Training
Certifications
Books
Special Offers
Community




 
Active Directory™ Services for Microsoft® Windows® 2000 Technical Reference
Author David Iseminger
Pages 480
Disk N/A
Level Int/Adv
Published 01/12/2000
ISBN 9780735606241
ISBN-10 0-7356-0624-2
Price(USD) $49.99
To see this book's discounted price, select a reseller below.
 

More Information

About the Book
Table of Contents
Sample Chapter
Index
Related Series
Related Books
About the Author

Support: Book & CD

Rate this book
Barnes Noble Amazon Quantum Books

 

Table of Contents


Acknowledgmentsx
Introductionxi
PART I UNDERSTANDING ACTIVE DIRECTORY SERVICES 
CHAPTER 1 Understanding Directory Services3
    Network History and the Need for Directory Services3
        The Growth of Networks4
        The Expansion of the Enterprise Network4
        Administration Needs in the Small Company5
    The Laws of Computing6
        Metcalfe’s Law7
        Moore’s Law7
        Murphy’s Law9
    The Directory Defined9
        What Is a Directory?10
        What Is a Directory Service?10
    The Enterprise Directory Service Shopping List12
        Enterprise Directory Service Requirements13
        How Active Directory Services Meets Enterprise Directory Service Requirements14
    Real-Life Directory Examples17
        The Simple Directory Example17
        The Advanced Directory Service Example18
    Directory Service vs. Relational Database21
    Conclusion21
CHAPTER 2 Active Directory Services as a Directory Service Implementation23
    Active Directory Technical Specifications24
        Centralization and Scalability24
        Ease of Administration25
        Security26
        Interoperability and Standardization27
    Active Directory Features28
        Administration Delegation28
        Automated Software Distribution29
        Backup Services29
        Backward Compatibility29
        DEA Platform29
        DEN Platform29
        IntelliMirror30
        Printer Search Capabilities31
        Required Authentication Mechanism31
    Where Is Active Directory Services?31
        Departure from the Windows NT 4 Approach32
    Conclusion36
CHAPTER 3 Windows 2000 Domains and Active Directory Services37
    Windows 2000 Domains37
        The Domain Hierarchy38
        Administrative Boundaries45
    Active Directory Services Interaction47
        Emulating the Domain Hierarchy47
        Cataloging the Domain (the Directory Partition)47
        Cataloging the Enterprise (the Global Catalog)52
    Conclusions52
CHAPTER 4 Active Directory Services Scalability Architecture55
    The Importance of Scalability55
    Partitioning Approach56
    Catalog Services (the Global Catalog)58
        Namespace59
        Object59
        Naming Context61
        Schema61
        How the Global Catalog Operates62
    Replication64
        Replication Process Overview65
        Failure Recovery65
        Resolving Collisions66
        Reducing Network Traffic66
    FSMO Roles68
    Conclusion70
CHAPTER 5 More Active Directory Services Architecture71
    Achieving Ease of Administration71
        Easing Administration with Centralization72
        Easing Administration with Standards Compliance72
        Administration Building Blocks72
    Achieving Security73
    Achieving Application Integration74
        Schema Extensibility74
        Application Interfaces74
    Achieving Standardization and Openness75
    Achieving Centralization77
        Centralized Administrative Interface77
        Single Sign-on77
        Active Directory Connectors79
        Extensible Schema79
CHAPTER 6 Active Directory Services and DNS81
    Understanding DNS82
        Computer Names, Host Names, FQDNs, and Relative Distinguished Names83
        DNS Concepts84
        DNS Components87
    DNS Name-Resolution Operations99
        Recursive Queries100
        Iterative Queries101
    How Active Directory Services Uses DNS103
        Domain Controller Registration103
        SRV Resource Record Registration104
        Locating a Domain Controller109
    Integrating DNS with Active Directory Services112
PART II DEPLOYING ACTIVE DIRECTORY SERVICES 
CHAPTER 7 Planning an Active Directory Services Deployment117
    Overview of Planning Decisions118
        Components of Your Active Directory Services Plan118
        Understanding Windows 2000 Groups120
        Noteworthy Built-In Windows 2000 Groups123
    Active Directory Services Planning Recommendations124
        Planning the Forest124
        Planning Domains127
        Planning Organizational Units140
        Planning Sites: Getting Tight with the Network143
    Conclusions148
CHAPTER 8 Active Directory Services and Security149
