Windows Server
Windows Server
Index
Page
Date Topics Covered number
15-02-24
(Thurs)
16-02-24
(Fri)
1
Server:
A server is a computer that makes data available to other computers. It can serve data across the Internet
to systems on a LAN or a WAN.
Windows Server:
Designed by Microsoft, Windows Server is a group of operating systems to support enterprises and small
and medium-sized businesses with data storage, communications, and applications.
Microsoft Windows Server OS (operating system) is a series of enterprise-class server operating
systems designed to share services with multiple users and provide extensive administrative control of data
storage, applications and corporate networks.
With just a quick glance, you might have trouble telling the difference between Windows Server and
normal versions of Windows. The desktop looks the same, including the taskbar, desktop icons, and Start
button.
As it turns out, every Windows Server release corresponds to a consumer version of Windows. Windows
Server 2003, for instance, is the server version of Windows XP. Current versions include Windows Server
2016, which is based on the Windows 10 Anniversary Update, and Windows Server 2019, based on version
1809 of Windows 10.
Because Windows Server and Windows share a code base, you can perform many of the same functions on
both. You can download and install programs like browsers and photo editors on Windows Server, and
many Windows basics like Notepad are included in Windows Server.
However, Windows Server and Windows Pro/Home have more differences than similarities. Let's review
some of them.
Because Windows Server is intended for businesses, it includes plenty of enterprise software. Below are a
few roles that a server can perform thanks to these tools:
Active Directory: Active Directory is a user management service that allows a server to act as a
domain controller. Instead of each user logging into a local computer, the domain controller handles
all user account authentication. See our explanation of Windows domains for more on this.
2
DHCP: Dynamic Host Configuration Protocol is a protocol that lets a server automatically assign IP
addresses to all devices on the network. At home, your router probably handles this. But in a
business setting, IT staff can take advantage of the greater DHCP functionality in Windows Server.
File and Storage: Having a file server for your company is another common use. This allows you to
keep important data in a central location and set permissions to control who can access which files.
Print Services: If a business has dozens of printers across the building, it's a waste of time for IT staff
to configure them individually for each new workstation. Setting up a print server allows you to
easily map printers to computers and reduce redundant work.
Windows Update Services: Often, businesses don't want all Windows updates to come through
right away. By setting up a server as a Windows Update controller, you can route all workstation
updates through that server and configure specific rules for how they should work.
These are only a few of the server roles Windows Server can handle. Often, a company will have more than
one server and split the above roles across multiple devices.
Standard copies of Windows don't include these capabilities out of the box. You can install some third-
party tools to replicate some of this functionality, but it won't be as robust.
Most people don't worry about the maximum amount of RAM they can put in their computer. A 64-bit
installation of Windows 10 Pro allows you to install up to a huge 2TB of RAM. However, the majority of
users don't have more than 32GB of RAM in their systems, so even installing 1TB of RAM is far out of the
question.
Knowing this, can you believe that Windows Server supports up to 24TB of RAM? It also allows you to use
up to 64 CPU sockets, which is much greater than the two sockets that Windows 10 Pro supports.
This might sound ridiculous, but there are good reasons for these high hardware caps. A server can power
important functionality for hundreds of people in a business, so it often needs to be extremely powerful.
For instance, a server running dozens of virtual machines needs loads of RAM in order to keep them all
running smoothly at the same time. This points out another important factor of Windows Server: it doesn't
always run on physical hardware. Some businesses purchase a few physical servers, then run many virtual
machines (with Windows Server) on them to handle different functions, like those discussed above.
3
Windows Server Doesn't Include Extraneous Features
As you'd expect, Windows Server retains power user features like the Command Prompt and other
administrative tools. However, Server editions of Windows strip out a lot of the quality-of-life features that
Windows 10 includes.
For example, in Windows Server 2016 and 2019, you won't see the Microsoft Store, Cortana, and
other new Windows 10 features. It doesn't bundle in apps like Your Phone, and even on Windows Server
2019, you have to download Microsoft Edge separately.
Windows Server OSes also don't let you log in with a Microsoft account. Because they're designed for
enterprise use, you don't need these consumer-facing tools on a server OS.
Additionally, some apps check to see if you're using Windows Server before you install them. In some
cases, the app won't work on a server version of Windows.
Windows Server is also much more locked down by default. It still uses Internet Explorer as the default
browser, but the security settings are much more restrictive than usual. This makes sense, as having a
server compromised would be catastrophic, compared to just one workstation.
As you may expect from a business-oriented product, Windows Server doesn't come cheap. It's much more
expensive than a consumer version of Windows, and comes in various flavors depending on your needs.
Microsoft's Windows Server 2019 pricing page gives an idea of what you might pay for the server OS.
Depending on how many people will access the server, you also need to pay for CALs (Client Access
Licenses) to use the services legally.
4
Businesses historically installed Windows Server on a physical onsite server, which has much greater
hardware capabilities than a workstation as mentioned above. However, you also have the option of
running Windows Server in a cloud service like Microsoft Azure.
This allows you to offload the burden of maintaining a physical server to a cloud provider like Microsoft. In
addition, this enables companies to spread the cost of upgrading out over a subscription instead of paying
all at once for a new physical server. What works best depends on the specific organization's needs.
There is an abundance of operating systems available today. According to some statistics, roughly 80% of
all servers use some variation of Linux, while about 20% of servers use Windows.
The stark difference in market share is likely because Linux is free and doesn't require user-based licensing
like Windows.
Each OS has its pros and cons, and its ease of use depends on the user's technical competence level. The
following list is not exhaustive, but it comprises the most common server operating systems.
1. Windows Server
Microsoft developed the Windows operating system family for everyday personal use and professional use
in servers. The Windows Server OS supports enterprise-level management, data storage, and a vast array
or applications.
Windows Server features virtual memory management, a complete desktop GUI experience, allows
multitasking, and supports various peripheral devices. Microsoft usually provides 10 years of support for
Windows Server.
The pros of a Windows server OS are the intuitive GUI, support for symmetric multi-processor systems,
great third-party application support, and many versions to choose from. The cons are the need for user-
based licensing and more virus security threats compared to other platforms.
5
2. Linux
Linux is a family of UNIX-like operating systems that have all the features of UNIX. It is open-source,
available for free, facilitating multi-user, multi-process, multi-thread operations. However, Linux servers
require more technical knowledge - from installation to maintenance and bug fixing.
One of the most common website hosting platforms, the LAMP stack, is based on Linux (Linux, Apache,
MariaDB/MySQL, Perl/PHP/Python).
Ubuntu Server.
Debian Server.
Fedora.
OpenSUSE Leap.
SUSE Linux Enterprise Server.
Arch Linux.
The pros of a Linux server OS are high security, a wide variety of distributions, integrated open-source
software, including high-level language compilers, and the ability to control the system using a GUI.
The cons are the lack of long-term support for some distributions and certain complex operations, such as
system updates.
RHEL is a paid Linux desktop and server distribution created by Red Hat. Initially, RHEL was released as
the Red Hat Linux Advanced Server and later renamed Red Hat Enterprise Linux AS, which included two
distributions - Red Hat Enterprise Linux ES and Red Hat Enterprise Linux WS.
The RHEL source code is freely available, but Red Hat uses strict regulations that limit its official Linux OS
version redistribution. These limitations don't apply to third-party derivatives that don't include the non-
free components, such as Red Hat's trademarks.
Note: In 2021, Red Hat has decided to make its RHEL OS free for small workloads.
