MCTS 70-640 Cert
Guide:
Windows Server
2008
Active
Directory,
Configuring
Don Poulton
Pearson
800
East
96th Streetiv MCTS 70-640 CertGuide: WindowsServer2008 Active
Directory, Configuring
Table
of Contents
Introduction 3
Goals and Methods 3
How ThisBook Is
Organized
4Study
andExamPreparation Tips
7Learning Styles
7StudyTips
8Study Strategies
9Pretesting
Yourself
10 ExamPrep
Tips
10Microsoft 70-640 Exam
Topics
12Chapter
1Getting
Started with ActiveDirectory
17The FoundationofActive
Directory
17 X.S00 17LDAP 18
Naming
Standards of X.500andLDAP 19Distinguish
ed Names 19 RelativeDistinguished
Names 20User
Principal
Names 21Globally Unique Identifiers
21Security Identifiers
21Active
Directory
Canonical Names 22The
Building
Blocks ofActiveDirectory
22Namespaces
22Objects
23 Containers 24 Schemas 24 GlobalCatalogs
24 Partitions 25V
Global
Catalog
Servers 31Operations
Masters 32New Features of Active
Directory
in Windows Server 2008 33Server
Manager
35Adding
Roles and Features 36Command-Line Server
Management
36 Windows Server2008R2 37Summary
40Chapter
2Installing
andConfiguring
DNSfor Active Directory 43 "Do I KnowThisAlready?"
Quiz
43The HierarchicalNatureofDNS 48
Installing
DNS onWindowsServer2008 R2 49Configuring
DNS Zones 51DNSZone
Types
52Primary
Zones S3Secondary
Zones 53 Stub Zones S3Active
Directory-Integrated
Zones 53 GkbalNames Zones 54DNS Name Server Roles 55
Primary
Name Server 55Secondary
NameServer 55Caching-Only
Server 56Forwarders 56
Creating
DNS Zones 57 ForwardLookup
Zones 57 ReverseLookup
Zones 59DNS Resource Records 61
Configuring
DNS ZoneProperties
62Configuring
ZoneTypes
63Adding
Authoritative DNS ServerstoaZone 63Dynamic, Nondynamic,
and SecureDynamic
DNS 64Zone
Scavenging
65 TimetoLive 66Integrating
DNS withWINS 68MCTS 70-640 Cert Guide: WindowsServer2008Active
Directory, Configuring
Complete
the Tables and Lists fromMemory
71 Definitions ofKey
Terms 71Chapter
3Installing
ActiveDirectory
Domain Services 73 "Do I KnowThisAlready?"
Quiz
73Planning
the ActiveDirectory
Namespace
77Subdividing
the ActiveDirectory Namespace
77Administrativeor
Geographical
Organization
ofDomains 78Use
ofMultiple
Trees 79 Best Practices 80Creating
Forests and Domains 81Requirements
forInstalling
ActiveDirectory
Domain ServicesInstalling
ActiveDirectory
Domain Services 82New Forests 83
New Domains in
Existing
Forests 88Existing
Domains 89Performing
Unattended Installations of ActiveDirectory
90 Server Core DomainControllers 92Removing
ActiveDirectory
92Interoperability
with Previous Versions of ActiveDirectory
93 Forest and Domain Functional Levels 94Upgrading
Domain and Forest Functional Levels 95 TheAdprepUtility
96Running
the Adprep IfarestprepCommand 96Running
the Adprep Idomainprep Command 97Upgrading
aWindowsServer 2003 DomainController 97AdditionalForest and Domain
Configuration
Tasks 98Verifying
theProper
Installationof ActiveDirectory
98Active
Directory Migration
Toolv.3.1 100AlternativeUser
Principal
Name Suffixes 101 ReviewAll theKey Topics
103Complete
the Tables and Lists fromMemory
103 Definitions ofKey
Terms 104Chapter
4Configuring
DNS ServerSettings
andReplication
107 "Do I Know ThisAlready?"
Quiz
107Configuring
DNS ServerSettings
112Forwarding
112vii Root Hints 116
Configuring
ZoneDelegation
117 Debug Logging
119Event
Logging
121DNS
Security
Extensions 121AdvancedServer
Options
123Server
Options
123Round Robin 124 Disable Recursion 125 Name
Checking
125Loading
Zone Data 126 ServerScavenging
126Monitoring
DNS 127Configuring
Zone Transfers andReplication
128Replication Scope
128Types
of Zone Transfers 130 Full ZoneTransfer
130 lncre?nental ZoneTransfer
131Configuring
ZoneTransfers
132Configuring
DNSNotify
133SecureZone Transfers 134
Configuring
Name Servers 136Application Directory
Partitions 138Installing
andConfiguring Application Directory
Partitions 138CreatingApplication Directory
PartitionReplicas
139Application Directory
PartitionReference
Domains 139 Review All theKey Topics
140Complete
the Tables and Lists fromMemory
140 Definitions ofKey
Terms 140Chapter5 Global
Catalogs
andOperations
Masters 143 "Do IKnowThisAlready?"
