
Use groups in Active Directory Domain Services to assign permissions and manage access, describe group types and scopes, manage membership with group policy, and cover default groups and special identities.
Explore security and distribution groups in Windows Server 2016, their permissions, and acl control. Learn how converting between group types affects access tokens, permissions, and large-scale exchange deployments.
Demonstrates creating a test group in Active Directory, explains security versus distribution groups, shows converting between group types, protects from accidental deletion, and uses PowerShell to view group attributes.
Examine the four Active Directory group scopes: local, domain local, global, and universal, and how each defines membership and permissions across domains and resources.
Explore group scopes in active directory, including domain local, global, and universal, and see how to assign domain local resources, add members, and join a computer to the domain.
Compare security versus distribution groups and how scopes affect permissions and email distribution. Identify universal, global, and local scopes and their forest or local limitations.
Learn how to implement group nesting in Active Directory with IGAD L.A. concepts, using global, domain local, and universal groups, plus role groups and resource access management for read permissions.
Learn to implement group management in Active Directory with nested and domain local groups, role based access, and secure resource sharing, including finance reports on a Windows 11 client.
Explore group nesting strategies with the DLA and Igla models to manage identities, global and domain local groups, and role based access.
Learn to manage local and domain group memberships with restricted groups in group policy, applying to OUs and domain controllers, including nesting and automatic removal of non-designated members.
Identify the default local and domain groups in Windows Server 2016, including administrators, backup operators, domain admins, enterprise admins, and schema admins, and recognize why protected groups demand careful customization.
Learn to manage active directory users and groups via the administrative center, verify George's group membership, and audit nested groups with gpresult and get-add-principal-group-membership.
Explore default and protected groups in Active Directory, including Enterprise Admins and Schema Admins, and learn best practices for managing administrative privileges and ACLs.
Explore special identities in Active Directory, including authenticated users, everyone, interactive, network, and creator owner; learn how these groups grant rights and permissions based on authentication type.
Learn to create a new group, add members, change the group type to universal, adjust the scope, and configure a group manager in the Active Directory Administrative Center.
Explore managing computer objects in Active Directory, including joining computers to a domain, configuring computer accounts and secure channels, and performing offline domain join.
Create dedicated organizational units for client and server computer objects instead of using the default computers container to enable delegation and targeted group policy application.
Identify the computers container as the default location for computer accounts in Active Directory and learn why creating custom OUs improves GPO linkage and management.
Ensure you have permissions on the computer object, are in the local administrators group, stay under the machine account quota, and recreate computer object in the correct OU before joining.
Learn how to join a Windows computer to a domain by accessing the computer name tab in advanced system settings, providing domain credentials, and restarting after the join.
Understand how the computer account and domain establish a secure channel and what happens when trust fails. Reset the secure channel or rejoin the domain using AD tools.
Learn how a member computer stores its domain password as an LSA secret for the netlogon secure channel, and how to reset trust with netdom, nltest, dsmod, and PowerShell commands.
Learn how to perform an offline domain join by provisioning a domain join file with the disjoint command, transferring the save file, and rebooting to complete the join.
Plan the OU structure and implement delegation of control wizard to assign permissions by task, ensuring administrative tasks align with your organization's needs.
Plan and implement OUs in an Active Directory domain using location-based, resource-based, organization-based, multi-tenancy, and hybrid strategies to delegate administration, apply group policies, and manage objects efficiently.
Evaluate OU design in Active Directory through location-based, resource-based, organization-based, multi-tenant, and hybrid strategies. The knowledge check tests understanding of planning OUs and delegated administration.
Design the OU structure for administrative purposes and consistent GPO application, reflecting same control needs. Plan for change by managing inheritance and using lower-level OUs or security filtering for departments.
Explore considerations for using organizational units in Active Directory, including creating OUs with graphical tools or PowerShell, protecting them from accidental deletion, and moving them with permission implications.
Explore Active Directory OU design, delegation, and GPO application. Learn about inheritance, change management, and the practical steps to create or move OUs.
Explore how Active Directory delegation works, including OU-based permissions, inheritance, and security descriptors, and learn how to configure delegated admins and review access using the security tab.
Delegate Active Directory permissions by using object type delegation or role-based delegation, assigning rights to groups rather than individuals for targeted tasks across OUs and resources.
