<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; Active Directory</title>
	<atom:link href="http://www.winadmin.ro/tag/active-directory/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Wed, 28 Jul 2010 15:34:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Account lockout tools &#8211; Acctinfo.dll &amp; Acctinfo2.dll</title>
		<link>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/</link>
		<comments>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/#comments</comments>
		<pubDate>Thu, 06 May 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Account Lockout Tools]]></category>
		<category><![CDATA[ADUC]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1383</guid>
		<description><![CDATA[Probabil ca ati folosit pana acum Account Lockout Tools sau daca nu, macar ati auzit de ele. Despre gasiti aici: http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx Si download aici: http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&#38;displaylang=en Parte din acest packet este si Acctinfo.dll care adauga un nou tab in AD Users and Computers destul de folositor pentru taskurile de administrare. Problema e ca acest dll functioneaza [...]]]></description>
			<content:encoded><![CDATA[<p>Probabil ca ati folosit pana acum Account Lockout Tools sau daca nu, macar ati auzit de ele.</p>
<p>Despre gasiti aici:</p>
<p><a title="http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx" href="http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx</a></p>
<p>Si download aici:</p>
<p><a title="http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en</a></p>
<p>Parte din acest packet este si Acctinfo.dll care adauga un nou tab in AD Users and Computers destul de folositor pentru taskurile de administrare.</p>
<p>Problema e ca acest dll functioneaza numai pe Windows x86 si cum W2K8 R2 vine numai in versiune x64 nu o sa mai functioneze. Mai nou umbla pe net si versiunea Acctinfo2.dll care mai avea cateva optiuni in plus dar nu era suportata de MS.</p>
<p>Recent am gasit si versiunea x64 a lui Acctinfo2.dll care merge inclusiv pe W2K8 R2. O gasiti aici <a title="http://www.activedir.org/ACCTINFO2_64BIT.zip" href="http://www.activedir.org/ACCTINFO2_64BIT.zip">http://www.activedir.org/ACCTINFO2_64BIT.zip</a></p>
<p>Pentru prima versiune era nevoie doar sa inregistrezi dll-ul, acum e nevoie de mai multi pasi. Ii gasiti pe toti in documentul din arhiva.</p>
<p>Dupa ce faceti ce scrie acolo tab-ul din ADUC o sa arate cam asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image19.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb19.png" width="362" height="484" /></a></p>
<p>Optiunea Most Recent Logon iti arata serverul care a autentificat ultima data acel cont.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image20.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb20.png" width="426" height="161" /></a></p>
<p>Poti vedea si replication metadata pentru acel obiect fara a mai fi nevoie de repadmin.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image21.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb21.png" width="644" height="461" /></a></p>
<p>Si pe baza lui lastlogon poti afla site-ul in care se afla utilizatorul si ii poti schimba parola chiar in acel site.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image22.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb22.png" width="510" height="226" /></a></p>
<p>&#160;</p>
<p>Nota: Acctinfo2.dll nu este suportat de MS. Nu numai ca nu e suportat, MS nu a publicat niciodata oficial acest dll. So use it on your own risk.</p>
<p>&#160;</p>
<p>Spor!</p>
<p>Andrei.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Probleme cu RODC</title>
		<link>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/</link>
		<comments>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 19:51:52 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/</guid>
		<description><![CDATA[Studiam o problema de autentificare legata de clienti cu RODC (Read Only Domain Controller) in site si am dat peste urmatorul KB: http://support.microsoft.com/kb/944043 KB-ul descrie problemele care pot aparea atunci cand ai un RODC in retea si contine update-uri care trebuie instalate pe Windows 2003, XP si Vista. Deci, de retinut: daca folosesti RODC e [...]]]></description>
			<content:encoded><![CDATA[<p>Studiam o problema de autentificare legata de clienti cu RODC (Read Only Domain Controller) in site si am dat peste urmatorul KB:</p>
<p><a title="http://support.microsoft.com/kb/944043" href="http://support.microsoft.com/kb/944043">http://support.microsoft.com/kb/944043</a></p>
<p>KB-ul descrie problemele care pot aparea atunci cand ai un RODC in retea si contine update-uri care trebuie instalate pe Windows 2003, XP si Vista.</p>
<p>Deci, de retinut: daca folosesti RODC e obligatoriu sa instalezi updateurile de mai sus pe clienti si chiar si pe domain controllerele care mai ruleaza Windows 2003 in domeniu.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Identificarea conturilor inactive din Active Directory folosind Administrative Center</title>
