Setting a Base Image with SYSPREP
Course Content
0 / 488 completedModule 1 Installing and configuring domain controllers. Overview
AD DS components
What is the AD DS schema
Course introduction
What is an AD DS forest
What are OUs
What is an AD DS domain
What is Azure AD
Overview of AD DS administration tools
Demo 2 Overview of AD DS administration tools and components
Demo 1 Overview of AD DS administration tools and components
Using the Active Directory Administrative Center to administer and manage AD DS
Demo What is a DC
Introduction
What is a global catalog
What is a domain controller
Demo What is a global catalog
Overview of domain controller SRV records
Demo Overview of domain controller SRV records
Demo AD DS sign-in process
Transferring and seizing roles
AD DS sign-in process
What are operations masters
Deploying a domain controller
Demonstration Installing a domain controller from Server Manager
Installing a domain controller on a Server Core installation of Windows Server 2
Demo Part 1. Installing a domain controller from Server Manager
Demo Part 2. Installing a domain controller from Server Manager
Demo Installing a domain controller on a Server Core
Installing a domain controller by installing from media
Cloning domain controllers
Demonstration Cloning domain controllers
Best Practices for Domain Controller Virtualization
Demonstration Adding Another domain controllers
Demonstration FSMO Roles
Demonstration Installing a domain controller with Powershell
Activating Windows Server 2022
Introduction and Installing Windows Server 2022
Post-Install Tasks. Part 1
Recap
Post-Install Tasks. Part 2
Setting up your first DC
Setting a Base Image with SYSPREP
Installing WAC and Joing a workstation to the domain
Server Core
Adding a Child Domain to the Lab
AD DS Admin Tools
Recap Base Lab SOP
Managing user accounts
Creating user accounts
Demo Configuring user account attributes
Demo Managing user accounts
Creating user profiles
Demo Creating user profiles
Demo User account templates
Using Windows PowerShell cmdlets to manage user accounts
Using Windows PowerShell to create users
Using Windows PowerShell for bulk users operations
Using Windows PowerShell to add users to groups
Using Windows PowerShell for bulk users operations
Using Windows PowerShell to modify users' properties
Using Windows PowerShell to modify users' properties. Part2
Using Windows PowerShell to delete users
Using Windows PowerShell to enablemove users
Managing groups in AD DS Section Overview
Demo Group types
Group types
Demo Group scopes
Group scopes
Demo Implementing group management (IGDLA)
Implementing group management
Managing members with GPO
Demo Using Restricted Groups Setting
Special identities
Demonstration Managing groups in Windows Server
Default groups
Managing computer objects in AD DS Section Overview
Controlling permissions to create computer accounts
Joining a computer to a domain
Specifying the location of computer accounts
Performing an offline domain join
Resetting the computer account (secure channel)
Implementing and managing OUs Section Overview
Planning OUs
OU hierarchy considerations
AD DS permissions
Considerations for using OUs
Delegating AD DS permissions
Using Windows PowerShell for AD DS administration Section Overview
Using Windows PowerShell cmdlets to manage groups
PowerShell Managing, configuring and modifying Group objects. Part 2
PowerShell Managing, configuring and modifying Group objects. Part 1
PowerShell Managing, configuring and modifying Group objects. Part 3
PowerShell Managing, configuring and modifying Group objects. Part 4
PowerShell Managing, configuring and modifying Group objects. Part 5
Windows PowerShell cmdlets to manage computers and OUs
PowerShell Managing, configuring and modifying Computer objects. Part 1
PowerShell Managing, configuring and modifying Computer objects. Part 2
Powershell Key Concepts
Course Overview
Section Overview
Overview of domain and forest boundaries in an AD DS structure
Why implement multiple domains
Why implement multiple forests
Deploying a domain controller in Azure IaaS
Managing objects in complex AD DS deployments
AD DS domain functional levels
AD DS forest functional levels
Deploying a distributed AD DS environment. Section Overview
Deploying new AD DS domains
Considerations for implementing complex AD DS environments
Demo Installing a domain controller in a new domain in an existing forest
Configuring AD DS trusts. Section Overview
Overview of different AD DS trust types
Upgrading a previous version of AD DS to Windows Server 2016
