SlideShare uma empresa Scribd logo
1 de 21
07/11/2008   1
 Introduction to Active Directory
 Active Directory Logical Structure
 Active Directory Physical Structure




                                        07/11/2008   2
 What Is Active Directory?
 Active Directory Objects
 Active Directory Schema
 Lightweight Directory Access Protocol (LDAP)




                                       07/11/2008   3
Directory Service
  Directory Service                 Centralized Management
                                    Centralized Management
    Functionality
     Functionality

 Organize
 Organize                    Single point of administration
                              Single point of administration

 Manage
 Manage         Resources
                 Resources    Full user access to directory
                              Full user access to directory
 Control
 Control                      resources by a single logon
                               resources by a single logon



                                                      07/11/2008   4
   A directory service stores all the information
    needed to use and manage these objects in a
    centralized location, simplifying the process of
    locating and managing these resources.
 What Is a Directory Service?
 What Is a Schema?
 What Is the Global Catalog?




                                 07/11/2008   6
A structured repository of information about people and
resources in an organization


         Domain
            OU1                                  KimYoshida
                   Computers
                                          Attributes  Values
                      Computer1
                                          Name        Kim Yoshida
                   Users
                       User1              Building    117
             OU2                          Floor       1
                   Users
                       User2
                   Printers
                        Printer1
A repository is a collection of resources that can be
accessed to retrieve information. Repositories often consist
of several databases tied together by a common search
                                                    07/11/2008      7
engine.
defines all the objects and attributes that the directory service uses
  to store data



      Examples of object                              Examples of
           class                                       attributes
                                                   accountExpires
              User                                 distinguishedName
                                                   directReports
                                                   dNSHostName
                                                   operatingSystem
              Computer                             firstName
                                                   lastName

              Printer
   The global catalog is the central repository of
    information about objects in a tree or forest. By
    default, a global catalog is created automatically on
    the initial domain controller in the first domain in the
    forest. A domain controller that holds a copy of the
    global catalog is called a global catalog server.
    It stores only attributes about each objects ,such as
    objects location




                                                Read Only

        Global Catalog
◦ Provide a way to design and administer the
  hierarchical structure, logical structure of the
  network Include
   Domains and organizational units
   Trees and forests
Domain Tree
                         Domain




     Domain         Domain       Domain


                                          OU
                       Objects
Domain     Domain

                                  OU           OU

                                     Domain

              Organizational Unit


         Forest
   Logical collection of users and computers.
   Several benefits of domain
    Enable you to organize objects within a
    single dept. or location.
   Act as a security boundaries.
   Domain Objects are fully replicated to the
    domain controller’s within a domain, not to
    other domains .
Tree Root Domain

   Contiguous linking of one or more
    AD domains that shares a common
    namespace or in a Parent-Child           Parent
                                              Parent
    Relationship.                                                Parent Domain
   Two-way transitive trust                  contoso.msft
    automatically created
   Tree Root Domain :- first domain in
    a tree or parent domain                                            Child Domain
                                                             Child
                                                              Child

                                                  sales.contoso.msft




                                                                        New
                                                                       Domain
   Combination of One or More Trees
   A forest is a disjointed namespace
   www.microsoft.com
   www.msn.com
   Transitive Trusts created automatically
Forest Root Domain
   The Forest Root Domain Is
    the First Domain Created
    in a Forest

                                             Domain

                         Forest         Tree
    Tree Root Domain

                                                              OU
                                  Domain

            Domain                                     OU
                                                            Domain   OU



            Tree

Domain                 Domain
                                                Objects
   An organizational unit (OU) is a subdivision within an Active
    Directory into which you can place users, groups, computers,
    and other organizational units. You can create organizational
    units to mirror your organization's structure.
   Implements a Structure inside a Domain
   Can be nested as needed
   Can not be assigned any rights
   Typically used for Administrative Reasons         OU


    ◦ e.g. System Policies                       OU
                                                    Domain OU




                                          Objects
   Benefits of using OUs
    ◦ Easier to locate and manage the Active Directory objects
    ◦ Define more advanced features by applying Group Policy to
      an OU
    ◦ Delegate administrative control over OUs
 Not related to logical Structure
 Modeled via „Sites“
 A site is well connected via fast Network Links
 One Site can home multiple Domains
 One Domain can spread across many Sites
 Domain Database is stored on Domain Controllers
   Sites
   Domain controllers
   WAN links
                                      Site