Quiz
143Configuring
GlobalCatalog
Servers 148Planning
the PlacementofGlobalCatalog
Servers 148Promoting
Domain ControllerstoGlobalCatalog
Servers 150Using
UniversalGroup
Membership Caching
151MOTS70-640 Cert Guide: Windows Server 2008 ActiveDirectory, Configuring
Configuring Operations
Masters 153 Schema Master 153Configuring
theSchema 154Extending
theSchema 155Deactivating
SchemaObjects
159Domain
Naming
Master 160 PDC Emulator 160TimeService 161
Infrastructure Master 162 RID Master 162
Placement of
Operations
Masters 163Transferring
andSeizing
ofOperations
Master Roles 164Transferring Operations
Master Roles 165Seizing Operations
Masters Roles 167 Review All theKey
Topics
169Complete
theTables and ListsfromMemory
169Definitionsof
Key
Terms 170Chapter
6Configuring
ActiveDirectory
Sites andReplication
173 "DoIKnow ThisAlready?"
Quiz 173The Needfor Active
Directory
Sites 178Configuring
Sites and Subnets 179Creating
Sites 180Adding
D omain Controllers 181Creating
andUsing
Subnets 182Site
Links,
Site LinkBridges,
andBridgehead
Servers 184 The Need for SiteLinks andSiteLinkBridges
184Configuring
SiteLinks 185SiteLink
Bridges
185SiteLinkCosts 186 Sites Infrastructure 189
Knowledge Consistency
Checker 189 IntersiteTopology
Generator 189Configuring
ActiveDirectory
Replication
189Concepts
of ActiveDirectory Replication
190 Intersite and IntrasiteReplication
191Distributed File
System
192ix
Bridgehead
Servers 193Replication
Protocols 194PortsUsed
for
IntersiteReplication
195Replication Scheduling
196 IntersiteReplication Scheduling
196 IntrasiteReplication
Scheduling
198Forcing
IntersiteReplication
200 Review All theKey
Topics
201Complete
theTablesand Lists fromMemory
202 Definitions ofKey
Terms 202Chapter
7 AdditionalActiveDirectory
Roles 205 "Do IKnow ThisAlready?"
Quiz 205New Server Rolesand Features 210
Active
Directory
Lightweight
Directory
Services 211Installing
AD LDS 213Installing
the AD LDS Role 213Installing
AD LDSInstances 214Configuring
Data WithinADLDS 217Using
the ADSIEditSnap-in
217UsingLdp.exe
218Using
the ActiveDirectory
SchemaSnap-in
220Using
theActiveDirectory
Sites and ServicesSnap-in
221Migrating
to ADLDS 221Configuring
anAuthentication Server 222Creating
ADLDS User AccountsandGroups
222Binding
toanADLDS Instance -withanADLDS User 224Using
ADLDSonServer Core 224Active
Directory Rights
Management
Services 225Installing
AD RMS 226Certificate
Request
andInstallation 228Self-Enrollments 230
Delegation
230Active
Directory Metadirectory
Services 231Active
Directory
FederationServices 231Installing
the AD FS Server Role 2 3 3x MOTS 70-640 CertGuide: Windows Server 2008 ActiveDirectory,
Configuring
Configuring
FederationTrusts 238Creating
Claims 239Creating
AccountStores 240Enabling
Applications
241Creating
FederationTrusts 242Windows Server 2008 R2 Virtualization 244 Review M the
Key Topics
247Complete
theTablesand Lists fromMemory
247Definitions of
Key
Terms 248Chapter
8Read-Only
Domain Controllers 251 "Do I KnowThisAlready?"
Quiz
251Installing
aRead-Only
DomainController 254Planning
theUse of RODCs 254Installing
RODCs 256Prestaging
anRODC 257Managing
aRead-Only
DomainController 259 UnidirectionalReplication
260Administrator Role
Separation
261Read-Only
DNS 262BitLocker 263
Preparing
YourComputer
to Use BitLocker 265Enabling
BitLocker 265Managing
BitLocker 269Replication
of Passwords 270Planning
aPasswordReplication
Policy
271Configuring
aPasswordReplication
Policy
2 72Credential
Caching
213Administering
theRODCs Authentication Lists 275 syskey 276Review ail the
Key
Topics
278Definitions of
Key
Terms 278Chapter
9 ActiveDirectory
User andGroup
Accounts 281 "DoIKnow ThisAlready?"
