Referring to the directory, we first think of the directory of the phone book, as well as the directory of books, yes, today we are going to explain the Active Directory is also this meaning. The directory on the server refers to the centralized storage of network resources, what is network resources? The so-called network resources is to agree to store user accounts, computer accounts, security policies, etc., subject to strict security protection. Now the fast searching of network resources needs perfect index system and convenient search interface. Activity refers to the expansion of scale, object-oriented design concept. Active Directory is a directory service provided in Microsoft Windows Server that centralizes network resources in a directory database for easy administration.
Microsoft's management of computer and user accounts is divided into two types: one is decentralized management, and the other is centralized management. Decentralized management is the main representative of the Working Group, each computer is only responsible for managing the account of the computer, the main representative of centralized management is the domain environment, all the account information is stored on the domain controller.
Let's look at a typical case to understand the domain controller
Requirements: Server01 do dns,server02 do domain controller, server03 do staff machine
1. Prepare DNS
2. Deploying a domain Controller
3. Create a computer account
4. Create a user account
Step one, first install the NDS service on the Server01
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F8/wKiom1UX8nTibrVxAAIX_zHPV2E786.jpg "style=" width : 600px;height:248px; "title=" Qq20150329203047.png "alt=" wkiom1ux8ntibrvxaaix_zhpv2e786.jpg "width=" "height=" 248 "border=" 0 "hspace=" 0 "vspace=" 0 "/>
Click Add roles and features, next
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F2/wKioL1UX863SNEAuAAK82VKoYpw307.jpg "style=" width : 600px;height:429px; "title=" Qq20150329203107.png "alt=" wkiol1ux863sneauaak82vkoypw307.jpg "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F8/wKiom1UX8nSCtcr6AAKoY6moKrA018.jpg "style=" width : 600px;height:428px; "title=" Qq20150329203141.png "width=" "height=" 428 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux8nsctcr6aakoy6mokra018.jpg "/>
In the IP address must ensure that the IP address and the local IP address of the same time can be the next step
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/F2/wKioL1UX866AnQQWAAEXt_3aufA083.jpg "style=" float: none; "title=" Qq20150329203155.png "alt=" Wkiol1ux866anqqwaaext_3aufa083.jpg "/>
Add Features
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F8/wKiom1UX8nXQpx3xAAMS6SQ6PvQ665.jpg "style=" width : 600px;height:426px; "title=" Qq20150329203208.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux8nxqpx3xaams6sq6pvq665.jpg "/>
Select a DNS server
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F2/wKioL1UX87DzECsjAALO7271nXg628.jpg "style=" width : 600px;height:429px; "title=" Qq20150329203221.png "alt=" wkiol1ux87dzecsjaalo7271nxg628.jpg "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "/>
Without adding anything, the next step
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F8/wKiom1UX8nfyg9TkAAJHHCEOzyE095.jpg "style=" width : 600px;height:435px; "title=" Qq20150329203236.png "alt=" wkiom1ux8nfyg9tkaajhhceozye095.jpg "width=" "height=" 435 "border=" 0 "hspace=" 0 "vspace=" 0 "/>
Installation can
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F2/wKioL1UX87GRItxFAAIG3peEpJM184.jpg "style=" width : 600px;height:429px; "title=" Qq20150329203408.png "alt=" wkiol1ux87gritxfaaig3peepjm184.jpg "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "/>
When you see this interface it means that the installation has been successful.
Next create the primary zone
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX-iTALxE7AAGi42Yu-m4914.jpg "style=" width : 600px;height:417px; "title=" Qq20150329210210.png "width=" "height=" 417 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-italxe7aagi42yu-m4914.jpg "/>
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX-OrQ_lnNAAHx7JdQY-A289.jpg "style=" float: none; "title=" Qq20150329210220.png "alt=" Wkiom1ux-orq_lnnaahx7jdqy-a289.jpg "/>
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UX-iThkUFDAAFbqXFoVtE065.jpg "style=" float: none; "title=" Qq20150329210317.png "alt=" Wkiol1ux-ithkufdaafbqxfovte065.jpg "/>
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UX-Ovjra6LAAGkXaF_akg710.jpg "style=" float: none; "title=" Qq20150329210329.png "alt=" Wkiom1ux-ovjra6laagkxaf_akg710.jpg "/>
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX-iWSo0BeAAIUKNyMviE977.jpg "style=" float: none; "title=" Qq20150329210338.png "alt=" Wkiol1ux-iwso0beaaiuknymvie977.jpg "/>
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5B/F9/wKiom1UX-OzD5ScVAAIqf3dceV0778.jpg "style=" float: none; "title=" Qq20150329210359.png "alt=" Wkiom1ux-ozd5scvaaiqf3dcev0778.jpg "/>
Modify NS and SOA records
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX-4PQSfXZAAGbVuXZnO0153.jpg "style=" width : 600px;height:420px; "title=" Qq20150329210831.png "width=" "height=" 420 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux-4pqsfxzaagbvuxzno0153.jpg "/>
Right-click in the right margin, property
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UX-4OAcJsTAAHFAI7WIao652.jpg "style=" width : 600px;height:741px; "title=" Qq20150329211500.png "width=" "height=" 741 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux-4oacjstaahfai7wiao652.jpg "/>
Change the name of the master server to the server01.uec.com owner.
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX_L2CmXVtAAFuWGQv02o585.jpg "style=" width : 600px;height:504px; "title=" Qq20150329211527.png "width=" "height=" 504 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux_l2cmxvtaafuwgqv02o585.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F9/wKiom1UX-4OSlZlVAAHS-4UVpYA645.jpg "style=" width : 600px;height:732px; "title=" Qq20150329211538.png "width=" "height=" 732 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux-4oslzlvaahs-4uvpya645.jpg "/>
Edit---Add-----server01.uec.com----IP Address: 192.168.1.101
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX_L2AMOFiAAH8AeN-Abg737.jpg "style=" width : 600px;height:414px; "title=" Qq20150329211548.png "width=" "height=" 414 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux_l2amofiaah8aen-abg737.jpg "/>
Refresh in a blank place
Adhesion a record appears
Ii. Deploying a domain Controller
On SERVER02, first point DNS to the DNS server
2. Build a domain controller on the SERVER02
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX9oCQgd0lAAJv_gHUAHo049.jpg "style=" width : 600px;height:423px; "title=" Qq20150329204623.png "width=" "height=" 423 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9ocqgd0laajv_ghuaho049.jpg "/>
Next
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F8/wKiom1UX9UbRSbaAAAIRxP8dxTI601.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204630.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9ubrsbaaaairxp8dxti601.jpg "/>
Next
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX9oDSIihOAAK-f8nA494504.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204644.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9odsiihoaak-f8na494504.jpg "/>
Note the IP address, next
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F8/wKiom1UX9UfgMmjCAAK9VU76A34427.jpg "style=" width : 600px;height:432px; "title=" Qq20150329204654.png "width=" "height=" 432 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9ufgmmjcaak9vu76a34427.jpg "/>
Install Active Directory services, Next
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UX9oHCA9ElAALrhxWj16I355.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204708.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9ohca9elaalrhxwj16i355.jpg "/>
Next
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F8/wKiom1UX9UjwD_oUAAKoaYS5PBw679.jpg "style=" width : 600px;height:426px; "title=" Qq20150329204736.png "width=" "height=" 426 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9ujwd_ouaakoays5pbw679.jpg "/>
Next
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX9oLCbktBAALL-YLKaKo954.jpg "style=" width : 600px;height:423px; "title=" Qq20150329204745.png "width=" "height=" 423 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux9olcbktbaall-ylkako954.jpg "/>
Installation
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F8/wKiom1UX9h-QNVhRAAKUk0jN05k087.jpg "title=" Qq20150329205252.png "width=" "height=" 429 "border=" 0 "hspace=" 0 "vspace=" 0 "style=" WIDTH:600PX;HEIGHT:429PX; "alt = "Wkiom1ux9h-qnvhraakuk0jn05k087.jpg"/>
The installation is successful and the following will promote the domain
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F9/wKiom1UX9z7z8l7OAAB9NgLUCvQ222.jpg "style=" width : 600px;height:293px; "title=" Qq20150329205428.png "width=" "height=" 293 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z7z8l7oaab9nglucvq222.jpg "/>