            WAN Link




                                Domain Controllers
    Site
      A site is one or more IP subnets connected
      by a fast and reliable link.
   Domain Controller is a server on a Microsoft Windows
    Network that is responsible for allowing host access to
    Windows domain resources. The domain controllers in
    your network are the centerpiece of your Active
    directory service.  It stores user account information,
    authenticates users and enforces security policy for a
    Windows domain
Lightweight Directory Access Protocol (LDAP)




                                   Contoso.msft

                                       Finance

                                           Sales

Relative distinguished name                      Suzan Fine


  CN=Suzan Fine,OU=Sales,OU=Finance,DC=contoso,DC=msft
                                            07/11/2008        21

Mais conteúdo relacionado

Mais procurados

Active directory architecture
Active directory architectureActive directory architecture
Active directory architecturerahuldaredia21
 
02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptx02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptxAdiWidyanto2
 
VMware vSphere technical presentation
VMware vSphere technical presentationVMware vSphere technical presentation
VMware vSphere technical presentationaleyeldean
 
Administer Active Directory
Administer Active DirectoryAdminister Active Directory
Administer Active DirectoryHameda Hurmat
 
VMware Overview
VMware OverviewVMware Overview
VMware OverviewMadhu Bala
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxMeriemBalhaddad
 
Active directory ii
Active directory   iiActive directory   ii
Active directory iideshvikas
 
Active directory and application
Active directory and applicationActive directory and application
Active directory and applicationaminpathan11
 
Active directory domain services
Active directory domain servicesActive directory domain services
Active directory domain servicesIGZ Software house
 
VMware Vsphere Graduation Project Presentation
VMware Vsphere Graduation Project PresentationVMware Vsphere Graduation Project Presentation
VMware Vsphere Graduation Project PresentationRabbah Adel Ammar
 
Sistemas de gestión de base de datos
Sistemas de gestión de base de datosSistemas de gestión de base de datos
Sistemas de gestión de base de datosjudithmore16
 
Active Directory Ii
Active Directory   IiActive Directory   Ii
Active Directory Iideshvikas
 

Mais procurados (20)

Active directory architecture
Active directory architectureActive directory architecture
Active directory architecture
 
02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptx02-Active Directory Domain Services.pptx
02-Active Directory Domain Services.pptx
 
VMware vSphere technical presentation
VMware vSphere technical presentationVMware vSphere technical presentation
VMware vSphere technical presentation
 
Active Directory
Active Directory Active Directory
Active Directory
 
Administer Active Directory
Administer Active DirectoryAdminister Active Directory
Administer Active Directory
 
Active Directory component
Active Directory componentActive Directory component
Active Directory component
 
Active Directory
Active DirectoryActive Directory
Active Directory
 
VMware Overview
VMware OverviewVMware Overview
VMware Overview
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptx
 
Active directory ii
Active directory   iiActive directory   ii
Active directory ii
 
Fsmo roles
Fsmo rolesFsmo roles
Fsmo roles
 
Active directory and application
Active directory and applicationActive directory and application
Active directory and application
 
Active directory domain services
Active directory domain servicesActive directory domain services
Active directory domain services
 
HDFS Federation
HDFS FederationHDFS Federation
HDFS Federation
 
VMware Vsphere Graduation Project Presentation
VMware Vsphere Graduation Project PresentationVMware Vsphere Graduation Project Presentation
VMware Vsphere Graduation Project Presentation
 
Sistemas de gestión de base de datos
Sistemas de gestión de base de datosSistemas de gestión de base de datos
Sistemas de gestión de base de datos
 
Data Guard Architecture & Setup
Data Guard Architecture & SetupData Guard Architecture & Setup
Data Guard Architecture & Setup
 
Creating database
Creating databaseCreating database
Creating database
 
VMware
VMware VMware
VMware
 
Active Directory Ii
Active Directory   IiActive Directory   Ii
Active Directory Ii
 

Destaque

Лекц 13
Лекц 13Лекц 13
Лекц 13Muuluu
 
Лекц 10
Лекц 10Лекц 10
Лекц 10Muuluu
 
1.1 windows server 2003
1.1 windows server 20031.1 windows server 2003
1.1 windows server 2003Muuluu
 
Лекц 11
Лекц 11Лекц 11
Лекц 11Muuluu
 
Лекц 9
Лекц 9Лекц 9
Лекц 9Muuluu
 
2.1 users & groups
2.1 users & groups2.1 users & groups
2.1 users & groupsMuuluu
 
Lecture 2
Lecture 2Lecture 2
Lecture 2Muuluu
 
1.2 ad installation
1.2 ad installation1.2 ad installation
1.2 ad installationMuuluu
 