Quiz
281Creating
User andGroup
Accounts 286Introducing
UserAccounts 2 86Introducing
Group
Accounts 287xi
Useof
Template
Accounts 290Using
BulkImport
toAutomateAccount Creation 291Csvde 292
Ldifde 293 Dsadd 294
AdditionalCommand-LineTook 295
Scripts
296Configuring
the UPN 296 UPNSuffixes
296.
Adding
orRemoving
UPNSuffixes
291Configuring
Contacts 298Creating
Distribution Lists 299Managing
andMaintaining
Accounts 300Creating
Organizational
Units 301Configuring Group
Membership
304 AGDLP/AGUDLP 306Account Resets 308
Deny
Domain LocalGroup
308 ProtectedAdmin 309Local Versus Domain
Groups
310Deprovisioning
Accounts 312Delegating
Administrative Control ofActiveDirectory Objects
313ReviewAllthe
Key Topics
317Complete
the Tablesand Lists fromMemory
318Definitionsof
Key
Terms 318Chapter
10 TrustRelationships
in ActiveDirectory
321 "Do I Know ThisAlready? "Quiz
321Types
of TrustRelationships
325 Transitive Trusts 325 Forest Trusts 326ExternalTrustsand Realm Trusts 326 ShortcutTrusts 327
Creating
andConfiguring
TrustRelationships
328Creating
aForestTrustRelationship
329Creating
External TrustRelationships
335Creating
Realm TrustRelationships
336xii MCTS 70-640 Cert Guide: Windows Server 2008 ActiveDirectory,
Configuring
Managing
TrustRelationships
338Validating
TrustRelationships
338Authentication
Scope
338 SIDFiltering
340Removing
aCross-forest TrustRelationship
341Review All the
Key Topics
343Complete
the Tables and Lists fromMemory
343 Definitions ofKey
Terms 343Chapter
11Creating
andApplying Group Policy Objects
345 "Do I Know ThisAlready?"
Quiz
345Overview of
Group Policy
351Components
ofGroup Policy
351Group
Policy
Containers 352Group Policy
Templates
352New Features of
Group Policy
in Windows Server 2008 and Windows Server 2008 R2 354Creating
andApplying
GPOs 355Managing
GPOs 359Linking
GPOs 360Managing
GPO Links 361Deleting
a GPO 362Delegating
Controlof
GPOs 362Specifying
aDomain Controller 365Configuring
GPOHierarchy
andProcessing Priority
365OVHierarchy
361Enforced
367 Block Inheritance 369Modifying
theSequence of
GPOApplication
3 70Disabling
UserObjects
370Group
Policy Filtering
371Security
Filtering of
GPOs 371Windows
Management
Instrumentation 3 74 Windows PvmerShell 374Configuring
GPOTemplates
376Group
Policy Loopback
Processing
377User
Rights
378ADMX Central Store 379
xiii Restricted
Groups
3 84Starter GPOs 385
ShellAccess Policies 387 Review All the
Key
Topics
38 9Complete
the Tables and Lists fromMemory
389 Definitions ofKey
Terms 390Chapter
12Group Policy
SoftwareDeployment
393"DoIKnowThis
Already?"
Quiz
393Types
of SoftwareDeployment
398Assigning
andPublishing
Software 399Assigning
Software
toUsers 399Assigning Software
toComputers
399Publishing Software
to Users 399Deploying
SoftwareUsing Group Policy
400 ZAP Files 402SoftwareInstallation
Properties
403 SoftwarePackage Properties
405Upgrading
Software 407Use of Transform Filesto
Modify
SoftwarePackages
409Redeployment
ofUpgraded
Software 411Removal of Software 413 Review All the
Key Topics
414Complete
the Tables and ListsfromMemory
414Definitions of
Key
Terms 414Chapter
13 AccountPolicies andAudit Policies 417 "Do I Know ThisAlready?"
Quiz 417Useof
Group Policy
toConfigure Security
422Configuring
Account Policies 422Domain Password Policies 423 Account Lockout 426
Unlocking
anAccount 427Kerberos
Policy
428Fine-Grained PasswordPolicies 428 Password
Settings
Precedence 429Configuring
Fine-GrainedPassword Policies 430Managing
Fine-Grained Password Policies 43 JMCTS 70-640 Cert Guide:Windows Server 2008 Active
Directory, Configuring
Security Options
436Using
AdditionalSecurity Configuration
Tools 439Auditing
of ActiveDirectory
Services 441New Features of Active
Directory Auditing
441Using
GPOstoConfigure Auditing
442Available
Auditing
Categories
442Configuring
BasicAuditing
Policies 443Configuring
Advanced AuditPolicies 446Using
Auditpol.exe toConfigure Auditing
447 ReviewAlltheKey Topics
449Complete
the Tablesand Lists fromMemory
450 Definitions ofKey
Terms 450Chapter
14Monitoring
ActiveDirectory
453 "Do I Know ThisAlready?" Quiz
453 Tools UsedtoMonitor ActiveDirectory
459NetworkMonitor 459
Task
Manager
463Configuring
Application Priority
465 EventViewer 466Customizing
Event Viewer 468Customizing
Event Viewer Detail 470Reliability
and Performance Monitor 471 Resource Monitor 473Reliability
Monitor 473Performance
Monitor 476 DataCollector Sets 479Windows
System
ResourceManager
484Server Performance Advisor 486
XV
showconn 493
replsummary 494
dcdiag 494
Troubleshooting
theApplication
ofGroup Policy Objects
496Resultant Set of
Policy
496Planning Mode/Group Policy
Modeling
497Logging
Mode/Group
Policy
Results 501Using
theDelegation
of
Control Wizard 509 Gpresult 509Review All the
Key Topics
512Complete
the Tables and Lists fromMemory
513Definitions of
Key
Terms 513Chapter
15Maintaining
ActiveDirectory
515 "DoI KnowThisAlready?"
