AD DS 2008 R2 Flashcards
2008 R2 licensing changes
Cal for R2 without Hper V Editions CAL requirement initiation when used to host virtual machines license suites for VD infrastructure Foundation Remote Desktop Services
new install options
improved command line and server manager
updated system center manager 2007 mgmt pack
AD Forest Functional Level
Creation of an answer file
integrated Best Practices Analyzer
when installing you can choose to Use Advanced Mode Installation option - don’t need to run the dcpromo with the /adv anymore
install in Advance mode options
create a new domain tree
define the PRP - short for password replication policy for an RODC
Choose which source DC to use for the AD DS install
decrease initial replication network traffic
modify the default generated NetBios Name
can’t use this wizard to configure DNS or RODC roles
AD DS install wiz has some new pages:
set function levels select domain select a site confg addt DC options create DNS delegation specify the Password Replication Policy Delegate RODC installation and administration
2008 R2 supports several upgrade paths
2003 SP2 2003 R2 2008 RTM-SP1 (release to manufacturing version with SP1) 2008 SP2 2008 RC (release candidate) 2008 IDS (internal developer server) 2008 RTM
adprep /options
found in the cd 2008 R2 \support\adprep install disc
you need to prep all existing DCs to work with the first 2008 R2 DC in a forest
/forestprep
/domainprep - has to be run on the infrastructure master or on any that will be DCs
domainprep/gpprep - same as above - it brings inheritable access control entries ACEs on the GPOs located in Sysvol shared resource and also allows for RSop functionality to be enabled
/rodcprep
in order to use the AD recycle bin
server function level has to be set to 2008 R2
Can’t add a DC lower than the highest function level. So if you need to have a DC 2008 or earlier don’t raise it to 2008 R2
to raise forest level
AD Domains and Trusts
right click on same node and choose raise forest function level
for domain, right click the domain node and do the same thing
WSM - Windows Migration Tool
needs to be installed on both servers
servers have to be a member of the network, unique server name and IP Address
MIgration assumes that after the migration the destination server will take over the source server’s functions and that source server will be removed, retired, retained as an addtl DC or changed into a member server
migration steps for 2008 R2
- planning
- preparing the source server
- gathering DNS and AD settings from the source server
- Preparing the destination server for migration by adding the server to the network and making this Windows Server 2008 R2 64 based server a DC
- migrating the mandatory sedtting sof the AD and DNS
- Validating that migration process was successful by verifying the destination server config
- Carrying out all post-migration tasks
- Migrating DNS Server Role
Active Directory Administrative Center
an AD data mgmt tool for mgmt of AD objects, admin and object tasks
can’t use it to mgmt LDAP instances or configuration sets
use it for:
new or mng existing groups and user accounts, OUs and containers, computer accounts
Using the query building search feature to filter AD data
Connecting to on or more DC or Domains
Managing or viewing the DC or Domains Directory info
new functions to this are
the breadcrumb bar
object property page
query building search
You install this feature by:
installing the AD DS server role
specifying a server as a DC
Manually using a wizard - do it by add features wizard in the Remote Server Admin Tools, needs net framework 3.5.1 and powershell’s AD module
install by server manager feature node, install remote server admin tools
AD DS and AD LDS Tools
global searches -
Normal Mode if you want touse keywords and build a global search query
ADWS
Active Directory Web Services
new 2008 R2
provides a web service interface to AD Directory mounting tool instances, AD LD Services instances,aka AD LDS and AD domains
can adjust parameters in the ADWS config file. Adjustments do not affect other DC because they are only applicable to the ADWS running on the DC whose parameters you adjusted. use microsoftactivedirectory.webservices.exe config file.
on this versions
Datacenter
Enterprise
Standard
AD Mangement Gateway service provides the same thing and is needed to run the AWDS service and can be installed on 2003 SP2, R2, 2008 and 2008 SP2 - it doesn’t support AD Database Mounting Tool
2003 and 2008 (not R2)
you could restore deleted AD objects via:
backups of AD DS through ntdsutil
has to be offline DSRM for an authoritative restore and changes between backup and restore will be lost for that object
Tombstone reanimation - restoring through a process before it is actually deleted which is 180 days by default - drawbacks, ln valued attributes are removed during the process of being tombstoned ie: group membership and the same for non linked values
AD Recycle Bin
online
maintain there original state
logical deletion, put in the deleted objects container for a period of time (deleted objects lifetime) in its original state - logically deleted
Once time frame as a logically deleted object it is changed and is stripped of its links and is called recycled object and then can only be restored through authoritative restore
When lifetime completely expires they are completely removed from db through garbage collection process
disabled by default need to consider:
forest function lever - has to be 2008 R2
Irreversibility -
once enabled you cannot turn it off or disable.
make changes by using the DN of the object:
CN=Partitions,CN=Configurations, DC=mydomain,DC=com:Acitve Directory Recycle Bin GUID
Enable-ADOptionalFeature - Identity ADOptionalFeature -Scope ADOptionalFeatureScope - Target ADEntity
steps to do before enabling AD Recycle Bin
Prepare forest - run adprep /forestprep
Schema Master
Infrastructure Master - adprep /domainprep/gpprep
update all DC to 2008R2
raise the forest level - run setADForestMode cmdlet or by running ldp.exe