		<link>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/</link>
		<comments>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 04:00:06 +0000</pubDate>
		<dc:creator>Sebi22</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[cleanup]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1130</guid>
		<description><![CDATA[Active Directory Administrative Center este un nou instrument de administrare a obiectelor din Active Directory, inclus in Windows Server 2008 R2 si disponibil in Windows 7 prin instalarea Remote Server Administration Tools. Folosind aceasta consola putem crea obiecte de tip user, computer, OU, sau le putem administra pe cele existente. De asemenea, putem efectua cautari [...]]]></description>
			<content:encoded><![CDATA[<p>Active Directory Administrative Center este un nou instrument de administrare a obiectelor din Active Directory, inclus in Windows Server 2008 R2 si disponibil in Windows 7 prin instalarea <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7D2F6AD7-656B-4313-A005-4E344E43997D&amp;displaylang=en">Remote Server Administration Tools</a>. Folosind aceasta consola putem crea obiecte de tip user, computer, OU, sau le putem administra pe cele existente. De asemenea, putem efectua cautari filtrate dupa diverse criterii. Aceste cautari ne pot ajuta, de exemplu, pentru Active Directory clean up, adica identificarea, dezactivarea si/sau stergerea conturilor de tip user sau computer nefolosite.</p>
<p>Sa vedem cum procedam. Deschidem ADAC ( Active Directory Administrative Center) din Administrative Tools :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0021.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image002_thumb1.jpg" border="0" alt="clip_image002" width="811" height="596" /></a></p>
<p>Mergem la Global Search si, in partea dreapta, expandam Add criteria. Bifam “Users with enabled accounts who have not logged on for more than a given numbers of days” si dam click pe Add :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0041.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image004_thumb1.jpg" border="0" alt="clip_image004" width="812" height="391" /></a></p>
<p>Acum putem selecta numar de zile :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0061.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image006_thumb1.jpg" border="0" alt="clip_image006" width="811" height="280" /></a></p>
<p>Sa zicem 60 de zile. Dupa care dam un click pe Search si avem rezultatul. Acum, ii putem selecta si, cu click dreapta sau din partea dreapta a consolei ( Tasks ), ii putem dezactiva sau sterge din Active Directory :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0081.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image008_thumb1.jpg" border="0" alt="clip_image008" width="811" height="286" /></a></p>
<p>Traducerea in LDAP a acestei cautari arata cam asa : cautam obiecte de tip user – persoana, enabled (vezi atributul UserAccountControl) inactive in perioada data curenta minus 60 zile, folosindu-ne de atributul lastLogonTimestamp. Valoarea acestuia din urma este updatata implicit la interval de 14 zile asa ca sfatul meu e sa nu folositi intervalul de 15 sau chiar 30 de zile pentru clean up, ca sa nu riscati sa stergeti conturi active. Convertirea valorii in format standard de timp este descrisa <a href="http://support.microsoft.com/kb/555936">aici</a> .</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0101.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image010_thumb1.jpg" border="0" alt="clip_image010" width="813" height="500" /></a></p>
<p>Cum putem cauta computerele inactive timp de 60 de zile? Editam query-ul, inlocuind valoarea “person” a atributului objectCategory cu “computer”. Click pe Apply si gasim si computerele inactive pe care, de asemenea, le putem dezactiva sau sterge:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0121.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image012_thumb1.jpg" border="0" alt="clip_image012" width="812" height="431" /></a></p>
<p>Spuneam ca ADAC a aparut de la Windows Server 2008 R2. Consola poate fi folosita totusi si cu Active Directory 2003 si 2008. Vedeti <a href="http://www.winadmin.ro/2009/12/04/powershell-active-directory-module-si-windows-2003-domain-controllers/">aici</a> conditiile. Sunt valabile si pentru ADAC.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to force DFSR SYSVOL replication?</title>
		<link>http://www.winadmin.ro/2010/03/25/how-to-force-dfsr-sysvol-replication/</link>
		<comments>http://www.winadmin.ro/2010/03/25/how-to-force-dfsr-sysvol-replication/#comments</comments>
		<pubDate>Thu, 25 Mar 2010 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[DFSR]]></category>
		<category><![CDATA[SYSVOL]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/03/25/how-to-force-dfsr-sysvol-replication/</guid>
		<description><![CDATA[Pana la Windows 2008 cam stiam cum se procedeaza cu SYSVOL-ul si nu era simplu deloc. Cu totii stim utilitarele folosite pentru a forta replicarea FRS-ului si problemele aparute mai de fiecare data. DFSR a fost bine venit si pacat ca nu l-au folosit la SYSVOL si in 2003. Zilele astea am fost nevoit sa [...]]]></description>
