Title: Installing Active Directory
1Installing Active Directory
2Preparing for AD Installation
- Issues to consider
- IP addressing schemes and DNS
- Domain naming context
3Preparing for AD Installation
- View DNS records
- Ensure that DCs for new domains or additional DCs
for a domain have the correct DNS addresses and
that the addresses are registered with DNS server
4Installing AD
- On a previously configured server, use
dcpromo.exe to activate the AD Installation Wizard
5Creating Windows 2003 Domains
- Recall
- Domains - computers sharing a security boundary
- Domain trees - domains sharing a schema, GC, and
contiguous namespace - Domain forests - domains trees sharing a common
schema, configuration, and GC, but not a
contiguous namespace
6Using the Active Directory Wizards
- Select the role of the DC
7Using the Active Directory Wizards
- Select the domain context
8Using the Active Directory Wizards
9Using the Active Directory Wizards
10Using the Active Directory Wizards
- Specify the AD database and logfile locations
11Using the Active Directory Wizards
- Specify the shared system volume location
- Contains Policies and is replicated to all DCs
12Using the Active Directory Wizards
- Install DNS or verify installed.
13Using the Active Directory Wizards
- Enter AD Restore Mode password
- Not authenticated through AD, uses SAM
14Using the Active Directory Wizards
- Verify installation selections
15Using the Active Directory Wizards
- Promoting a member server to a DC
- Needs to be have Enterprise Administrator account
to add a DC for a new domain - Needs to be a members server before promotion
when adding an additional DC for a domain - Needs to be have Domain Administrator account to
add an additional DC for a domain
16Using the Active Directory Wizards
- Promoting a member server to a DC
- select the domain for the new DC
17Using the Active Directory Wizards
- Demoting a DC to a member server
- use dcpromo.exe
18Using the Active Directory Wizards
- Demoting a DC to a member server
- set local password for administrator of member
server
19Using the Active Directory Wizards
- Demoting a DC to a member server
- verify removal of DC
20Understanding the Active Directory Database
- Database and database log files are used to
maintain the directory - Database file is stored in a file named ntds.dit
- That file is stored in two locations
- systemroot\NTDS\ntds.dit (after promotion)
- systemroot\System32\ntds.dit (during promotion)
21Understanding the Active Directory Database
- Database log files should be located in a
separate partition, or on a separate physical
drive as the database file (fault-tolerance
measure) - Circular and noncircular logging
22Understanding Active Directory Domain Modes
- Windows 2003 supports two modes of operation
- Windows 2000 Mixed mode
- Windows 2000 Native mode
- Windows 2003 Interim mode
- Windows 2003 Native mode
23Understanding Active Directory Domain Modes
- Windows 2000 mixed mode -supports replication
with Windows NT DCs - Use if
- unable to upgrade all DCs
- unable to secure DCs in AD
- lack resources to upgrade DCs
- wish to use NT as a fallback
- SAM replication only for Windows NT, Windows
2000, and Windows 2003. - No universal groups, no nesting groups, no group
conversions
24Understanding Active Directory Domain Modes
- Windows 2003 Interm-mode supports replication
with Windows NT DCs - Use if
- unable to upgrade all DCs
- unable to secure DCs in AD
- lack resources to upgrade DCs
- wish to use NT as a fallback
- SAM replication only for Windows NT and Windows
2003. - Must have only Windows 2003 and Windows NT servers
25Understanding Active Directory Domain Modes
- Windows 2000 Native mode - does not support
replication with Windows NT DCs - Netlogon service is disabled Windows NT DCs can
no longer be added to domain - Multimaster replication only for Windows
2000/2003. - Use if all DCs have been upgraded to Windows
2000/2003
26Understanding Active Directory Domain Modes
- Switching to native mode
- select a domain
- Active Directory Domains and Trusts
27Understanding Active Directory Domain Modes
28Understanding Active Directory Domain Modes
29Windows 2000 Native Mode Operation
- Domain uses AD multimaster replication
exclusively - Support for NETLOGON replication is halted
- Windows NT DCs can no longer join the domain
- All DCs can perform directory updates using
multi-master replication - Windows 2000/2003 native mode universal groups
are enabled - Windows 2000/2003 native mode global group
nesting is enabled - Domain Renaming
30Windows 2003 Native Mode Operation
- All features of Windows 2000 Native Mode
- Windows 2003 servers only
- Domain Controller Renaming
- Passwords for inetOrgPerson Objects