Deployment of Active Directory

Source: Internet
Author: User

Referring to the directory, we first think of the directory of the phone book, as well as the directory of books, yes, today we are going to explain the Active Directory is also this meaning. The directory on the server refers to the centralized storage of network resources, what is network resources? The so-called network resources is to agree to store user accounts, computer accounts, security policies, etc., subject to strict security protection. Now the fast searching of network resources needs perfect index system and convenient search interface. Activity refers to the expansion of scale, object-oriented design concept. Active Directory is a directory service provided in Microsoft Windows Server that centralizes network resources in a directory database for easy administration.

Microsoft's management of computer and user accounts is divided into two types: one is decentralized management, and the other is centralized management. Decentralized management is the main representative of the Working Group, each computer is only responsible for managing the account of the computer, the main representative of centralized management is the domain environment, all the account information is stored on the domain controller.

Let's look at a typical case to understand the domain controller

Requirements: Server01 do dns,server02 do domain controller, server03 do staff machine

1. Prepare DNS

2. Deploying a domain Controller

3. Create a computer account

4. Create a user account


Step one, first install the NDS service on the Server01



650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F8/wKiom1UX8nTibrVxAAIX_zHPV2E786.jpg "style=" width : 600px;height:248px; "title=" Qq20150329203047.png "alt=" wkiom1ux8ntibrvxaaix_zhpv2e786.jpg "width=" "height=" 248 "border=" 0 "hspace=" 0 "vspace=" 0 "/>

Click Add roles and features, next

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F2/wKioL1UX863SNEAuAAK82VKoYpw307.jpg "style=" width : 600px;height:429px; "title=" Qq20150329203107.png "alt=" wkiol1ux863sneauaak82vkoypw307.jpg "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F8/wKiom1UX8nSCtcr6AAKoY6moKrA018.jpg "style=" width : 600px;height:428px; "title=" Qq20150329203141.png "width=" "height=" 428 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux8nsctcr6aakoy6mokra018.jpg "/>



In the IP address must ensure that the IP address and the local IP address of the same time can be the next step

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/F2/wKioL1UX866AnQQWAAEXt_3aufA083.jpg "style=" float: none; "title=" Qq20150329203155.png "alt=" Wkiol1ux866anqqwaaext_3aufa083.jpg "/>


Add Features



650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F8/wKiom1UX8nXQpx3xAAMS6SQ6PvQ665.jpg "style=" width : 600px;height:426px; "title=" Qq20150329203208.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux8nxqpx3xaams6sq6pvq665.jpg "/>


Select a DNS server

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F2/wKioL1UX87DzECsjAALO7271nXg628.jpg "style=" width : 600px;height:429px; "title=" Qq20150329203221.png "alt=" wkiol1ux87dzecsjaalo7271nxg628.jpg "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "/>


Without adding anything, the next step

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F8/wKiom1UX8nfyg9TkAAJHHCEOzyE095.jpg "style=" width : 600px;height:435px; "title=" Qq20150329203236.png "alt=" wkiom1ux8nfyg9tkaajhhceozye095.jpg "width=" "height=" 435 "border=" 0 "hspace=" 0 "vspace=" 0 "/>

Installation can

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F2/wKioL1UX87GRItxFAAIG3peEpJM184.jpg "style=" width : 600px;height:429px; "title=" Qq20150329203408.png "alt=" wkiol1ux87gritxfaaig3peepjm184.jpg "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "/>

When you see this interface it means that the installation has been successful.


Next create the primary zone

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX-iTALxE7AAGi42Yu-m4914.jpg "style=" width : 600px;height:417px; "title=" Qq20150329210210.png "width=" "height=" 417 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-italxe7aagi42yu-m4914.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX-OrQ_lnNAAHx7JdQY-A289.jpg "style=" float: none; "title=" Qq20150329210220.png "alt=" Wkiom1ux-orq_lnnaahx7jdqy-a289.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UX-iThkUFDAAFbqXFoVtE065.jpg "style=" float: none; "title=" Qq20150329210317.png "alt=" Wkiol1ux-ithkufdaafbqxfovte065.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UX-Ovjra6LAAGkXaF_akg710.jpg "style=" float: none; "title=" Qq20150329210329.png "alt=" Wkiom1ux-ovjra6laagkxaf_akg710.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX-iWSo0BeAAIUKNyMviE977.jpg "style=" float: none; "title=" Qq20150329210338.png "alt=" Wkiol1ux-iwso0beaaiuknymvie977.jpg "/>

