360 likes | 503 Views
Installing Active Directory. Learning Objectives. Create a Windows 2003 domain Understand the role of DCPromo.exe and the Configure Your Server wizard Promote a member server to a domain controller Demote a domain controller to a member server
E N D
Learning Objectives • Create a Windows 2003 domain • Understand the role of DCPromo.exe and the Configure Your Server wizard • Promote a member server to a domain controller • Demote a domain controller to a member server • Understand the role of the Active Directory database
Learning Objectives • Understand the role of the shared system volume • Understand Active Directory domain modes • Install Active Directory on a Windows 2003 server • Add additional domain controllers to a domain • Change the mode of a Windows 2003 domain
Roles • DC’s • Store the AD database • DC’s are peers • Provide logon, security, and management • Member Servers • Participate in Domain providing services • Do not run AD service • AD Clients
Preparing for AD Installation • Don’t necessarily follow all the defaults when configuring your first Windows 2003 DC • Issues to consider: • IP addressing schemes and DNS • Existing naming convention may be NETBIOS based • Domain context • Relationship to other Domains • AD wizard provides info about existing Domains • If none exist creates a new Domain
Preparing for AD Installation • Possible domain organizations for Texas Pinball and Cattle Company Organized by business function Geographically organized
Installing AD • On a previously configured server, use dcpromo.exe to activate the AD Installation Wizard • Launching • dcpromo.exe • Configure Your Server
Installing AD • You can also use dcpromo.exe to demote a DC to a member server
Creating Windows 2003 Domains • Recall: • Domains - computers sharing a security boundary • Everything shares the same security, rights, and relationships • Domain trees - domains sharing a schema, GC, and contiguous namespace • Domain forests - domains trees sharing a common schema, configuration, and GC, but not a contiguous namespace
Starting DC Promo • Start -> Run -> DCPromo • Installation Wizard appears
Database and Log Folder Locations • Specify the AD database and logfile locations • %systemroot%\NTDS default • Separate drives
Shared System Volume Location • Specify the shared system volume location • Scripts • Policies • NT • netlogon • NTFS • Disk Manager • convert /?
How AD uses DNS SVR records –RFC 2782 DNS server Where is the nearest DC? Its over there! Ok!! Userid and password Domain Controller Client
Using the Active Directory Wizards • View DNS records
Using the Active Directory Wizards • Promoting a member server to a DC (dcpromo) • Must be logged on locally as administrator • Create new or additional Domain • specify the network account for AD installation
Using the Active Directory Wizards • Demoting a DC to a member server • use dcpromo.exe • Remove 1 DC • Completely removethe Domain
Using the Active Directory Wizards • Demoting a DC to a member server • set local password for administrator of member server
Using the Active Directory Wizards • Demoting a DC to a member server • verify removal of DC
Understanding the Active Directory Database • Database and database log files are used to maintain the directory • Database file is stored in a file named ntds.dit • That file is stored in two locations: • %systemroot%\NTDS\ntds.dit • %systemroot%\System32\ntds.dit • Size may not be reported correctly
Understanding the Active Directory Database • Database log files should be located in a separate partition, or on a separate physical drive as the database file (fault-tolerance measure) • AD activity logged to edb.log • Applied to AD database (ntds.dit) when activity low • Circular logging • Overwrites existing log file • Noncircular logging • Creates new log files • HKEY_LOCAL_MACHINE\CurrentControlSetServices\NTDS\Parameters\logging • ERD
Understanding Active Directory Domain Modes • Windows 2003 supports four modes of operation: • Native mode • Mixed mode • Windows 2003 Intermediate Functional • Windows 2003 Functional
Understanding Active Directory Domain Modes • Mixed mode -supports replication with Windows NT DCs • Use if: • unable to upgrade all DCs • unable to secure DCs in AD • lack resources to upgrade DCs • wish to use NT as a fallback
Understanding Active Directory Domain Modes • Native mode - does not support replication with Windows NT DCs • Use if all DCs have been upgraded to Windows 2000 or 2003
Understanding Active Directory Domain Modes • Switching to native mode • Active Directory Domains and Trust • select a domain
Understanding Active Directory Domain Modes • Switching modes
Understanding Active Directory Domain Modes • Switching modes