			<content:encoded><![CDATA[<p>Pana la Windows 2008 cam stiam cum se procedeaza cu SYSVOL-ul si nu era simplu deloc. Cu totii stim utilitarele folosite pentru a forta replicarea FRS-ului si problemele aparute mai de fiecare data. DFSR a fost bine venit si pacat ca nu l-au folosit la SYSVOL si in 2003.</p>
<p>Zilele astea am fost nevoit sa fortez o replicare de SYSVOL intre doua DC-uri cu Windows 2008 R2 si am descoperit o metoda interesanta de a face asta. inainte de toate trebuie sa spun ca replicarea SYSVOL-ului urmareste programul de replicare definit in Sites &amp; Services. Deci SYSVOL-ul se va replica la acelasi interval cu restul informatiilor din AD. Fortand replicarea folosind REPADMIN automat fortam si replicarea SYSVOL-ului.</p>
<p>Dar cum as putea sa fac sa replic doar SYSVOL-ul? Cu DFSRDIAG:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image103.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb103.png" width="644" height="331" /></a> </p>
<p>Comanda din imaginea de mai sus forteaza sincronizarea cu replica de pe server1 si mentine aceasta sincronizare timp de un minut (tot ce va aparea in backlog pe server1 in interval de un minut va fi replicat).</p>
<p>HTH,</p>
<p>Andrei.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/03/25/how-to-force-dfsr-sysvol-replication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conceptul de site in AD + instalarea celui de-al doilea domain controller</title>
		<link>http://www.winadmin.ro/2010/03/23/conceptul-de-site-in-ad-instalarea-celui-de-al-doilea-domain-controller/</link>
		<comments>http://www.winadmin.ro/2010/03/23/conceptul-de-site-in-ad-instalarea-celui-de-al-doilea-domain-controller/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Ghidul incepatorului]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/03/22/conceptul-de-site-in-ad-instalarea-celui-de-al-doilea-domain-controller/</guid>
		<description><![CDATA[Articolul urmator face parte din Ghidul incepatorului de AD inceput aici si din care sper ca oricine doreste sa invete Active Directory sa poata sa gaseasca ceva util. Am descris cum se instaleaza primul domain controller (next,next,next) iar acum o sa vedem cum il punem si pe al doilea. O sa continui pe o infrastructura [...]]]></description>
			<content:encoded><![CDATA[<p>Articolul urmator face parte din Ghidul incepatorului de AD inceput <a href="http://www.winadmin.ro/2010/03/17/installing-active-directory-ghidul-incepatorului/">aici</a> si din care sper ca oricine doreste sa invete Active Directory sa poata sa gaseasca ceva util. Am descris cum se instaleaza primul domain controller (next,next,next) iar acum o sa vedem cum il punem si pe al doilea. O sa continui pe o infrastructura diferita asa ca nu va speriati daca numele serverelor nu se potrivesc cu cele din prumul articol.</p>
<p>De ce am avea nevoie de al doilea? Pai AD-ul devine pilonul principal de autentificare si autorizare in infrastructura si daca se intampla sa nu functioneze, e de rau. Asa ca mai instalezi un domain controller.</p>
<p>NOTA: backup-ul e backup si adaugarea unui DC aditional nu il inlocuieste. Backup-ul trebuie facut, indiferent de scenariu.</p>
<p>Si scenariile pot continua: infrastructuri raspandite in mai multe locatii in care ai nevoie de un punct de autentificare local, numar mare de useri si nevoia de balansare a serviciului de autentificare, aplicatii care folosesc intensiv serviciul directory.</p>
<p>Bun. Inainte sa incepem instalarea o sa incerc sa definesc conceputul de SITE. Site in terminologia AD se refera la o retea in care toate sistemele sunt conectate prin legaturi de mare viteza. Putem face o comparatie cu retea locala dintr-un sediu al unei firme. Toate sistemele de acolo sunt conectate prin legaturi 100Mb.</p>
<p>In Active Directory putem defini un obiect de tip site pe care il declaram ceva de genul: toate sistemele care fac parte din subnetul 192.168.1.0/24 apartin locatiei (site-ului) Bucuresti. Si pot continua asa pentru toate locatiile mele.</p>
<p>Intrebarea e, la ce ne foloseste sa definim aceste obiecte de tip Site? Simplu, site-ul ne ajuta sa controlam autentificarea si replicarea datelor intre domain controllere. Si o sa dau din nou cateva exemple:</p>
<p>- asociez domain controllerul meu (sa-i spunem DC1) cu site-ul Bucuresti ceea ce inseamna ca toti clientii din subnetul asociat cu site-ul Bucuresti vor incerca sa se autentifice mai intai pe DC1, si nu pe nu stiu ce domain controller aflat in alta locatie la care conexiunea se face peste un VPN de 512Kbps.</p>
<p>- asociez DC2 cu site-ul Constanta, redirectez cererile de autentificare catre DC2 in interiorul site-ului si pot face reguli de control al replicarii intre domain controllere. Exemplu: la ce interval sa se efectueze replicarea intre domain controllerele aflate in site-urile Bucuresti si Constanta (pentru DC-urile aflate in acelasi site nu poti influenta modul in care se face replicarea).</p>
<p>Cam asta e scopul lor. Nimic mai mult. Ar mai fi cate ceva, insa in 99.99% din cazuri, sunt folosite numai pentru scenariile de mai sus: autentificare si replicare.</p>