Quiz 515Backing
Up
andRecovering
ActiveDirectory
520Backup
Permissions 521Use of Windows Server
Backup
521Installing
Windows ServerBackup
521Backing Up
Critical Volumesof
aDomain Controller 522Thewbadmin Command 525
Scheduling
aBackup
526Using
Removable Media 527Recovering
ActiveDirectory
528Directory
Services Restore Mode 528Performing
aNonauthoritativeRestore 529Using
thewbadmin CommandtoRecover Your Server 534Performing
anAuthoritative Restore 536Recovering
Back-LinksofAuthoritatively
RestoredObjects
537Performing
aFullServerRecovery of
aDomain Controller 538Linked-Value
Replication
and Authoritative Restoreof Group Memberships
539The Active
Directory Recycle
Bin 540Enabling
theActiveDirectory
Recycle
Bin 541Using
the ActiveDirectory
Recycle
BintoRestore DeletedObjects
543Backing Up
andRestoring
GPOs 545Backing
Up
GPOs 545Restoring
GPOs 545Importing
GPOs 547MOTS 70-640 Cert Guide: Windows Server 2008 Active Directory,
Configuring
Offline Maintenance of Active
Directory
549RestartableActive
Directory
549Offline
Defragmentation
andCompaction
550Online
Defragmentation
551Offline Defragmentation
551Active
Directory
DatabaseStorage
Allocation 553 Review All theKey Topics
555Complete
the Tables and Lists fromMemory
556 Definitions ofKey
Terms 556Chapter
16Installing
andConfiguring
CertificateServices 559 "Do I Know ThisAlready?"
Quiz
559What's New with CertificateServices inWindowsServer 2008?
NewFeatures of Active
Directory
Certificate Services in Windows Server 2008 R2 564Installing
ActiveDirectory
Certificate Services 565Configuring
CertificateAuthority Types
and Hierarchies 565Installing
Root CAs 567Installing
Subordinate CAs 571Understanding
CertificateRequests
571Using
Certificate PracticeStatements 572Configuring
CertificateAuthority
ServerSettings
573Installing
theCertificatesSnap-in
573Working
with CertificateStores 575Using Group Policy
toImport Certificates
575Backing Up Certificates
andKeys
576Restoring
Certificates
andKeys
577Using Group Policy
toEnable CredentialRoaming
578Backing Up
andRestoring
Certificate Databases 580Assigning
Administration Roles 581Configuring Certificate
Server Permissions 582Review All the
Key Topics
583Complete
the Tables andLists fromMemory
584 Definitions ofKey
Terms 5 84Chapter
17Managing
CertificateTemplates,
Enrollments, and Certificate Revocation 587"Do IKnow This
Already?"
Quiz 587xvii
Understanding
CertificateTemplate
Types
592Configuring
CertificateTemplates
593Securing
Template
Permissions 595Enabling
the Useof Templates
591Managing
Different CertificateTemplate
Versions 597Archiving
Keys
599Configuring Key Recovery Agents
599Managing
Certificate Enrollments 602Understanding
Network DeviceEnrollmentServices 602Enabling
CertificateAutoenrollment 605Configuring
WebEnrollment 606Configuring
SmartCard Enrollment 609Creating
EnrollmentAgents
610Using Group Policy
toRequire
Smart Cardsfor
Logon
614Managing
CertificateRevocation 616Configuring
CertificateRevocation Lists 617Configuring
a CPJL Distribution Point 619Troubleshooting
CRLs 620Configuring
OnlineResponders
621Configuring Responder Properties
622Adding
aRevocationConfiguration
623Configuring
Arrays
624Configuring Authority
InformationAccess 624 Review All theKey Topics
62 5Complete
the Tables and Lists fromMemory
626 Definitions ofKey
Terms 626Practice Exam 629
Answersto Practice Exam 691
AppendixA Answers to the "Do I Know ThisAlready?" Quizzes 729