In the * * * exclamation mark that click
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F3/wKioL1UX-HeyGwgSAAC97ttYSVQ313.jpg "style=" width : 600px;height:508px; "title=" Qq20150329205439.png "width=" "height=" 508 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-heygwgsaac97ttysvq313.jpg "/>
Click Promote this server to a domain controller
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX9z6yZCsDAAGrRk0_luw747.jpg "style=" width : 600px;height:435px; "title=" Qq20150329205458.png "width=" "height=" 435 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z6yzcsdaagrrk0_luw747.jpg "/>
Add to New Forest
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UX-HjzzDUfAAIULJbH45Q428.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205536.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-hjzzdufaaiuljbh45q428.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UX9z_yweuHAAFfVaZg1ks300.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205606.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z_yweuhaaffvazg1ks300.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UX9z_xwf0eAAG1t_drYdA495.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205622.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1ux9z_xwf0eaag1t_dryda495.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F3/wKioL1UX-HmQEM9MAAMU6AI2vMM643.jpg "style=" width : 600px;height:438px; "title=" Qq20150329205646.png "width=" "height=" 438 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1ux-hmqem9maamu6ai2vmm643.jpg "/>
Install in here
Check:
Check whether the Active Directory Management tool is working properly
Check for DNS records (SRV SOA NS OA)
Check shared Netlogon and SYSVOL
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UYALaAISU8AAHAeHojGWE541.jpg "style=" width : 600px;height:857px; "title=" Qq20150329212437.png "width=" "height=" 857 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uyalaaisu8aahaehojgwe541.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UYALaj-XRQAAH6LL5zkxk798.jpg "style=" width : 600px;height:420px; "title=" Qq20150329213540.png "width=" "height=" 420 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uyalaj-xrqaah6ll5zkxk798.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F3/wKioL1UYAfCgBLOiAAGMgyMeTUo250.jpg "style=" width : 600px;height:392px; "title=" Qq20150329213557.png "width=" "height=" 392 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uyafcgbloiaagmgymetuo250.jpg "/>
3. Create a computer account
Join SERVER03 to the domain (DNS is pointed to the DNS server side)
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F4/wKioL1UYBSeBvrGaAALfzGln1x4714.jpg "style=" width : 600px;height:278px; "title=" Qq20150329214220.png "width=" "height=" 278 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uybsebvrgaaalfzgln1x4714.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/5B/F9/wKiom1UYA-7SAFlQAAFxP7ZifVY166.jpg "style=" width : 600px;height:833px; "title=" Qq20150329214239.png "width=" "height=" 833 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uya-7saflqaafxp7zifvy166.jpg "/>
Add a previously built domain name to the domain
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F4/wKioL1UYBSjBqIbsAADVSa7QypE917.jpg "style=" width : 600px;height:403px; "title=" Qq20150329215055.png "width=" "height=" 403 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uybsjbqibsaadvsa7qype917.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/5B/F9/wKiom1UYA-6xPr23AADhDlvMwEw429.jpg "style=" width : 600px;height:400px; "title=" Qq20150329215127.png "width=" "height=" "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uya-6xpr23aadhdlvmwew429.jpg "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/F4/wKioL1UYBSjgnPACAABxJPiz_qw696.jpg "style=" width : 600px;height:455px; "title=" Qq20150329215138.png "width=" "height=" 455 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1uybsjgnpacaabxjpiz_qw696.jpg "/>
That's how it works.
You can view the logged-in user information at the command line set U
4. Create a user account
Create a new user on the DC
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/5B/FA/wKiom1UYBW_gRQIWAAHF3a9jR3k004.jpg "style=" width : 600px;height:984px; "title=" Qq20150329215638.png "width=" "height=" 984 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiom1uybw_grqiwaahf3a9jr3k004.jpg "/>
In the red circle, click
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/F4/wKioL1UYBqnABfhGAADQnQI4htc885.jpg "style=" float: none; "title=" Qq20150329215720.png "alt=" Wkiol1uybqnabfhgaadqnqi4htc885.jpg "/>
On the uec.com, right-click Properties. New---organizational unit, named HR
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5B/FA/wKiom1UYBXDDrNAeAAFCd4V7kGg480.jpg "style=" float: none; "title=" Qq20150329215749.png "alt=" Wkiom1uybxddrnaeaafcd4v7kgg480.jpg "/>
Create a new user on an organizational unit
Verification: The result of user Uec\gwy login to Server03 can, landing on the Server02 can not. Therefore, the domain controller only allows administrators to log on.
This article from the "DNS Mystery (a)" blog, reproduced please contact the author!
Deployment of Active Directory