SlideShare uma empresa Scribd logo
1 de 19
   Create user objects to represent the employees, customers, or
    students in your environment.

   group :-
          is just a collection of things. Groups are used most frequently
    in a security context you set up a group of users and apply certain
    permissions or rights to that group. Using a group is much easier
    when applying security than using individual users because you
    have to apply the security only once instead of once per user.
A convention for naming user accounts should
accommodate:

  Employees with duplicate names

  Different types of employees, such as temporary
  or contract employees




                                          11/11/2008   3
Local user accounts
(stored on local computer)




Domain user accounts
(stored in Active Directory)

                               Windows Server 2003 Domain




                                               11/11/2008   4
   Two different types of user accounts can be created:
    1. local user accounts
    2. domain user accounts.

   Local user accounts :- are used to control access to the
    computer on which you are working. They are created on
    Windows Server 2003 by using the Local Users and Groups
   Domain accounts:- are created in Active Directory and are
    considerably different from local user accounts. Rather than
    storing information on the local machine, account information is
    stored in the directory and replicated to other DCs.
 Account  names can be between 1 and
  20 characters (letters and/or numbers).
 Account names are not case sensitive.
 The following characters cannot be

  used in the account name:
 ◦" /  [ ] : ; | , + = * ? < > @



                                    11/11/2008   6
Create a domain user account
Create a local user account




                               11/11/2008   7
11/11/2008   8
11/11/2008   9
   Using groups, you can perform a variety of tasks that will affect the
    accounts and groups that are members. These include:
    Assigning rights to a group account to authorize them to perform a
    certain task
    Assigning permissions on shared resources to a group, so that all
    members can access the resource in the same manner
    Distributing bulk e-mail to all members of the group
   There are two different types, which are used for two different
    purposes:
      1. Security groups
      2. Distribution groups

   Security Groups:-A security group is a collection of users who
    have specific rights and permissions to resources.
    Rights are assigned to users and groups, to control the actions a
    user or member of a group can take. rights are also sometimes
    called privileges.
    Permissions are used to control access to resources.
    When permissions are assigned to a group, it determines what
    the members of the group can do with a particular resource.
   Distribution groups:- are used for sharing information. This type of
    group has nothing to do with security. It is used for distributing e-
    mail messages to groups of users.
   Distribution groups allow applications such as Microsoft Exchange
    to send e-mails to collections of users.

   Active Directory provides three different scopes for groups:
     1. Universal
     2. Global
     3. Domain Local
◦ Global Groups :-
  Global security groups are most often used to organize users who
  share similar network access requirements. A global group has
  the following characteristics:

◦ Limited membership You can add members only from the
  domain in which you create the global group.

◦ Access to resources in any domain You can use a global
  group to assign permissions to gain access to resources that are
  located in any domain in the tree or forest.
   Domain Local Groups :-
    Domain local security groups are most often used to assign
    permissions to resources. A domain local group has the following
    characteristics:
   Open membership You can add members from any domain.
   Access to resources in one domain You can use a domain local
    group to assign permissions to gain access to resources that are
    located only in the same domain where you create the domain local
    group.
   Universal Groups
    Universal security groups are most often used to assign permissions
    to related resources in multiple domains. A universal security group
    has the following characteristics:
   Open membership You can add members from any domain in the
    forest.
   Access to resources in any domain You can use a universal
    group to assign permissions to gain access to resources that are
    located in any domain in the forest.
2.1 users & groups

Mais conteúdo relacionado

Mais procurados

Introduction_of_ADDS
Introduction_of_ADDSIntroduction_of_ADDS
Introduction_of_ADDS
Harsh Sethi
 
Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02
gameaxt
 
Chapter03 Creating And Managing User Accounts
Chapter03      Creating And  Managing  User  AccountsChapter03      Creating And  Managing  User  Accounts
Chapter03 Creating And Managing User Accounts
Raja Waseem Akhtar
 
Workgroup vs domain
Workgroup vs domainWorkgroup vs domain
Workgroup vs domain
tameemyousaf
 