Лекц 11
Лекц 11Лекц 11
Лекц 11Muuluu
 
Dns server
Dns serverDns server
Dns serverMuuluu
 
Лекц 12
Лекц 12Лекц 12
Лекц 12Muuluu
 
2.1 user practical
2.1 user practical2.1 user practical
2.1 user practicalMuuluu
 
Lecture 3
Lecture 3Lecture 3
Lecture 3Muuluu
 
Switch configuration
Switch configurationSwitch configuration
Switch configurationMuuluu
 
Switch function
Switch functionSwitch function
Switch functionMuuluu
 
Lecture 5
Lecture 5Lecture 5
Lecture 5Muuluu
 
2.2 determining trust relationships
2.2 determining trust relationships2.2 determining trust relationships
2.2 determining trust relationshipsMuuluu
 
User account policy
User account policyUser account policy
User account policyMuuluu
 

Destaque (18)

Лекц 13
Лекц 13Лекц 13
Лекц 13
 
Лекц 10
Лекц 10Лекц 10
Лекц 10
 
1.1 windows server 2003
1.1 windows server 20031.1 windows server 2003
1.1 windows server 2003
 
Лекц 11
Лекц 11Лекц 11
Лекц 11
 
Лекц 9
Лекц 9Лекц 9
Лекц 9
 
2.1 users & groups
2.1 users & groups2.1 users & groups
2.1 users & groups
 
Lecture 2
Lecture 2Lecture 2
Lecture 2
 
1.2 ad installation
1.2 ad installation1.2 ad installation
1.2 ad installation
 
Лекц 11
Лекц 11Лекц 11
Лекц 11
 
Dns server
Dns serverDns server
Dns server
 
Лекц 12
Лекц 12Лекц 12
Лекц 12
 
2.1 user practical
2.1 user practical2.1 user practical
2.1 user practical
 
Lecture 3
Lecture 3Lecture 3
Lecture 3
 
Switch configuration
Switch configurationSwitch configuration
Switch configuration
 
Switch function
Switch functionSwitch function
Switch function
 
Lecture 5
Lecture 5Lecture 5
Lecture 5
 
2.2 determining trust relationships
2.2 determining trust relationships2.2 determining trust relationships
2.2 determining trust relationships
 
User account policy
User account policyUser account policy
User account policy
 

Semelhante a 1.2 active directory

Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
ActivedirecotryfundamentalsShekhar Singh
 
MCSA 70-410 5 introduction to active directory and basic installation
MCSA 70-410 5 introduction to active directory and basic installationMCSA 70-410 5 introduction to active directory and basic installation
MCSA 70-410 5 introduction to active directory and basic installationTarek Amer
 
Virtualization & Server2008 R2 AD
Virtualization & Server2008 R2 ADVirtualization & Server2008 R2 AD
Virtualization & Server2008 R2 ADEdward Jude
 
Active Directory for Auditors
Active Directory for AuditorsActive Directory for Auditors
Active Directory for AuditorsAndrew Clark
 
Active directory
Active directory Active directory
Active directory deshvikas
 
Active Directory I
Active Directory   IActive Directory   I
Active Directory Ideshvikas
 
Hunt for Domain Controller : Active Directory Pentesting Session
Hunt for Domain Controller : ActiveDirectory Pentesting SessionHunt for Domain Controller : ActiveDirectory Pentesting Session
Hunt for Domain Controller : Active Directory Pentesting Sessionhacknpentest
 
FileTable and Semantic Search in SQL Server 2012
FileTable and Semantic Search in SQL Server 2012FileTable and Semantic Search in SQL Server 2012
FileTable and Semantic Search in SQL Server 2012Michael Rys
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questionssubhashmr
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questionsUmesh Sawant
 
domain controller vs child domain controller.
domain controller vs child domain controller.domain controller vs child domain controller.
domain controller vs child domain controller.Vignesh kumar
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxJavedAjmal1
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview Enraj240969
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview Enraj240969
 
activedirectory-i-100902105735-phpapp01.pdf
activedirectory-i-100902105735-phpapp01.pdfactivedirectory-i-100902105735-phpapp01.pdf
activedirectory-i-100902105735-phpapp01.pdfsamarth97
 

Semelhante a 1.2 active directory (20)

Active diirecotry
Active diirecotryActive diirecotry
Active diirecotry
 
70 640 Lesson01 Ppt 041009
70 640 Lesson01 Ppt 04100970 640 Lesson01 Ppt 041009
70 640 Lesson01 Ppt 041009
 
Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
Activedirecotryfundamentals
 
MCSA 70-410 5 introduction to active directory and basic installation
MCSA 70-410 5 introduction to active directory and basic installationMCSA 70-410 5 introduction to active directory and basic installation
MCSA 70-410 5 introduction to active directory and basic installation
 