<p>Trecem mai departe si continuam cu instalarea celuilalt domain controller, care se afla in alt site. Pentru inceput, ii configuram adresa IP statica iar la DNS punem adresa primului DC (daca el e responsabil pentru zona DNS AD).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image65.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb65.png" width="408" height="451" /></a> </p>
<p>Putem declara noul site in AD si acum si dupa promovare. Recomand sa il facem acum. Si tot acum o sa fac si pentru primul site – avand doar un DC pana acum, nu a fost nevoie sa declar un site.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image66.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb66.png" width="546" height="245" /></a> </p>
<p>Implicit exista un site numit Default-First-Site-Name, in care apare si primul meu DC numit acum SERVER1. O sa-l redenumesc.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image67.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb67.png" width="559" height="265" /></a> </p>
<p>Si o sa-i asociez un subnet (pe care mai intai trebuie sa-l declar).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image68.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb68.png" width="507" height="382" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image69.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb69.png" width="394" height="484" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image70.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb70.png" width="608" height="259" /></a> </p>
<p>Si acum subnetul 192.168.0.0/24 e asociat cu site-ul Bucuresti.</p>
<p>Sa ne apucam si de site-ul Constanta.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image71.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb71.png" width="442" height="328" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image72.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb72.png" width="445" height="374" /></a> </p>
<p>In acest punct selectati DEFAULTIPSITELINK si o sa vedem mai tarziu la ce se refera.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image73.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb73.png" width="409" height="299" /></a> </p>
<p>Ii asociem un subnet:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image74.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb74.png" width="395" height="484" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image75.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb75.png" width="460" height="244" /></a> </p>
<p>Acum e momentul sa pornim promovarea celui de-al doilea DC (numit DC2) aflat in subnetul din Constanta.</p>
<p>Rulam DCPROMO.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image76.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb76.png" width="507" height="480" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image77.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb77.png" width="507" height="479" /></a> </p>
<p>Introducem numele domeniului si setam credentialele contului de admin din domeniul existent</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image78.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb78.png" width="507" height="478" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image79.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb79.png" width="504" height="479" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image80.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb80.png" width="505" height="478" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image81.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb81.png" width="507" height="479" /></a> </p>
<p>Si automat wizardul se ofera sa puna noul DC in site-ul corespunzator.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image82.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb82.png" width="506" height="480" /></a></p>
<p>Verificati sa aveti selectata si bifa pentru DNS.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image83.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb83.png" width="506" height="479" /></a></p>
<p>Selectam YES. </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image84.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb84.png" width="417" height="234" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image85.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb85.png" width="507" height="479" /></a> </p>
<p>Setam parola pentru DSRM.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image86.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb86.png" width="509" height="480" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image87.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb87.png" width="508" height="481" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image88.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb88.png" width="440" height="310" /></a> </p>
<p>Dupa reboot ne logam cu contul de domeniu.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image89.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb89.png" width="489" height="463" /></a> </p>
