Get in Touch

Course Outline

1. Introduction

  • Foundations of Active Directory Domain Services (AD DS)
  • Course goals and expected learning outcomes
  • The role of Active Directory in enterprise infrastructures
  • Overview of the training lab environment
  • Essential Active Directory terminology and core concepts

2. Overview of Active Directory Features and Architecture

  • Architectural components of Active Directory
  • Distinguishing logical versus physical structures
  • Concepts of Domains, Trees, and Forests
  • Utilizing Organizational Units (OUs)
  • Role of Domain Controllers and Global Catalog
  • Flexible Single Master Operations (FSMO) roles
  • Sites and Subnets configuration
  • DNS integration within Active Directory
  • Active Directory partitions and underlying database structure

3. Overview of Identity Management Solutions and Concepts

  • Basics of Identity and Access Management (IAM)
  • Differentiating Authentication and Authorization
  • Implementing Kerberos authentication
  • Understanding NTLM authentication
  • Single Sign-On (SSO) mechanisms
  • Role-Based Access Control (RBAC) models
  • Managing the identity lifecycle
  • Concepts in hybrid identity management

4. Setting up Active Directory

  • Planning strategies for Active Directory deployment
  • Installation of Active Directory Domain Services
  • Promoting a server to become a Domain Controller
  • Creating new forests and domains
  • Installation and configuration of DNS
  • Verifying successful installation
  • Adhering to deployment best practices

5. Implementing Active Directory Domain Services

  • Creation of Organizational Units
  • Management of users, groups, and computer objects
  • Administering user accounts
  • Understanding Group scopes and types
  • Delegating administrative controls
  • Managing service accounts
  • Joining computers to the domain

6. Configuring and Managing Replication

  • Core concepts of Active Directory replication
  • Multi-master replication models
  • Understanding replication topology
  • Utilizing the Knowledge Consistency Checker (KCC)
  • Configuring Sites and replication schedules
  • Diagnosing replication issues
  • Monitoring replication health

7. Implementing and Managing Group Policy

  • Group Policy architectural components
  • Creation of Group Policy Objects (GPOs)
  • Linking GPOs to containers
  • Group Policy inheritance rules
  • Implementing Loopback processing
  • Use of Administrative Templates
  • Deploying software via GPO
  • Configuring Folder Redirection
  • Applying security policies
  • Defining Password and account lockout policies
  • Troubleshooting Group Policy issues

8. Implementing a Certification Authority (CA) Hierarchy

  • Introduction to Public Key Infrastructure (PKI)
  • Architecture of Certificate Services
  • Roles of Root and Subordinate Certification Authorities
  • Installation of Active Directory Certificate Services
  • Designing an effective CA hierarchy
  • Managing Certificate templates
  • Configuring Auto-enrollment

9. Managing Certificates

  • Managing the certificate lifecycle
  • Process of issuing certificates
  • Certificate renewal procedures
  • Handling Certificate revocation
  • Understanding Certificate Revocation Lists (CRLs)
  • Utilizing Online Certificate Status Protocol (OCSP)
  • Administering certificate templates
  • Troubleshooting certificate-related issues

10. Implementing and Administering Active Directory Federation Services (AD FS)

  • Introduction to federation services
  • AD FS architectural components
  • Implementing Claims-based authentication
  • Installation of AD FS
  • Configuring trust relationships
  • Implementing Single Sign-On
  • Integrating external applications
  • Monitoring and troubleshooting AD FS

11. Enabling Data Access

  • Core concepts of access control
  • Configuring NTFS permissions
  • Managing Shared folder permissions
  • Reviewing Effective permissions
  • Implementing Access-Based Enumeration
  • Using Dynamic Access Control
  • Deploying File Classification Infrastructure
  • Auditing file access activities

12. Securing Active Directory Domain Services

  • Best practices for Active Directory security
  • Understanding the Administrative security model
  • Implementing Tiered administration
  • Applying Privileged Access Management (PAM)
  • Securing Domain Controllers
  • Enforcing Password policies
  • Configuring Fine-Grained Password Policies
  • Setting Account lockout policies
  • Conducting Auditing and monitoring
  • Considering Backup and recovery strategies

13. Implementing and Managing Rights Management Services (RMS)

  • Introduction to Active Directory Rights Management Services
  • RMS architectural components
  • Installation of AD RMS
  • Protecting sensitive documents
  • Defining Information protection policies
  • Integration with Microsoft Office
  • Managing user access rights

14. Implementing Microsoft Entra ID (formerly Azure Active Directory)

  • Introduction to Microsoft Entra ID
  • Cloud identity management concepts
  • Hybrid identity architectural models
  • Configuring Microsoft Entra Connect
  • Implementing Password Hash Synchronization
  • Setting up Pass-through Authentication
  • Federation integration with AD FS
  • Overview of Conditional Access
  • Managing identity synchronization
  • Administering cloud identities

15. Integrating Active Directory with OpenLDAP

  • LDAP protocol fundamentals
  • Active Directory's LDAP support capabilities
  • Overview of OpenLDAP
  • Methods for identity synchronization
  • Integration of authentication mechanisms
  • Common interoperability scenarios
  • Security considerations during integration
  • Troubleshooting LDAP connectivity issues

16. Monitoring Active Directory

  • Essential monitoring tools
  • Utilizing Event Viewer
  • Using Performance Monitor
  • Managing via Active Directory Administrative Center
  • Leveraging PowerShell for monitoring tasks
  • Monitoring replication status
  • Conducting Health checks
  • Auditing system changes
  • Optimizing performance

17. Troubleshooting

  • Resolving User logon issues
  • Addressing DNS-related problems
  • Diagnosing Replication failures
  • Troubleshooting Group Policy application
  • Resolving Authentication issues
  • Fixing Certificate-related problems
  • Performing Domain Controller health checks
  • Using Diagnostic tools (dcdiag, repadmin, nltest, gpresult)
  • Executing Backup and recovery procedures
  • Handling Disaster recovery scenarios

18. Summary and Conclusion

  • Review of key concepts covered
  • Best practices for Active Directory administration
  • Security recommendations for implementation
  • Operational maintenance checklist
  • Access to additional Microsoft resources and documentation
  • Open Q&A session
  • Final hands-on review and lab wrap-up

Requirements

  • Background in system administration
  • Familiarity with Windows Server operations

Intended Audience

  • System administrators
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories