68
Welcome to this TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information and community resource for IT professionals in the UK: FREE bi-weekly technical newsletter FREE regular technical events hosted across the UK FREE weekly UK & US led technical webcasts FREE comprehensive technical web site Monthly CD / DVD subscription with the latest technical tools & resources FREE quarterly technical magazine To subscribe to the newsletter or just to find out more, please visit www.microsoft.com/uk/technet or speak to a Microsoft representative during the break

Welcome to this TechNet Event

  • Upload
    gryta

  • View
    36

  • Download
    0

Embed Size (px)

DESCRIPTION

Welcome to this TechNet Event. We would like to bring your attention to the key elements of the TechNet programme; the central information and community resource for IT professionals in the UK: FREE bi-weekly technical newsletter FREE regular technical events hosted across the UK - PowerPoint PPT Presentation

Citation preview

  • Welcome to this TechNet Event

    We would like to bring your attention to the key elements of theTechNet programme; the central information and communityresource for IT professionals in the UK:

    FREE bi-weekly technical newsletterFREE regular technical events hosted across the UKFREE weekly UK & US led technical webcastsFREE comprehensive technical web siteMonthly CD / DVD subscription with the latest technical tools & resources FREE quarterly technical magazine

    To subscribe to the newsletter or just to find out more, please visit www.microsoft.com/uk/technet or speak to a Microsoft representativeduring the break

  • Active DirectoryDan Lewis

  • PrerequisitesUnderstanding of day-to-day administration tasksUnderstanding of administration challenges in a network environment

  • What Well CoverIntroduction to Active Directory Group PolicyAdvanced Active Directory TasksMicrosoft Resources and Training Options

  • Microsoft Official Curriculum

  • Microsoft Certified Professional Programhttp://www.microsoft.com/learning/

  • Introduction to Active Directory

  • OverviewActive Directory BasicsCreating the Organization

  • Lesson: Active Directory Basics What are Directory Services?Benefits of Active DirectoryMultimedia: The Logical Structure of Active Directory

  • What are Directory Services?Provides a focal point for management, security, and interoperability

  • Benefits of Active DirectoryFlexible AdministrationSimplified AdministrationScalability

  • Multimedia: The Logical Structure of Active Directory

  • Lesson: Creating the OrganizationMicrosoft Management Console Organizational UnitsOrganization Unit Hierarchical modelsUser AccountsGroups PrintersDemonstration: Creating Active Directory Objects

  • Microsoft Management ConsoleSnap-insMMC hosts tools, called snap-ins, that perform administrative functions

  • Organizational Units Organizes objects in a domainAllows you to delegate administrative controlSimplifies the management of commonly grouped resources

  • Organizational Unit Hierarchical Models

  • User AccountsDomain user accounts (stored in Active Directory)Local user accounts (stored on local computer)Windows Server 2003 Domain

  • GroupsGroups simplify administration by enabling you to assign permissions for resourcesGroups are characterized by scope and typeThe group scope determines whether the group spans multiple domains or is limited to a single domainThe three group scopes are global, domain local, and universalGroup

    Group TypeDescriptionSecurityUsed to assign user rights and permissions Can be used as an e-mail distribution listDistributionCan be used only with e-mail applicationsCannot be used to assign permissions

  • Printers

  • Demonstration: Creating Active Directory ObjectsHow to create: Organizational Units User Accounts Groups Printers

  • Group Policy

  • OverviewIntroduction to Group PolicyUsing Group Policy for Organizational Control

  • Introduction to Group PolicyPurpose of Group PolicyGroup Policy Processing GPMC Administration

  • Purpose of Group PolicyComputer ConfigurationUser ConfigurationSecurity SettingsCentralized Management Consistent ConfigurationsAutomatic Configurations

  • Group Policy Processing

  • Group Policy Management ConsoleWhat is the GPMC?New administrative tool for managing Group PolicySet of scriptable interfaces for managing Group PolicyMMC Snap-in, built on these interfacesWeb release of stand-alone version concurrent with launch of Windows Server 2003Requires users to have a licensed copy of Windows Server 2003 in their organizationGPMC Design GoalsUnify management of Group Policy, including both Windows 2000 and Windows Server 2003 domainsAddress key deployment issuesProvide better UI for visualizationEnable programmatic access to Group Policy