<p>Si putem observa ca avem o replica ce contine toate informatiile de pe primul domain controller.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image90.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb90.png" width="635" height="371" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image91.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb91.png" width="563" height="346" /></a> </p>
<p>Acum e momentul sa schimbam setarile pentru DNS pe noul server (doar daca am instalat si serviciul de DNS – by default la promovare) si sa setam IP-ul local primul in lista de DNS resolvere (e logic, nu? de ce sa interoghez un DNS remote, cand zona mea DNS responsabila pentru domeniul AD, este replicata si pe acest DC; aici e mult de vorbit – pentru alte detalii just ask).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image92.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb92.png" width="407" height="450" /></a> </p>
<p>Acum sa aruncam un ochi si pe acel DEFAULTIPSITELINK </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image93.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb93.png" width="566" height="340" /></a></p>
<p>Putem observa ca avem cele doua site-uri existente asociate cu acest obiect – ceea ce inseamna ca replicarea intre aceste domain controllerele din aceste doua locatii se va face pe baza setarilor acestui link: replicarea se efectueaza o data la 180 de minute.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image94.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb94.png" width="408" height="484" /></a> </p>
<p>Iar in schedule vedem intervalele in care e permisa aceasta replicare.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image95.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb95.png" width="519" height="318" /></a> </p>
<p>Dar, acest obiect doar stabileste niste reguli, care sunt folosite de un process numit KCC, responsabil pentru generarea conexiunilor de replicare intre DC-uri. deci site link-ul nu face nici un enforcement, ci este doar un sablon folosit de un proces automat de generare a topologiei de replicare.</p>
<p>Link-urile de replicare le gasim aici:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image96.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb96.png" width="644" height="317" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image97.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb97.png" width="407" height="450" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image98.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb98.png" width="513" height="319" /></a> </p>
<p>Dupa cum vedeti conexiunea de replicare generata automat are un schedule ce respecta regulile definite in site link.</p>
<p>Se pot genera si conexiuni de replicare manuale, insa va recomand sa setati sitelink-urile bine si sa lasati KCC-ul sa-si faca treaba.</p>
<p>Sper sa fie suficient pentru instalarea celui de-al doilea DC si sper ca toata lumea a inteles la ce folosesc site-urile in AD.</p>
<p>&#160;</p>
<p>Have fun!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/03/23/conceptul-de-site-in-ad-instalarea-celui-de-al-doilea-domain-controller/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing Active Directory &#8211; Ghidul incepatorului</title>
		<link>http://www.winadmin.ro/2010/03/17/installing-active-directory-ghidul-incepatorului/</link>
		<comments>http://www.winadmin.ro/2010/03/17/installing-active-directory-ghidul-incepatorului/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Ghidul incepatorului]]></category>
		<category><![CDATA[Instalare]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=922</guid>
		<description><![CDATA[Datorita cererii de materiale pentru incepatori m-am decis sa incep cu un scurt “how to” despre instalarea Active Directory. Cazul de mai jos se refera la instalarea primului domain controller din domeniu. Nota: Domain controller este serverul care hosteaza (tine/ofera) serviciul Active Directory. Pentru inceput trebuie sa verificam setarile TCP/IP ale placii de retea de [...]]]></description>
			<content:encoded><![CDATA[<p>Datorita cererii de materiale pentru incepatori m-am decis sa incep cu un scurt “how to” despre instalarea Active Directory. Cazul de mai jos se refera la instalarea primului domain controller din domeniu.</p>
<p>Nota: Domain controller este serverul care hosteaza (tine/ofera) serviciul Active Directory.</p>
<p>Pentru inceput trebuie sa verificam setarile TCP/IP ale placii de retea de pe server. Recomandat e ca serverul sa aiba doar o placa de retea si nu mai multe (se accepta doar in cazul in care se face team).</p>
<p>IP-ul serverului trebuie sa fie unul fix si il configuram ca mai jos, iar adresa serverului de DNS ar cam trebui sa fie acceasi cu IP-ul serverului. Asta pentru ca zona DNS necesara pentru buna functionare a Active Directory va fi tinuta tot de acest server.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image14.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb14.png" width="409" height="453" /></a></p>
