Overview Active Directory

Video Activity

Overview of Active Directory This lesson offers a comprehensive overview of the Active Directory. The Active Directory has many functions and benefits. The active directory offers: - A centralized resource and security administration - A single logon for access to global resources - Fault tolerance and redundancy - Simplified resource location - Ce...

Join over 3 million cybersecurity professionals advancing their career
Sign up with

Already have an account? Sign In »

1 hour 40 minutes
Video Description

Overview of Active Directory This lesson offers a comprehensive overview of the Active Directory. The Active Directory has many functions and benefits. The active directory offers: - A centralized resource and security administration - A single logon for access to global resources - Fault tolerance and redundancy - Simplified resource location - Centralized user and group management All of these things are very important in how we manage our network. Within the active directory; Windows provides two directories; the Active Domain Services (AD DS) and the Active Directory Lightweight Directory Services (AD LDS). The active directory structure consists of forests, domain trees and domains and the name spaces are in a Fully Qualified Domain Name (FQDN) format. The active directory is based upon a schema. The schema is a very important thing to be able to understand as it is the overall component that handles the Active Directory and controls the layout and rules which govern the objects of the database. There are both physical (e.g., Domain controllers) and logical (partitions) components in the Active Directory and all of them have different roles and functions. This lesson also covers Active Directory Naming Standards Finally, participants learn about the Windows Authentication process.