Microsoft Active Directory
Microsoft Active DirectoryMicrosoft Active Directory
Microsoft Active Directory
thebigredhemi
 
Active directory
Active directory Active directory
Active directory
deshvikas
 
Active Directory Services
Active Directory ServicesActive Directory Services
Active Directory Services
Varun Arora
 

Mais procurados (20)

Microsoft Active Directory.pptx
Microsoft Active Directory.pptxMicrosoft Active Directory.pptx
Microsoft Active Directory.pptx
 
Understanding the Windows Server Administration Fundamentals (Part-1)
Understanding the Windows Server Administration Fundamentals (Part-1)Understanding the Windows Server Administration Fundamentals (Part-1)
Understanding the Windows Server Administration Fundamentals (Part-1)
 
Introduction to Active Directory
Introduction to Active DirectoryIntroduction to Active Directory
Introduction to Active Directory
 
Windows server
Windows serverWindows server
Windows server
 
Windows Server 2019 -InspireTech 2019
Windows Server 2019 -InspireTech 2019Windows Server 2019 -InspireTech 2019
Windows Server 2019 -InspireTech 2019
 
Introduction_of_ADDS
Introduction_of_ADDSIntroduction_of_ADDS
Introduction_of_ADDS
 
Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02Microsoft Offical Course 20410C_02
Microsoft Offical Course 20410C_02
 
Introduction to Network and System Administration
Introduction to Network and System AdministrationIntroduction to Network and System Administration
Introduction to Network and System Administration
 
Active directory and application
Active directory and applicationActive directory and application
Active directory and application
 
Chapter03 Creating And Managing User Accounts
Chapter03      Creating And  Managing  User  AccountsChapter03      Creating And  Managing  User  Accounts
Chapter03 Creating And Managing User Accounts
 
Workgroup vs domain
Workgroup vs domainWorkgroup vs domain
Workgroup vs domain
 
Windows Network concepts
Windows Network conceptsWindows Network concepts
Windows Network concepts
 
ACTIVE-DIRECTORY.ppt
ACTIVE-DIRECTORY.pptACTIVE-DIRECTORY.ppt
ACTIVE-DIRECTORY.ppt
 
Administer Active Directory
Administer Active DirectoryAdminister Active Directory
Administer Active Directory
 
Microsoft Active Directory
Microsoft Active DirectoryMicrosoft Active Directory
Microsoft Active Directory
 
Active directory
Active directory Active directory
Active directory
 
Active Directory Services
Active Directory ServicesActive Directory Services
Active Directory Services
 
Active Directory
Active DirectoryActive Directory
Active Directory
 
Windows Server 2019.pptx
Windows Server 2019.pptxWindows Server 2019.pptx
Windows Server 2019.pptx
 
DNS - Domain Name System
DNS - Domain Name SystemDNS - Domain Name System
DNS - Domain Name System
 

Destaque

1.1 windows server 2003
1.1 windows server 20031.1 windows server 2003
1.1 windows server 2003
Muuluu
 
Dns server
Dns serverDns server
Dns server
Muuluu
 
Switch function
Switch functionSwitch function
Switch function
Muuluu
 
2.2 determining trust relationships
2.2 determining trust relationships2.2 determining trust relationships
2.2 determining trust relationships
Muuluu
 
User account policy
User account policyUser account policy
User account policy
Muuluu
 
2.1 user practical
2.1 user practical2.1 user practical
2.1 user practical
Muuluu
 
Lecture 3
Lecture 3Lecture 3
Lecture 3
Muuluu
 
Switch configuration
Switch configurationSwitch configuration
Switch configuration
Muuluu
 
Лекц 11
Лекц 11Лекц 11
Лекц 11
Muuluu
 
Лекц 11
Лекц 11Лекц 11
Лекц 11
Muuluu
 
Лекц 9
Лекц 9Лекц 9
Лекц 9
Muuluu
 
1.2 ad installation
1.2 ad installation1.2 ad installation
1.2 ad installation
Muuluu
 
