Synopses & Reviews
Praise for the First Edition
“Trust me on this one...if youre an Active Directory engineer or architect, this is the book you need. Its the companion thats going to help you keep your job if youre up in the middle of the night trying to understand how something works or why its not working. Its truly an amazing book.”
—Scott Rachui, MCSE and Senior Active Directory Engineer, author of MCSE Exchange Server 5.5 for Dummies
“This is the best book on Windows 2000 that I have read and one of the best computer books I have ever read. The most unique quality is the excellent explanation of how to use scripting to maximize your results and minimize your effort. This book is especially well suited to the enterprise audience that has to deploy many servers (100+) and not just 1-10. If you have even a small bit of programming experience, you will really appreciate the in-depth explanations of Windows 2000 under the covers.”
“Wow!! I love this book. Id trade all my books covering Active Directory for this book in a second. The material is covered at a depth that I havent seen in any other book—and Ive looked at most of them. The material is presented in a straightforward manner that doesnt put you to sleep. An NT4 administrator could easily read this book and become an expert at Active Directory. I especially appreciated the chapter on Active Directory security.” Praise for the Second Edition
—Brian Arkills, author of LDAP Directories Explained
“If you are committed and really desire to know what makes Active Directory tick—and with it the backbone of the latest, and greatest, generation of Windows Network Operating Systems—then there is no better guide to get you there than this book. Inside Active Directory has no equal in the breadth, depth, and scope of its value to a technical practitioner.”
—Rick Kingslan, Microsoft MVP, Directory Services
“Kouti and Seitsonen provide excellent coverage of topics a lot of people have difficulty understanding and setting up properly. This book supplies you with sound background theory so you can understand these concepts and at the same time gives just the right amount of detail to actually accomplish what you are trying to do.”
—Harold McFarland, Editor, Readers Preference Reviews
“The style of this book is very appealing. It gives sufficient detail for the experienced administrator and explains what is happening behind the scenes at each step, which is extremely helpful when problems arise. An excellent read and an essential component for any skilled administrator!”
—Jeff Dunkelberger, Solutions Architect
“An outstanding refresh of an already great book, Inside Active Directory, Second Edition, should be in the toolbox of any serious Active Directory administrator, architect, or developer. Inside Active Directory is one of the five books I refer to on a weekly basis. Thanks to the authors for all their hard work and dedication.”
—Joe Richards, Microsoft MVP, Windows Server/Active Directory
The most practical, comprehensive, and highly praised guide to Active Directory has now been fully updated for Windows Server 2003. The second edition of Inside Active Directory: A System Administrators Guide offers a definitive reference to the design, architecture, installation, and management of Active Directory, the cornerstone technology within Windows 2000 and Windows Server 2003 distributed networks. This new edition—based on the final release software of Windows Server 2003—emphasizes security and covers all the new features, including enhancements in replication and Group Policy, forest trusts, functional levels, and working with dynamic objects.
Inside this core reference, youll find practical strategies for managing Active Directory, along with detailed instructions for efficiently administering your entire network operating environment. You will find detailed coverage of the following:
- Site basics and replication topologies, processes, and diagnostics
- Group Policy architecture, planning, management, and diagnostics
- Security and permission architecture and management scenarios
- Administration scripts, from basic concepts to advanced topics, including more than 50 sample scripts
- New cross-forest security features, including Selective Authentication, SID Filtering, and Name Suffix Routing
- A detailed drill-down to the schema, and practical strategies and examples for extending it
- Using Active Directory hierarchies to implement an effective structure for your network
This is an indispensable reference for anyone working with Active Directory. Network operating system novices will gain a solid understanding of Active Directory, while administrators experienced in NT, NetWare, or UNIX will learn how to utilize their current skills in Active Directory. Experienced Windows 2000/Windows Server 2003 professionals will pick up advanced techniques, and developers will benefit strongly from the architecture topics.
About the Author
M.S. (Tech), is a senior trainer and consultant for Sovelto, the leading training company in Finland. He started working with networks in 1986 and his articles have appeared in Windows NT Magazine
(now Windows and .NET Magazine
). Sakari was one of the first MCSEs in the world back in 1994.
Mika Seitsonen is a senior trainer at Sovelto. His network experience spans more than ten years, and he was one of the first MCSE: Security on Microsoft Windows Server 2003 certified persons in the world. Mika was awarded MVP—Directory Services in 2004 and holds an M.S. (Tech) from University of Nottingham (U.K.) and Lappeenranta University of Technology (Finland).
Table of Contents
About the Authors.
I. BACKGROUND SKILLS.
1. Active Directory: The Big Picture.
Introduction to Active Directory.
Basic Building Blocks.
Security and Policies.
2. Active Directory Installation.
Domain and Forest Functional Levels.
Installing Active Directory.
After Active Directory Installation.
Automating Active Directory Installation.
Problems with Active Directory Installation.
Uninstalling Active Directory.
II. CORE SKILLS.
3. Managing OUs, Users, and Groups.
Active Directory after Installation.
Administering Users, InetOrgPersons, and Contacts.
Administering Computer Objects.
Tips on Tools.
4. Securing Active Directory.
Introduction to Windows Security.
Background for Active Directory Access Control.
Managing Active Directory Permissions.
Delegation of Control Wizard.
Default Permissions for Objects.
Usage Scenarios for Active Directory Permissions.
Auditing Active Directory Access.
Access Control Architecture.
Domain Controller Access.
5. Sites and Replication.
Concepts of the Physical Structure.
Managing the Physical Structure.
6. Domains and Forests.
Domain Controller Placement.
Designing Domains and Forests.
Managing Domains and Forests.
LDAP and Searches.
7. Group Policy.
Group Policy Concepts.
Group Policy Contents.
Group Policy Objects and Links.
Processing Group Policy.
Managing Group Policies.
Software Management with Group Policy.
Troubleshooting Group Policy.
III. ADVANCED SKILLS.
8. Active Directory Schema.
Overview of the Active Directory Data Model.
Attributes and Syntaxes.
9. Extending the Schema.
When and Why to Modify.
Planning the Modifications.
The Modification Process.
Bringing the Extensions to the User Interface.
Extending the User Class.
10. Administration Scripts: Concepts.
11. Administration Scripts: Examples.
Access Control Lists.
OU, Group, and Computer Management.
ADSI without Active Directory.