Video Transcription
sort of the benefits and functions of
active directory. Well, first of all, we centralize both. Resource is security administration.
We coulda signal log on process to global resource is
we could fault tolerance and redundancy.
We simplify our ability locate resource is within the environment. It was sexualized user group management,
Very important functions benefits in terms of how we manage our network
after directory is basically two options. So there's the actor director debated Service is a D. D. S, which is what most people consider active directory. It's full fledged directory service and it actually applies in your server environment and has managed on your mate controllers
you also have starting with 2008. You actually had an implementation of active directory Lightweight director service is no, it's a D L D s, which is essentially an upgrade for a replacement for L DAP type environment. So it's designed to have the functionality of an actor director environment, but not being active directory itself so it doesn't have to actually
have a direct integration to your active directory environment.
So a T. D s attitude Ermin service is a D is not the next 500 rolled up standard. It has a tree concept from entering the resource is and because, as a trick concept, it stores information about the network. Resource is service is such as user's computers, printers, servers, databases, groups and security policies.
In a database structure
identifies all the resource is on the network, makes it accessible to authorized users and applications and very importantly, requires desk as a. D. D. S is not hierarchical structure. So that's what we have to pay attention to its not hierarchical structure.
Here's an example. Left. You see, we have a standard L dap for X 500 times structure where you have example folder under a folder on their folder or file and folder, etcetera. Active directory to the work Like that actor directory on the right has a tree structure where things are connected logically based on their location within the environment.
Idiot asses are
methodology for actually supporting this
so actor director structure that starts basically at the top of the forest so the top levels could serve your forest, and there has one or more debate trees. It could have just one Dimitri, or it can have multiple debate trees with child means on each tree can have its own unique needs space. That being said, So you have
a Dimitri that's, for example, a date of dot com,
a debate tree. Part of that would be researched at a day, a date of dot com, of sales, that a date of dot com something of that nature, and we could have multiple forests that actually have relationship with each other.
So the debate trees
are all within a contiguous Dave Space. So you keep going down the list. It's Celtic that salting dot com or something that something that something that Cobb keeps going down.
The maids themselves or a logical unit basically of computers and objects in network resources. They're defined within a security boundary and administrative boundary. So that's what we have to bear in mind debates. Just a logical concept. So these faces have to be in the f g d ed, because D S is a
Cree critical and key component.
Of our 80 is infrastructure.
80 objects include a variety of things, obviously user's computers, servers, groups, organization units, printers, etcetera, group policies, Aaron object, all objects that the director you must have a name that is unique from an F K D and stay on point
objects are assigned a global, unique identify, which is used by actor director to control the object. Remember, Global. You globally unique identifiers actually also work across different for us.
Objects have both required in our actual attributes, so defined what? Where, when, how, If you think about this,
a user object is going to have objects related to that user, for example, or user name is also to have group membership. It's also going to have things like maybe a phone number or an address or a department as opposed to, ah, computer. I was not gonna have a phone number. That's not the way it works. So do you have to take that into account?
That's what you're after directory objects are dealing with.
So all this is based on a ski boat. Ski was kind of important to stay because that's actually the overarching compote ID that actually handles your after directory. It's basically a specialized database, and the schema controls now the layout of the data in that database, but also rules that govern the objects in the database. Or I should say,
if you think about a true database would be the record, but
it actor director they're considered objects
defines the object stored within the active directory and the properties or attributes associated with each object. So it keeps track of, For example, use this phone number.
Users, groups and computers have different properties. After Director keeps a record of each and every piece of information related that summer optional, some are required, and they are actually manageable. Beyond that, we could actually even add
it. Did additional component Starsky Ba. If we so desire,
we gain the whole process of active directory fault tolerance. Redundancy sits. Active Directory uses a multi master domain controller design. There is only one type of debate controller. If you've been around since the days of tea, we had a primary day to be in control. Are back up to make controller. That doesn't exist anymore. All that Bay controllers are just debate controllers, so they're all
do the exact same job. They'll have the exact same information.
The only difference that, as exist, is our festival rolls, which we'll get to love it.
Changes made on 81 debate controller are replicated to all of the debate Controllers of environment
Now bear in mind that you have some tickle to read only two main controller, which we're going to talk about again in the minute that actually it does not allow changes to be made on that D. C.
It's obviously recommended to have two or war debate controllers preach to me because you don't have fault. Tolerance of redundancy, if you only have one single point of failure, is still a single point of failure,
and any debate controller can log on any user in the debate at any time.
So our F s several roles which you mentioned earlier that we're talking about again, we have five of them. You have two of them that exist once in the entire force and three that exist what's in each domain in the force. So if you have a signal of a forest, we have all five of them exist. What's the entire force? Does she have multiple domains? So you have a child to me. Research today date of dot com. It would have
the additional three.
1st 1 is risky, but master, which at the forest level is responsible for the replication of your actor directed Read Service's ski. But throughout the forest
