Get in Touch

Course Outline

1. Introduction

  • Foundations of Active Directory Domain Services (AD DS)
  • Course goals and expected learning outcomes
  • The role of Active Directory within enterprise environments
  • Introduction to the training lab environment
  • Key Active Directory terminology and concepts

2. Active Directory Features and Architecture Overview

  • Architectural components of Active Directory
  • Distinguishing between logical and physical structures
  • Concepts of Domains, Trees, and Forests
  • Utilizing Organizational Units (OUs)
  • Domain Controllers and the Global Catalog
  • Flexible Single Master Operations (FSMO) roles
  • Configuring Sites and Subnets
  • Integration of DNS with Active Directory
  • Active Directory partitions and database organization

3. Identity Management Solutions and Concepts

  • Core principles of Identity and Access Management (IAM)
  • Differentiating Authentication from Authorization
  • Kerberos authentication protocol
  • NTLM authentication mechanism
  • Implementing Single Sign-On (SSO)
  • Role-Based Access Control (RBAC)
  • Managing the identity lifecycle
  • Understanding hybrid identity models

4. Setting Up Active Directory

  • Planning an Active Directory deployment strategy
  • Installing Active Directory Domain Services
  • Elevating a server to Domain Controller status
  • Creating new forests and domains
  • Installing and configuring DNS
  • Validating the installation
  • Deployment best practices

5. Implementing Active Directory Domain Services

  • Creating Organizational Units
  • Managing users, groups, and computer objects
  • Administrating user accounts
  • Understanding group scopes and types
  • Delegating administrative controls
  • Managing service accounts
  • Connecting computers to the domain

6. Configuring and Managing Replication

  • Core concepts of Active Directory replication
  • Multi-master replication model
  • Replication topology design
  • Knowledge Consistency Checker (KCC)
  • Site-based replication schedules
  • Diagnosing replication issues
  • Monitoring replication health

7. Implementing and Managing Group Policy

  • Group Policy architectural framework
  • Creating Group Policy Objects (GPOs)
  • Linking GPOs to scope targets
  • Managing Group Policy inheritance
  • Loopback processing techniques
  • Utilizing Administrative Templates
  • Deploying software via GPO
  • Configuring Folder Redirection
  • Implementing security policies
  • Setting password and account lockout policies
  • Resolving Group Policy issues

8. Building a Certification Authority (CA) Hierarchy

  • Introduction to Public Key Infrastructure (PKI)
  • Architecture of Certificate Services
  • Roles of Root and Subordinate Certification Authorities
  • Installing Active Directory Certificate Services
  • Designing the CA hierarchy structure
  • Managing certificate templates
  • Configuring Auto-enrollment

9. Managing Certificates

  • Overseeing the certificate lifecycle
  • Issuing certificates
  • Handling certificate renewals
  • Revoking certificates
  • Managing Certificate Revocation Lists (CRLs)
  • Online Certificate Status Protocol (OCSP)
  • Administering certificate templates
  • Troubleshooting certificate-related issues

10. Implementing and Administering Active Directory Federation Services (AD FS)

  • Introduction to federation services
  • AD FS architectural components
  • Claims-based authentication mechanisms
  • Installing AD FS
  • Configuring trust relationships
  • Implementing Single Sign-On
  • Integrating external applications
  • Monitoring and resolving AD FS issues

11. Enabling Data Access

  • Foundations of access control
  • Configuring NTFS permissions
  • Setting shared folder permissions
  • Determining effective permissions
  • Implementing Access-Based Enumeration
  • Utilizing Dynamic Access Control
  • File Classification Infrastructure
  • Auditing file access activities

12. Securing Active Directory Domain Services

  • Security best practices for Active Directory
  • The administrative security model
  • Implementing tiered administration
  • Privileged Access Management (PAM)
  • Securing Domain Controllers
  • Enforcing password policies
  • Applying Fine-Grained Password Policies
  • Configuring account lockout policies
  • Conducting auditing and monitoring
  • Considering backup and recovery strategies

13. Implementing and Managing Rights Management Services (RMS)

  • Introduction to Active Directory Rights Management Services
  • RMS architectural overview
  • Installing AD RMS
  • Protecting sensitive documents
  • Defining information protection policies
  • Integration with Microsoft Office
  • Managing user access rights

14. Implementing Microsoft Entra ID (formerly Azure Active Directory)

  • Introduction to Microsoft Entra ID
  • Cloud identity fundamentals
  • Hybrid identity architecture design
  • Using Microsoft Entra Connect
  • Password Hash Synchronization
  • Pass-through Authentication
  • Federation integration with AD FS
  • Overview of Conditional Access
  • Managing identity synchronization
  • Administering cloud identities

15. Integrating Active Directory with OpenLDAP

  • LDAP fundamental concepts
  • LDAP support within Active Directory
  • Overview of OpenLDAP
  • Methods for identity synchronization
  • Integrating authentication processes
  • Common interoperability use cases
  • Security implications
  • Troubleshooting LDAP connections

16. Monitoring Active Directory

  • Essential monitoring tools
  • Using the Event Viewer
  • Utilizing Performance Monitor
  • Active Directory Administrative Center
  • Leveraging PowerShell for monitoring
  • Tracking replication performance
  • Performing health checks
  • Auditing configuration changes
  • Optimizing performance

17. Troubleshooting

  • Resolving user logon issues
  • Addressing DNS-related problems
  • Diagnosing replication failures
  • Troubleshooting Group Policy application
  • Resolving authentication errors
  • Fixing certificate-related issues
  • Conducting Domain Controller health checks
  • Using diagnostic tools (dcdiag, repadmin, nltest, gpresult)
  • Executing backup and recovery procedures
  • Handling disaster recovery scenarios

18. Summary and Conclusion

  • Recap of key concepts
  • Best practices for Active Directory administration
  • Security recommendations
  • Operational maintenance checklist
  • Additional Microsoft resources and documentation
  • Questions and answers session
  • Final hands-on review and lab conclusion

Requirements

  • Background in system administration
  • Practical experience with Windows Server

Target Audience

  • System administrators
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories