Book Image

Active Directory Administration Cookbook - Second Edition

By : Sander Berkouwer
Book Image

Active Directory Administration Cookbook - Second Edition

By: Sander Berkouwer

Overview of this book

Updated to the Windows Server 2022, this second edition covers effective recipes for Active Directory administration that will help you leverage AD's capabilities for automating network, security, and access management tasks in the Windows infrastructure. Starting with a detailed focus on forests, domains, trusts, schemas, and partitions, this book will help you manage domain controllers, organizational units, and default containers. You'll then explore Active Directory sites management as well as identify and solve replication problems. As you progress, you'll work through recipes that show you how to manage your AD domains as well as user and group objects and computer accounts, expiring group memberships, and Group Managed Service Accounts (gMSAs) with PowerShell. Once you've covered DNS and certificates, you'll work with Group Policy and then focus on federation and security before advancing to Azure Active Directory and how to integrate on-premise Active Directory with Azure AD. Finally, you'll discover how Microsoft Azure AD Connect synchronization works and how to harden Azure AD. By the end of this AD book, you’ll be able to make the most of Active Directory and Azure AD Connect.
Table of Contents (18 chapters)

Configuring Extranet Smart Lockout

This recipe shows how to configure Extranet Smart Lockout on an Active Directory Federation Services (AD FS) farm running Windows Server 2016 or newer versions.

Getting ready

When using AD FS on Windows Server, ensure that at least the June 2018 cumulative update for Windows Server 2016 (KB4284880 – https://support.microsoft.com/en-us/help/4284880/windows-10-update-kb4284880 – and OS Build 14393.2312) is installed on all AD FS servers in the AD FS farm.

Sign in with an account that is an AD FS administrator. By default, members of the Domain Admins group have the required permissions.

Sign in to the primary AD FS server when the AD FS farm is using the Windows Internal Database (WID) as its replication model, or any AD FS server when the AD FS farm leverages SQL Server as its configuration database.

How to do it...

To enable Extranet Smart Account Lockout for an AD FS farm running SQL Server, run the following lines...