Training
Certifications
Books
Special Offers
Community




 
Active Directory® for Microsoft® Windows® Server 2003 Technical Reference
Author Stan Reimer and Mike Mulcare
Pages 480
Disk N/A
Level Int/Adv
Published 04/16/2003
ISBN 9780735615779
Price $49.99
To see this book's discounted price, select a reseller below.
 

More Information

About the Book
Table of Contents
Sample Chapter
Index
Related Series
Related Books
About the Author

Support: Book & CD

Rate this book
Barnes Noble Amazon Quantum Books

 

Table of Contents


    List of Tablesxii
    Dedicationsxiii
    Acknowledgmentsxiv
    Introductionxv
PART I Windows Server 2003 Active Directory Overview 
1   Active Directory Concepts3
    The Evolution of Microsoft Directory Services3
        LAN Manager for OS/2 and MS-DOS4
        Windows NT and SAM 4
        Windows 2000 and Active Directory6
        Windows Server 2003 Domains and Active Directory 7
    Active Directory Open Standards8
        X.500 Hierarchies8
        Lightweight Directory Access Protocol (LDAP)10
    Key Features and Benefits of Active Directory 12
        Centralized Directory12
        Single Sign-On12
        Delegated Administration12
        Common Management Interface13
        Integrated Security13
        Scalability13
    What's New in Windows Server 2003 Active Directory 14
        Active Directory Users And Computers Improvements14
        Levels of Functionality14
        Domain Rename15
        Application Directory Partitions15
        Additional Domain Controller Installed from Backup Media15
        Deactivation of Schema Objects16
        Disabling Compression of Replication Traffic Between Different Sites16
        Global Catalog Not Required for Logon16
        Group Membership Replication Improvements16
        Object Picker UI Improvements17
        Lingering Object Removal Mechanism17
        inetOrgPerson Support17
    Summary17
2   Active Directory Components19
    Active Directory Physical Structure19
        The Directory Data Store 19
        Domain Controllers 20
        Global Catalog Servers20
        Operations Masters 23
        Transferring Operations Master Roles25
        The Schema26
    Active Directory Logical Structure31
        Active Directory Partitions32
        Domains36
        Domain Trees37
        Forests38
        Trusts39
        Sites43
        Organizational Units46
    Summary48
3   Active Directory and Domain Name System49
    DNS Overview49
        Hierarchical Namespace50
        Distributed Database51
        Name Resolution Process51
        Resource Records52
        DNS Domains, Zones, and Servers54
    DNS and Windows Server 2003 Active Directory61
        DNS Locator Service61
        Active Directory Integrated Zones66
        DNS Enhancements69
    Summary75
4   Active Directory Replication and Sites77
    Active Directory Replication Model77
    Replication Enhancements in Windows Server 2003 Active Directory79
    Intrasite and Intersite Replication80
        Intrasite Replication81
        Intersite Replication82
        Replication Latency83
        Urgent Replication83
    Replication Topology Generation84
        Knowledge Consistency Checker84
        Connection Objects85
        Intrasite Replication Topology86
        Global Catalog Replication91
        Intersite Replication Topology93
    Replication Process95
        Update Types96
        Replicating Changes96
    Configuring Intersite Replication102
        Creating Additional Sites103
        Site Links103
        Site Link Bridges105
        Replication Transport Protocols106
        Configuring Bridgehead Servers107
    Monitoring and Troubleshooting Replication108
    Summary110
PART II IMPLEMENTING WINDOWS SERVER 2003 ACTIVE DIRECTORY 
5   Designing the Active Directory Structure113
    Designing the Forest Structure113
        Forests and Active Directory Design114
        Single or Multiple Forests116
        Defining Forest Ownership119
        Forest Change Control Policies120
    Designing the Domain Structure121
        Domains and Active Directory Design121
        Determining the Number of Domains121
        Designing the Forest Root Domain124
        Designing Domain Hierarchies125
        Domain Trees and Trusts128
        Changing the Domain Hierarchy129
        Defining Domain Ownership130
    Designing the DNS Infrastructure131
        Examining the Existing DNS Infrastructure131
        Namespace Design132
    Designing the Organizational Unit Structure143
        Organizational Units and Active Directory Design143
        Designing an OU Structure144
        Creating an OU Design146
    Designing the Site Topology149
        Sites and Active Directory Design149
        Networking Infrastructure and Site Design150
        Creating a Site Design150
        Designing Server Locations153
    Summary158
6   Installing Active Directory159
    Prerequisites for Installing Active Directory159
        Hard Disk160
        Network Connectivity160
        DNS161
        Administrative Permissions163
    Active Directory Installation Options163
        Configure Your Server Wizard163
        Active Directory Installation Wizard (Dcpromo.exe)164
        Unattended Installation165
    Using the Configure Your Server Wizard165
    Using the Active Directory Installation Wizard167
        Operating System Compatibility168
        Domain and Domain Controller Types169
        Naming the Domain171
        File Locations172
        Verify or Install a DNS Server173
        Selecting Default Permissions for User and Group Objects175
        Completing the Installation176
    Performing an Unattended Installation178
    Installing Active Directory from Restored Backup Files179
    Removing Active Directory180