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5B/F9/wKiom1UX-OzD5ScVAAIqf3dceV0778.jpg "style=" float: none; "title=" Qq20150329210359.png "alt=" Wkiom1ux-ozd5scvaaiqf3dcev0778.jpg "/>



Modify NS and SOA records

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX-4PQSfXZAAGbVuXZnO0153.jpg "style=" width : 600px;height:420px; "title=" Qq20150329210831.png "width=" "height=" 420 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux-4pqsfxzaagbvuxzno0153.jpg "/>


Right-click in the right margin, property

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UX-4OAcJsTAAHFAI7WIao652.jpg "style=" width : 600px;height:741px; "title=" Qq20150329211500.png "width=" "height=" 741 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux-4oacjstaahfai7wiao652.jpg "/>

Change the name of the master server to the server01.uec.com owner.

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX_L2CmXVtAAFuWGQv02o585.jpg "style=" width : 600px;height:504px; "title=" Qq20150329211527.png "width=" "height=" 504 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux_l2cmxvtaafuwgqv02o585.jpg "/>



650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F9/wKiom1UX-4OSlZlVAAHS-4UVpYA645.jpg "style=" width : 600px;height:732px; "title=" Qq20150329211538.png "width=" "height=" 732 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux-4oslzlvaahs-4uvpya645.jpg "/>

Edit---Add-----server01.uec.com----IP Address: 192.168.1.101


650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX_L2AMOFiAAH8AeN-Abg737.jpg "style=" width : 600px;height:414px; "title=" Qq20150329211548.png "width=" "height=" 414 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux_l2amofiaah8aen-abg737.jpg "/>


Refresh in a blank place


Adhesion a record appears


Ii. Deploying a domain Controller

    1. On SERVER02, first point DNS to the DNS server

2. Build a domain controller on the SERVER02

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX9oCQgd0lAAJv_gHUAHo049.jpg "style=" width : 600px;height:423px; "title=" Qq20150329204623.png "width=" "height=" 423 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9ocqgd0laajv_ghuaho049.jpg "/>

Next

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F8/wKiom1UX9UbRSbaAAAIRxP8dxTI601.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204630.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9ubrsbaaaairxp8dxti601.jpg "/>

Next

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX9oDSIihOAAK-f8nA494504.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204644.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9odsiihoaak-f8na494504.jpg "/>


Note the IP address, next

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F8/wKiom1UX9UfgMmjCAAK9VU76A34427.jpg "style=" width : 600px;height:432px; "title=" Qq20150329204654.png "width=" "height=" 432 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9ufgmmjcaak9vu76a34427.jpg "/>


Install Active Directory services, Next

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UX9oHCA9ElAALrhxWj16I355.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204708.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9ohca9elaalrhxwj16i355.jpg "/>


Next

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F8/wKiom1UX9UjwD_oUAAKoaYS5PBw679.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204736.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9ujwd_ouaakoays5pbw679.jpg "/>


Next

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX9oLCbktBAALL-YLKaKo954.jpg "style=" width : 600px;height:423px; "title=" Qq20150329204745.png "width=" "height=" 423 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9olcbktbaall-ylkako954.jpg "/>

Installation

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F8/wKiom1UX9h-QNVhRAAKUk0jN05k087.jpg "title=" Qq20150329205252.png "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "style=" WIDTH:600PX;HEIGHT:429PX; "alt = "Wkiom1ux9h-qnvhraakuk0jn05k087.jpg"/>

The installation is successful and the following will promote the domain

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F9/wKiom1UX9z7z8l7OAAB9NgLUCvQ222.jpg "style=" width : 600px;height:293px; "title=" Qq20150329205428.png "width=" "height=" 293 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z7z8l7oaab9nglucvq222.jpg "/>

In the * * * exclamation mark that click


650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX-HeyGwgSAAC97ttYSVQ313.jpg "style=" width : 600px;height:508px; "title=" Qq20150329205439.png "width=" "height=" 508 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-heygwgsaac97ttysvq313.jpg "/>