Migrating to Windows Server 2016 AD DS from a previous version
How trusts work in a forest
How trusts work between forests
Configuring advanced AD DS trust settings
What are AD DS partitions
Characteristics of AD DS replication
How AD DS replication works within a site
Resolving replication conflicts
How SYSVOL replication works
What are AD DS sites
How replication topology is generated
Why implement additional sites
Configuring AD DS sites Section Overview
How replication works between sites
How client computers locate domain controllers within sites
Overview of SRV records
What is the ISTG
Moving domain controllers between sites
Configuring and monitoring AD DS replication Section Overview
What are AD DS site links
What is universal group membership caching
What is site link bridging
Lab Sites and Replication. Solution
Lab Sites and Replication. Exercies and Tasks
What is Configuration management
Demonstration Exploring Group Policy tools and consoles
Computer Configuration and User Configuration
Overview of Group Policy tools and consoles
Benefits of using Group Policy
Group Policy Objects
Lesson 2 Implementing and administering GPOs
Overview of GPO scope
The Group Policy Client service and client-side extensions
Overview of GPO inheritance
What are domain-based GPOs
GPO storage
What are starter GPOs
Delegating administration of Group Policy
Common GPO management tasks
Lesson 3 Group Policy scope and Group Policy processing
Demo Delegating administration of Group Policy
What are GPO links
Group Policy processing order
Configuring GPO inheritance and precedence
Using security filtering to modify Group Policy scope
What are WMI filters
How to enable or disable GPOs and GPO nodes
Loopback policy processing
Considerations for slow links and disconnected systems
Identifying when settings become effective
Lab A Solution Implementing a Group Policy infrastructure
Lab Review
Lab A Tasks Implementing a Group Policy infrastructure
Troubleshooting the application of GPOs Lesson Overview
Examining Group Policy event logs
Demo Performing a what-if analysis with Group Policy Modeling Wizard
What is RSoP and Generating RSoP Report
Detecting Group Policy health issues
Review and Takeaways
Lab Review
Module Review and Takeaways
Lab B Solution Troubleshooting Group Policy infrastructure
Lab B Tasks Troubleshooting Group Policy infrastructure
What are administrative templates
What are .adm and .admx files
Overview of the central store
Demonstration Configuring settings with administrative templates
Importing security templates
Managing administrative templates
What is Folder Redirection
Section Overview
Settings for configuring Folder Redirection
Demonstration Configuring Folder Redirection
Group Policy settings for applying scripts
Security settings for redirected folders
Demonstration Configuring scripts with GPOs
Managing software with Group Policy
Item-level targeting options
Demonstration Configuring Group Policy preferences
Features of Group Policy preferences
Lab Review Managing user settings with Group Policy
What are Group Policy preferences Comparing with Policy settings
Module Review and Takeaways Managing user settings with Group Policy
Lab Tasks Managing user settings with Group Policy
Lab Solution Managing user settings with Group Policy
Designing a 'Group Policy Friendly AD'
Demo Designing a 'Group Policy Friendly AD'
Best Practices for GP Deployment
Demo Best Practices for GP Deployment
Module Review and Takeaways
Designing for Performance
The Microsoft Group Policy PowerShell Module
Demo The Microsoft Group Policy PowerShell Module
Basic GPO Management With PowerShell
Demo Basic GPO Management With PowerShell
Modifying the security settings of domain controllers
Security risks that can affect domain controllers
Securing physical access to domain controllers
Deploying an RODC
What are RODCs
Planning and configuring an RODC password replication policy
Demonstration Configuring a password replication policy
Separating RODC local administration
Implementing secure authentication
Account lockout policies
Password policies
Kerberos policies
Demonstration Configuring a fine-grained password policy
Tools for creating PSOs
Fine-grained password and lockout policies
Protecting groups in AD DS
Demonstration Configuring authentication-related audit policies and viewing log
PSO precedence and resultant PSO
Configuring user account policies
Account-security options
Scoping audit policies
Demonstration Configuring authentication-related audit policies and viewing log
Account logon and logon events