DC
DCDC
DC
 
Ads overview-en
Ads overview-enAds overview-en
Ads overview-en
 
Virtualization & Server2008 R2 AD
Virtualization & Server2008 R2 ADVirtualization & Server2008 R2 AD
Virtualization & Server2008 R2 AD
 
Active Directory for Auditors
Active Directory for AuditorsActive Directory for Auditors
Active Directory for Auditors
 
Active directory
Active directory Active directory
Active directory
 
Active Directory I
Active Directory   IActive Directory   I
Active Directory I
 
Hunt for Domain Controller : Active Directory Pentesting Session
Hunt for Domain Controller : ActiveDirectory Pentesting SessionHunt for Domain Controller : ActiveDirectory Pentesting Session
Hunt for Domain Controller : Active Directory Pentesting Session
 
FileTable and Semantic Search in SQL Server 2012
FileTable and Semantic Search in SQL Server 2012FileTable and Semantic Search in SQL Server 2012
FileTable and Semantic Search in SQL Server 2012
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questions
 
Active directory interview_questions
Active directory interview_questionsActive directory interview_questions
Active directory interview_questions
 
domain controller vs child domain controller.
domain controller vs child domain controller.domain controller vs child domain controller.
domain controller vs child domain controller.
 
Active-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptxActive-Directory-Domain-Services.pptx
Active-Directory-Domain-Services.pptx
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview En
 
Ads Overview En
Ads Overview EnAds Overview En
Ads Overview En
 
activedirectory-i-100902105735-phpapp01.pdf
activedirectory-i-100902105735-phpapp01.pdfactivedirectory-i-100902105735-phpapp01.pdf
activedirectory-i-100902105735-phpapp01.pdf
 
Active directory
Active directoryActive directory
Active directory
 

Mais de Muuluu

Өгөгдлийн бүтэц
Өгөгдлийн бүтэцӨгөгдлийн бүтэц
Өгөгдлийн бүтэцMuuluu
 
Basic software
Basic software Basic software
Basic software Muuluu
 
Wide area networks
Wide area networksWide area networks
Wide area networksMuuluu
 
NAT and PAT
NAT and PATNAT and PAT
NAT and PATMuuluu
 
Spanning tree protocol
Spanning tree protocolSpanning tree protocol
Spanning tree protocolMuuluu
 
Firewall
FirewallFirewall
FirewallMuuluu
 
User practical
User practicalUser practical
User practicalMuuluu
 
Hardware
HardwareHardware
HardwareMuuluu
 
windows server 2003
 windows server 2003 windows server 2003
windows server 2003Muuluu
 
Процессорын архитектур
Процессорын архитектурПроцессорын архитектур
Процессорын архитектурMuuluu
 
6 network devices
6 network devices6 network devices
6 network devicesMuuluu
 
Бие даалт
Бие даалтБие даалт
Бие даалтMuuluu
 
Лекц 15
Лекц 15Лекц 15
Лекц 15Muuluu
 
Лекц 14
Лекц 14Лекц 14
Лекц 14Muuluu
 
Лекц 16
Лекц 16Лекц 16
Лекц 16Muuluu
 
Лекц 15
Лекц 15Лекц 15
Лекц 15Muuluu
 
Лекц 14
Лекц 14Лекц 14
Лекц 14Muuluu
 
Лекц 13
Лекц 13Лекц 13
Лекц 13Muuluu
 
Лекц 12
Лекц 12Лекц 12
Лекц 12Muuluu
 
Switch configuration
Switch configurationSwitch configuration
Switch configurationMuuluu
 

Mais de Muuluu (20)

Өгөгдлийн бүтэц
Өгөгдлийн бүтэцӨгөгдлийн бүтэц
Өгөгдлийн бүтэц
 
Basic software
Basic software Basic software
Basic software
 
Wide area networks
Wide area networksWide area networks
Wide area networks
 
NAT and PAT
NAT and PATNAT and PAT
NAT and PAT
 
Spanning tree protocol
Spanning tree protocolSpanning tree protocol
Spanning tree protocol
 
Firewall
FirewallFirewall
Firewall
 
User practical
User practicalUser practical
User practical
 
Hardware
HardwareHardware
Hardware
 
windows server 2003
 windows server 2003 windows server 2003
windows server 2003
 
Процессорын архитектур
Процессорын архитектурПроцессорын архитектур
Процессорын архитектур
 
6 network devices
6 network devices6 network devices
6 network devices
 
Бие даалт
Бие даалтБие даалт
Бие даалт
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
 
