840 likes | 1.1k Views
CHAPTER Creating and Managing Users and Groups. Chapter Objectives. Explain the use of Local Users and Groups Tool in the Systems Tools Option to create and manage user accounts Describe the various account related properties of a user
E N D
Chapter Objectives • Explain the use of Local Users and Groups Tool in the Systems Tools Option to create and manage user accounts • Describe the various account related properties of a user • Present different options that are available to define a user’s network environment
Chapter Modules • User Manager in Windows NT • Adding a User • Setting Additional User Account Properties • Adding Multiple Users • Account Policy • User Environment: Home Directory • User Environment: User Profiles • User Environment: Logon Scripts • User Rights
Generic Networking Model Network OS Installation Hardware Installation User Configuration
MODULE User Manager of Windows NT © N. Ganesan, All rights reserved.
Module Objectives • Authorized user managers • The user manager module • Ways of launching the user manager • From start, through shortcut and by running usrmgr • Case study domain details • Case study users in the domain
Who Can Create User Accounts? • Administrators • Domain Administrators • Account Operators
User Manager • The GUI module that enables user management • Activation • Through the start menu • Through command level activation by running the command usrmgr • From an already created short-cut
Creating a Short Cut: The Steps C:\Winnt\Profiles\All Users\ Start Menu\Programs\ Administrative Tools\ User Manager for Domains Explorer Right Click Create Shortcut Drag and place on the desktop screen.
Activating the User Manager: Demonstration Running usrmgr From Start Shortcut
Domain Details NAFTA US Canada Mexico
Users in the Domain Administrator California Texas Nevada
MODULE Adding a User © N. Ganesan, All rights reserved.
Module Objectives • The steps for adding a user • Password options • Demonstration of adding a user • Further notes on the user
Adding a User: Steps User Manager User New User Username Full Name Description Password
Password Options Password Options User must change PW. User cannot change PW. PW never expires. Add User
Adding Users: Demonstration Adding the user California.
Notes on the User • A user created becomes a member of the built-in User group • Additional user account properties can be set: • at the time of creation of the account • later through the User Properties feature
MODULE Setting Additional User Account Properties © N. Ganesan, All rights reserved.
Module Objectives • Reaching user properties menu • User optional properties • Assignment to groups • Profile • Hours restriction • Workstation access restriction • Account properties • Dial-in properties • Demonstration of properties configuration
Reaching User Properties Menu • The menu can be reached through the User Manager for Domain Window • Select user and double-click • Select user and select Properties from the User Option from the top
User Optional Properties Groups Logon To Profile Account Hours Dialin
Groups • Enables the user to be assigned to a group • The user acquires the group privileges • Enable a user to be removed from a group
Groups Demonstration Administrator Server Operator Etc. To be assigned User California Default
Profile • User Profile Path • Logon Script Name • Local Path to Home Directory • User environment profile is discussed later
Hours • Restricting the user to a fixed time period for using the network • For demonstration: • User California is restricted to logon to the network from 8:00 a.m. to 6:00 p.m., Monday to Friday
Logon To • Restricting the user to a predefined number of workstations on the network • The network can be accessed only from these workstations
Demonstration of Logon To US Others Canada Mexico California
Account • Account time limit • Never expires or • Specify expiry date • Account type • Global for possible entry into other domains • Local for restricting to local resources • For demonstration: • User California’s account will never expire
Dial-in • Allows the user dial-in access to the network • Provides callback for security verification • For the purpose of demonstration: • User California will be given dial-in access privileges • Callback security will not be imposed
Dial-in Setup California Dial-in with no callback security. Modem US Canada Mexico
Additional Properties: Demonstration Groups Hours Logon To Account Dial-in
MODULE Adding Multiple Users © N. Ganesan, All rights reserved.
Module Objectives • Copying user account details • Overview, case example and demonstration • Changing the account properties of multiple users • Operation on multiple users
Copying User Account Details • Can be copied from an existing user while creating a new user • Properties can then be modified to customize the new user properties
Copying User Account Details: Case Example Copy account details to new user Nevada from California Modify Nevada, if required.
Changing the Account Properties of Multiple Users • Multiple users can be chosen for account property modification • Example: • Enforcing the same logon time restriction on a group of users
Operation on Multiple Users: Case Example Administrator Texas Nevada Addition to administrator group and then deletion from administrator group.
MODULE Account Policy © N. Ganesan, All rights reserved.
Module Objectives • Account policy for all users in the domain • Password protection • Account lockout protection • Other protection • Account policy setting demonstration
User Account Policy for All Users in the Domain • Major components • Password related • Account lockout related • Password • Security against password guessing • Account lockout • Thwart unauthorized attempt to access the network
Password Protection Maximum PW age. Minimum PW age. Maximum PW length. PW uniqueness.
Account Lockout Protection Lockout after ___ bad logon attempts Lockout duration: Forever or in minutes. Reset counter after ______ minutes.
Other Protection Disconnect remote users after logon time expires. Require users to logon to change password.