Лекц 10
Лекц 10Лекц 10
Лекц 10
Muuluu
 
1.2 active directory
1.2 active directory1.2 active directory
1.2 active directory
Muuluu
 
Лекц 12
Лекц 12Лекц 12
Лекц 12
Muuluu
 
Лекц 13
Лекц 13Лекц 13
Лекц 13
Muuluu
 

Destaque (18)

1.1 windows server 2003
1.1 windows server 20031.1 windows server 2003
1.1 windows server 2003
 
Dns server
Dns serverDns server
Dns server
 
Switch function
Switch functionSwitch function
Switch function
 
Lecture 5
Lecture 5Lecture 5
Lecture 5
 
2.2 determining trust relationships
2.2 determining trust relationships2.2 determining trust relationships
2.2 determining trust relationships
 
User account policy
User account policyUser account policy
User account policy
 
2.1 user practical
2.1 user practical2.1 user practical
2.1 user practical
 
Lecture 3
Lecture 3Lecture 3
Lecture 3
 
Switch configuration
Switch configurationSwitch configuration
Switch configuration
 
Лекц 11
Лекц 11Лекц 11
Лекц 11
 
Лекц 11
Лекц 11Лекц 11
Лекц 11
 
Лекц 9
Лекц 9Лекц 9
Лекц 9
 
1.2 ad installation
1.2 ad installation1.2 ad installation
1.2 ad installation
 
Лекц 10
Лекц 10Лекц 10
Лекц 10
 
Lecture 2
Lecture 2Lecture 2
Lecture 2
 
1.2 active directory
1.2 active directory1.2 active directory
1.2 active directory
 
Лекц 12
Лекц 12Лекц 12
Лекц 12
 
Лекц 13
Лекц 13Лекц 13
Лекц 13
 

Semelhante a 2.1 users & groups

Discuss the two group classifications that exist in Windows Server 2.pdf
Discuss the two group classifications that exist in Windows Server 2.pdfDiscuss the two group classifications that exist in Windows Server 2.pdf
Discuss the two group classifications that exist in Windows Server 2.pdf
kesav24
 
Users and groups in xp
Users and groups in xpUsers and groups in xp
Users and groups in xp
Rauf Wani
 
Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
Activedirecotryfundamentals
Shekhar Singh
 
Chapter04 Implementing And Managing Group And Computer Accounts
Chapter04      Implementing And  Managing  Group And  Computer  AccountsChapter04      Implementing And  Managing  Group And  Computer  Accounts
Chapter04 Implementing And Managing Group And Computer Accounts
Raja Waseem Akhtar
 
Net essentials6e ch9
Net essentials6e ch9Net essentials6e ch9
Net essentials6e ch9
APSU
 
Net essentials6e ch9
Net essentials6e ch9Net essentials6e ch9
Net essentials6e ch9
APSU
 
Chapter01 Introduction To Windows Server 2003
Chapter01     Introduction To  Windows  Server 2003Chapter01     Introduction To  Windows  Server 2003
Chapter01 Introduction To Windows Server 2003
Raja Waseem Akhtar
 

Semelhante a 2.1 users & groups (20)

Presentation gggffggggg.pdf
Presentation                     gggffggggg.pdfPresentation                     gggffggggg.pdf
Presentation gggffggggg.pdf
 
70 640 Lesson05 Ppt 041009
70 640 Lesson05 Ppt 04100970 640 Lesson05 Ppt 041009
70 640 Lesson05 Ppt 041009
 
Discuss the two group classifications that exist in Windows Server 2.pdf
Discuss the two group classifications that exist in Windows Server 2.pdfDiscuss the two group classifications that exist in Windows Server 2.pdf
Discuss the two group classifications that exist in Windows Server 2.pdf
 
Users and groups in xp
Users and groups in xpUsers and groups in xp
Users and groups in xp
 
Activedirecotryfundamentals
ActivedirecotryfundamentalsActivedirecotryfundamentals
Activedirecotryfundamentals
 
