Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Company Confidential
UNDERSTANDING THE
GLOBAL CATALOG
Central repository for forest-wide data.
Subset of attributes from objects forestwide.
First domain controller in the forest is
automatically configured as a global
catalog server.
Other domain controllers can become
global catalog servers.
FUNCTIONS OF THE
GLOBAL CATALOG
Facilitate searches for objects in the forest
Resolve User Principal Names (UPNs)
Provide universal group membership
information
If the domain is in Microsoft Windows 2000
native functional level or later, global catalog
information is required in order for users to log
on.
UNIVERSAL GROUP
MEMBERSHIP CACHING
New for Microsoft Windows Server 2003.
When enabled, non-global catalog domain
controllers can process logons without contacting
a global catalog server.
Refreshed on an eight-hour interval.
Eliminates the need to place a global catalog
server in a remote site to facilitate logons.
Provides better logon performance.
Can be used to minimize wide area network
(WAN) link usage.
ENABLING A GLOBAL
CATALOG SERVER
UNDERSTANDING
FLEXIBLE SINGLE MASTER
OPERATIONS ROLES
Flexible Single Master Operations (FSMO)
roles
Assigned automatically to the first domain
controller in a domain
Roles can be transferred to other domain
controllers
10
DOMAIN-SPECIFIC ROLES
RID masterAssigns RIDs to other domain
controllers
Infrastructure masterAllows security principals
to be tracked between domains
PDC emulator
Backward compatibility with Microsoft Windows NT
Server version 4.0 domains and later client computers
(Microsoft Windows 98 and Windows Me)
Time synchronization
User account password change replication
11
DOMAIN-WIDE
OPERATIONS MASTERS
12
RID MASTER
Used when security principals are created
RID makes the individual security principal
security identifier (SID) unique within a
domain
Built-in RIDs are consistent between domains,
for example, Built-in Administrator has a RID
of 500
13
14
INFRASTRUCTURE MASTER
Manages user and group references for objects between
domains
Updates ACLs and group memberships as required
Queries the global catalog to ensure that references are
current
Role should not be assigned to a global catalog server
Exception 1: There is only a single domain in the forest
Exception 2: All domain controllers are also global catalog
servers
15
PDC EMULATOR
Provides backward compatibility for pre
Windows 2000 client computers
Acts as the PDC in Windows 2000 mixed
functional level for any Windows NT Server
version 4.0 backup domain controllers
(BDCs) that are present on the network
Acts as a central manager for user password
changes, replication, and account lockouts
Handles time synchronization
16
17
18
SCHEMA MASTER
Controls access to the schema.
Ensures modifications are replicated to all
domain controllers in the forest.
The schema cannot be modified if the
schema master is not available.
Schema Admins level access is required
to modify the schema.
19
20
21
22
23
Schema master
Domain naming master
PDC emulator
RID master
Infrastructure master
24
MANAGING ROLES
Active Directory Users And Computers
RID master
Infrastructure master
PDC emulator
25
SUMMARY
26
27