Académique Documents
Professionnel Documents
Culture Documents
Steve Clines
Agenda
1. Active Directory Overview 2. Active Directory Domain Services 3. Active Directory LDS 4. Active Directory Federation Services 5. Active Directory Certificate Services 6. Active Directory RMS
The AD Umbrella
Domain Services
RMS
AD at a Glance
AD DS
AD LDS
AD FS
AD CS
AD RMS
Provides directory-based authentication/ authorization services in support of Microsoft-based networked services and applications
Provides an LDAP accessible directory service that supports identity management scenarios
Provides solution to secure how users utilize content (i.e. Office documents)
RODC Functionality
No rm
al A D
Re p lic
atio n
Main Office
Branch Office
RODC Prerequisites
PDC emulator role holder must be running Windows Server 2008 The replication partner of RODC must run Windows Server 2008 Windows Server 2003 native mode or higher Run ADPREP/RODCPREP on existing forest (if not native 2008) No writeable DC in same domain/site as RODC
Windows Server 2008 Server Core Can install 2008 in two ways
A full installation with full GUI and all available software services A minimal installation supporting command line interface
AD DS AD LDS DNS DHCP File Server Hyper-V Windows Media Services Print Management
NETSH configure network settings NETDOM rename computer/join domain SLMGR Software Licensing Manager OCLIST List the available roles/features OCSETUP Install the DNS roles DCPROMO Turn into DC using an answer file
AD DS Auditing
Previously audited what attribute changed Now audit information includes the previous and new values Now subdivided into four areas
AD DS Auditing
5136 Successful modification to an attribute 5137 New object is created in the directory 5138 Object is undeleted in the directory 5139 Object is moved in the directory
AD DS Auditing
Not turned on by default
Can disable auditing within the attributes schema definition to fine-tune the audit collection (bit 9 in searchFlag property on)
DNS Changes
Support for IPv6 Support for AD-integrated zones on a RODC Background Loading GlobalZone Link Local Multicast Name Resolution (LLMNR)
AD DS is a separate service from LSA DC with stopped AD service is equivalent to a member server
AD Lightweight Directory Services Previously introduced as ADAM Provides an LDAP accessible DS Removes all other AD DS features
No Kerberos authentication No forests, domains, DC, GC No dependency on DNS No site topology No group policies
AD LDS Scenarios
Uses for AD LDS
AD LDS Instances
Each AD LDS server can host multiple directory stores (i.e. instances) Within each instance
AD LDS Replication
Supports multimaster replication through configuration sets
AD FS is a service that allows for the creation of federated relationships between organizations for web application authentication
AD Certificate Services
Not significantly different than CS in 2003 Provides a certificate issuance/revokation services as well as CA service New items
Online Responder Service via Online Certificate Status Protocol (OCSP) Network Device Enrollment via Simple Certificate Enrollment Protocol (SCEP)
AD Rights Management Services Updated version of RMS Management of information usage Supported by Office 2003, 2007 and Sharepoint
Thank You!