The pros of RHEL are the extensive support and available patches, upgrades, and solutions for security
vulnerabilities. The cons of RHEL are expensive training courses and the lack of personalized solutions.
In the beginning, UNIX was a time-sharing operating system for small computers, and over time it has
become one of the most widespread client-server environment operating systems. The UNIX programming
language is C, which facilitated the creation of UNIX ports for many machines.
The pros of UNIX are a multi-user environment, built-in TCP/IP support, and a high level of stability and
security. The downside is that it is paid, and different vendors sell different UNIX versions, so there is no
standard UNIX version.
6
5. NetWare
Novell NetWare is a server-based network operating system that requires a dedicated server to function. It
was a widespread OS in early LANs.
Note: Learn the difference between a dedicated server and a cloud server.
The pros of NetWare are its support for multiprocessors and large-capacity physical memory management,
as well as top-notch file sharing and printing functions in corporate networks. The OS also offers a wide
range of management interfaces, including a Web interface.
The cons are the price, poor support, a challenging installation process, and low third-party app support.
6. macOS Server
The macOS Server is a UNIX-like server operating system based on macOS, developed by Apple. The OS
builds on top of macOS and adds server functionality and system administration tools, as well as the tools
to manage macOS and iOS devices.
The macOS Server is a great choice if you use Mac clients in your network, considering its ability to create
features for Mac clients easily.
The macOS Server pros are easy administration, intuitive GUI, great support, and easy workload
distribution across multiple machines. Thus, it is easy to increase the processing power. The OS comes with
an unlimited user license.
The cons are that macOS Server only runs on Apple hardware, which can be pricey, and there aren't many
third-party applications. Also, while Apple implements open-source software in its system, there are
changes specific to macOS, requiring working around some issues not present in Linux.
7. FreeBSD
FreeBSD is a free and open-source Unix-like operating system. The OS maintains a complete system,
delivering the kernel, drivers, utilities, and documentation, and includes an extensive server-related
software collection. Thus, FreeBSD is easily configured as a mail server, web server, firewall, etc.
FreeBSD has its security team that inspects all the software shipped with the base distribution and allows
the installation of third-party applications from binary packages.
The pros of FreeBSD are that it is fast, completely free, has good security that utilizes the ipfw firewall, and
has a lot of tools available and owned by the FreeBSD Team.
The cons of FreeBSD are that it is not very easy to learn since it has poorer community support than Linux
and lacks driver support.
This section explains which server operating systems best suit your organization based on its size. The
list is not exhaustive, but it shows the best server OS choices.
7
Small
The best OS choice for a small business server depends on the budget, server type, and the maintenance
team's expertise.
If you have a budget that can handle a server OS purchase, a good OS choice is the Windows Server
Essentials (formerly Windows Small Business Server). It is a good solution for companies under 25 users
and a small maintenance team.
The OS features a familiar interface and broad third-party app support at a reasonable price. It facilitates
connectivity and includes email clients, remote access, support for mobile devices, file and printer sharing,
backup and restore, and other features.
If you prefer a free and stable production OS, choose a free Linux distribution, such as Ubuntu
Server or Debian.
Both Linux distributions are very popular and stable, featuring great community and official support. For
example, Ubuntu's LTS (long-term support) releases receive updates for five years.
Note: CentOS is another great Linux distribution. However, official support for its latest version ended in
December 2021, making it unusable for production environments.
Linux requires extensive knowledge, so make sure to have a knowledgeable system admin to handle
configuration and the more complex operations.
Medium
For a medium-sized business, it's essential to choose an OS that allows your business to grow. However,
you don't want heavy investments you may not need.
Because of their scalability, Linux distributions are possibly the best choice for a medium-sized business.
An example is Ubuntu Server, a free, stable, easy-to-install OS with a trusted name. Since it is open-source,
it features extensive customizability, allowing you to tailor the OS to your business needs.
Saving money on an OS means a bigger budget for scaling and implementing security features.
Other solutions that come with a price tag, but are cost-effective, are RHEL and Windows Server Standard
Edition.
Large
Choosing an OS for a large business depends on the server type and its function. For example, a Windows
Server in an Active Directory domain is a good choice for a file server, authentication server, or email
server. On the other hand, both Windows and Linux are good choices for a web server.
For example, the Windows Server Datacenter Edition is a good choice for a highly virtualized datacenter or
a cloud environment. The OS allows for an unlimited number of Windows server instances on a server,
both in physical and virtual environments.
8
On the other hand, SUSE Linux Enterprise Server (SLES) is an open-source operating system. It is designed
for extensive workloads in large data centers, but also for single-server environments. SLES is subscription-
based and provides access to patches, fixes, and security updates through the SLES customer portal.
Microsoft released its Windows NT operating system in two formats: one for workstations and the other
for servers. The 32-bit operating system featured a hardware abstraction layer (HAL), which provided more
system stability by blocking applications from direct access to system hardware. Companies could use
Advanced Server as a domain controller to store user and group rights.
Microsoft updated key networking features in this server release and added integrated support
for TCP/IP and Winsock. Other networking improvements allowed users on other non-Microsoft operating
systems to access files and applications on the domain.
Microsoft fine-tuned this release to boost performance and reduce the amount of required memory. This
server OS was optimized to deliver services faster to users through its updated networking stack. Microsoft
added more connectivity support for companies in a mixed environment with both Windows NT
and NetWare servers to allow users to get services from each with a single credential.
Microsoft borrowed the Windows 95 interface for this server OS release and also used many of the
applications in the client OS, such as the File Explorer. Microsoft expanded the networking protocol
capabilities in this release to make network resources available to a wider array of non-Microsoft
machines. Key features in this release were the ability to use a server as an Internet Information Server --
now called Internet Information Services (IIS) -- and a domain name system server. This server OS also
could walk administrators through various tasks, such as sharing a hard disk with a feature called
Administrative Wizards.
Windows 2000 introduced Active Directory, a directory service that stores and manages information
about network objects, including user data, systems and services. Active Directory lets administrators
perform various tasks, such as virtual private network configuration, data encryption and granting access
to file shares on networked computers.
Microsoft also introduced several other key features in this release, including:
9
Microsoft Management Console (MMC),
Windows 2000 had three editions -- Server, Advanced Server and Datacenter -- that were built to work
with Windows 2000 Professional, the client OS.
Microsoft introduced the "Windows Server" brand with the release of Windows Server 2003 and touted its
security improvements over Windows 2000. Microsoft hardened IIS, the web server feature, and disabled
more default services to reduce exploit opportunities.
Microsoft introduced server roles with this release, which allowed administrators to assign a specific
function to a server, such as domain controller or DNS server.
Other new features in this release included expanded encryption functionality, built-in firewall, greater
Network Address Translation (NAT) support and Volume Shadow Copy Service.
Windows Server 2003 had four editions: Standard, Enterprise, Datacenter and Web.
Rather than a version number, Microsoft began using the R2 -- or release two -- designation with Windows
Server 2003 R2. Organizations always need to buy a new Windows Server license to use the new server
operating system, but R2 releases used the client access licenses (CALs) of the immediately preceding
server version to eliminate the need to upgrade those licenses.
This version improved on the security and safety features in Windows Server 2003.
Active Directory Federation Services, which lets administrators broaden single sign-on access to
applications and systems beyond the corporate firewall.
Active Directory Application Mode, which stores data for applications that may be considered
not secure enough to use in the Active Directory system.
10
This version also added enhancements to file replication and data compression for branch office servers.