Лекц 16
Лекц 16Лекц 16
Лекц 16
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
 
Лекц 13
Лекц 13Лекц 13
Лекц 13
 
Лекц 12
Лекц 12Лекц 12
Лекц 12
 
Switch configuration
Switch configurationSwitch configuration
Switch configuration
 

1.2 active directory

  • 2.  Introduction to Active Directory  Active Directory Logical Structure  Active Directory Physical Structure 07/11/2008 2
  • 3.  What Is Active Directory?  Active Directory Objects  Active Directory Schema  Lightweight Directory Access Protocol (LDAP) 07/11/2008 3
  • 4. Directory Service Directory Service Centralized Management Centralized Management Functionality Functionality  Organize  Organize  Single point of administration  Single point of administration  Manage  Manage Resources Resources  Full user access to directory  Full user access to directory  Control  Control resources by a single logon resources by a single logon 07/11/2008 4
  • 5. A directory service stores all the information needed to use and manage these objects in a centralized location, simplifying the process of locating and managing these resources.
  • 6.  What Is a Directory Service?  What Is a Schema?  What Is the Global Catalog? 07/11/2008 6
  • 7. A structured repository of information about people and resources in an organization Domain OU1 KimYoshida Computers Attributes Values Computer1 Name Kim Yoshida Users User1 Building 117 OU2 Floor 1 Users User2 Printers Printer1 A repository is a collection of resources that can be accessed to retrieve information. Repositories often consist of several databases tied together by a common search 07/11/2008 7 engine.
  • 8. defines all the objects and attributes that the directory service uses to store data Examples of object Examples of class attributes accountExpires User distinguishedName directReports dNSHostName operatingSystem Computer firstName lastName Printer
  • 9. The global catalog is the central repository of information about objects in a tree or forest. By default, a global catalog is created automatically on the initial domain controller in the first domain in the forest. A domain controller that holds a copy of the global catalog is called a global catalog server.  It stores only attributes about each objects ,such as objects location Read Only Global Catalog
  • 10. ◦ Provide a way to design and administer the hierarchical structure, logical structure of the network Include  Domains and organizational units  Trees and forests
  • 11. Domain Tree Domain Domain Domain Domain OU Objects Domain Domain OU OU Domain Organizational Unit Forest
  • 12. Logical collection of users and computers.  Several benefits of domain  Enable you to organize objects within a single dept. or location.  Act as a security boundaries.  Domain Objects are fully replicated to the domain controller’s within a domain, not to other domains .
  • 13. Tree Root Domain  Contiguous linking of one or more AD domains that shares a common namespace or in a Parent-Child Parent Parent Relationship. Parent Domain  Two-way transitive trust contoso.msft automatically created  Tree Root Domain :- first domain in a tree or parent domain Child Domain Child Child sales.contoso.msft New Domain
  • 14. Combination of One or More Trees  A forest is a disjointed namespace  www.microsoft.com  www.msn.com  Transitive Trusts created automatically
  • 15. Forest Root Domain  The Forest Root Domain Is the First Domain Created in a Forest Domain Forest Tree Tree Root Domain OU Domain Domain OU Domain OU Tree Domain Domain Objects
  • 16. An organizational unit (OU) is a subdivision within an Active Directory into which you can place users, groups, computers, and other organizational units. You can create organizational units to mirror your organization's structure.  Implements a Structure inside a Domain  Can be nested as needed  Can not be assigned any rights  Typically used for Administrative Reasons OU ◦ e.g. System Policies OU Domain OU Objects
  • 17. Benefits of using OUs ◦ Easier to locate and manage the Active Directory objects ◦ Define more advanced features by applying Group Policy to an OU ◦ Delegate administrative control over OUs
  • 18.  Not related to logical Structure  Modeled via „Sites“  A site is well connected via fast Network Links  One Site can home multiple Domains  One Domain can spread across many Sites  Domain Database is stored on Domain Controllers
  • 19. Sites  Domain controllers  WAN links Site WAN Link Domain Controllers Site A site is one or more IP subnets connected by a fast and reliable link.
  • 20. Domain Controller is a server on a Microsoft Windows Network that is responsible for allowing host access to Windows domain resources. The domain controllers in your network are the centerpiece of your Active directory service.  It stores user account information, authenticates users and enforces security policy for a Windows domain
  • 21. Lightweight Directory Access Protocol (LDAP) Contoso.msft Finance Sales Relative distinguished name Suzan Fine CN=Suzan Fine,OU=Sales,OU=Finance,DC=contoso,DC=msft 07/11/2008 21