Challenges of using service accounts
Overview of managed service accounts
Overview of service accounts
What are group MSAs
Demonstration Configuring group MSAs
Lab Review
Lab Securing AD DS. Solution. Part 2
Module Review and Takeaways
Lab Securing AD DS. Solution
Lab Securing AD DS Exercises and Tasks
SMB Security Features
Demo Securing SMB - Auditing and Blocking SMBv1
Demo Securing SMB Part 2 - SMB Signing and Encryption
NTLM Security
DNS Security
Secure Management
Implementing DNSSEC
Managing Servers Using Windows Admin Center
Implementing NTLM Security
Protecting Credentials
Authentication Policy and Silo
Microsoft Tiering Model
Using the Protected Users Group
Local Admin Password Solution (LAPS)
Protecting Privileged Accounts with Authentication Policies and Silos
Installing the LAPS Client Side Extension
Credential Guard
Verifying Hardware Compatibility for Credential Guard
Preparing Active Directory for LAPS
Working with LAPS
User Rights Assignment
Enabling Credential Guard
Privileged Access Workstation (PAW)
Working with User Rights Assignment
Plan Your Progress
Course Overview
What is AD CS
Standalone vs. enterprise CAs
Options for implementing CA hierarchies
Section Overview Deploying CAs
Considerations for deploying a subordinate CA
Demonstration Deploying an enterprise root CA
Considerations for deploying a root CA
How to use the CAPolicy.inf file for installing a CA
Configuring CA security
Section Overview Administering CAs
Managing CAs
Security roles for CA administration
Configuring CA policy and exit modules
Demonstration Configuring CA properties
Configuring CDPs and AIA locations
Configuring Root CA Settings
Configuring Offline Root Certification Authority
Installing IIS Web Server and Importing Root CA Certificate
Configuring IIS Virtual Directory and Settings for PKI
Building a PKI Lab Environment with Hyper-V and Base Image
Configuring CRL and AIA Distribution Points on Subordinate CA
Setting Up an Enterprise Subordinate Certification Authority
Section Overview Troubleshooting CAs
Troubleshooting CAs
Renewing a CA certificate
Monitoring CA operations
Moving a root CA to another computer
Lab Task Deploying and managing AD CS
Lab Demonstration Steps Deploying and managing AD CS
What are certificates and certificate templates
Certificate template versions in Windows Server
Configuring certificate template settings
Configuring certificate template permissions
Options for updating a certificate template
Demonstration Modifying and enabling a certificate template
Assess Your Knowledge. Section Overview Managing certificate deployment
Certificate enrollment methods
Overview of certificate autoenrollment
What is an enrollment agent
How does certificate revocation work
Demonstration Configuring a CA for key archival
Overview of key archival and recovery
Using certificates for digital signatures
Using certificates for content encryption
Using certificates for SSL
Demonstration Signing a document digitally. Encrypting a file with EFS
Module Review and Takeaways
Lab Demonstration Steps Deploying and using certificates
Lab Task Deploying and using certificates
Overview of AD FS. Section Overview
What is identity federation
Overview of web services
What are claims-based identity and claims-based authentication
What is AD FS
How AD FS enables SSO in a single organization
What’s new in AD FS in Windows Server 2016
How AD FS enables SSO in a business-to-business federation
Section overview. AD FS requirements and planning
AD FS requirements
AD FS components
Federation server roles
PKI and certificate requirements
Planning a highly available AD FS deployment
Planning an AD FS deployment for online services
Capacity planning
Section Overview Deploying and configuring AD FS
What is a relying party trust
What is a claims provider trust
What are AD FS claims and claim rules
Configuring claims rules
Installing and configuring AD FS
How home realm discovery works
Configuring an account partner and a resource partner
Managing an AD FS deployment
Web Application Proxy. Section Overview
What is the Web Application Proxy
Web Application Proxy and AD FS proxy
Web Application Proxy authentication methods
Installing and configuring the Web Application Proxy
Scenarios for using the Web Application Proxy
Group Policy Processing
Group Policy Targeting
Demo Understanding Group Policy Processing
Demo Group Policy Targeting at Work
Group Policy Linking, Filtering, and Order of Processing
Demo Examples of GPO Linking, Filtering, and 'LSDOU'
Demo GPO Processing Hierarchy
Summary
GPO Processing Hierarchy
