Book description
Organize your network resources by learning how to design, manage, and maintain Active Directory. Updated to cover Windows Server 2012, the fifth edition of this bestselling book gives you a thorough grounding in Microsoft’s network directory service by explaining concepts in an easy-to-understand, narrative style.
You’ll negotiate a maze of technologies for deploying a scalable and reliable AD infrastructure, with new chapters on management tools, searching the AD database, authentication and security protocols, and Active Directory Federation Services (ADFS). This book provides real-world scenarios that let you apply what you’ve learned—ideal whether you’re a network administrator for a small business or a multinational enterprise.
- Upgrade Active Directory to Windows Server 2012
- Learn the fundamentals, including how AD stores objects
- Use the AD Administrative Center and other management tools
- Learn to administer AD with Windows PowerShell
- Search and gather AD data, using the LDAP query syntax
- Understand how Group Policy functions
- Design a new Active Directory forest
- Examine the Kerberos security protocol
- Get a detailed look at the AD replication process
Publisher resources
Table of contents
- Preface
- 1. A Brief Introduction
- 2. Active Directory Fundamentals
- 3. Active Directory Management Tools
- 4. Naming Contexts and Application Partitions
- 5. Active Directory Schema
- 6. Site Topology and Active Directory Replication
- 7. Searching Active Directory
- 8. Active Directory and DNS
-
9. Domain Controllers
- 9.1. Building Domain Controllers
- 9.2. Virtualization
- 9.3. Read-Only Domain Controllers
- 9.4. Summary
- 10. Authentication and Security Protocols
-
11. Group Policy Primer
- 11.1. Capabilities of Group Policy Objects
-
11.2. How Group Policies Work
- GPOs and Active Directory
- Prioritizing the Application of Multiple Policies
- Standard GPO Inheritance Rules in Organizational Units
- Blocking Inheritance and Overriding the Block in Organizational Unit GPOs
- When Policies Apply
- Combating Slowdown Due to Group Policy
- Security Filtering and Group Policy Objects
- Loopback Merge Mode and Loopback Replace Mode
- Summarizing Group Policy Application
- WMI Filtering
- Group Policy
- 11.3. Managing Group Policies
- 11.4. Troubleshooting Group Policy
- 11.5. Summary
- 12. Fine-Grained Password Policies
-
13. Designing the Active Directory Structure
- 13.1. The Complexities of a Design
- 13.2. Where to Start
- 13.3. Overview of the Design Process
- 13.4. Domain Namespace Design
- 13.5. Design of the Internal Domain Structure
- 13.6. Other Design Considerations
- 13.7. Design Examples
- 13.8. Recognizing Nirvana’s Problems
- 13.9. Summary
-
14. Creating a Site Topology
- 14.1. Intrasite and Intersite Topologies
- 14.2. Designing Sites and Links for Replication
- 14.3. Design Examples
- 14.4. Additional Resources
- 14.5. Summary
- 15. Planning for Group Policy
-
16. Active Directory Security: Permissions
and Auditing
- 16.1. Permission Basics
- 16.2. Using the GUI to Examine Permissions
- 16.3. Using the GUI to Examine Auditing
-
16.4. Designing Permissions Schemes
-
The Five Golden Rules of Permissions Design
- Rule 1: Apply permissions to groups whenever possible
- Rule 2: Design group permissions so that you have minimal duplication
- Rule 3: Manage advanced permissions only when absolutely necessary
- Rule 4: Allow inheritance; do not protect sections of the domain tree from inheritance
- Rule 5: Keep a log of changes
- How to Plan Permissions
- Bringing Order out of Chaos
-
The Five Golden Rules of Permissions Design
- 16.5. Designing Auditing Schemes
- 16.6. Real-World Active Directory Delegation Examples
- 16.7. The AdminSDHolder Process
- 16.8. Dynamic Access Control
- 16.9. Summary
- 17. Designing and Implementing Schema Extensions
- 18. Backup, Recovery, and Maintenance
- 19. Upgrading Active Directory
-
20. Active Directory Lightweight Directory
Services
- 20.1. Common Uses for AD LDS
- 20.2. AD LDS Terms
-
20.3. Differences Between AD and AD LDS
- Standalone Application Service
- Configurable LDAP Ports
- No SRV Records
- No Global Catalog
- Top-Level Application Partition Object Classes
- Group and User Scope
- FSMOs
- Schema
- Service Account
- Configuration/Schema Partition Names
- Default Directory Security
- User Principal Names
- Authentication
- Users in the Configuration Partition
- New and Updated Tools
- 20.4. AD LDS Installation
- 20.5. Tools
- 20.6. The AD LDS Schema
- 20.7. Using AD LDS
- 20.8. Summary
- 21. Active Directory Federation Services
-
A. Programming the Directory with the .NET
Framework
- A.1. Choosing a .NET Programming Language
- A.2. Choosing a Development Tool
- A.3. .NET Framework Versions
- A.4. Directory Services Programming Landscape
- A.5. .NET Directory Services Programming by Example
- A.6. Summary
- Index
- About the Authors
- Colophon
- Copyright
Product information
- Title: Active Directory, 5th Edition
- Author(s):
- Release date: May 2013
- Publisher(s): O'Reilly Media, Inc.
- ISBN: 9781449320027
You might also like
book
Active Directory Cookbook, 4th Edition
Take the guesswork out of deploying, administering, and automating Active Directory. With hundreds of proven recipes, …
book
Mastering Active Directory - Third Edition
Become an expert at managing enterprise identity infrastructure with Active Directory Domain Services 2022. Purchase of …
book
Mastering Active Directory
Become a master at managing enterprise identity infrastructure by leveraging Active Directory About This Book Manage …
book
Active Directory Cookbook, 3rd Edition
When you need practical hands-on support for Active Directory, the updated edition of this extremely popular …