you grant permissions to a group, all accounts that are part of that particular group are granted the permissions. Permissions actually controls which actions users can perform on a network resource. Rights on the other hand relate to system tasks. Windows Server 2003 provides user accounts and group accounts (of which users can be a member). User accounts are designed for individuals. Group accounts are designed to make the administration of multiple users easier. The following entitie...

What’s New In Windows Server 2003 Active Directory

Image
An Introduction to the Active Directory Features With the release of Microsoft Windows Server 2003 quite a few enhancements and features were introduced that were not previously available in Windows 2000. These enhancements were aimed at improving the scalability, efficiency, speed and performance of Active Directory, and addressed a few deficiencies or shortcomings of the earlier version of Active Directory utilized in Windows 2000 Server. When a domain controller running Windows Server 2003 is created, a number of Active Directory basic features are immediately installed and available to the Windows Server 2003 domain controller. Certain other Active Directory features are only available when particular conditions exist in the network. Additional Active Directory features can be enabled but is dependant on the following conditions, or factors: The operating system (OS) running on the domain controller The domain functional level. In Windows 2000 Active Dir...

Understanding Organizational Units

Image
An Overview of Organizational Units (OUs) An organizational unit (OU) is a container that is used to logically organize and group Active Directory objects within domains. OUs are not part of the DNS namespace. They are used to organize Active Directory objects into logical administrative groups. OUs therefore serve as containers in which you can create and manage Active Directory objects. OUs are considered the smallest unit to which an Administrator can assign permissions to resources within Active Directory. An OU enables you to apply security policies, deploy applications, delegate administrative control for Active Directory objects, and to run scripts. An important thing to understand is that OUs are not security principals. The user accounts, group accounts, and computer accounts within the OUs are security principals. The Active Directory object types that can be located in OUs are listed below: User, group, and computer objects; shared folders, printers, appl...