    Windows 2000 Security149
        Windows 2000 Security Primitives149
        Security Implementation vs. Security Protocols151
    Active Directory Security152
        Object and Attribute Security153
        Directory Database Security155
    Understanding the Windows 2000 Security Infrastructure156
        Logon, Authentication, and Authorization157
        Understanding the Kerberos Protocol159
        Understanding Public Key Infrastructure170
        Understanding SSL/TLS181
    Security and Active Directory Deployments183
        Security and Domain Trusts183
        Physical Security185
CHAPTER 9 Managing Active Directory Services189
    Everyday Management190
        Mapping Windows NT Tasks to Windows 2000 Interfaces192
        Promoting Windows 2000 Servers to Domain Controllers193
        Using Active Directory Services Snap-Ins203
        Delegating Administration241
        Performing Active Directory Services Backups and Restores246
    Advanced Management254
        Managing Replication Strategies255
        Windows 2000 Group Policy261
        Managing FSMO Roles265
    Command-Line Management270
        Getting the Most out of the Command Line271
        Active Directory Services Command-Line Utilities277
    Conclusion284
CHAPTER 10 Working with the Active Directory Services Schema285
    Understanding the Schema285
        The Schema Namespace286
        Content and Structure Enforcement287
        Object Interaction Clarified291
    The Base Schema295
        Base DIT Class Listing295
        Base DIT Class Hierarchy295
        Base DIT Attribute Listing296
    Extending the Schema297
        classSchema Configuration Parameters298
        Creating New Schema Class Objects300
        attributeSchema Object Configuration Parameters308
        Creating New Schema Attribute Objects314
        Deactivating Classes and Attributes315
        Resurrecting Classes and Attributes316
        The Schema Cache316
    Conclusion317
CHAPTER 11 Upgrading to Active Directory Services319
    Understanding Your Upgrade Options320
        Upgrade or Restructure: Choosing the Right Path321
    Upgrading from a Windows NT Environment324
        The Upgrade Process324
        Upgrading Additional Domains331
        Transitioning LAN Manager Replication to File Replication Services (FRS)331
        Transitioning Routing and Remote Access Service (RRAS) Servers332
    Restructuring a Windows NT Environment333
        Understanding Restructuring333
        Transitioning Resource Domains into OUs336
    Conclusion337
CHAPTER 12 Migrating to Active Directory Services339
    Migrating from Novell NDS340
    Migrating from Exchange Server340
        Active Directory Services and Exchange Server 5.5341
    Authentication Methods and Their Security343
        Integration of Exchange Server Platinum and Active Directory Services345
    Migrating from Other Directory Services348
        DirSync348
        The LDIFDE Command-Line Utility349
        ADSI Scripting351
    Conclusions352
CHAPTER 13 Making Postdeployment Organizational Changes355
    Making Forest Changes356
        What You Can Change357
        What You Cannot Change359
    Making Domain Changes359
        What You Can Change360
        What You Cannot Change361
        Understanding SIDhistory362
        Using MoveTree364
        Using ClonePrincipal367
    Making OU Changes368
        What You Can Change368
        What You Cannot Do with OUs371
    Making Site Changes372
        What You Can Do with Sites372
    Conclusions373
CHAPTER 14 Administratively Leveraging Active Directory Services375
    Managing Change376
        What Change and Configuration Management Enables377
    Using IntelliMirror379
        Technologies That Enable IntelliMirror382
        User Data Management383
        Software Installation and Maintenance384
        User Settings Management387
        Implementing IntelliMirror388
        Life Without IntelliMirror398
    Using Remote OS Installation398
        Technologies That Enable Remote OS Installation400
        Implementing Remote OS Installation402
        Living Without Remote OS Installation411
    Using Distributed File System412
        Technologies That Enable Dfs414
        Dfs Technical Details414
        Implementing Dfs415
    Conclusions424
PART III APPENDIXES 
APPENDIX A Windows 2000 DIT Classes429
APPENDIX B Base DIT Class Hierarchy431
APPENDIX C Windows 2000 Base DIT attributeSchema Objects435
Index445


Visit Microsoft Press for more information on
Active Directory™ Services for Microsoft® Windows® 2000 Technical Reference


Top of Page


Last Updated: Saturday, July 7, 2001