and inclusive OS upgrades out of your stage server, et cetera. Skip a master role. Although critical to the overall functioning and set up of it, it's not necessarily critical tohave running on the domain controller on the day to day basis. Because you're not changing your environment that often you're not adding
due OS for your debate controllers every day you're not adding their stage serve every day,
so that's not as critical saved with debate. Navy Master Although it's important that it be around and you know where it is,
it's since it's only managing the debate days space starting at the force level, UH, a date of dot com and moving
down through the child levels, obviously not adding a new debate every day. So if it's off line for a day, that's probably gonna make much of a difference. Now we get down to the debate loves
those are very important. Those they're they're offline, create lots of have a kegger implementation. So you're PDC every later, which is ah, call back to a legacy of the anti days but still has a very critical function in the current generation, you're PDC every later. What's for D Made?
It's critical for Kerb Rosa Password Replication in time synchronization.
If you want people to be belong out to your network,
come to your debate that you DJ pdc every later F S m a role server up and running
Red Master.
Red Master is one of six that
is important. Could you live without it for a short period of time? Possibly.
Remember each object into demean has a sit associated with the rid Master manages that rid pool, which keeps track of Sid's cross. It are forced not just a single domain.
Now, if you're not adding new items or new objects to your Dominion on a daily basis, if the ringmasters off line for a day, it's probably not going to be too much of a critical factor for you. But remember, having every master offline can wreak havoc very quickly. Your infrastructure master, your debate keeps track of cross debate object reference manager.
So if you have a single to be a forest
infrastructure, master really is not critical. But remember, all of these should be out of debating controller and kept up and running at all times. We have options to work with that, including moving them around to any domain controller. What we could have one for Dominion control it. We could have all five of the one to make control. Doesn't matter how we set it up,
but with the infrastructure master one
we really want, ideally have that on a drink controller that is not also a global catalog has to do with the way things they're registered. Information reports.
So what are our components of active directory? Well, we have physical evidence, obviously. Today, Controllers Data Store that's actually database a global catalog server, which is going to be on intimate controller function. Also read only debate controllers.
Logically, we have other things that are concepts that would come out of our database. We have partitions where information is isolated, our skee ball, which is the overarching design of our active directory infrastructure.
Debate's debate Trees, Forests sites, which is logical groupings of our debate controllers, based on T. C P I. P. Functionality and organizational units are oh, use those air. The other components that were to talk about
So you're a controller,
stores the actor director database and authenticate users with the network Turn lager. It's not all does, but that's primary function in most networks. Awesome stores. The data base inspiration. A dynamic updates with other debate controllers intimate with the exception, obviously of real. The Dominion controllers, which just get a copy of it in a reed alert format
database replication makes after directory a multi master environment. So basically, if you remember this, all these D C's are all the same. That has priority over the others. The only difference between one to see the next is if it holds an F S m o role.
Really. Debate controllers. These were introduced with Windows Server 2008. Basically, it's a domain controller has a copy of the active director database file but cannot modify it locally. So basically it replicates. This changes from a rideable debate controller that is, with an actor director infrastructure. Remember that rideable domain controller
has to be at or above the OS level of the redolent of a controller.
It's very well suited for
location where there are no mate avid's, or there's a security concern in terms of the actual physical box being, for example, stolen and it also prevents unauthorized modifications to the actor director environment. And we can also control the passwords that are replicated to it.
Physical components carrying out. We have our data store, which are actually the files on the D. C. The container a. D. D. S information. The maid would begin T d s that d A T s are espresso database log files. So ah, the DBS on our system, which we use the replication. Also
the little catalog server of host. The a partial read only copy of all objects in the entire force Will catalogue keeps track of everything in the forest, no matter what debate it's in. So I makes searching and resolution of connectivity between these different environments much faster,
really. Debate controls we are. We should mention our specialized DC Sever that maintains a really copy of the 88 80 database. And it must get a copy of that Be a replication from a rideable debate controller.
Logical components. We have partitions which are sections or a. D. D. S database that could be viewed, managed and replicated individually.
If you think about this, we could have an application that needs it So several partition it actor director You work in a d. L. D s functionality that we may want to replicate
a skipper,
so that's a logical road. It defines the master list of object types and attributes from which a. D. D s objects have derived. But basically, this is our master control center. So we want to be very careful. I tell we do anything with the ski boat.
Other last coca votives forest which basically water war debates that are part of the save 80 D s structure. So, basically to say, actor director debate space, So a. D. D s
a debate is logical or administrative boundary for a d. D s objects. It's also used for security boundaries. In some cases.
Dmitri, these are child debates or sub debates of I'd meet. So, basically is we work our way down to common domain name space that everything underneath that would be a member of the Dimitri
site aside is logical grouping of objects based on T c V i p network configuration Julia. Now, really, it's what it is is a logical grouping of a D. D. A s tum. A controller objects because the actual
individual computer office news objects are not really considered part of a site. They're not even managed from that environment sites and managed to d. C to D d C work only it does allow controlled replication of the database environment. So we can they live it in amount of traffic because across the way And, for example,
