Active Directory Best Practices - Ten Years Later

  Рет қаралды 47,520

Adam Marshall

Adam Marshall

7 жыл бұрын

This is not my video and I take no ownership of this video. If the owner contacts me to take it down, I definitely will oblige. I've tried to contact Dan Holme directly and indirectly through a Microsoft Rep on Spiceworks but I've had no response. I can't find this video anywhere else so I posted my copy. It has GREAT information that should be shared with the world.

Пікірлер: 33
@KanchanaRandika
@KanchanaRandika 5 жыл бұрын
I learned a lot in less than one hour. Brilliant presentation from Dan. Thank you for uploading!
@AllenOlayiwola
@AllenOlayiwola 4 жыл бұрын
Never thought the MMC was this good, amazing video! Thanks for sharing.
@GamingCentralTV1
@GamingCentralTV1 5 жыл бұрын
This is a gem microsoft vid
@reveng6705
@reveng6705 Жыл бұрын
Many if not all stuff that is discussed in this great video also applies to AD running on Server 2019. Thanks for your work, Adam
@Adamj_1
@Adamj_1 Жыл бұрын
And Server 2022...anything on prem.
@jerryxie777
@jerryxie777 5 жыл бұрын
Great demo,I find that there are a lots of skills I don't know. Thank you😀
@andrecinelli
@andrecinelli 3 жыл бұрын
2021... Thank you!
@Kent21F1
@Kent21F1 5 жыл бұрын
wow ! great video !
@hisgreatness2
@hisgreatness2 5 жыл бұрын
very good video!
@vasylvolyk
@vasylvolyk Жыл бұрын
Useful. Thanks!
@jerryxie777
@jerryxie777 4 жыл бұрын
Thanks for your sharing, is there any new update skill for ad in windows 2019? I'm looking forward to that🥰
@karolkula9166
@karolkula9166 2 жыл бұрын
[Q] Where I could find more about implementation of "notification based replication between the sites"?
@ilishmaach
@ilishmaach 6 жыл бұрын
Do you have the script to extend the schema and assign computer ownership to users?
@Adamj_1
@Adamj_1 6 жыл бұрын
Please see my blog post at www.ajtek.ca/guides/role-based-access-security/
@dj9choco
@dj9choco 2 жыл бұрын
Dude, i never thought a regular user will fit my env because im the only it employe, and i manage all the network, computers and erp. but with the mmc properly tweaked will be safe and easy to manage all the env
@Adamj_1
@Adamj_1 2 жыл бұрын
Yep. Separate Admin and Regular User - even for the single IT person (I'd also argue especially for the single IT person)
@bradzima1779
@bradzima1779 Жыл бұрын
I don't suppose you have a copy of the slide deck from this presentation?
@Adamj_1
@Adamj_1 Жыл бұрын
I do not. Sorry. Only the RBAC scripts on www.ajtek.ca/guides/role-based-access-security/
@tkazi
@tkazi Жыл бұрын
A monochrome PDF version of these are available at the following Microsoft download URL. I couldn't find the color version of these. download.microsoft.com/download/e/a/7/ea75457b-65d0-481c-b53b-d7ca2ae7ee08/s2b%20-%209.pdf
@aleJohnny
@aleJohnny 3 жыл бұрын
I love you.
@omarionrobinson4020
@omarionrobinson4020 2 жыл бұрын
So blunt 😍
@gareginasatryan6761
@gareginasatryan6761 4 жыл бұрын
I don’t know if he’s conflating domains with trees. Because while multi tree forests have decreased in popularity, his claim that “single domain forests” are the rage is flat out untrue. Most enterprises I’ve seen have multiple levels of subdomains.
@andreas956
@andreas956 4 жыл бұрын
Propably differs depending on your location and field. In my experience, a majority of my clients have had single domain forests.
@xerr0n
@xerr0n 4 жыл бұрын
@@andreas956 the presentation is old, in the end hes talking about hoping that people enjoyed students to business 2011. Also note the server 2008 references in the video.....
@chancemanning8418
@chancemanning8418 2 жыл бұрын
Edit: Please take my opinion with a grain a salt. Different Environments will work better with different OU structure. Great video. Not exactly sure how that OU structure shown around minute 10-11 would be best practice? It’s not very efficient for identifying users. Having All system users under a single OU then separating out by Security Groups seems to defeat the purpose of creating any OU in general. Identity Management should be a key component when organizing your AD.
@chancemanning8418
@chancemanning8418 2 жыл бұрын
Having OU structure of departments OR regions of those users and computers would seem to be a better fit for deploying GPO. Security groups should be identified before hand and then be made to how granular you want to make security rules. Those groups could be placed within the OUs to organize them. But then again, the set up of OUs really isn’t that important, as long as it’s standardized and capable of identity management of your users.
@Adamj_1
@Adamj_1 2 жыл бұрын
See the video at part 43:30 to the end. You MANAGE via saved queries. For example You couldn't care if Joe Smith was in whatever department OU that you've created, you want to have your HelpDesk team reset his password. If you create your setup like in the video, management is SIMPLE and you set the permission ONCE. If you do it the way you're saying - creating department OUs and the like, you must grant access to reset passwords in MULTIPLE OUs instead of just the 1...
@julianhamann4925
@julianhamann4925 Жыл бұрын
@@Adamj_1 Hey Adam, if I add a taskpad view to a saved query and then open the saved .msc as a different user (to delegate administration) then the taskpad view for the saved query is no longer visible. I have been unable to fix this issue. Is there something you need to do in order to have taskpad views in a saved query usable by other admins?
@Adamj_1
@Adamj_1 Жыл бұрын
@@julianhamann4925 Just tested this - Saved a taskpad and a saved query and a taskpad to a saved query and all 3 are showing up properly when executing on a different physical server VM, different user account as a delegation would. Not sure what you are experiencing as I can't replicate it.
Understanding Active Directory and Group Policy
51:56
Kevin Brown
Рет қаралды 1,5 МЛН
Techdays 2011 - Role-Based Management Extreme Makeover
1:15:23
Adam Marshall
Рет қаралды 22 М.
Каха заблудился в горах
00:57
К-Media
Рет қаралды 7 МЛН
Red❤️+Green💚=
00:38
ISSEI / いっせい
Рет қаралды 84 МЛН
路飞太过分了,自己游泳。#海贼王#路飞
00:28
路飞与唐舞桐
Рет қаралды 28 МЛН
Introduction to Active Directory Directory Services Structure in Windows Server 2012
46:31
Beyond the Mcse: Active Directory for the Security Professional
49:53
MCITP 70-640: Active Directory different group types available
18:41
ITFreeTraining
Рет қаралды 134 М.
How to Setup Active Directory Domain With VirtualBox and Join Computers - 2020
45:59
What is Active Directory?
23:37
ManageEngine IAM and SIEM
Рет қаралды 273 М.
Active Directory Best Practices That Frustrate Pentesters
1:03:51
Black Hills Information Security
Рет қаралды 34 М.
2016 Active Directory Training for IT Support
33:13
Jobskillshare Skills-Based Platform
Рет қаралды 178 М.
Administrators’ Idol   Windows and Active Directory Best Practices
1:35:12
Understanding Active Directory Sites
31:45
Kevin Brown
Рет қаралды 85 М.
Каха заблудился в горах
00:57
К-Media
Рет қаралды 7 МЛН