Among the security improvements in this release was the Security Configuration Wizard, which let
administrators apply consistent security policies to multiple machines.
failover clustering,
Event Viewer,
Server Core -- the minimal deployment option managed via the command line, and
Server Manager console, used to add and manage server roles and features on local and remote
machines.
Microsoft also overhauled the networking stack and Active Directory to enhance its Group
Policy and identity management capabilities.
Windows Server 2008 came in four editions: Standard, Enterprise, Datacenter and Web.
Microsoft used its Windows 7 kernel for this server operating system and touted its
improved scalability and availability features.
Microsoft enhanced Active Directory for improved handling of user accounts and more granular control
with policies. The company also updated Terminal Services functionality and rechristened it to Remote
Desktop Services (RDS).
New features in this release include BranchCache and DirectAccess, both aimed at improving how users in
remote locations are able to get their work done.
This server OS, like its predecessor, shares some of the administrative and security functionality used in the
Windows Vista client operating system. Windows Server 2008 R2 also marked a change from a 32-bit
server operating system to a 64-bit version.
11
2012: Windows Server 2012
Microsoft embedded a number of cloud-related features to Windows server 2012, going so far as to dub it
the "Cloud OS," so organizations could run services more easily in public or private clouds. The company
also made significant updates to the operating system's storage infrastructure and Hyper-V virtualization
platform.
New features worth noting in this release were the Hyper-V virtual switch, Hyper-V Replica, Storage
Spaces and ReFS file system.
In another change with this release, Microsoft switched the default installation option to Server Core,
which requires administrators to use PowerShell. Upon this release, PowerShell had
2,300 cmdlets available for management.
This server version came in four editions: Essentials, Foundation, Standard and Datacenter. The Standard
and Datacenter editions had the same feature set, but a Standard license permitted organizations to run
two virtual machines (VMs), while Datacenter permitted an unlimited number of VMs.
Microsoft made expansive changes across the board with Windows Server 2012 R2, including significant
updates to virtualization, storage, networking, information security and web services.
Desired State Configuration (DSC) built on PowerShell to prevent configuration drift and
maintain consistency across the organization's machines.
Work Folders allow users to retrieve and save company files on work and personal devices
through replication to servers in the organization's data center.
Microsoft nudged enterprises closer to the cloud with a number of new features tailored to ease workload
migrations, such as support for Docker containers and software-defined enhancements in networking.
Microsoft debuted Nano Server, a minimal server deployment option intended to boost security by
shrinking the attack vector. Microsoft says Nano Server is 93% smaller than a full Windows Server
deployment.
12
Another nod to security comes in the new Hyper-V shielded VM feature, which uses encryption to prevent
data inside a VM from being compromised.
The Network Controller is a key new networking feature that allows administrators to manage
the switches, subnets and other devices on the virtual and physical networks.
This server OS comes in Standard and Datacenter editions. In previous Windows Server versions, the
Standard and Datacenter editions had the same feature set, but different license rights and use
restrictions. In Windows Server 2016, the Standard edition does not have the more advanced features in
virtualization, storage and networking.
In June 2017, Microsoft announced it would split Windows Server into two channels: the Semi-Annual
Channel (SAC) and the Long-Term Servicing Channel (LTSC) -- formerly the Long-Term Servicing Branch.
The SAC caters to enterprises with a DevOps framework that prefer a shorter term between feature
updates to get the most recent updates for rapid application development cycles. SAC releases will come
every six months -- one in the spring and one in the fall -- with mainstream support of just 18 months.
Microsoft tailors the LTSC for companies that prefer the more traditional release cycle of two to three
years between major feature updates with the typical five years of mainstream support followed by five
years of extended support.
The LTSC naming convention will retain the Windows Server YYYY format -- such as Windows Server 2016 --
while the SAC releases will follow a format of Windows Server version YYMM. Microsoft said it plans to add
most of the enhancements -- with some variations -- from the SAC releases into upcoming LTSC releases.
Microsoft released its first SAC release -- Windows Server version 1709 -- in October 2017. Highlights of
this release were support for Linux containers with kernel isolation provided by Hyper-V and a refactored
Nano Server strictly for use as a base OS container image.
Businesses with Software Assurance on their Windows Server Standard or Datacenter licenses or a
Microsoft Developer Network (MSDN) license can download the SAC releases from Microsoft's Volume
Licensing Service Center. Organizations without Software Assurance can use SAC releases in Azure or
another cloud or hosting environment.
13
Windows Server 2019:
Windows Server 2019 is the most used Windows Server version. It was released in October 2018 and
included comprehensive features to meet emerging networking requirements, including the following:
1. Windows Admin Center: The Windows Admin Center was designed to centralize server
management. It also includes several tools IT teams can use daily for things such as
configuration management, performance monitoring, and managing services running on
different servers.
2. Hyper Converged Infrastructure (HCI): Microsoft moved to virtualization after adding
Hyper-V in Windows Server 2008. VMs in the latest Windows version included enhanced HCI
features built to give network administrators the ability to manage virtualized services.
3. Microsoft Defender Advanced Threat Protection: One of the major concerns of businesses
today is cybersecurity, particularly advanced persistent threats. Attackers use whaling, spear
phishing, and social media profiling to gain entry to the network, and antivirus systems can
help prevent these attacks. This provides advanced threat protection against emerging
cyberattacks. Microsoft released Microsoft Defender ATP as part of Windows Server 2019. It
not only monitors accounts for suspicious activity but tracks the activities of users, prevents
unauthorized changes, and automatically investigates attacks. It also provides options for
remediation.
This version was part of Microsoft's semi-annual release cycle for Windows Server, focusing
primarily on delivering new features and enhancements in containers, Kubernetes, and hybrid
cloud scenarios.
Another semi-annual release focused on incremental updates and improvements, particularly in the
areas of containers, Kubernetes, and hybrid cloud integration.
This release introduced enhancements to Windows Subsystem for Linux (WSL) 2, improving
compatibility and performance for running Linux containers on Windows Server.
It also included updates to container networking and Azure Kubernetes Service (AKS) integration.
Similar to the previous semi-annual releases, this version brought incremental improvements and
updates, focusing on performance optimizations and reliability enhancements.
14
Improved hybrid capabilities with Azure Arc integration for managing servers across on-
premises, multi-cloud, and edge environments.
Increased scalability and performance improvements for virtualization, storage, and
networking.
Enhanced management experience with Windows Admin Center updates and integration
with Azure services.
Editions:
Standard Edition
Datacenter Edition
Microsoft continues to provide regular updates, security patches, and support for Windows Server
versions through the Windows Server Semi-Annual Channel (SAC) and the Long-Term Servicing
Channel (LTSC). It's essential for IT professionals and administrators to stay updated with the latest
releases, features, and security patches to ensure the efficient operation and security of Windows
Server environments.
Top performance metrics to monitor for Windows Server
The top performance metrics to monitor for Windows Server performance include the following:
o CPU utilization: Regular CPU monitoring can be crucial for analyzing the CPU load and overcoming
performance issues. CPU usage and monitoring statistics help identify outages and more, so you can
more easily drill down to the root cause of downtime or CPU spikes to better ensure high
performance.
o Memory utilization: Memory usage monitoring helps identify underused and excessive use of
servers and server overloads to redistribute loads more effectively.
o Processor queue length: The processor queue length can be defined as the number of threads each
processor serves. Continuously monitoring these processors can help you find out whether a
processor can optimally handle the number of threads.
o Disk usage with a capacity plan: Getting an idea of disk usage can be critical for your system to keep
track of irregular or sudden spikes. Measuring these metrics can help you plan and tab disk
utilization and resolve the issue before it becomes critical and affects your server's overall
performance.
o Top process by CPU and memory: It is important to analyze the CPU usage to get an insight into
how much load is being placed on the servers’ processor at any given time. Based on this data, you
can solve performance problems by adding more CPU's, upgrading the hardware or shutting down
unnecessary services.