<p>Promovarea serverului la rolul de Domain Controller se face prin comanda DCPROMO.</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image15.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb15.png" width="409" height="205" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image16.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb16.png" width="379" height="235" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image17.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb17.png" width="507" height="481" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image18.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb18.png" width="508" height="480" /></a></p>
<p>Pana aici ajungem prin Next, iar acum trebuie sa selectam daca serverul nostru este primul domain controller (in continuare o sa prescurtez prin DC) dintr-un domeniu nou sau un DC aditional la un domeniu existent. Alegem “Create a new domain in a new forest”.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image19.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb19.png" width="508" height="480" /></a></p>
<p>In momentul promovarii, contul local Administrator va deveni contul de administrator de domeniu, asa ca daca nu aveti o parola setata, in acest moment va trebui sa setati una.</p>
<p>Alegem numele domeniului, care e indicat sa nu fie single label (gen winadmin). Adaugati un suffix care sa nu va creeze probleme (conflicte) pe viitor, gen local, net, org, orice care nu intra in conflict cu un nume de domeniu existent.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image20.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb20.png" width="508" height="479" /></a></p>
<p>Fiind primul DC din domeniu putem merge linistiti pe optiunea Windows Server 2008 R2. Celelalte optiuni sunt pentru compatibilitatea cu alte DC-uri din acelasi domeniu care ruleaza OS-uri mai vechi. Avand un singur DC optiunea e simpla.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image21.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb21.png" width="508" height="480" /></a></p>
<p>Wizard-ul se ofera sa instaleze pentru noi serviciul DNS (va amintiti ca la inceput ca server de DNS am ales IP-ul propriu?) si sa faca acest server Global Catalog (detalii alta data).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image22.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb22.png" width="509" height="482" /></a></p>
<p>Just ignore this, cititi doar “no action is required”.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image23.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb23.png" width="419" height="234" /></a></p>
<p>Acum trebuie sa alegem locatiile pentru cateva componente ale AD-ului: baza de date, transaction logurile si folderul SYSVOL. Fiind un DC pentru un scenariu de test, putem sa lasam locatiile default. puteti sa lasati default si in scenarii de productie. Schimbarea locatiei default e necesara in special pentru imbunatatirea performantei serviciului si se intampla atunci cand ai mii de useri care acceseaza serviciul simultan.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image24.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb24.png" width="507" height="480" /></a></p>
<p>AD-ul mai are si un mod special de mentenanta. E un fel de Safe Mode in care pornesti serverul cu AD-ul oprit.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image25.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb25.png" width="509" height="481" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image26.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb26.png" width="508" height="480" /></a></p>
<p>Inca un next …</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image27.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb27.png" width="441" height="310" /></a></p>
<p>Dupa reboot trebuie sa ne logam in formatul numedomeniu\username.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image28.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb28.png" width="441" height="421" /></a></p>
<p>Vedem ca au fost instalate si aplicatiile de management pentru AD.</p>
<p>&#160;<a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image29.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb29.png" width="464" height="484" /></a></p>
<p>Iata si principala consola folosita pentru administrarea informatiilor din AD.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image30.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb30.png" width="644" height="452" /></a></p>
<p>Aruncam un ochi si pe DNs, sa vedem ce s-a intamplat aici.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image31.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb31.png" width="644" height="451" /></a></p>
<p>Si cam asta e tot. Simplu, nu?</p>
<p>PS: sper sa nu mai vad pe forumuri intrebari despre cum sa instalezi AD. E prea simplu.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/03/17/installing-active-directory-ghidul-incepatorului/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>How to control DSRM administrator account password</title>