Explore tokens, security descriptors, and delegation methods in Active Directory, then validate understanding through knowledge-check questions on inheritance, role-based delegation, and the Delegation of Control Wizard.
Use Windows PowerShell to automate AD DS administration, manage groups, computer accounts, and OUs, perform bulk operations, query and modify objects, and work with comma-separated files.
Use Windows PowerShell to create, modify, and delete Active Directory groups, and manage group membership with commands to add, remove, and view group members.
Learn to manage Active Directory groups and memberships with PowerShell by creating security groups (global, domain local, universal), adding and removing members, and modifying group objects.
Add users and computers to security groups in Active Directory using PowerShell. Learn to add single or multiple members, from files or OUs, and verify results in the GUI.
Learn to manage computer accounts in Active Directory with PowerShell, add them to security groups using Add-ADGroupMember, and verify membership with Get-ADGroupMember for policy and deployment tasks.
Learn to nest security groups in Active Directory with PowerShell, explore domain local, global, and universal scopes, and perform bulk creation and member addition to a parent group.
List security group members with Get-ADGroupMember and Get-ADGroup, inspect object class, and export results to csv; remove members or groups with Remove-ADGroupMember and Remove-ADGroup, including bulk removal from csv.
Explore Windows PowerShell cmdlets to manage computers and OUs, including creating and deleting computer accounts with New-ADComputer, testing secure channels, resetting passwords, and organizing units with New-ADOrganizationalUnit.
Learn to manage computer objects in Active Directory with PowerShell: create, modify, move, and enable or disable computer accounts using New-ADComputer, Set-ADComputer, and Move-ADObject.
Enable, disable, and remove stale computer accounts in Active Directory with PowerShell. Follow security policies and regular reconciliations using Get-ADComputer, Enable-ADAccount, Disable-ADAccount, and Remove-ADComputer.
Learn the foundations of PowerShell, including pipelines, aliases, navigation, and common commands like Get-ChildItem, Get-Command, and Get-Help, to build scripts and manage objects.
Learn how WMI and CIM, built on DMTF standards, provide a common information repository via Windows PowerShell. Compare ad hoc WMI connections and session-based CIM connections through WinRM.
Explore the five FSMO roles—schema master, domain naming master, read master, infrastructure master, and PDC emulator master—and how they prevent replication conflicts by designating the controlling domain controllers.
Transfer or seize Fisma roles in an Active Directory environment, using GUI tools or NTDSUTIL and PowerShell, to move roles between domain controllers while understanding replication and last-resort seizing.
Immerse yourself in the exciting world of Active Directory (AD) management with our comprehensive and hands-on course: "Active Directory: Managing Groups, Computers and OUs". This course offers over 3 hours of high-quality video content, specially designed to help you gain a deep understanding of Active Directory Domain Services (AD DS).
This course is perfect for IT administrators, professionals, and enthusiasts who want to expand their knowledge base and improve their skills in managing Active Directory. Whether you're just starting out or have some experience under your belt, this course provides you with the tools you need to excel in your role.
In Section 1, we explore the management of groups in AD DS. Learn about different group types, scopes, and how to effectively implement group management. You'll understand managing members with Group Policy Object (GPO), dealing with default groups, and understanding special identities. Plus, a hands-on demonstration will give you real-world insights into managing groups in Windows Server.
In Section 2, we delve into managing computer objects in AD DS. We cover everything from specifying the location of computer accounts to controlling permissions and performing an offline domain join. You'll be equipped to manage computer objects like a pro.
Section 3 guides you through the process of implementing and managing Organizational Units (OUs). With lectures focused on planning OUs, considering OU hierarchy, and delegating AD DS permissions, you'll understand the nuances of OU management in no time.
Finally, Section 4 introduces you to the power of Windows PowerShell for AD DS administration. Get hands-on with managing, configuring, and modifying group and computer objects using PowerShell cmdlets. An introduction to Windows Management Instrumentation (WMI) and Common Information Model (CIM) wraps up this section, cementing your understanding of AD DS administration.
This course offers a balanced mix of theory and practical knowledge, ensuring you not only understand the concepts but can apply them in real-life scenarios. Are you ready to up your game in Active Directory management? Join us in "Active Directory: Managing Groups, Computers and OUs". Don't just learn it; master it!