
Centralize authentication with Active Directory by storing users, computers, printers, file shares, and security groups in a domain controller, enabling single-point password management with group policy.
Set up an Active Directory and Group Policy lab with VMware Workstation or VirtualBox, deploying Windows Server 2019 as a domain controller and a Windows 10 client.
Download Windows Server 2019 and Windows 10 for training with a free trial ISO, sign in with a Microsoft account, choose 32-bit or 64-bit, English, and start the download.
Download and install VMware Workstation Pro from vmware.com, selecting the Windows or Linux version, and register for a vmware.com account to access the full product.
Install VMware workstation from VMware.com by running as administrator, accept license, enable keyboard driver, and reboot; then activate a license or start a 30-day trial on Windows desktop or server.
Set up a lab in VMware Workstation to install Windows Server 2019 as a domain controller and a Windows 10 client, enabling hands-on practice with Active Directory and Group Policy.
Configure virtual machines for the lab by renaming the host, disabling Windows firewall, setting admin passwords, assigning static IPs, and enabling Remote Desktop to connect to Active Directory domain services.
Install the Active Directory Domain Services and DNS roles on a server, then promote it to a domain controller for lab.local, configuring forest and domain functional levels.
Navigate the Active Directory via server manager to explore the Active Directory users and computers panel, domain controllers, delegate control, filters, and the domain functional level.
Join a Windows 10 client to the domain services in Active Directory, configure DNS to the domain controller, and log in with a domain administrator account.
Create a new user in Active Directory by selecting an organizational unit within the domain, entering a logon name and initial password, and enforcing password change at next logon.
Discover how to search and locate objects in Active Directory domains, including users, computers, and containers, using the find function, advanced options, and wildcard searches.
Reset a user’s password, force change at next logon, unlock accounts, and ensure the correct logon name; if blocked by policy, adjust minimum password age via group policy.
Create and manage groups and object memberships in Active Directory users and computers, exploring security and distribution groups, group scopes, domain local, global, universal, and cross-domain access.
Configure logon time restrictions in Active Directory by denying all times and allowing a window, such as 7 a.m. to 7 p.m., with Fridays to Sundays blocked.
Learn to restrict a user’s logon to a single computer in Active Directory by assigning a computer name. Then test login from a separate account after granting domain admin rights.
Map a shared folder for all domain users in Active Directory, granting read and write access. Map the folder as a network drive (Z:) for easy access.
Map multiple folders to domain users using a startup script in group policy, employing a net use command to mount a hidden share (dollar sign) and assign read/write access.
Learn how group policy lets administrators configure users and computers in Active Directory by applying GPOs to OUs, enabling security settings and selective access across the domain.
Launch group policy management console to navigate forest and domains. Use group policy modeling and results, review default domain and domain controller policies, and study WMI filters.
Create and link group policy objects (GPOs) in Active Directory to apply user and computer settings across domains and organizational units, and manage links and deletions.
Link and manage group policy objects in active directory by applying policies to domain users and computers, using authentication-based filtering, inheritance, and delegation for controlled access.
Learn how group policy precedence decides which settings apply when multiple GPOs configure the same option. Understand apply order from local to site, domain, and organizational units, including enforce GPOs.
Explore editing group policy objects by choosing computer or user configurations, linking GPOs to OUs, and applying policies or preferences across Windows settings, including desktop cleanup wizard.
Use gpresult and gpupdate from the command line to troubleshoot group policy objects, view applied policies, and understand default domain policy and test policies on domain controllers.
Create non-inheriting organizational units in Active Directory, apply and enforce group policy to selected users and computers, and verify policy results with gpupdate and gpresult.
Create and link a GPO to disable Windows Defender firewall for domain computers by applying it to the domain root, then test with gpupdate to confirm policy application.
Create a GPO to set a logon banner for domain computers, configure an interactive logon message title and text, apply the policy, and force update to display at logon.
Create and link a group policy object to deploy a desktop wallpaper from a shared folder, configure permissions, test with gpupdate, and apply the wallpaper to domain users.
Deploy software over the domain by sharing an MSI folder, configuring a software deployment GPO in computer configuration, and applying via gpupdate to install Adobe Acrobat Reader and Mozilla Firefox.
This lecture demonstrates creating two Active Directory groups and users, sharing folders for each group, and automatically mapping those shares via group policy drive maps, with proper permissions and delegation.
Configure domain password policies in the default domain policy via group policy, enforcing a 24-password history, a 60-day maximum age, a zero minimum age, and a 12-character minimum with complexity.
Configure the account lockout policy in computer configuration to lock a domain user after three invalid logon attempts, set the ten-minute duration, and test with three wrong passwords.
Configure domain computers firewall rules with group policy to allow ICMP ping via a dedicated firewall policy linked to the sales OU.
Grant domain users administrative permissions using the Microsoft Management Console by adding the computer management snap-in and running as administrator; manage disk management and device manager, then log off.
Configure restricted group via group policy to grant local administrator rights to IT groups while protecting domain admin credentials, using gpupdate /force and careful policy application.
rename the administrator and guest accounts on domain computers using group policy. apply the changes with gpupdate /force and understand the security rationale for disabling password changes.
Deny control panel access on all domain computers using group policy by enabling prohibit access to control panel and PC settings under user configuration, then run gpupdate /force.
Apply a deny policy to domain admins to restore control panel access, while domain users remain denied; force policy update with gpupdate /force and verify the result.
