Showing posts with label domain. Show all posts
Showing posts with label domain. Show all posts

Sunday, March 26, 2017

Configuring Domain Group Policy for Windows 2003

Configuring Domain Group Policy for Windows 2003


Windows 2003 Group Policies allow the administrators to manage a group of people accessing a resource efficiently. The group policies can be used to control both the users and computers.
They give better productivity to administrators and save their time by allowing them to manage all the users and computers centrally in just one go.
The group policies are of two types, Local Group Policy and Domain-based Group Policy. As the name suggests, the Local Group Policies allow the local administrator to manage all the users of a computer to access the resources and features available on the computer. For example an administrator can remove the use of Run command from the start menu. This will ensure that the users will not find Run command on that computer.
The Domain-based Group Policies on the other hand allow the domain/enterprise administrators to manage all the users and the computers of a domain/ forest centrally. They can define the settings and the allowed actions for users and computers across sites, domains, and OUs through group policies.
There are more than 2000 pre-created group policy settings available in Windows Server 2003/ Windows XP. A default group policy already exists. You only need to modify it by setting values of different policy settings according to your specific requirements. You can also create new group policies to meet your specific business requirements. The group policies allow you to implement:
  • Registry based settings: Allows you to create a policy to administer operating system components and applications.
  • Security settings: Allows you to set security options for users and computers to restrict them to run files based on path, hash, publisher criteria, or URL zone.
  • Software restrictions: Allows you to create a policy that would restrict users to run unwanted applications and protect computers against virus and hacking attack.
  • Software distribution and installation: Allows you to either assign or publish software application to domain users centrally with the help of a group policy.
  • Automation of tasks using computer and User Scripts
  • Roaming user profiles: Allow mobile users to see a familiar and consistent desktop environment on all the computers of the domain by storing their profile centrally on a server.
  • Internet Explorer maintenance: Allow administrators to manage the IE settings of the users computers in a domain by setting the security zones, privacy settings, and other parameters centrally with the help of group policy.

Configuring a Domain-Based Group Policy
Just as you used group policy editor to create a local computer policy, to create a domain-based group policy you need to use Active Users and Computers snap-in from where you can open the GPMC .
Follow the steps below to create a domain-based group policy
1. Select Active Directory Users and Computers tool from the Administrative Tools.
2. Expand Active Directory Users and Computers node, as shown below.
3. Right-click the domain name and select Properties from the menu that appears.
tk-windows-gp-domain-1
The properties window of the domain appears.

4. Click the Group Policy tab.
5. The Group Policy tab appears with a Default Domain Policy already created in it, as shown in here:
tk-windows-gp-domain-2

You can edit the Default Domain Policy or create a new policy. However, it is not recommended to modify the Default Domain Policy for regular settings.
We will select to create a new policy instead. Click New to create a new group policy or group policy object. A new group policy object appears below the Default Domain Policy in the Group Policy tab, as shown below:
tk-windows-gp-domain-3

Once you rename this group policy, you can either double-click on it, or select it and click Edit.
Youll next be presented with the Group Policy Object Editor from where you can select the changes you wish to apply to the specific Group Policy:
tk-windows-gp-domain-4

In this example, we have selected to Remove Run menu from Start Menu as shown above. Double-click on the selected setting and the properties of the settings will appear. Select Enabled to enable this setting. Clicking on Explain will provide plenty of additional information to help you understand the effects of this setting.
tk-windows-gp-domain-5
When done, click on OK to save the new setting.
Similarly you can set other settings for the policy. After setting all the desired options, close the Group Policy Object editor . You new group policy will take effect.

Available link for download

Read more »

Friday, February 24, 2017

Configuring permissions and groups Windows Server 2003 domain controller

Configuring permissions and groups Windows Server 2003 domain controller


Configuring permissions and groups (Windows Server 2003 domain controller)

If Microsoft Windows Server 2003 is a domain controller, you must complete these tasks to configure users and groups to access IBM® InfoSphere® Information Server. This configuration is required only for the engine tier computer and is only applicable to the users of the operating system where the engine tier components are installed.