Installing the GPMC
Navigating the GPMC
Demo Navigating the GPMC
Demo Downloading and Installing GPMC
Understanding GPO Properties
Creating and Editing GPOs
Demo Creating, Editing, and Commenting GPOs
Demo Understanding GPO Properties
The Group Policy Processing Cycle
Background and Foreground Processing
Synchronous and Asynchronous Processing
Demo Synchronous and Asynchronous Processing
Group Policy Processing Mechanics
Demo Group Policy Processing Mechanics
Manual GP Processing
Demo Manual GP Processing
Understanding Administrative Templates Policy
Demo How Registry Tattooing Works
Administrative Templates and ADMX Files
Demo Administrative Templates and ADMX Files
Summary
Deploying Administrative Templates
Deployment Scenario Managing Windows Firewall
Deployment Scenario Group Membership Control
Demo Group Membership Control
Overview of Available Security Policy
Application Control Policies (AppLocker)
Demo AppLocker
Demo Managing Windows Firewall
Demo AppLocker
The Three Policy Areas for Managing IE
Demo Introducing the Three IE Policy Areas
Using GP Preferences Internet Settings
Demo Using GP Preferences Internet Settings
Using IE Administrative Templates
Managing (and Removing) IE Maintenance Policy
Demo Managing (and Removing) IE Maintenance Policy
Demo Using IE Administrative Templates
Capabilities and Features in Group Policy Software Installation
Demo Capabilities & Features in Group Policy Installation
Managing the Software Lifecycle
Demo Deploying Software Using Group Policy
GPSI Best Practices
Demo Patching an Existing Deployment
Summary
Demo Understanding the User Profile
How Folder Redirection Helps Redirect User Settings & Data
Implementing Folder Redirection
Using Group Policy Preferences for Folder Redirection
Demo Using Group Policy Preferences for Folder Redirection
Demo Implementing Folder Redirection
Group Policy Preferences Overview
Managing Local Users and Groups
GPP Drive Mapping
Demo Group Policy Preferences Overview
Demo Managing Local Users and Groups
GPP Printer Mapping
Demo GPP Drive Mapping
Demo GPP Printer Mapping
Using GPP for Registry Changes
Summary
Demo Using GPP for Registry Changes
Group Policy Scripts Capabilities and Limitations
Demo Navigating Group Policy Scripts
Deploying StartupShutdown Scripts
Deploying LogonLogoff Scripts
Demo Deploying StartupShutdown Scripts
Demo Deploying LogonLogoff Scripts
Script Configuration Options
Summary
Understanding Group Policy Loopback Processing
Kiosk Configurations and Loopback Processing
Demo Understanding Group Policy Loopback Processing
RDS, VDI, and Loopback Processing
Demo Kiosk Configurations and Loopback Processing
GPO Backup and Restoral
Demo GPO Backup and Restoral
GPO Import Tasks
Group Policy Delegation
Demo Group Policy Delegation
Demo Starter GPO
Demo GPO Import Tasks
Common Group Policy Problems
Troubleshooting with RSoP
Monitoring GPO Replication
Group Policy Logging
Demo Monitoring GPO Replication
Demo Troubleshooting with RSoP
Group Policy Tracing
Demo Group Policy Logging
Demo Group Policy Tracing
What is AD RMS
Usage scenarios for AD RMS
Overview of AD RMS components
AD RMS certificates and licenses
How AD RMS works
Comparing AD RMS, Azure RMS, and Azure RMS for Office 365
Lesson 2 Deploying and managing an AD RMS infrastructure
What is Azure RMS
Configuring the AD RMS cluster
AD RMS client requirements
Lesson 3 Configuring AD RMS content protection
Providing rights policy templates for offline use
Backuping, Decommissioning, Monitoring
Configure Password Replication Policies (PRP) for an RODC
Perform Active Directory Restore
Back up Active Directory and SYSVOL
Monitor and Manage Replication
Automate User Account Lockout Maintenance
Automate Password Resets
Perform AD Maintenance Tasks
Manage Inactive and Disabled Accounts
Manage containers, OUs, Groups
Manage Service Principal Names
Understand and Manage Group Managed Service Accounts
Configure Kerberos Policy Settings and Constrained Delegation
Magage groups
Configure Virtual Account
Delegate Password Settings Management and Configure PSOs
Configure Domain Password Policy Settings and Account Lockout Settings
Configure Password Replication Policies (PRP) for an RODC
Monitor and Manage Replication
Perform Active Directory Restore
Back up Active Directory and SYSVOL
Perform AD Maintenance Tasks
What is new in AD DS in Windows Server 2016
Demo Using the Active Directory Administrative Center
Demonstration Managing user accounts
Demonstration Managing groups in Windows Server with Powershell
Installing a domain controller from Server Manager