  • Lesson: Using Group Policy for Organizational ControlUsing Group Policy to Control SecuritySecurity TemplatesOU Design for SecurityClassroom Practice: Applying a Security TemplateUsing Group Policy to Control the User Environment GPO Settings to Control the User EnvironmentSoftware Restriction PoliciesADM TemplatesDeploying SoftwareClassroom Discussion: Assigning and Deploying SoftwareBest Practices

  • Using Group Policy to Control SecurityCreate an OU structureDetermine Multiple Operating System RequirementsUse Security Templates Based on RoleUse Group Policy to apply templates

  • Security Templates

  • OU Design for SecurityIdentify the security template that most closely matches the configuration required by client computers or serversCreate a new Group Policy object for each security template you will be usingIn the new Group Policy object, import the security templateIf necessary, modify the group policy object to add any additional security settingsLink the new Group Policy object to the appropriate OUMove computer objects for client computers and servers to the appropriate OU

  • Applying a Security TemplateCreate a new GPOImport a security template

  • Using Group Policy to Control the User EnvironmentUse Group Policy to:Manage users and computers Deploy softwareEnforce security settingsEnforce a consistent desktop environment

  • GPO Settings to Control the User Environment Group Policy settings for users:Desktop settingsSoftware settingsWindows settingsSecurity settingsGroup Policy settings for computers:Desktop settingsSoftware settingsWindows settingsSecurity settings

  • Software Restriction Policies Group Policy can restrict software installation and execution

    Can restrict by:Hash rulePath ruleCertificate ruleZone rule

  • Administrative TemplatesDefault templatesOffice Templates Custom templatesText files that end with an .adm extensionUpdate the user or computer portion of the registry

    Adding ADM templates into a GPO

  • Overview of the Software Deployment Process

  • Assigning Software vs. Publishing Software

    User configurationAssign: The application is installed the next time the user activates the applicationPublish: The application is installed when the user selects it from Add/Remove Programs in Control PanelThe application is installed when the user double-clicks an unknown file type (document activation)Computer configurationAssign: The application is installed the next time the computer starts

  • Group Policy Best Practices

  • Controlling the User EnvironmentSecuring Client and Servers Using Administrative TemplatesDeploying SoftwareControlling the User EnvironmentTesting the User Environment

  • SummaryIntroduction to Group PolicyUsing Group Policy for Organizational Control

  • Advanced Active Directory Tasks

  • OverviewDelegation and Custom MMCsFile Server ManagementAdditional Management Techniques

  • Delegation and Custom MMCsDelegating ControlDemo: Delegating ControlDemo: How to Create a Custom MMCMMC Taskpads

  • Delegation of ControlGrant Permissions to:Delegate control to other administrators for specific organizational units Modify specific attributes of an object in a single organizational unitPerform the same task in all organizational units

  • Demo: Delegating ControlHow to delegate control of an OU for specific tasks

  • How to Create a Custom MMC

  • MMC TaskpadsCreates custom of the MMC snap-inAllows for specific tasks to be set in Task PadCustomizes view of MMCRemoves confusing toolbarsRemoves menu optionsRemoves configuration optionsUseful for novice administrators

  • File Server ManagementEncrypting File SystemDisk QuotasVolume Shadow CopiesDemonstration: How to Restore a Previous VersionDistributed File SystemDistributed File System Capabilities

  • Encrypting File SystemEFS encryption makes data unintelligible without a decryption key EFS encrypts dataUsers encrypt a file or folder by setting the encryption propertyAll files and subfolders created in or added to an encrypted folder are automatically encrypted Use EFS to access encrypted dataWhen accessing an encrypted file, users can read the file normally When users close the file, EFS encrypts it again Use EFS to decrypt dataThe file remains decrypted until it is encrypted againUse the cipher command to display or alter encryption of folders and files on NTFS volumes