Procedure

Because you cannot add the built-in authenticated users group to a group that you create in steps 2 and 3, you might prefer to skip steps 2 and 3 and use the authenticated users group directly.
  1. Log in to Microsoft Windows Server 2003 as an administrator.
  2. Configure the server to allow local users to log in.
    1. Click Start > Control Panel > Administrative Tools > Domain Security Policy.
    2. In the Domain Security Policy window, expand Local Policies > User Rights Assignment to display the policies.
    3. In the Domain Security window, click the Allow log on Locally policy, and click Actions > Properties.
    4. In the Allow log on Locally Properties window, click Add User or Group.
    5. Click Browse.
    6. In the Select Users, Computers, or Groups window, click Advanced and then click Find Now.
    7. In the search results, click Authenticated Users, and then click OK three times to return to the Domain Security Policy window.
    8. Close the Domain Security Policy window.
  3. Create a group.
    1. Click Start > Control Panel > Administrative Tools > Active Directory and Computers.
    2. In the Active Directory and Computers window, click Users in the current domain.
    3. In the window that opens, click Action > New Group.
    4. In the New Group window, type the name for the group.
    5. Leave Group scope as Global and Group type as Security.
    6. Click OK
  4. Add users to the group.
    1. In the Users in the current domain window, click the name of the group that you want to add users to, and click OK. Authenticated users are not available.
    2. Click Action > Properties.
    3. In the Properties window, click the Members tab, and then click Add.
    4. In the window that opens, click Advanced, and then click Find Now.
    5. Click the names of users that you want to add to the group, and then click OK. Authenticated users are not available.
    6. Click OK two times to save your results and to return to the Active Directory and Computers window.
    7. Close the Active Directory and Computers window.
  5. Set permissions on the server folder.
    1. In Windows Explorer, locate the server folder. The default location is c:IBMInformationServerServer.
    2. Click File > Properties.
    3. In the Properties window, click the Security tab, and click Add.
    4. In the Select Users, Computers, or Groups window, click Locations.
    5. In the window that opens, click Advanced, and then click Find Now.
    6. Click the name of the group that you want to set permissions for.
    7. Click OK, and then click OK again.
    8. Click the name of the group that you want to set permissions for.
    9. In the Permissions list, locate Modify.
    10. Click Write in the Allow column for this item, and click OK.
    11. If you receive a message to confirm your changes, confirm by clicking Apply changes to this folder, subfolders and files.

Available link for download

Read more »

Saturday, October 29, 2016

Install Active Directory Domain Services ADDS Role

Install Active Directory Domain Services ADDS Role


Install Active Directory Domain Services (ADDS) Role

Launch Server Manager
Click Add Roles and Features


Click Next

Select Role-based or feature-based installation and press Next

Since I am installing my forest locally I will select “Select a server from the server pool”
Select the server, in my case its DC2012
Press Next

Check off Active Directory Domain Services



When you check off Active Directory Domain Services a dialog window will pop up
Press Add Features

Press Next

Press Next on the features section, you do not need to check anything off here.
Some things will be checked off because you selected Active Directory Domain Services in the last section.

Read the important things to note about this installation.
Press Next

Press Install

Installation will complete. Press Close

Configure ADDS Forest and Domain

Next time your launch Server Manager. You will see a notification icon. Press the exclamation point. Select Promote this server to a domain controller


Warning: Do not create new Active Directory forests with the same name as an external DNS name. For example, if your Internet DNS URL is http://contoso.com, you must choose a different name for your internal forest to avoid future compatibility issues. That name should be unique and unlikely for web traffic. For example: corp.contoso.com.
Select Add a new forest
Specify the root domain name, in my case its pintolab.net
Press Next

In my new lab all servers will be Windows Server 2012. So I will be setting the functional level to Windows Server 2012. To understand more about Functional Levels please visit: http://technet.microsoft.com/en-us/library/cc771294.aspx
I will select Domain Name System (DNS), because ADDS needs DNS. This machine will function as the DNS server for the whole forest.
Enter a password for Directory Services Restore Mode (DSRM)
Press Next

Press Next. If there was an existing DNS server you would be able to change this option.