		<link>http://www.winadmin.ro/2010/03/10/how-to-control-dsrm-administrator-account-password/</link>
		<comments>http://www.winadmin.ro/2010/03/10/how-to-control-dsrm-administrator-account-password/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[DSRM]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/03/10/how-to-control-dsrm-administrator-account-password/</guid>
		<description><![CDATA[Care e treaba cu acest DSRM account? Pai este contul folosit sa ne logam pe domain controller atunci cand il restartam in modul Directory Service Restore Mode. Este contul de Administrator stocat in SAM, folosit atunci cand AD-ul este oprit pe un server. In mod normal parola pentru acest cont este setata atunci cand promovam [...]]]></description>
			<content:encoded><![CDATA[<p>Care e treaba cu acest DSRM account? Pai este contul folosit sa ne logam pe domain controller atunci cand il restartam in modul Directory Service Restore Mode. Este contul de Administrator stocat in SAM, folosit atunci cand AD-ul este oprit pe un server. In mod normal parola pentru acest cont este setata atunci cand promovam un domain controller si poate fi diferita pe fiecare DC din domeniu; mai exact, contul nu este replicat, ci este stocat local pe fiecare server in parte.</p>
<p>Atunci cand avem mai multe domain controllere si facem greseala sa nu documentam aceasta parola la instalarea fiecarui DC, o sa avem o problema atunci cand vom fi nevoiti sa bootam DC-ul in DSRM mode.</p>
<p>Parola pentru DSRM poate fi schimbata atunci cand serverul este pornit in modul Active Directory din NTDSUTIL folosind urmatoarea secventa de comenzi:</p>
<p><strong>ntdsutil</strong></p>
<p><strong>set dsrm password</strong></p>
<p><strong>reset password on server null</strong></p>
<p>In cazul in care se doreste schimbarea parolei pe un server remote, se poate specifica numele serverului in loc de null. Null se refera la serverul local.</p>
<p>Comanda mai merge scrisa si astfel:</p>
<p><strong>ntdsutil &quot;set dsrm password&quot; &quot;reset password on server null”</strong></p>
<p>Dupa un anumit service pack in Windows 2000 mai exista si comanda <strong>setpwd</strong> in afara NTDSUTIL, insa aceasta nu mai este folosita in Windows 2008, asa ca nu o sa mai detaliem.</p>
<p>In afara de varianta de mai sus, mai exista ceva mai comod aparut odata cu Windows 2008 R2 si 2008 SP2. Putem sincroniza DSRM password cu un cont de domeniu. Pentru asta folosim:</p>
<p><strong>ntdsutil &quot;set dsrm password&quot; &quot;sync from domain account &quot; &quot;sync from domain account <font color="#ff0000">DSRMaccount</font>&quot;</strong></p>
<p>Unde DSRMaccount reprezinta contul de domeniu folosit pentru sincronizare.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image6.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb6.png" width="644" height="320" /></a> </p>
<p>Recomand ca dupa ce faceti acest cont sa il dezactivati si sa-i setati o parola complexa.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/image7.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/03/image_thumb7.png" width="474" height="329" /></a> </p>
<p>Mai departe puteti sa setati taskuri pe fiecare domain controller care sa sincronizeze DSRM password cu acest cont. Pentru task-uri comanda se modifica putin:</p>
<p><strong>ntdsutil &quot;set dsrm password&quot; &quot;sync from domain account &quot; &quot;sync from domain account <font color="#ff0000">DSRMaccount</font>&quot; q q</strong></p>
<p>In acest fel scapati de taskurile time consuming de schimbare a acestei parole, distributia ei si storage-ul facandu-se securizat prin Active Directory.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/03/10/how-to-control-dsrm-administrator-account-password/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Group Policy Preferences</title>
		<link>http://www.winadmin.ro/2009/12/09/group-policy-preferences/</link>
		<comments>http://www.winadmin.ro/2009/12/09/group-policy-preferences/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 06:00:19 +0000</pubDate>
		<dc:creator>Sebi22</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=288</guid>
		<description><![CDATA[Group Policy Preferences reprezinta un feature introdus in Windows Server o data cu aparitia versiunii 2008. Sunt incluse, atat pentru computere, cat si pentru useri, extensii care ne permit sa configuram anumite setari pentru care obisnuiam (de fapt eram nevoiti) sa folosim scripturi. De exemplu, folosind Group Policy Preferences, putem seta parola userului local Administrator [...]]]></description>
			<content:encoded><![CDATA[<p>Group Policy Preferences reprezinta un feature introdus in Windows Server o data cu aparitia versiunii 2008.</p>
<p>Sunt incluse, atat pentru computere, cat si pentru useri, extensii care ne permit sa configuram anumite setari pentru care obisnuiam (de fapt eram nevoiti) sa folosim scripturi. De exemplu, folosind Group Policy Preferences, putem seta parola userului local Administrator sau adauga un user in grupul de administratori locali pe toate computerele sau pe o parte din ele, putem mapa Network Drives, putem face deploy de imprimante, putem configura Power Options, Folder Options, Registry settings si multe altele.</p>