Windows Server performance monitoring refers to different processes through which you can accurately
measure key metrics. With the basic built-in tools in Windows Server, you can analyze and troubleshoot
common issues such as CPU, memory, hard disk, and more. However, you need third-party tools to
monitor your Windows Server, measure critical metrics, and identify issues.
Let's look at some monitoring best practices to help ensure your server is efficient, accurate, and useful.
15
o Define a baseline: A best practice is to keep track of your server activities. Make sure you have set
baselines and measurements for performing a system-level analysis by examining the entire system,
not just a single metric or component at a time.
o Monitor consistently: Windows Server performance monitoring should be done consistently.
Monitoring processes can help you watch critical components and their metrics. You can also
automate and schedule monitoring processes to look for errors and server downtime.
o Use tools: Measuring specific performance statistics and monitoring relevant metrics can be crucial
to pinpoint problems. Organizations may utilize various tools such as patch management to
automate the most strenuous processes, helping their servers stay up-to-date, checking for failed
patches, and quickly fixing issues.
o Introduction to Active Directory
Understand the purpose and role of Active Directory in a Windows environment.
Learn about the components of Active Directory, including domains, forests,
domain controllers, and objects (users, groups, computers).
Active Directory:
Microsoft Active Directory, simply put, is a database and a directory service. It is an identity and access
management solution that allows you to define who can do what in your network. Enterprises rely on
Active Directory to efficiently manage their networks.
As a database, Active Directory allows you to store user information such as emails, phone numbers, and
passwords. As a directory service, it allows users to authenticate themselves to access a resource and
authorizes access for users in the network itself.
1. Container objects can contain other objects – just like a file folder can contain other file folders or
files. Container objects include security groups and organizational units.
2. Leaf objects are individual objects that don’t contain other objects – just like a file can’t contain
other files. All single objects – user accounts, computers, and printers – are types of leaf objects.
So, you know that objects are the network resources – but what about the detailed info for each object?
16
Each object will have a set of values that define what the object is. For a user account, the values will
include things like department, employee ID, and contact information.
An easy way to visualize what the objects and values are is to compare Active Directory to the “contacts”
app on your mobile device. On your phone’s “contacts” app, your individual contacts are like the objects on
AD. And the contact information for each contact – phone number, email address, and notes – are like
the values on Active Directory.
Active Directory offers the following services to secure and maintain your
organization's network.
Active Directory Domain services (AD DS) is the fundamental and primary directory service in a
Windows domain. The domain controller that hosts AD DS stores and authenticates network
resources. AD DS oversees replication and communication between domain controllers in the
network.
Active Directory Lightweight Directory Services (AD LDS) provides directory services to
applications independent of Active Directory and its restrictions. It can also be run as a stand-alone
directory with multiple AD LDS instances.
Active Directory Federation Services (AD FS) facilitates federated identity management and single
sign-on access to applications.
Active Directory Certificate Services (AD CS) acts as a Certificate Authority and provides public key
infrastructure functionality in your Active Directory environment.
Active Directory Rights Management Services (AD RMS) uses information rights management to
manage and restrict access to documents in your Active Directory network.
A domain is a group of objects, such as users or devices, that share the same AD database.
Domains have a domain name system
17
A tree is one or more domains grouped together. The tree structure uses a contiguous
namespace to gather the collection of domains in a logical hierarchy. Trees can be viewed as trust
relationships where a secure connection, or trust, is shared between two domains. Multiple
domains can be trusted where one domain can trust a second, and the second domain can trust a
third. Because of the hierarchical nature of this setup, the first domain can implicitly trust the third
domain without needing explicit trust.
A forest is a group of multiple trees. A forest consists of shared catalogs, directory schemas,
application information and domain configurations. The schema defines an object's class and
attributes in a forest. In addition, global catalog servers provide a listing of all the objects in a forest.
According to Microsoft, the forest is Active Directory's security boundary.
Organizational Units (OUs) organize users, groups and devices. Each domain can contain its
own OU. However, OUs cannot have separate namespaces, as each user or object in a domain must
be unique. For example, a user account with the same username cannot be created.
Containers are like OUs, but Group Policy Objects cannot be applied or linked to container
objects.
Active Directory stores information about network users (names, phone numbers,
passwords, etc.) and resources (servers, storage volumes, printers, etc.) in a
hierarchical structure consisting of domains, trees, and forests.
A domain is a collection of objects (e.g. users, devices) that share the same
Active Directory database. A domain is identified by a DNS name like
[Link].
A tree is a collection of one or more domains with a contiguous namespace
(they have a common DNS root name like [Link],
[Link], and [Link]).
A forest is a collection of one or more trees that share a common schema,
global catalog, and directory configuration—but aren’t part of a contiguous
namespace. The forest typically serves as the security boundary for an
enterprise network.
Objects within a domain can be grouped into organizational units (OUs) to simplify
administration and policy management. Administrators can create arbitrary
organizational units to mirror functional, geographical, or business structures, and
then apply group policies to OUs to simplify administration. OUs also make it easier to
delegate control over resources to various administrators.
18
Active Directory also includes:
A set of rules, the schema, that defines the classes of objects and
attributes contained in the directory, the constraints and limits on instances
of these objects, and the format of their names. For more information about
the schema, see Schema.
A query and index mechanism, so that objects and their properties can
be published and found by network users or applications. For more
information about querying the directory, see Searching in Active Directory
Domain Services.
What is a domain?
These terms are all about computer networking, the way that computers communicate with one another
across a network. Let’s start with understanding what a domain is. If you use a domain, you will have one
centralized database that’s on a domain controller. In fact, you might even have more than one domain
controller. All user accounts, machines, and even additional hardware like printers etc will be registered
with the domain controller. You can have as many devices as you want that are all within the same
19
domain, and they could even be in different locations, enabling remote working while keeping the same
security rules or corporate policies for all assets and employees.
The main purpose of a domain managed by a domain controller is so that an IT admin or service can
control the network, including any security issues and permissions all from one centralized location. When
a network administrator makes a change to one device, it will be automatically made for all of the other
devices that exist within the same domain. It also allows users to collaborate and share equipment and
assets with greater ease. If a user has credentials to a specific domain, they will be able to use any machine
without necessarily having an account for a specific computer or device. You can immediately see how for
a large or complex network, this will save a lot of time, admin and overhead.
What is a workgroup?
A workgroup is a whole different ball game from using a domain. A far simpler one. Within a workgroup,
no computers have any control over the behavior, permissions or security of any other computer inside the
workgroup. Instead, they share common responsibilities and resources with a peer-to-peer (P2P) model.
This means any computer could start a communication session, and could operate as either the client or
the server in the communication, and they communicate over a Local Area Network (LAN). Every device or
asset inside the workgroup needs to be connected to the same LAN or subnet.
Unlike in a domain, a LAN is usually limited to a smaller physical area, usually an office or facility like a
manufacturing plant, a hospital, or a school or university. Within a workgroup, each computer will have
user accounts which are accessed using account credentials. Just because an employee works in the same
facility and shares resources like printers, files and folders, or security technologies, that doesn’t mean that
they can use the shared workgroup to access other devices. Each device will have its own dedicated
storage.
