Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Lab 1-56
Introducing Active Directory Domain Services (AD DS)
IP Address: 10.0.0.11
If you need to open the Initial Configuration Tasks window in the future, you
do so by running the Oobe.execommand.
3. Click the Close button at the bottom of the window.
Server Manager appears.
Server Manager enables you to configure and administer the roles and features of
a server running Windows Server 2008. You will use Server Manager in the next
exercise.
4. At the bottom of the Server Manager window, a status message informs
you, Console cannot refresh until computer is restarted.
5. Click the Restart link next to the status message.
You are prompted with the message Do you want to restart now?
6. Click Yes.
The computer restarts.
In the Roles Summary section of Server Managers home page, youll notice an
error message indicated by a red circle with a white x. Youll also notice a
message in the Active Directory Domain Services section of the Roles page.
Both of these links will take you to the Active Directory Domain Services role
page of Server Manager. The message shown reminds you that it is necessary
to run dcpromo.exe, which you will do in the next task.
Task 2: Configure a new Windows Server 2008 forest named contoso.com with
HQDC01 as the first domain controller
1. In Server Manager, expand the Roles node in the tree pane, and then
click Active Directory Domain Services.
2. Click the Run the Active Directory Domain Services Installation Wizard
(dcpromo.exe) link.
The Active Directory Domain Services Installation Wizard appears.
3. Click Next.
4. On the Operating System Compatibility page, review the warning about the
default security settings for Windows Server 2008 domain controllers, and
then click Next.
5. On the Choose a Deployment Configuration page, click Create a new
domain in a new forest, and then click Next.
6. On the Name the Forest Root Domain page, type contoso.com, and then
click Next.
The system performs a check to ensure that the DNS and NetBIOS names are
not already in use on the network.
7. On the Set Forest Functional Level page, choose Windows Server 2008,
and then click Next.
The Additional Domain Controller Options page appears.
Each of the functional levels is described in the Details box on the page.
Choosing Windows Server 2008 forest functional level ensures that all domains
in the forest operate at the Windows Server 2008 domain functional level,
which enables several new features provided by Windows Server 2008.
In a production environment, you would choose Windows Server 2008 forest
functional level when creating a new forest if you require the features provided
by the Windows Server 2008 domain functional level and if you will not be
adding any domain controllers running operating systems prior to Windows
Server 2008.
DNS Server is selected by default. The Active Directory Domain Services
Installation Wizard will create a DNS infrastructure during AD DS installation.
The first domain controller in a forest must be a global catalog server and
cannot be a read-only domain controller (RODC).
8. Click Next.
A Static IP assignment warning appears.
Because discussion of IPv6 is beyond the scope of this training kit, you did not
assign a static IPv6 address to the server in Exercise 2. You did assign a static
IPv4 address in Exercise 1, and other labs in this course will use IPv4. You can
therefore ignore this error in the context of the exercise.
9. Click Yes, the computer will use a dynamically assigned IP address
(not recommended).
A warning appears that informs you that a delegation for the DNS server
cannot be created.
In the context of this exercise, you can ignore this error. Delegations of DNS
domains will be discussed later in this course.
10. Click Yes to close the Active Directory Domain Services Installation
Wizard warning message.
11. On the Location for Database, Log Files, and SYSVOL page, accept the
default locations for the database file, the directory service log files, and the
SYSVOL files, and then click Next.
The best practice in a production environment is to store these files on three
separate volumes that do not contain applications or other files not related to
AD DS. This best practice design improves performance and increases the
efficiency of backup and restore.
12. On the Directory Services Restore Mode Administrator Password page,
type a Pa$$w0rd in both the Password and Confirmed Passwordboxes.
Click Next.
In a production environment, you should use a very strong password for the
Directory Services Restore Mode Administrator Password. Do not forget the
password you assign to the Directory Services Restore Mode Administrator.
13. On the Summary page, review your selections.
If any settings are incorrect, click Back to make modifications.
14. Click Next.
Configuration of AD DS begins. After several minutes of configuration, the
Completing the Active Directory Domain Services Installation Wizard page
appears.
15. Click Finish.
16. Click Restart Now.
The computer restarts.
17. Continue with Task 3 (optional) or skip to Task 4.
Open the Add or Remove Snap-ins dialog box and use the Move Up, Move
Down, and Remove buttons to rearrange your console. For future labs, you
will need the console in the condition it was in at the end of Task 3, so do not
save your changed console. Instead, close the console without saving changes.
10. Log off of DESKTOP101 and HQDC01. Do not shut down or reset the virtual
machines.
Note: Do not shut down the virtual machines once
you are finished with this lab as the settings you
have configured here will be used in the Lab B.
Click Continue.
If the UAC dialog box gives you the option to Use another account:
a. Click Use Another Account.
b. In User Name, type the username.
c. In Password, type the password.
6. Double-click Query_NonExpPW.
The Edit Query dialog box appears.
7. Click OK.
8. Log off of HQDC01.
Note: Do not shut down the virtual machine once you are
finished with this lab as the settings you have configured here
will be used in the Lab C.
Notice that administrators using this tool will rarely, if ever, need to dive in to the
organizational unit structure underneath the contoso.com domain in the console tree. Almost
all day-to-day administrative tasks can be performed with the views in Saved Queries.
Note: Do not shut down the virtual machine once
you are finished with this lab as the settings you
have configured here will be used in the Lab C.
Click Continue.
If the UAC dialog box gives you the option to Use another account:
a.
If you receive an error that says, The specified name is already a member of
the group, use Active Directory Users and Computers to remove Scott Mitchell
and Linda Mitchell from the Special Project group, then try again.
You may receive an Access Denied error. What is causing this error, and
what can you do to work around it?
If you launched the command prompt without Run As Administrator, your user
account (Pat.Coleman) does not have credentials to change the group
membership.
2. Using a single command, retrieve the e-mail address of all users in the
Vancouver office.
Users in the Vancouver office have the word Vancouver in
the Description field.
If you dont know what attribute switch to use (-desc), type dsquery user
/?.
dsquery user -desc "*Vancouver*"
If you receive a warning that your DSQuery has reached its limit, what can you
do to ensure all results are returned?
dsquery user -desc "*Vancouver*" -limit 0
3. Using a single command, change the office attribute of the two users named
Mitchell to Vancouver.
dsquery user -name "*Mitchell" | dsmod user -office "Vancouver"
Note: After completing this exercise, turn off all virtual
machines and discard undo disks.