        Removing Additional Domain Controllers182
        Removing the Last Domain Controller183
        Unattended Removal of Active Directory184
    Summary184
7   Migrating to Active Directory185
    Migration Paths186
        The Domain Upgrade Migration Path187
        The Domain Restructure Migration Path189
        The Upgrade-Then-Restructure Migration Path191
    Determining Your Migration Path192
        Migration Path Decision Criteria192
        Choosing the Domain Upgrade Path193
        Choosing the Domain Restructure Path195
        Choosing the Upgrade-Then-Restructure Path197
    Preparing for Migration to Active Directory198
        Planning the Migration198
        Testing the Migration Plan204
        Conducting a Pilot Migration204
    Upgrading the Domain205
        Upgrading from Windows NT Server 4205
        Upgrading from Windows 2000 Server213
    Restructuring the Domain215
        Creating the Pristine Forest217
        Migrating Account Domains222
        Migrating Resource Domains226
    Upgrading then Restructuring231
    Configuring Interforest Trusts232
    Summary236
PART III Administering Windows Server 2003 Active Directory 
8   Active Directory Security239
    Active Directory Security Basics239
        Security Principals240
        Access Control Lists240
        Access Tokens241
        Authentication241
        Authorization242
    Kerberos Security242
        Introduction to Kerberos243
        Kerberos Authentication245
        Delegation of Authentication251
        Configuring Kerberos in Windows Server 2003253
        Integration with Public Key Infrastructure254
        Integration with Smart Cards257
        Interoperability with Other Kerberos Systems258
    NTLM Security260
    Summary260
9   Delegating the Administration of Active Directory261
    Active Directory Object Permissions261
        Standard Permissions262
        Special Permissions264
        Permissions Inheritance268
        Effective Permissions270
        Ownership of Active Directory Objects273
    Auditing the Use of Administrative Permissions274
    Delegating Administrative Tasks276
    Customized Tools for Delegated Administration280
        Customizing the Microsoft Management Console280
        Creating a Taskpad for Administration281
    Planning for the Delegation of Administration282
    Summary283
10   Managing Active Directory Objects285
    Managing Users285
        User Objects285
        inetOrgPerson Objects290
        Contact Accounts291
    Managing Groups292
        Group Types292
        Group Scope293
        Creating a Security Group Design296
    Managing Computers299
    Managing Printer Objects301
        Publishing Printers in Active Directory301
    Managing Published Shared Folders304
    Windows Server 2003 Active Directory Administration Enhancements305
    Summary306
11   Introduction to Group Policies307
    Group Policy Overview308
    Implementing Group Policies311
        Creating GPOs312
        Administering Group Policy Objects313
        Group Policy Inheritance and Application314
        Modifying the Default Application of Group Policies316
        Group Policy Processing321
        Delegating Administration of GPOs326
        Implementing Group Policies Between Domains and Forests327
    Group Policy Management Tools328
        RSoP Tool328
        GPResult329
        GPUpdate330
        Group Policy Management Console330
    Group Policy Design332
    Summary333
12   Using Group Policies to Manage Software335
    Windows Installer Technology336
        Creating a .msi file336
    Deploying Software Using Group Policies337
        Deploying Applications338
        Using Group Policies to Distribute Non-Windows Installer Applications341
    Configuring Software Package Properties343
        Setting the Default Software Installation Properties345
        Installing Customized Software Packages345
        Updating an Existing Software Package347
        Managing Software Categories349
        Configuring File Extension Activation350
        Removing Software Using Group Policies351
    Using Group Policies to Configure Windows Installer352
    Planning for Software Distribution Using Group Policies354
    Limitations to Using Group Policies to Manage Software357
    Summary359
13   Using Group Policies to Manage Computers361
    Desktop Management Using Group Policies362
    Managing User Data and Profile Settings364
        Managing User Profiles364
        Folder Redirection368
    Configuring Security Settings with Group Policies372
        Configuring Domain-Level Security Policies372
        Configuring Other Security Settings377
        Software Restriction Policies379
        Security Templates382
    Administrative Templates385
    Using Scripts to Manage the User Environment389
    Summary391
PART IV Maintaining Windows Server 2003 Active Directory 
14   Monitoring and Maintaining Active Directory395
    Monitoring Active Directory395
        Why Monitor Active Directory?396
        How to Monitor Active Directory398
        What to Monitor410
    Active Directory Database Maintenance411
        Garbage Collection411
        Online Defragmentation413
        Offline Defragmentation of the Active Directory Database414
        Managing the Active Directory Database Using Ntdsutil415
    Summary417
15   Disaster Recovery419
    Planning for a Disaster419
    Active Directory Data Storage420
    Backing Up Active Directory423
    Restoring Active Directory424
        Restoring Active Directory by Creating a New Domain Controller425
        Performing a Nonauthoritative Restore429
        Performing an Authoritative Restore431
        Restoring Sysvol Information433
        Restoring Operations Masters and Global Catalog Servers435
    Summary440
INDEX441