There is also a limit to the number of devices that there will be within a workgroup, usually between 10
and 20.
What are the practical differences when thinking about domain vs workgroup?
If you’re looking for a way to easily control a whole logical group of assets or computers, then you’ll need
domain functionality through a domain controller. In a workgroup, all computers only communicate as
peers, and therefore you cannot simply update one machine and expect to see the changes reflected
across the whole group.
Another difference is to do with user accounts, as on a domain any user can log in to any specific computer
within the same domain, and in a workgroup each computer has its own account alongside specific
credentials, and no user can access a device that is not their own.
There are also practical differences between domain vs workgroup. A domain can be distributed anywhere
in the world, while in a workgroup there will be small coverage over a specific geographic area. There’s also
the clear difference of capacity. A workgroup is very limited in number of users, while a domain can work
for hundreds of users/devices.
20
Do I need a workgroup or domain for my IT environment?
As an MSP or an IT professional, you might be considering how to manage a specific network of computers
and other networking devices, and whether to choose a workgroup or a domain. The following table might
help you to make the right choice for your business requirements.
The results are in! While a workgroup is the best choice for small businesses that don’t need to cross
locations or rely on centralized management and control, you’ll want to start thinking about using a
domain for your computers and other devices if you’re ready to take the next step in business growth.
While a domain is more complex and expensive to set up, it will allow for tighter security, and provide a
higher level of control for the network administrators to manage devices across the network with ease.
An Active Directory (AD) tree is a collection of domains within a Microsoft Active Directory network. The
term refers to the fact that each domain has exactly one parent, leading to a hierarchical tree structure.
A group of AD trees is known as a forest. Domains within the AD tree structure have a transitive trust
relationship, meaning that if a domain joins a tree, it automatically trusts all the other domains in that tree.
Active Directory is Microsoft's directory service that stores and organizes information about objects, such
as network resources, shared folders, files and users. It also enables the domain controller to authorize
and authenticate users looking to access system resources.
There are various objects or physical entities in the network's AD. Two such objects are AD tree and AD
forest.
21
An AD tree typically begins with a single parent or root, and branches out into multiple peripheral child
domains. The domains in the AD tree share the same namespace, and also share a boundary with each
other. Two different trees cannot share one namespace.
When a new domain is added under another domain in the tree, a parent-child relation is created between
the existing domain and the new domain.
All domains in the tree share a common structure/configuration and a common global catalog.
The global catalog acts as a repository of data about objects in the tree.
Multiple child domains have the same configuration to form the common namespace.
Whenever a new domain joins a tree, a two-way relationship builds among the domains of the
tree. All domains in the tree trust each other.
Domain. A logical group of network objects that share an AD database. Each domain is parented by one
parent.
Trust relationship. Trust is automatically built between parent and child domains, and between domains in
the AD tree. Users in different domains can use these trusts to access resources in another domain.
Global catalog server. The server contains partial information about every object in the AD forest. It
enables users to find resources in any domain in the forest.
Organizational units (OU). These are containers that hold AD objects like users, computers, printers and
shared folders, and are used to set security policies and delegate administrative control.
22
Cross-domain resource access configuration in Active Directory
Consider a parent domain [Link]. Any child domain in the parent [Link] domain will have a specific
name that is appended by the parent domain name. For example, a child domain can be [Link],
[Link], [Link] and so on.
A child domain can also have multiple domains established under it. For instance, the child domain
[Link] can have [Link], [Link], etc.
23
The AD tree is a collection of one or more domains sharing a contiguous namespace and is linked in a
transitive trust hierarchy. A forest is a collection of trees that share the same characteristics like a global
catalog, directory schema, directory configurations and logical structure.
In a tree, communication within domains occurs as either one-way or two-way trust. However, an object in
one forest can only communicate with an object in another forest if the two forests have forest-level trust.
An Active Directory forest is the highest level of organization within Active Directory. Each forest shares a
single database, a single global address list and a security boundary. By default, a user or administrator in
one forest cannot access another forest.
AD forests can be used to isolate Active Directory trees with specific data and give autonomy to the user to
interact with the data. Several models for AD forests exist, all with advantages and disadvantages
depending on organizational needs.
The first step in creating a new Active Directory domain forest is to install Windows Server. After doing so,
the Active Directory Domain Services role and the DNS Server role needs to be deployed. Once these roles
have been installed, the user can promote the server to a domain controller.
When the option to promote a server to a domain controller has been chosen, Windows launches the
Active Directory Domain Services Configuration Wizard. This wizard's initial screen provides an option to
create a new forest. The user can simply choose this option, specify a root domain name and follow the
remaining prompts.
The primary advantage to creating an Active Directory forest is that the forest acts as a centralized
mechanism for managing and controlling authentication and authorization across the organization.
Administrators can create user objects (user accounts) within the Active Directory. These user objects act
as security principals, meaning that the Active Directory can authenticate logins.
Additionally, group policy settings can be applied at various levels of the Active Directory hierarchy to
enforce user account or computer configurations. For example, group policy settings can be used to
enforce password length and complexity requirements for user accounts.
24
Administrators are also able to create security groups within the Active Directory. These security groups
act as collections of user objects and play an important role in data security. Security groups are typically
linked to the access control lists associated with folders and other resources, thereby granting permissions
to group members.
Disadvantages include security vulnerabilities, such as the possibility for more exploitation. While using a
multi-forest design could be an option, it is not secure by default because it still requires setup for
permissions and authentication for each forest. Multi-forest designs also increase costs. It's recommended
to consolidate AD forests as much as possible to reduce cost.
Active Directory forests can be constructed according to several different architectural models, including:
The simplest of these models is the organizational forest model. In smaller organizations, this model
establishes a single AD forest that contains all the organization's resources. Larger organizations may have
a separate Active Directory forest for each department or division. Creating multiple AD forests provides an
isolation boundary between departments. If collaboration is required between departments, a forest level
trust can be created.
A second type of forest model is the resource forest model. In this model, user accounts are created within
an organizational forest. Separate forests are created to accommodate the resources related to individual
departments, divisions or projects. These resource forests do not contain user accounts aside from those
required for administrative purposes. Instead, trust relationships allow users from the organizational forest
to access resources in resource forests. Resource forests are a good choice for helping to isolate problems.
An Active Directory problem occurring in one resource forest will not affect another resource forest
because of the forest level boundaries that are in place.
A third forest design model is the restricted access forest model. The This model involves multiple forests,
with no trust relationships between them. The users in one forest cannot access any of the resources in
another forest. This design is used in high-security environments because it creates extremely strong
isolation boundaries.
25
Flexible Single-Master Operator (FSMO) roles.
AD allows the possibility of maintaining a writable copy of its own domain’s partition. To put it simply, it
replicates automatically whatever changes are made to your domain controller to your other domain
controllers. This process is called multi-master replication. This allows most of the operations to be
processed reliably by multiple domain controllers and so it provides high levels of redundancy, availability
and accessibility in your Active Directory. With all of these capabilities, you have to apply some exceptions
to some AD operations that are highly sensitive or simply restrict them to a specific domain controller. This
is where Flexible Single-Master Operator (FSMO) roles.