Create local folders and copy files to domain computers and users using group policy, with share and security permissions adjusted for read access. Run gpupdate /force to verify deployment.
Learn to map and share printers via group policy for domain users, configure manual network printer settings, enable sharing in Active Directory, and force gpupdate to apply the policy.
Practice configuring group policy to deny log on locally or allow login for specific users on designated computers, using the deny log on locally policy and user rights assignments.
Disable Windows task manager for users using a group policy in Active Directory, including creating a GPO, removing task manager, and applying gpupdate /force, and exempt domain admins via delegation.
Enable remote desktop connection using group policy to securely grant domain users remote access, configure permissions, test with gpupdate, and manage firewall considerations.
Configure group policy to deny access to USB storage for domain users, using the all removable storage class policy under computer configuration, and refresh with gpupdate /force to block access.
Configure audit policy in Active Directory and group policy to track user behavior, including logon events and account management, with events recorded in the security log via event viewer.
Learn how to configure folder redirection with group policy to move specific user profile folders like desktop and documents to a shared network location, enabling roaming profiles and offline access.
deploy group policy startup, shutdown, logon, and logoff scripts to display background info on clients using a batch file and a public folder, exporting bg info configuration for domain-wide deployment.
Back up all or individual group policies to a safe shared location, then restore as needed; note links may not be restored, and you restore one GPO at a time.
Install and promote a second domain controller in a lab, configure DNS to the first domain controller, and set up replication with optional global catalog and read-only options.
Deploy a read-only domain controller in a remote office, optionally use a local DNS server, and limit password replication to the allowed password replication group.
Learn to deploy a read-only domain controller as a dns server, configure a primary read-only zone, perform zone transfers, and route clients to writable dns servers to reduce cross-site traffic.
Demonstrates what happens when the first domain controller becomes unavailable, and how a second DC and DNS help logons and maintain Active Directory operations, including global catalog roles.
Connect with the instructor on LinkedIn and explore course resources, including Gns3 and eve-ng lab images, pre-built labs, and ova imports for ccna, ccnp, and cci practice.
Master Active Directory & Group Policy with Windows Server | Hands-On LAB Training for Beginners & IT Professionals
This practical Active Directory & Group Policy training course is designed for both beginners entering the IT field and experienced IT professionals who want to strengthen their Microsoft infrastructure skills using real-world LAB scenarios.
In this course, you will learn how to deploy, configure, manage, secure, and troubleshoot Active Directory environments using Windows Server 2019. You will also gain hands-on experience with Group Policy management, organizational design, domain administration, and enterprise best practices.
*** If you have any questions or need help, feel free to contact me on LinkedIn. ***
What You Will Learn
Active Directory Fundamentals
Active Directory Deployment
Installing & Configuring Domain Controllers
User & Computer Account Management
Organizational Unit (OU) Design & Administration
Group Administration
Group Policy (GPO) Fundamentals
Applying & Managing Group Policies
Deploy Additional Domain Controllers
Deploy Read-Only Domain Controllers (RODC)
Configure Active Directory Sites & Services
FSMO Roles Management
Global Catalog Planning
Active Directory Trust Relationships
Forest & Domain Functional Levels
Disaster Recovery & Backup Strategies
Restoring Deleted Active Directory Objects
Securing Active Directory Environments
Real Enterprise Administration Tasks
Hands-On LAB Training
This course is heavily focused on practical LAB experience using virtualization technologies. You will build your own Active Directory environment step-by-step and practice real administrative tasks used in enterprise production networks.
All installation files, ISOs, and LAB materials are included so you can start practicing immediately without wasting time searching online.
Understanding Group Policy
Group Policy is one of the most powerful administration tools in Microsoft Active Directory environments. It allows administrators to centrally manage users, computers, security settings, desktop configurations, scripts, software deployment, and much more across the entire domain.
You will learn:
How Group Policy works
GPO Processing Order & Hierarchy
Applying GPOs to Users, Computers & OUs
Security Policies & Restrictions
Managing Workstations with GPOs
Using Group Policy Management Console (GPMC)
Troubleshooting Group Policy Issues
Using gpupdate & gpresult Commands
Real Enterprise Skills
This course is designed to provide skills that are directly applicable to real-world IT jobs and enterprise environments. Instead of only learning theory, you will gain practical experience managing Active Directory infrastructures like a real system administrator.
Course Includes
6+ Hours of Practical Video Training
Downloadable LAB Files & ISOs
Step-by-Step Active Directory Deployment
Hands-On Group Policy Configuration
Q&A Support
Valuable Resources & Links
Real Enterprise LAB Scenarios
Who This Course Is For
Beginners Interested in IT & System Administration
Windows Server Administrators
Network Engineers
Help Desk & IT Support Engineers
University Students
Anyone Preparing for Real Active Directory Administration
Requirements
Basic TCP/IP Networking Knowledge
Basic Virtualization Knowledge
VMware Workstation Recommended for LAB Practice
Why Learn Active Directory?
Active Directory remains one of the most important technologies used in enterprise environments worldwide. Companies rely heavily on Active Directory for:
User Authentication
Centralized Administration
Security Management
Group Policy Enforcement
Access Control
Infrastructure Management
Learning Active Directory and Group Policy can significantly improve your IT administration skills and help prepare you for real-world system administration roles.
Beginner-Friendly Training
This course is designed in a simple, step-by-step format so even beginners can follow along easily and build a fully functional Active Directory LAB environment from scratch.
PS: Check the Free Preview videos to learn more about the course and become familiar with my teaching style and accent.