  • Disk Quotas

  • Volume Shadow CopiesViews the read-only contents of network folders as they existed at various points of timeUse shadow copies to:Recover files that were accidentally deleted Recover files that were accidentally overwritten Allow version checking while working on documentsIs enabled on a per-volume basis, not on specific sharesIs not a replacement for regular backupsWhen storage limits are reached, the oldest shadow copy is deleted and cannot be retrieved To change the storage volume, delete the shadow copies first

  • Demo - How to Restore a Previous Version

  • Distributed File SystemLogically group shared folders into a single hierarchyShared folders reside on different serversSingle shared folder contains all network resources

  • Distributed File System Capabilities Unified namespaceName transparencyFlexible storage managementLoad sharingFault toleranceSecurity integrationClient caching of DFS namespaceCompatibility with Windows NT , Windows 95, and Windows 98

  • Additional Management Techniques Software Update ServicesIntelliMirror

  • Software Update ServicesWindows Update Web siteInternet

  • Demo - How to Install and Configure Software Update ServicesHow to configure Automatic Updates by creating an Automatic Updates GPO for your organizational unit How to configure Software Update Services

  • What is Intellimirror?User Data ManagementSoftware Installation and MaintenanceUser Settings Management Remote Installation

  • SummaryDelegation and Custom MMCsFile Server ManagementSoftware Update ServicesIntelliMirror

  • Microsoft Resource and Training Options

  • OverviewWindows Server 2003 VersionsWindows NT 4.0 Migration StrategiesNovell Migration StrategiesMicrosoft Learning Courses

  • Windows Server 2003 Family

  • Windows Server 2003 Family Editions

  • Windows NT 4.0 Upgrade Maximize return/minimize risk when choosing servers/roles to upgrade Domain Controller upgrades provide the most immediate benefits of Active Directory File Server upgrades give greatest ROIAlways have a fallback plan Test your plan before the upgrade Leverage your partners expertise in the upgrade process Excellent experience to draw upon

  • Novell Migration StrategiesInventory NetWare Servers and Respective RolesDetermine Migration Methodology GradualDirect Prepare and install Microsoft Directory Synchronization Service (MSDSS )Migrate NDS/Bindery to Active DirectoryMigrate File and PrintMigrate Files

  • Microsoft Training CoursesCourse 2270: Updating Support Skills from Microsoft Windows NT 4.0 to the Windows Server 2003 FamilyCourse 2273: Managing and Maintaining a Microsoft Windows Server 2003 EnvironmentCourse 2274: Managing a Microsoft Windows Server 2003 EnvironmentCourse 2275: Maintaining a Microsoft Windows Server 2003 EnvironmentCourse 2276: Implementing a Microsoft Windows Server 2003 Network Infrastructure: Network HostsCourse 2277: Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure: Network ServicesCourse 2278: Planning and Maintaining a Microsoft Windows Server 2003 Network InfrastructureCourse 2279: Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure

  • ServicesMonitored NewsgroupsOnline ConciergeMicrosoft Partner Support for Your UpgradeSupport for Microsoft Partners Advisory ServicesMicrosoft Online Support for Windows Server 2003

  • SummaryWindows Server 2003 VersionsWindows NT 4.0 Migration StrategiesNovell Migration StrategiesMicrosoft Learning Courses

    Upgrades can provide rapid payback! As we discussed, upgrading/migrating is a large process, but a well thought out plan allows you to execute very well on the upgrades and many customers have had great success with the upgrade. Invite your partner onsite for a free IOE assessment to see what the financials for the upgrade may look like for your organization

    Maximize return/minimize risk when choosing servers/roles to upgrade when discussing the migration, see what roles will provide the best payback for your organization. For instance, if you have a very complex domain setup that would be difficult/impossible to restore in a disaster situation, domain upgrade may be the best place to start. Or, if youre a law firm that relies heavily on file/print performance, upgrading file servers and print servers can give you an instant return. Always have a fallback plan: Proper testing is essential. There are lots of resources available today to allow you to quickly and easily model your proposed changes in a lab environment prior to upgrading.

    Leverage your partners expertise in the upgrade process: We (partner) have a lot of expertise in migrating servers by role. In addition, planning resources such as the project templates, the IOE tool, etc. give you a very good understanding of how long the migration should take, what the expected financial benefits will be, etc.

    The first four are the names of papers and books available for download on microsoft.com