Before we discuss these five roles, let’s give you an overview of how FSMO roles work. In every forest,
there is a single Schema Master and a single Domain Naming Master. In each domain, there is one
Infrastructure Master, one RID Master and one PDC Emulator. However at any given time, there can be
only one DC performing the functions of each role. Therefore, a single DC could be running all five FSMO
roles; however, in a single-domain environment, there can be no more than five servers that run the roles.
Schema Master – Schema Master is an enterprise-level FSMO role; there is only one Schema
Master in an Active Directory forest. The Schema Master role owner is the only domain controller in
an Active Directory Forest that contains a writable schema partition. As a result, the DC that owns
the Schema Master FSMO role must be available to modify its forest’s schema. Examples of actions
that update the schema include raising the functional level of the forest and upgrading the
operating system of a DC to a higher version than currently exists in the forest.
Domain Naming Master – Domain Naming Master is an enterprise-level role; there is only one
Domain Naming Master in an Active Directory Forest. The Domain Naming Master role owner is the
only domain controller in an Active Directory Forest that is capable of adding new domains and
application partitions to the forest. Its availability is also necessary to remove existing domains and
application partitions from the forest. The Domain Naming Master role has little overhead, and its
loss can be expected to result in little to no operational impact, since the addition and removal of
26
domains and partitions are performed infrequently and are rarely time-critical operations.
Consequently, the Domain Naming Master role should need to be seized only when the DC that
owns the role cannot be brought back online.
Relative ID (RID) Master – Relative Identifier Master (RID Master) is a domain-level role; there is
one RID Master in each domain in an Active Directory Forest. The RID Master role owner is
responsible for allocating active and standby Relative Identifier (RID) pools to DCs in its domain. RID
pools consist of a unique, contiguous range of RIDs, which are used during object creation to
generate the new object’s unique Security Identifier (SID). The RID Master is also responsible for
moving objects from one domain to another within a forest.
PDC Emulator – The Primary Domain Controller Emulator (PDC Emulator or PDCE) is a domain-level
role; there is one PDCE in each domain in an Active Directory Forest. The PDC Emulator controls
authentication within a domain, whether Kerberos v5 or NTLM. When a user changes their
password, the change is processed by the PDC Emulator.
Creating AD users:
In this lesson, I'll be showing you how you can create Active Directory user accounts.
Now, I am picking it up right where I left off in the last lesson and I have the Active Directory console open.
If you know how that opens, you are following along in the IT lab, go ahead and open it now.
ADUC Console
What I am going to do is expand my domain [Link] and I want to mention right away that
it's extremely important that you create the Active Directory user account in the right location. If you
created the AD user in the wrong spot that means they could get the wrong set of Group Policy security
settings. So, just to explain this a little bit more, we have a full course at [Link] for Group
Policy. We are not going to get deep into it in this course, but, if I have an Organizational Unit, Server
Academy, which you'll notice almost every organization has this, they'll have a Domain and then they'll
have an OU that kind of mimics the same name, so I have [Link]. Up here is my domain
and I have an OU for that where I am going to put ALL of my domain infrastructure.
27
ADUC Server Academy OU Structure
So, I have Domain Admins and Domain Users. Now, it's possible that they'll be different Group Policy
objects applied to this OU versus this OU. So, Domain Users and Domain Admins will get different security
settings than Users in Domain Users.
28
ADUC Domain Users
That's important because you don't want to create a user in the Domain Admins if they are not supposed
to be a Domain Admin because you don't want them to have more access than they should, okay? This all
again would have to go back to how Group Policy and how is configured for your Domain, and you really
don't know that until you open the Group Policy management console, but I just want to stress that it is
important we create the AD users in the correct location.
If you guys are starting an IT job, I don't want you taking this training and then creating all your users under
the root of the domain or in the Users container worst of all. We want to create everything in the Server
Academy Organizational Unit where they belong.
Now, again, this is going to differ from every enterprise, so not all are going to have the same layout here,
this OU I created manually, and I created these OUs specifically for this IT Lab because this is generally how
I see it setup. But just note that it may be different in your workplace, and if you are not sure just ask. It
never hurts to ask and that's going to be something that everyone is going to expect you to act before you
just go out and figure it out on your own.
Now, with that being said there are a couple of different ways we can create a user. I am going to choose
the Organizational Unit where I want to create the user account. In this case, we’ll create it under Domain
Users, and we can select the New User button up here. We can right-click on the OU and choose New
User. Or we can right-click once we've opened the Organizational Unit and select New User.
29
ADUC New > User
I am just going to choose this one, and a new pop-up will appear, and what we are going to do here is just
type in the information of the user. I am going to use myself so that will be Paul Hill, and well call
it [Link] as my username. Generally, I like to use first name dot last name but every company is going to
have a different naming convention for their user accounts. If you are not sure just take a look at the other
user accounts and see how they are naming their users and hopefully there's some kind of standard or
convention and you can follow that.
30
New Object - User Information
Once I have that defined I am going to go ahead and click Next and I’ll type and confirm the
password here.
31
Now, when the user logs in to this new account that we created for them they may get a prompt that says
"You must Change Your Password" forcing them to create a new password at login. This is a good idea
because generally when you are creating a password you are going to use the same password for every
user. That's probably a bad practice, you probably shouldn't do that, but it's a very common thing for
people to do. Enforcing users to change their password as soon as they log in, this is a good idea.
The next two options are security vulnerabilities you'll be introducing to your network if you check them.
The first is, "User cannot Change password", and this simply means that they never have to change their
password. Again, this is a very bad idea because changing your password makes your network more
secure.
"Password Never Expire", this the same thing their password won't expire, so they can continue to log in
using that old password and this is just a bad idea. Every user should be changing their password every 60
or 90 days and you should not be using a single password for every account, especially not for privileged
accounts. Now, I've seen this done for service accounts. But again, is a terrible idea. All these account
passwords should be getting rotated on a regular basis.
32
New Object - New User Account Summary
So, what we are going to do is just click Next and it gives us a summary here of what we are doing. Full
Name Paul Hill. User logon name, it gives me the full username as well as the fully qualified domain name.
Now, they can log in with this but they can also just specify [Link] to login. It gives us another synopsis
here "The user must change the password at the next logon." and "The account is disabled."
What we are going to do now is go ahead and click Finish, and now we have this user account listed here
Paul Hill.
And, you'll notice there's a little down arrow icon over here and that simply means the account
is disabled so if I right-click on this I am able to enable the account.
33
Paul Hill Enable User Account Object
Now it says the "Object Paul Hill has been enabled." and the account can be now logged into. If we let that
disabled if a user tries to use it will say the account is disabled even if they have the right username and
password but now since I enabled, it that account is ready to go.
34
ADUC Reset Password
However, if I was to refresh this Organizational Unit, and again, we are going to get this message here that
says, "2000 of approximately 4648 items were retrieved."
Now, this is because is trying to improve the performance so not all the user accounts were listed. So, I
may or may not be able to find my user account Paul Hill. So, if I hit the first letter on my keyboard, P, and
scroll down and look for Paul Hill, I am not going to see it in this list, and that's because not all user
accounts were retrieved. So, what we have to do is use the Find objects in Active Directory button. What I
need to do is type in the name of the user account and just hit Find Now and now I can see the user
account that I am looking for.
35
Find User Account Paul Hill
Now, one thing I want to point out is if I am in a different Organizational Unit, say I am on
the Users container and I do the exact same process, it will not work, meaning there will be no users
returned in the list here.
36
find User Account Paul Hill in the Users Container
And that's because we have to change what we are searching in. Right now it says, Users. So our option is
to choose for [Link] the Domain or the Entire Directory. You might be wondering, what's
the difference between these two, and we'll explain just in a second, but let's just choose the Domain and
hit Find Now.