Chapter04 Implementing And Managing Group And Computer Accounts
Chapter04      Implementing And  Managing  Group And  Computer  AccountsChapter04      Implementing And  Managing  Group And  Computer  Accounts
Chapter04 Implementing And Managing Group And Computer Accounts
 
Net essentials6e ch9
Net essentials6e ch9Net essentials6e ch9
Net essentials6e ch9
 
Net essentials6e ch9
Net essentials6e ch9Net essentials6e ch9
Net essentials6e ch9
 
Lecture 8 permissions
Lecture 8   permissionsLecture 8   permissions
Lecture 8 permissions
 
report on network security fundamentals
report on network security fundamentalsreport on network security fundamentals
report on network security fundamentals
 
9781111306366 ppt ch10
9781111306366 ppt ch109781111306366 ppt ch10
9781111306366 ppt ch10
 
G Mac Chapter04
G Mac Chapter04G Mac Chapter04
G Mac Chapter04
 
Chapter01 Introduction To Windows Server 2003
Chapter01     Introduction To  Windows  Server 2003Chapter01     Introduction To  Windows  Server 2003
Chapter01 Introduction To Windows Server 2003
 
IRJET- Research Paper on Active Directory
IRJET-  	  Research Paper on Active DirectoryIRJET-  	  Research Paper on Active Directory
IRJET- Research Paper on Active Directory
 
06 users groups_and_permissions
06 users groups_and_permissions06 users groups_and_permissions
06 users groups_and_permissions
 
29041329 interview-questions-for-server-2003
29041329 interview-questions-for-server-200329041329 interview-questions-for-server-2003
29041329 interview-questions-for-server-2003
 
Exploitation and distribution of setuid and setgid binaries on Linux systems
Exploitation and distribution of setuid and setgid binaries on Linux systemsExploitation and distribution of setuid and setgid binaries on Linux systems
Exploitation and distribution of setuid and setgid binaries on Linux systems
 
Active directory interview questions
Active directory interview  questionsActive directory interview  questions
Active directory interview questions
 
70 271 Stu Chap03
70 271 Stu Chap0370 271 Stu Chap03
70 271 Stu Chap03
 
Download It
Download ItDownload It
Download It
 

Mais de Muuluu

Өгөгдлийн бүтэц
Өгөгдлийн бүтэцӨгөгдлийн бүтэц
Өгөгдлийн бүтэц
Muuluu
 
Basic software
Basic software Basic software
Basic software
Muuluu
 
Wide area networks
Wide area networksWide area networks
Wide area networks
Muuluu
 
NAT and PAT
NAT and PATNAT and PAT
NAT and PAT
Muuluu
 
Spanning tree protocol
Spanning tree protocolSpanning tree protocol
Spanning tree protocol
Muuluu
 
Firewall
FirewallFirewall
Firewall
Muuluu
 
User practical
User practicalUser practical
User practical
Muuluu
 
Active directory
Active directoryActive directory
Active directory
Muuluu
 
Процессорын архитектур
Процессорын архитектурПроцессорын архитектур
Процессорын архитектур
Muuluu
 
6 network devices
6 network devices6 network devices
6 network devices
Muuluu
 
Бие даалт
Бие даалтБие даалт
Бие даалт
Muuluu
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
Muuluu
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
Muuluu
 
Лекц 16
Лекц 16Лекц 16
Лекц 16
Muuluu
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
Muuluu
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
Muuluu
 
Лекц 13
Лекц 13Лекц 13
Лекц 13
Muuluu
 
Лекц 12
Лекц 12Лекц 12
Лекц 12
Muuluu
 

Mais de Muuluu (20)

Өгөгдлийн бүтэц
Өгөгдлийн бүтэцӨгөгдлийн бүтэц
Өгөгдлийн бүтэц
 
Basic software
Basic software Basic software
Basic software
 
Wide area networks
Wide area networksWide area networks
Wide area networks
 
NAT and PAT
NAT and PATNAT and PAT
NAT and PAT
 
Spanning tree protocol
Spanning tree protocolSpanning tree protocol
Spanning tree protocol
 
