Section 5 - Chapter 13 Flashcards
ADSI Edit
Query, view and edit directory objects and attributes
DCDiag
diagnose AD DS directories and AD LDS instances
DFSRadmin
Manage DFS-R
DSACL
control access control lists on directory objects
Dsamain
Mount AD store (.dit) backups or snapshots
New in 2008 r2
DSdbutil
Maintenance AD DS store
Config AD LDS ports
View AD LDS instances
dsmgmt
manage application partitions and operations master roles
GPfixup
repair domain name dependencies in GPOs, relink GPOs after a domain rename operation
Ksetup
Config client to use Kerberos v5 realm instead of AD DS domain
ktpass
config a non Windows Kerberos service as a security principal in AD DS
ldp
perform LDAP operations against the directory
movetree
moves objects between domains in a forest
nltest
query rep status or verify trust relationships
nslookup
view info on name servers to diagnose DNS infrastructure problems
Ultrasound
troubleshoot and diagnose reps between DCs that use FRS, relies on WMI
W32tm
View settings, manage config, or diagnose problems with Windows Time
Offline Maintenance 2008 r2
Can now start and stop AD DS service to perform maintenance, no longer need to shut down and restart the DC in DSRM
Can now script defragmentation and compaction operations
AD Recycle Bin
2008 r2 Forest Functional Level
Enable-ADOptionalFeature -Identity ‘Cn=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT, CN=Services,CN=Configuration,DC=contoso,DC=com’ -scope ForestOrConfigurationSet -Target ‘contoso.com’
Win PS Set Forest Functional Level
Set-ADForestMode -Identity DNSForestName -ForestMode Windows2008R2Forest
Recovering AD Recycle Bin Objects
recoverable 180 days
ldp.exe, connect to server, bind current logged on user, Return Deleted Objects, cn=Deleted Objects,dc=contoso,dc=com, double click object
Edit entry value = isDeleted
DistinguishedName
Replace
make sure Extended check box is selected
Recovering Objects pre 2008 r2
can use ldp - make sure to check synchronous and extended check boxes
Win PS to Recover Objects
Get-AdOject and Restore-ADObject
System State Data
AD DS Role on Server Registry COM+ Class Registration database System Files under Windows Resource Protection AD DS database Sysvol directory
Other Roles
AD CS database
Cluster service info
IIS config files
Critical Volumes
System volume Boot volume Volume hosting sysvol share Volume hosting AD DS database Volume hosting AD DS logs
Restore Downed Server
Windows Recovery Environment (WinRE)
To install on DCs access to Windows Automated Installation Kit (WAIK) needed
Restore Options
Full server, system state only, individual files or folders