Book Image

Mastering Active Directory. - Second Edition

By : Dishan Francis
Book Image

Mastering Active Directory. - Second Edition

By: Dishan Francis

Overview of this book

Active Directory (AD) is a centralized and standardized system that automates networked management of user data, security, and distributed resources and enables inter-operation with other directories. This book will first help you brush up on the AD architecture and fundamentals, before guiding you through core components, such as sites, trust relationships, objects, and attributes. You will then explore AD schemas, LDAP, RMS, and security best practices to understand objects and components and how they can be used effectively. Next, the book will provide extensive coverage of AD Domain Services and Federation Services for Windows Server 2016, and help you explore their new features. Furthermore, you will learn to manage your identity infrastructure for a hybrid cloud setup. All this will help you design, plan, deploy, manage operations, and troubleshoot your enterprise identity infrastructure in a secure and effective manner. You’ll later discover Azure AD Module, and learn to automate administrative tasks using PowerShell cmdlets. All along, this updated second edition will cover content based on the latest version of Active Directory, PowerShell 5.1 and LDAP. By the end of this book, you’ll be well versed with best practices and troubleshooting techniques for improving security and performance in identity infrastructures.
Table of Contents (25 chapters)
Free Chapter
1
Section 1: Active Directory Planning, Design, and Installation
8
Section 2: Active Directory Administration
13
Section 3: Active Directory Service Management
18
Section 4: Best Practices and Troubleshooting

What this book covers

Chapter 1, Active Directory Fundamentals, explains what Active Directory is and its characteristics. This chapter also explains the main components (physical and logical structure), object types, and role services of Active Directory. Last but not least, this chapter also covers Azure Active Directory and its capabilities in a nutshell.

Chapter 2, Active Directory Domain Services 2016, explains what's new in AD DS 2016 and how it will help improve your organization's identity infrastructure.

Chapter 3, Designing an Active Directory Infrastructure, talks about what needs to be considered in Active Directory infrastructure design. This chapter discusses how to place the AD DS logical and physical components in the AD DS environment according to best practices. It also covers the approach we need to take in order to move to a hybrid identity.

Chapter 4, Active Directory Domain Name System, explains how DNS works in the AD DS infrastructure. This chapter also includes information about the DNS server component, different types of DNS records, zones, and DNS delegation.

Chapter 5, Placing Operations Master Roles, talks about the FSMO roles and their responsibilities. This chapter also describes things we need to consider when placing FSMO roles in an Active Directory environment.

Chapter 6, Migrating to Active Directory 2016, covers the AD DS installation with different deployment models. This chapter also provides a step-by-step guide to migrating from an older version of AD DS to the new version, AD DS 2016.

Chapter 7, Managing Active Directory Objects, discusses how to create objects, find objects, modify objects, and remove objects (small-scale and large-scale) by using built-in Active Directory management tools and PowerShell commands.

Chapter 8, Managing Users, Groups, and Devices, further explores the Active Directory objects by deep diving into attributes, managed service accounts, and management of different object types. Last but not least, you will also learn about Active Directory object management best practices.

Chapter 9, Designing the OU Structure, teaches you how to design the OU structure properly, using different models to suit business requirements. This chapter also describes how to create, update, and remove OU. Furthermore, this chapter also discusses how we can delegate AD administration by using OU.

Chapter 10, Managing Group Policies, mainly discusses Group Policy objects and their capabilities. Group policy processing in an AD environment depends on many different things. In this chapter, we will deep dive into group policy processing to understand the technology behind it. We are also going to look into the different methods we can use for group policy filtering. Last but not least, we will learn about how to use group policies in an infrastructure, according to best practices.

Chapter 11, Active Directory Services, walks us through the more advanced Active Directory topics, such as AD LDS, Active Directory replication, Active Directory sites, Active Directory database maintenance, RODC, AD DS backup, and recovery.

Chapter 12, Active Directory Certificate Services, discusses the planning, deployment, and maintenance of Active Directory Certificate Services. Furthermore, we will also learn about how signing, encryption, and decryption work in a public key infrastructure (PKI).

Chapter 13, Active Directory Federation Services, focuses on AD Federation Services such as planning, designing, deployment, and maintenance. This chapter also covers new features of AD FS 2016, such as built-in Azure MFA support.

Chapter 14, Active Directory Rights Management Services, covers the Active Directory Rights Management Service role, which we can use to protect sensitive data in a business. Data is the new oil, and the value of data keeps increasing. Therefore, protection of data is important for every business. In this chapter, we will learn about how AD RMS works and how to configure it.

Chapter 15, Active Directory Security Best Practices, covers the protection of the Active Directory environment. Recent attacks and studies prove that adversaries are increasingly targeting identities. So, we need to be mindful of protecting our Active Directory infrastructure at any cost. In this chapter, we will learn about different tools, services, and methods we can use to protect the Active Directory environment. If you are using Azure AD in hybrid mode, then there are different features and services that can be used to protect both environments (cloud and on-premises). In this chapter, we will also learn about some of these solutions, such as Azure AD Privileged Identity Management and Azure Information Protection.

Chapter 16, Advanced AD Management with PowerShell, is full of PowerShell scripts that can be used to manage, secure, audit, and monitor our Active Directory environment. We will also learn about the Azure Active Directory PowerShell for Graph module, which we can use to manage, query, and update AD objects in a hybrid AD environment.

Chapter 17, Azure Active Directory Hybrid Setup, discusses how we can extend our on-premises AD DS infrastructure to Azure Active Directory. Before we work on the implementation, we will deep dive into the planning process of the Azure AD hybrid setup. In this chapter, we will also learn about different authentication methods for a hybrid environment and the technology behind them.

Chapter 18, Active Directory Audit and Monitoring, teaches you how to monitor your on-premises/hybrid AD DS infrastructure using different tools and methods (cloud-based and on-premises). This chapter also demonstrates how to audit an Active Directory environment.

Chapter 19, Active Directory Troubleshooting, discusses how to troubleshoot the most common Active Directory infrastructure issues using different tools and methods. Furthermore, we will also look into the most common Azure AD connect errors, which can have a direct impact on the health of the Azure AD hybrid environment.

Appendix A, Assessments, covers the Question and Answer section chapter wise. It's freely available online for our readers and here is the link: https://static.packt-cdn.com/downloads/Mastering_Active_Directory_Assessments.pdf.

Appendix B, References, covers the Further reading section chapter wise. It's freely available online for our readers and here is the link: https://static.packt-cdn.com/downloads/Mastering_Active_Directory_References.pdf.