I like to set my domain name to 8 characters or less so that the NetBIOS name is the same as the domain name. If my domain name was longer, it would have truncated it. You can however make this anything you want. More information on NetBIOS Domain Names: http://technet.microsoft.com/en-us/library/cc961556.aspx
Press Next

Press Next

Press Next

Press Install
In my case I got a couple of warnings. The most important warning was the one saying I am using DHCP instead of an assigned IP Address. It’s important to make sure your Domain Controller and DNS Servers use static IP’s.

After Installation, Press Close

Setup will reboot the server, you will notice that the domain name is now in front of the username

One thing to take note of is that when DNS gets installed it will point the preferred DNS Server to itself and within DNS it will use the DNS Server that was in there before as a forwarder.


Managing Active Directory


Open Server Manager
Select AD DS
Right Click the Server Name, I find this is the quickest way to get to the Management Tools, since they removed the good ole start menu.

When you right click the server name you should see the familiar AD tools.

Active Directory Users and Computers thankfully has the same look and feel as previous versions.

 

Available link for download

Read more »

Sunday, September 25, 2016

Windows Server 2012 Domain Controller

Windows Server 2012 Domain Controller


In Windows Server 2012, dcpromo has been deprecated.
In order to make the windows server 2012 domain controller we will install ADDS (Active Directory Domain Services) role from the server manager on Windows Server 2012.
First we will change the server name let say server2012dc and  the IP address 10.10.21.1 (try to avoid using default 192.168.0.1)


INSTALLING AD DS ROLE

“Before You Begin” screen provides you basic information such as configuring strong passwords, IP addresses and Windows updates.
On Installation Type page, select the first option “Role-based or Feature-based Installation“.
Scenario-based Installation option applied only to Remote Desktop services.
On the “Server Selection” Page, select a server from the server pool and click next.
To install AD DS, select Active Directory Domain Services in turn it will pop-up to add other AD DS related tools. Click on Add Features.
After clicking “Add Features” above, you will be able to click “Next >” as shown in the screen below.
On the “Select Features” Page, Group Policy Management feature automatically installed during the promotion. Click next.
On the “Active Directory Domain Services” page, it gives basic information about AD DS. Click Next.
On the “Confirmation” Page, You need to confirm this to continue with this configuration. It will provide you an option to export the configuration settings and  also if you want the server to be restarted automatically as required.
After clicking “Install” the selected role binaries will be installed on the server.

After “Active Directory Domain Services” role binaries have been installed and now it is time to promote the server to a Domain Controller.


TechNet Article:
  • Install Active Directory Domain Services.

PROMOTING WINDOWS 2012 SERVER TO DOMAIN CONTROLLER

To create a new AD forest called “ArabITPro.local”, select add a new forest.
Type the name ArabITPro.local
Specify the FFL, DFL, whether or not it should be a DNS Server and also the DSRM administrator password. As you can see, it has selected the GC option by default and you cannot deselect it. The reason for this is that is the very first DC of the AD forest and at least one needs to be a GC.
DNS delegation warning.
Checks the NetBIOS name already assigned.
Specify the location of the AD related folders and then click next.
Summary Of All Installation Options/Selections.
Click View script for single command  line PowerShell script for dcpromo.
Before the actual install of AD, all prerequisites are checked. If All prerequisite checks are passed successfully then click Install.
When you click Install, DNS and the GPMC are installed automatically.
After the promotion of the server to a DC finished server restart automatically.
Once the server is booted and you logon to it, click on  Server Manager | Tools ,  will notice that following have been installed :
   •   Active Directory Administrative Center
   •   Active Directory Domains and Trusts
   •   Active Directory Module for Windows PowerShell
   •   Active Directory Sites and Services
   •   Active Directory Users and Computers
   •   ADSI Edit
   •   DNS
   •   Group Policy Management


Available link for download

Read more »