organizational unit or oh, use
these air important toe organize our objects within a D. D. S because we wanted want to do is we want to manage our environments. What manage our organization are objects via organization? You this. So, for example, one have sales in the sales group for research and research group, or we might do it by location. New York L. A.
It doesn't matter what it is, so we actually just choose that.
And if we plan r o u, and we could go multiple tears deep can have a no you under Nounou So we could have sales in New York, for example. We could do that, and it actually allows for simple five management and delegation, so we're allowed to delegate Awesome.
Here's our neighbor standard, and you'll see how this because potentially an issue. If you're not careful with euro you So here we have an example of a
Alex Smith.
So it's a user
that has actually remember the sales, are you?
And under a date of dot com. So if you look at our
Davis stated, we have a user ready leaf object is common name has that an organization unit object is no you that basically, you know, Uday and a debate, for example, are a D. C and Damian component. What for? Each part of the D. A s name. So this case, we would have CNN where the common day Because a Smith
Oh, you equal sales. So that's how it's written how to sales that's today. We have for it
now it might be, Oh, yuko sales comma O U equals New York. So if it sails under New York, we'd have to have another one in there. Um, d c equals date of d. C equals calm. So you see how that works. So notice there's no dots in here. Everything's a comma, and it's unequal side. So this is where you could get.
Really. Bessie, if you don't plan properly, is if you could have like
Oh, you eco's ao yukos b o u S e o u. His deal d C equals ABC, where this could be a very long structure and becomes a little bit management intensive if you go too deep. So in the example, we end up with a user name of a Smith for long guns or a Smith and a datum dot com, and they remember the sales. Are you
so force a debate? Functional levels. Remember they could be separate. We could have a maid that's functioning on the higher higher level than the force that is part of Remember, if we have a single the main force, we could even have the debate at a higher function level to the forest. Ideally, would you get off your debate? Controllers upgraded to later. Oh asked. You
promptly move your vibrant, too, that they arrest
So it allows the debate Control ist interoperate with D. C. Is running a prior versions of Microsoft Windows server. So that's report to pay attention are functional levels are well that hire folks level doesn't allow older versions of the Windows Server Two functions debate controllers,
but they do give us an additional functionality or futures. So what's we move up the functional ladder, so we will go to next functional level. We could no longer have a lower OS version on a domain controller anywhere in the forest or that made depending on which one we're talking about. And we can also never again add a lower functional level one
a lower OS functional level into that debate.
And it's also a one way process. We will raise the functional level. That's it is done. You can't go back.
It only has an impact of debate controllers, things like file servers, principles, Web servers. None of that matters Italy. It's only concerned with the debate Controllers West version
and raise the folks the level of the forest. So if you could be on the fourth part of the side of the house, you actually need the Be a member of the Enterprise average group that with your credentials, and you need to execute it on the debate control that actually holds this chemo master role.
Here's a little
example of the function levels we have,
and they're actually started with Windows 2000. There was a mixed mode, and the native mode in 2000 but all that's been obviously discontinued in terms of any support. So when its Server 2003 interim and server 2003 those the next ones and that was mixed between 3 4000 Remember, these are being retired. So
did you have a server? 8 4008 to 12 4000 art 12 are too. And we can actually take any one of these at the domain level. So right outside, anywhere these triangles could be at any one. These levels,
unless it's a forest, could actually be at a different level than that. The raids are
all this comes into play. The next step is with his authentication, basically would have put his authentication. We get what we log out was called a ticket granted tickets. So when you provide your credentials, you get a ticket granite ticket from the environment, so that then is used to get tickets
from individual servers of resource is everything is encrypted and it goes back and forth. And this is dear. Basically, this is in terms of milliseconds. None of this takes anything real time. So you're acting director database provides the ticket. Granny Ticket, which they get
tick is granted every time. These Texas A resource based on the information in the ticket granny ticket.
What resource is it has access to what rights and provisions.
So in a client server, actor, director environment, we have a database of dictators and objects to organize. A resource is according logical, a logical plan. So we have things like maids, sites,
users, security groups, uh, users. A part of security gives computers through Saudi security goods. Even security goods could be vital security gifts
trusts. So we have trust between the the debates or forests. Would you have a certificate authority if you want to have
September see multi factor authentication or if we want, actually have encryption? We have group policies, which we used to manage the actual users groups
basically grew policies are applied to organization units and then filter to skirt Igor's, for example. Rights and privileges depends on how you look at it. You have share rights, and yet did you have
beyond that, we have full privileges. Yeah, computers that you're dealing with printers file Share service is after Director command. All of these, we could actually control who has what what they have it.
So just to recap after directory, the foxes of benefits centralizing resource is secured. Administration
signal log on for access toe all global resource is
it's fault tolerant with redundancy. Why did we actually set it up with at least two to make controllers?
It simplifies our resource location both in the debate into the forest you've across force if we have trust built
and it centralizes our user group management and even allows for delegation of our group management. So that's active directory overview. And that's the information you're gonna need to know and understand if you really want to make your actor director function well for your environment thing.
Up Next
Microsoft Active Directory Domain Services

Module 2 explains how to implement virtualized domain controllers and read-only domain controller (RODCs)

Instructed By