37
Find User Account Paul Hill in the Domain
Now the user account is listed. We can also click Browse and we can expand this Server Academy OU and
select Domain Users, hit Find Now and now the user will be listed.
Now, what we want to do, nine times out of ten, you are going to get a phone call or you are going to get a
ticket that says "Hey, I need my password reset. I don't remember how to log in" or "I can't log in, I am
getting failed login attempts". So, there could be a couple of things that's going on here. The account could
get locked out, in which case we’ll have to unlock the account, and we just need to unlock the account or
will need to reset the password.
What I am going to do, if I know that I need to change the password, that is, they don't know the old
password and they need a completely new one, right-click the User and choose Reset Password. Now we
are going to type in the password that we want them to use, and we are going to say allow the user to
change the password at the next logon. Again, if somebody is connecting through a VPN or something like
that, you might want to uncheck this check box.
But, if they fail to log in a certain number of times, and your domain is configured this way, their account
may be locked for security reasons. This will tell you right here, "Account Lockout status on this Domain
Controller: Unlocked". That means I would not need to check this check box. But if somebody fails to log in
a certain number of times, this may say it's locked, and that means even if they did get the right password,
they will not be able to log in to this account. And this kind of stuff happens when somebody accidentally
presses the CAPSLOCK, and they don't realize it. Maybe they know their password, but they were just not
typing it correctly. In that case, we would just want to unlock the account not reset it, but we will talk
about that, the details of that in just a moment.
So, what I am going to do now is just click OK. And, it says The Password for Paul Hill has been changed.
Now, if we just need to unlock the account what I would do is right click the User click Properties go
to Account and check to uncheck the account. Again, here it will say that the account is locked out if it is
39
and all I would need to do to unlock it is select Apply and hit OK. And I can tell them "Hey your account is
unlocked go ahead and log in".
Now, that brings up one last fact that I would like to or one thing I would like to bring to your attention.
When you are working inside Active Directory you are holding the security of your domain in your hands,
so you need to make sure that whoever you are talking to is the actual owner of the active directory
account. You don't want to have a hacker call you and say "Hey, I can't get into my account, and you don't
want them talking to you and giving access to somebody else's account.
So, you can do things like opening an Active Directory user account, you can look up their address if they
have that information. You can ask them what their username is, and you can ask for what email address
they have, telephone number, and things like that to verify their identity. You may have other measures in
place to verify somebody's identity but you need to make sure before you reset a password for somebody
especially over the phone or over email that they are who they say they are before you do it.
Finally double-check you have the correct account, this will happen to you, I promise, I don't want it to, but
it probably will happen to you when you reset the password for the wrong user. For example, maybe
there's just, a search for Sam. I don't know who is here but we will search for Sam.
40
Find a Sam User Account
So maybe there's a Samar and he says "Hi, my name is Samar and I need my password reset, and you just
type in Samar, and you just picked the first one right? Maybe you picked Beck and the person on the phone
is Patel. You don't want this to happen when you are resetting the wrong user password, ok? So, make sure
you are checking and double-checking what passwords you are resetting because there is nothing worse
than you know, getting a call, you are going to fix an issue and instead you created another issue, hang up
the phone and now you have two unsolved issues, alright. So got to be really careful here when you are
resetting passwords.
Now, an Organizational Unit are these so-called folders that you see up here that contain Active Directory
Objects.
41
Active Directory Users and Computer Objects
Now, it gets kind of complicated because not all of these are OUs like Bultin, Computers, and
ForeignSecurityPrincipals. These are not necessarily Organizational Units but rather Containers.
This gets into the out of the scope of this fundamentals course. We have all this detailed out in the Active
Directory Course. If you are interested in that, please refer to the Active Directory in the Windows Server
Course. We are getting into a lot more detail there, but just for now know that an OU has a different icon,
so you can identify the OUs because you will see the icon slightly different here, this is an OU and these are
rather Containers. Also, Organizational Units can receive Group Policy Objects directly attached to them.
42
Now, that probably went right over your head, again, it kind of goes beyond the scope of what I can explain
just in this course. We do explain it inside of the Group Policy and the Active Directory courses.
Now, what I am going to do is create an Organizational Unit under Server Academy and I will just right-
click the OU and select New > Organizational Unit.
43
New Object - Organizational Unit
So, now we have this Organizational Unit here. If I try to Delete this OU, we are going to get an error
message that says You do not have sufficient privileges, or this object is protected from accidental
deletion. You remember when we checked that check box it was enabled.
44
Active Directory Users and Computer - Turn On Advanced Features
And, then I can re-navigate over here to Disabled Users, right-click and choose Properties and I am going
to go under Object and uncheck this Protect this object from accidental deletion. I'll hit Apply.
45
Disabled Users Properties tab
And now if I right-click on this OU I can click Delete and I am able to delete the Organizational unit. I am
going to turn off Advanced Features and I am just going to recreate that Organizational unit because we
want to use this Disabled Users OU in a future lecture. So, I am naming it Disabled Users and I'll click OK.
Now, we created this Disabled Users OU, currently, there are no users in this. So, let's go ahead and
disable the Paul Hill User account. Now again, to do this, we are just going to hit the Find button up here
and we are going to search for Paul Hill, and we are going to click Find Now.
46
Find Contacts, Users, and Groups window
Again, nothing is showing up because I need to change the OU that I am searching In, and I'll just select
the domain and hit Find Now.
Find Contacts, Users, and Groups window - Paul Hill User Account
Here we have the Paul Hill user account. Now, what I am going to do is right-click and choose Disable
Account.
47
Find Contacts, Users, and Groups window - Paul Hill User Account
Now, if anybody tries to access this user account they are going to get a message saying "Sorry, this
account is disabled you can't log in with it".
It's a good practice to move this user out of the Domain Users OU and put it in the Disabled Users OU. This
is because it allows you to kind of double-check your work, meaning that, if you want a user account to be
disabled it should be in this OU. That way if an account for some reason is not disabled but is in this OU, we
probably know that that account should be disabled. We can also write automation with PowerShell to
comb through it and disable any user account that is inside this OU. There's a lot of automation we could
do using this kind of setup, but what we are going to do since we disabled it is to right-click the User and
choose and we are going to choose Move. Next, we select Server Academy and we are going to
select Disabled Users and will hit OK.
48
Find Contacts, Users, and Groups window - Move object into a OU
So now if I close this and I Refresh this view here, now we have this Organizational Unit, Disabled Users,
and our disabled user Paul Hill is here. Again, if I click Enable Account and I look through this list and I see
Paull Hill is not disabled and it is in this OU then I probably know that it should be disabled. Or maybe it
was placed in this OU by accident.
Again, we can also create Group Policy Objects and apply policies that do things like, do not allow login to
the computers or things like that if they are in this OU, just is an added layer of security. Just in case
somebody does mean to disable the user account but they don't actually hit Disable Account.
49
Find Contacts, Users, and Groups window - Disable Paul Hill User Account
Now, if we want to delete an account you would disable the account for a certain period of time like
maybe 30 days or 90 days, and then you will delete the account. And, I have seen this done by simply going
to the Telephones Tab and adding a note saying I disabled this account on whatever today date is today.
So, to delete an account we are simply going to click and we are going to choose Delete. Now, keep in
mind that with most things in Active Directory you cannot easily undo things that you delete, okay, so is
very important that when you are deleting something you are very very careful.