Click Promote this server to a domain controller

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX9z6yZCsDAAGrRk0_luw747.jpg "style=" width : 600px;height:435px; "title=" Qq20150329205458.png "width=" "height=" 435 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z6yzcsdaagrrk0_luw747.jpg "/>


Add to New Forest

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UX-HjzzDUfAAIULJbH45Q428.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205536.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-hjzzdufaaiuljbh45q428.jpg "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX9z_yweuHAAFfVaZg1ks300.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205606.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z_yweuhaaffvazg1ks300.jpg "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UX9z_xwf0eAAG1t_drYdA495.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205622.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z_xwf0eaag1t_dryda495.jpg "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX-HmQEM9MAAMU6AI2vMM643.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205646.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-hmqem9maamu6ai2vmm643.jpg "/>



Install in here


Check:

  1. Check whether the Active Directory Management tool is working properly

  2. Check for DNS records (SRV SOA NS OA)

  3. Check shared Netlogon and SYSVOL

    650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UYALaAISU8AAHAeHojGWE541.jpg "style=" width : 600px;height:857px; "title=" Qq20150329212437.png "width=" "height=" 857 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uyalaaisu8aahaehojgwe541.jpg "/>

    650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UYALaj-XRQAAH6LL5zkxk798.jpg "style=" width : 600px;height:420px; "title=" Qq20150329213540.png "width=" "height=" 420 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uyalaj-xrqaah6ll5zkxk798.jpg "/>

    650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UYAfCgBLOiAAGMgyMeTUo250.jpg "style=" width : 600px;height:392px; "title=" Qq20150329213557.png "width=" "height=" 392 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uyafcgbloiaagmgymetuo250.jpg "/>

3. Create a computer account

Join SERVER03 to the domain (DNS is pointed to the DNS server side)

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F4/wKioL1UYBSeBvrGaAALfzGln1x4714.jpg "style=" width : 600px;height:278px; "title=" Qq20150329214220.png "width=" "height=" 278 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uybsebvrgaaalfzgln1x4714.jpg "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UYA-7SAFlQAAFxP7ZifVY166.jpg "style=" width : 600px;height:833px; "title=" Qq20150329214239.png "width=" "height=" 833 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uya-7saflqaafxp7zifvy166.jpg "/>


Add a previously built domain name to the domain

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F4/wKioL1UYBSjBqIbsAADVSa7QypE917.jpg "style=" width : 600px;height:403px; "title=" Qq20150329215055.png "width=" "height=" 403 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uybsjbqibsaadvsa7qype917.jpg "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UYA-6xPr23AADhDlvMwEw429.jpg "style=" width : 600px;height:400px; "title=" Qq20150329215127.png "width=" "height=" "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uya-6xpr23aadhdlvmwew429.jpg "/>

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F4/wKioL1UYBSjgnPACAABxJPiz_qw696.jpg "style=" width : 600px;height:455px; "title=" Qq20150329215138.png "width=" "height=" 455 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uybsjgnpacaabxjpiz_qw696.jpg "/>

That's how it works.

You can view the logged-in user information at the command line set U

4. Create a user account

Create a new user on the DC

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/FA/wKiom1UYBW_gRQIWAAHF3a9jR3k004.jpg "style=" width : 600px;height:984px; "title=" Qq20150329215638.png "width=" "height=" 984 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uybw_grqiwaahf3a9jr3k004.jpg "/>


In the red circle, click

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/F4/wKioL1UYBqnABfhGAADQnQI4htc885.jpg "style=" float: none; "title=" Qq20150329215720.png "alt=" Wkiol1uybqnabfhgaadqnqi4htc885.jpg "/>


On the uec.com, right-click Properties. New---organizational unit, named HR

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/FA/wKiom1UYBXDDrNAeAAFCd4V7kGg480.jpg "style=" float: none; "title=" Qq20150329215749.png "alt=" Wkiom1uybxddrnaeaafcd4v7kgg480.jpg "/>

Create a new user on an organizational unit

Verification: The result of user Uec\gwy login to Server03 can, landing on the Server02 can not. Therefore, the domain controller only allows administrators to log on.


This article from the "DNS Mystery (a)" blog, reproduced please contact the author!

Deployment of Active Directory

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.