Tables

22-1. Domain Functional Levels22
 2-2. Forest Functional Levels22
 2-3. Group Policy Setting Types48
33-1. Common Resource Records in Windows Server 2003 DNS53
 3-2. The SRV Record Components62
 3-3. A Subset of the DsGetDcName Flag Parameter Values65
44-1. Replication Rings in a Complex Site89
55-1. Linking Network Bandwidth to Site Link Costs151
66-1. Enabling Client OSs to Log On to Active Directory168
99-1. Special Permissions Configuration Columns264
1010-1. Account Properties for a User Object288
 10-2. Username Uniqueness Requirements289
 10-3. Active Directory Group Scopes294
1111-1. Group Policy Options308
 11-2. The Contents of the Group Policy Template310
 11-3. Configuring GPO Settings314
 11-4. GPMC Configuration Options331
1212-1. Deployment Options for a Software Package343
 12-2. Group Policy Setting Options for Windows Installer353
1313-1. Top-Level Containers in Default Domain Policy363
 13-2. Configuring User Profiles Using the Group Policy Object Editor366
 13-3. Password Policies373
 13-4. Account Lockout Policies374
 13-5. Kerberos Policies375
 13-6. Security Settings in Group Policies378
 13-7. An Administrative Templates Sampler386
 13-8. Default Templates Loaded in Windows Server 2003388
 13-9. Components of a Template Option389
1414-1. Core Active Directory Functions and Services400
 14-2. Replication Performance Counters401
 14-3. Key Security Volumes402
 14-4. Core Operating System Indicators402



Last Updated: April 15, 2003
Top of Page