So I am just going to say Do you want to delete the user Yes. And, now that User account has been deleted.
An Active Directory user object, or an AD user object, represents a real user who is part of an
organization’s Active Directory (AD) network. It is a leaf object, which means it can’t contain other AD
objects within itself. The user may be an employee of the organization such as a manager, HR person, or an
IT administrator who generally has elevated permissions over other users. A user object is a security
principal, which means that it would have a security identifier (SID) apart from a global unique identifier
(GUID). A user object in AD has attributes that contain information such as canonical name. first name,
middle name, last name, login credentials telephone number, manager who he or she reports to, address,
who their subordinates are, and more.
Adding a user to the network can be done using the Active Directory Users and Computers (ADUC) console.
For example, Joshua is a new employee in an organization, and the administrator needs to provide him
access to various resources of the organization. All that the administrator has to do is create a user object
through the Active Directory users and Computers console, and then assign access permissions to the user
object representing Joshua. Depending on the permissions the administrator assigns to the user object,
Joshua’s would get his access to the resources that is necessary for him.
50
Mandatory AD user object attributes
Every object has a set of mandatory and optional attributes. The values for the mandatory attributes are
required for the successful creation of the object, and cannot be empty. For example, the mandatory
attributes for a user object are:
cn: The distinguished name of the user object that is used to uniquely identify this object in the AD
network
ObjectCategory: This is a single value property that contains the distinguished name of either the
object class this user object belongs to, or the distinguished name of one of its superclasses.
Objectclass: The distinguished name of the object class that this user object belongs to.
sAMAccountName: The pre-Windows 2000 logon name of the object. This is a naming attribute
that is also used to identify this user object in the network uniquely.
These attributes are unique across a domain, and they are used to identify the objects across the domain
uniquely.
Go to Start -> Administrative Tools, and click on Active Directory Users and Computers. The ADUC
console will open.
Expand the console tree, and right-click on the user object whose mandatory properties you wish to
see.
From the menu that pops up, click Properties.
A dialogue box will appear that shows the user object’s properties. Select the Attribute Editor tab.
In the attribute editor tab click the Filter button. A submenu with a list of attribute types will pop
up.
From the menu, choose Mandatory.
The mandatory attributes of the user object will be shown.
51
The Attribute Editor Tab displaying the
Mandatory attributes
There are also other attributes that are optional such as telephoneNumber, Manager, and more. An AD
user object can be created without these attributes. These optional attributes are used to provide
additional information about the user that the user object references.
Active Directory (AD) groups enable administrators to bring together and manage a set of users,
computers, or other groups as a single object. Any change an admin makes to a group will be applied to all
the objects within that group, eliminating the need for the admin to deal with individual user or computer
accounts. Groups are primarily used for assigning permissions to AD resources and as email distribution
lists.
Types of groups in AD
There are two types of AD groups: distribution groups and security groups.
What is a distribution group?
Distribution groups are used for sending email messages to a target set of users via Microsoft Exchange or
Outlook. Distribution group membership can be managed based on who will be receiving the messages.
Distribution groups cannot be used to assign permissions to resources.
52
What is a security group?
Security groups are used to grant users, computers, and sub-groups access to resources. The access
permissions assigned to a security group vary depending on the roles of its members. Security groups can
also be used to filter Group Policy settings to a set of AD objects, allowing the admin to have granular
control over the AD environment.
Group scopes
There are 3 scopes for AD groups. A group's scope determines the possible members it can contain, as well
as its visibility across the domains in a forest. The 3 group scopes are:
1. Domain Local
2. Global
3. Universal
What is a domain local group?
Domain local groups are visible only within the domain in which they are created. Users, computers, global
groups, and universal groups from all trusted domains across forests can be members of a domain local
group. They can also contain other domain local groups from within the same domain. Domain local groups
are intended to be used for granting permissions to resources in their domain.
Global groups are visible across multiple domains within a tree. Global groups can contain users,
computers, and other global groups only from within the same domain in which they are created. They are
intended to organize the users or computers in a domain based on the roles they fulfill. For example, a
global group can be created to contain all members of the HR team in an organization.
Universal groups are visible throughout the entire forest. Users, computers, global groups, and other
universal groups from all domains across the forest can be members of a universal group. They are used in
multi-domain environments for assigning permissions to domain-specific resources. A universal group's
membership is stored in the Global Catalog Server (GSC) and replicated across the forest.
A domain local group can be converted to universal scope if it does not contain any other domain
local groups as members.
A global group can be converted to universal scope if it is not a member of any other global group.
A universal group can be converted to domain local scope if it is not a member of any other
universal group.
A universal group can also be converted to global scope if it does not contain any other universal
group as a member.
The table below summarizes how the 3 different group scopes work:
53
Group scope Group members Scope conversion Membership
Can be converted to
domain local scope if it's Can be added to domain
not a member of other local groups and
Users, computers,
universal groups. universal groups in the
global groups, and
same forest
Universal universal groups from
Can be converted to
any domain in the
global scope if it does Can be added to domain
same forest.
not contain other local groups from
universal groups as trusting forests.
members.
54
What is Group Policy in Active Directory?
Group Policy is used to regulate user and computer configurations within Windows Active Directory (AD)
domains. It is a policy-based approach that can be applied to the whole organization or selectively applied
to certain departments or groups in organizations. Group Policies are enforced by Group Policy Objects
(GPOs).
GPOs comprise of the user and computer configuration settings that will be applied to domains or
organizational units (OUs). GPOs need to be linked to an AD unit (domain or OU) to be applicable. Both the
user and computer configuration policies have Software Settings, Windows Settings, and Administrative
Templates. The Windows Settings contain important security policies like password and account lockout
policies, software restriction, and registry settings. Administrative Templates are used to regulate access to
the Control Panel, system settings, and network resources.
As mentioned earlier, Group Policies centralize management of organizational resources. Some Group
Policy examples include execution of login scripts upon startup of a computer, user password settings,
disabling users from changing the system time, and many other user and computer configurations. Group
Policy benefits include:
Wide scope of application: These policies can be applied based on organizational hierarchy by linking them
to AD sites, domains, and OUs.
Ease of management: Group Policy settings can be easily managed via GPOs. Multiple GPOs can be linked
to one domain. A single GPO can be linked to multiple domains. When linked to parent units, say a domain,
the policies are applied to all child units within the domain.
Priority-based application: GPOs have link order precedence, which helps resolve clashing policy settings.
For example, a GPO with link order "1" will take precedence over another GPO with link order "2." Thus,
the GPO with link order "1" will be applied last, overriding all the other GPOs. The link order can be
changed by sysadmins in the Group Policy Management Console (GPMC).
Hierarchical application: Besides link order precedence, Group Policy adheres to a strict hierarchy. Always,
policies are processed in this order: Local > Site > Domain > OU. Further, computer configuration policies
override user configuration policies regardless of link or precedence order. These features ensure that the
most relevant settings for the smallest unit (OU) are pushed.
Group Policies can be categorized into three segments based on where or how they can be applied. The
three types include:
Local Group Policy manages These are an aggregate set of Starter Group Policies
55
Local Group Policy Group Policy in AD Starter Group Policy
are templates to be
used within AD.
policies for individual (non- policies that can be applied to
Sysadmins can create
domain) computers. More all domain-joined computers.
one starter policy and
than one local GPO can be Both user and computer
then go on to create
created for different local configurations for all domain
multiple similar Group
users. users can be managed centrally.
Policies based on the
starter policy.
56