Firewall
FirewallFirewall
Firewall
 
User practical
User practicalUser practical
User practical
 
Active directory
Active directoryActive directory
Active directory
 
Hardware
HardwareHardware
Hardware
 
windows server 2003
 windows server 2003 windows server 2003
windows server 2003
 
Процессорын архитектур
Процессорын архитектурПроцессорын архитектур
Процессорын архитектур
 
6 network devices
6 network devices6 network devices
6 network devices
 
Бие даалт
Бие даалтБие даалт
Бие даалт
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
 
Лекц 16
Лекц 16Лекц 16
Лекц 16
 
Лекц 15
Лекц 15Лекц 15
Лекц 15
 
Лекц 14
Лекц 14Лекц 14
Лекц 14
 
Лекц 13
Лекц 13Лекц 13
Лекц 13
 
Лекц 12
Лекц 12Лекц 12
Лекц 12
 

2.1 users & groups

  • 1.
  • 2. Create user objects to represent the employees, customers, or students in your environment.  group :- is just a collection of things. Groups are used most frequently in a security context you set up a group of users and apply certain permissions or rights to that group. Using a group is much easier when applying security than using individual users because you have to apply the security only once instead of once per user.
  • 3. A convention for naming user accounts should accommodate: Employees with duplicate names Different types of employees, such as temporary or contract employees 11/11/2008 3
  • 4. Local user accounts (stored on local computer) Domain user accounts (stored in Active Directory) Windows Server 2003 Domain 11/11/2008 4
  • 5. Two different types of user accounts can be created: 1. local user accounts 2. domain user accounts.  Local user accounts :- are used to control access to the computer on which you are working. They are created on Windows Server 2003 by using the Local Users and Groups  Domain accounts:- are created in Active Directory and are considerably different from local user accounts. Rather than storing information on the local machine, account information is stored in the directory and replicated to other DCs.
  • 6.  Account names can be between 1 and 20 characters (letters and/or numbers).  Account names are not case sensitive.  The following characters cannot be used in the account name: ◦" / [ ] : ; | , + = * ? < > @ 11/11/2008 6
  • 7. Create a domain user account Create a local user account 11/11/2008 7
  • 10.
  • 11.
  • 12.
  • 13. Using groups, you can perform a variety of tasks that will affect the accounts and groups that are members. These include:  Assigning rights to a group account to authorize them to perform a certain task  Assigning permissions on shared resources to a group, so that all members can access the resource in the same manner  Distributing bulk e-mail to all members of the group
  • 14. There are two different types, which are used for two different purposes: 1. Security groups 2. Distribution groups  Security Groups:-A security group is a collection of users who have specific rights and permissions to resources. Rights are assigned to users and groups, to control the actions a user or member of a group can take. rights are also sometimes called privileges. Permissions are used to control access to resources. When permissions are assigned to a group, it determines what the members of the group can do with a particular resource.
  • 15. Distribution groups:- are used for sharing information. This type of group has nothing to do with security. It is used for distributing e- mail messages to groups of users.  Distribution groups allow applications such as Microsoft Exchange to send e-mails to collections of users.  Active Directory provides three different scopes for groups: 1. Universal 2. Global 3. Domain Local
  • 16. ◦ Global Groups :- Global security groups are most often used to organize users who share similar network access requirements. A global group has the following characteristics: ◦ Limited membership You can add members only from the domain in which you create the global group. ◦ Access to resources in any domain You can use a global group to assign permissions to gain access to resources that are located in any domain in the tree or forest.
  • 17. Domain Local Groups :- Domain local security groups are most often used to assign permissions to resources. A domain local group has the following characteristics:  Open membership You can add members from any domain.  Access to resources in one domain You can use a domain local group to assign permissions to gain access to resources that are located only in the same domain where you create the domain local group.
  • 18. Universal Groups Universal security groups are most often used to assign permissions to related resources in multiple domains. A universal security group has the following characteristics:  Open membership You can add members from any domain in the forest.  Access to resources in any domain You can use a universal group to assign permissions to gain access to resources that are located in any domain in the forest.