User Manager for Domains - PowerPoint PPT Presentation

About This Presentation
Title:

User Manager for Domains

Description:

Define user's desktop environment and network connections. Assign logon ... their desktop color and wallpaper settings. their control panel display access ... – PowerPoint PPT presentation

Number of Views:74
Avg rating:3.0/5.0
Slides: 9
Provided by: albe5
Learn more at: http://home.ubalt.edu
Category:

less

Transcript and Presenter's Notes

Title: User Manager for Domains


1
User Manager for Domains
2
User Manager for Domains
  • Manages the user accounts in a domain
  • It is located in the PDC
  • While User Manager exists in each NT machine, but
    it is local to each machine
  • Its core is a shared database of users
  • SAM (Security Access Manager)
  • part of the PDC registry

3
UMD Functions
  • Create, modify, and delete user accounts in the
    domain
  • Define users desktop environment and network
    connections
  • Assign logon scripts to user accounts
  • Manage groups and trust relationships
  • Manage a domains security policies
  • Changes only take effect after user logs off and
    logs on

4
User manager main screen and user properties
  • The main screen is shown here
  • User properties
  • account type and expiration date
  • Username, Password and Full Name
  • Logon script, workstations and hours
  • Profile
  • User accounts are assigned a SID (security
    identifier) when created -- never reused
  • looks like S-1-5-D1-D2-D3-RID

5
Guest account security
  • Guest account is NOT secure like in UNIX
  • You cannot delete the guest account, but you
    should be sure it is disabled
  • DOS, WFW and Windows 95 do not require login to a
    domain
  • NT WS does require but you can log to the local
    machine and to the network with guest privileges
    if Guest is enabled
  • Guest is member of the Everyone group.

6
Creating an user account
  • The process is graphical-oriented
  • New user dialog (the one shown is missing the
    hours, logon and account icons)
  • Assigning group membership dialog
  • by default an user can log any time in any
    workstation, but you can change this
  • You can set logon expiration of passwords
  • You should setup the user home directory, logon
    script name and profile path
  • Of course you can copy user accounts and rename
    them (templates)

7
Managing Security Policies
  • Account, characteristics of passwords
  • User Rights, which user or group is assigned what
    system rights
  • Audit, what kind of security events are to be
    logged
  • Trust Relationships, how domains interact (not
    shown)

8
System Policy Editor
  • Automatically installed in the NT Server, not in
    workstations see it here
  • You can set a variety of restrictions to users
  • their desktop color and wallpaper settings
  • their control panel display access
  • their system access
  • many shell characteristics
  • DONT try it if you are not an experienced
    administrator, and dont touch default user and
    computer
Write a Comment
User Comments (0)
About PowerShow.com