130 likes | 323 Views
Microsoft Active Directory Overview. 2001/11/06 李宣鋒. Outline. Four Major Components of Windows 2000 Network Three Building Blocks of Active Directory Global Catalog FSMO Groups. Four Major Components of Windows 2000 Network. 1. Domains.
E N D
Microsoft Active Directory Overview 2001/11/06 李宣鋒
Outline • Four Major Components of Windows 2000 Network • Three Building Blocks of Active Directory • Global Catalog • FSMO • Groups
1. Domains • X.500-based hierarchical structure of containers and objects • DNS domain name as unique identifier • Security boundary • account • domain trusts • Policies • users • machines
2. Domain Trees mycorp.com finance.mycorp.com sales.mycorp.com mktg.mycorp.com pre.sales.mycorp.com post.sales.mycorp.com
3. Forests • Forests are named after the first domain tree that they contain • Forest Root Domain • has special properties • if deleted, the forest would be irretrievably destroyed
4. Organizational Units • Organizational Units have domainlike properties, whereas Container do not. • Security boundary • There is no option to create a Container • Just use Organizational Units
Three Building Blocks of Active Directory Naming Contexts Parts • Domain Naming Contexts • users, groups, and Organizational Units for a domain • Configuration Naming Contexts • physical site layout • structure of trees in the forest • services • Schema Naming Contexts • object definitions
Global Catalog • Used to help in rapidly responding to searches • Forest wide • Hold a selection of object properties • Query comes GC Active Directory
FSMO • Flexible Single Master Operation • Multiple DCs potentially make conflicting changes • FSMO role owner • NTDSUTIL
FSMO (cont.) • Schema Master (enterprise-wide) • Allow changes to Schema • Domain Naming Master (enterprise-wide) • Control changes to namespace • PDC Advertiser (domain-wide) • Backward compatibility with NT • RID Master (domain-wide) • Make sure all SIDs are unique RID value • Infrastructure Master (domain-wide) • Maintain references to objects in other domains
Groups • Domain local (domain-wide) • Domain global (domain-wide) • Universal (forest-wide) • Each type of group can have two scopes • Distribution group: like mailing-list • Security group: ACLs
Reference • “Windows 2000 Active Directory” by Alistair G. Lowe-Norris, O’REILLY