<p> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image001.jpg"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image001_thumb.jpg" border="0" alt="clip_image001" width="843" height="633" /></a></p>
<p> </p>
<p>Toate aceste setari se pot aplica pe toate computerele, pe toti userii sau in functie de filtrele pe care le aplicam folosind Item-Level Targeting. Putem filtra aplicarea politicii dupa numele computerului sau al userului, dupa apartenenta la un grup sau OU, dupa sistemul de operare si multe alte criterii.</p>
<p> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image003.jpg"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image003_thumb.jpg" border="0" alt="clip_image003" width="850" height="529" /></a></p>
<p> </p>
<p>Pentru a putea folosi Group Policy Preferences, avem nevoie de urmatoarele:</p>
<p>- Pe computerele din domeniu trebuie instalat KB943729 – Group Policy Client-Side Extensions, disponibil pentru Windows XP minim SP2, Windows Server 2003 minim SP1, Windows Vista; XMLLite pe statiile cu Windows XP (KB915865) si Windows 2003 ( KB914783).</p>
<p>- Un server/statie de lucru cu Windows Server 2008/2008 R2 sau Windows Vista/7 cu RSAT.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/12/09/group-policy-preferences/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Searching for delegated rights in AD</title>
		<link>http://www.winadmin.ro/2009/12/08/searching-for-delegated-rights-in-ad/</link>
		<comments>http://www.winadmin.ro/2009/12/08/searching-for-delegated-rights-in-ad/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 06:05:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Scripting]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[VBScript]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=274</guid>
		<description><![CDATA[&#160; Scopul scriptului care il voi prezenta mai jos este de a cauta in Active Directory dupa delegarile facute la nivel de Organizational Unit-uri. Intr-un domeniu in care facem delegari pentru alti admini, daca acestea nu sunt documentate si sunt facute folosind useri si nu de grupuri, in timp sunt uitate iar userul va avea [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Scopul scriptului care il voi prezenta mai jos este de a cauta in Active Directory dupa delegarile facute la nivel de Organizational Unit-uri. Intr-un domeniu in care facem delegari pentru alti admini, daca acestea nu sunt documentate si sunt facute folosind useri si nu de grupuri, in timp sunt uitate iar userul va avea acces in continuare la resursele delegate chiar daca nu face parte din grupurile de administratori.</p>
<p>Scriptul arata cam asa:</p>
<blockquote><p>&#8216;Script created by Andrei Ungureanu      <br />&#8216;www.winadmin.ro </p>
<p>On error resume next      <br />Const ADS_SCOPE_SUBTREE = 2       <br />Const ADS_ACEFLAG_INHERITED_ACE = &amp;H10 </p>
<p>Set objConnection = CreateObject(&quot;ADODB.Connection&quot;)      <br />Set objCommand =&#160;&#160; CreateObject(&quot;ADODB.Command&quot;)       <br />objConnection.Provider = &quot;ADsDSOObject&quot;       <br />objConnection.Open &quot;Active Directory Provider&quot; </p>
<p>Set objCOmmand.ActiveConnection = objConnection      <br />objCommand.CommandText = _       <br />&#160;&#160;&#160; &quot;Select Name, distinguishedName from &#8216;LDAP://DC=itboard,DC=local&#8217; &quot; _       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; &amp; &quot;Where objectClass=&#8217;organizationalUnit&#8217;&quot;&#160; <br />objCommand.Properties(&quot;Page Size&quot;) = 1000       <br />objCommand.Properties(&quot;Searchscope&quot;) = ADS_SCOPE_SUBTREE       <br />Set objRecordSet = objCommand.Execute       <br />objRecordSet.MoveFirst </p>
<p>Do Until objRecordSet.EOF      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; strOU = objRecordSet.Fields(&quot;distinguishedName&quot;)&#160; <br />Set ObjUser = GetObject(&quot;LDAP://&quot; &amp; strOU)       <br />Set objsd = objUser.Get(&quot;ntSecurityDescriptor&quot;)       <br />Set dacl = objsd.DiscretionaryAcl </p>
<p>For Each ace In dacl      <br />If ace.Trustee = &quot;ITBOARD\andreiu&quot; Then       <br />&#160;&#160;&#160; iAceFlags = ace.AceFlags </p>
<p>&#160;&#160;&#160;&#160;&#160;&#160;&#160; If(iAceFlags And ADS_ACEFLAG_INHERITED_ACE)Then      <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; Exit For       <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160; End If </p>
<p>&#160;&#160;&#160; wscript.echo strOU      <br />&#160;&#160;&#160; Exit For       <br />End If       <br />next </p>
<p>&#160;&#160;&#160; objRecordSet.MoveNext      <br />Loop</p>
</blockquote>
<p>E nevoie sa inlocuiti in script ITBOARD\andreiu cu userul pe care il cautati si la fel numele domeniului din dc=itboard,dc=local in numele domeniului pe care rulati scriptul. Scriptul va verifica toata ierarhia de OU-uri si va afisa doar locatiile in care userul are permisiuni (daca exista deja permisiuni mostenite de la un OU parinte nu va mai verifica alte permisiuni pe acel OU).</p>
<p>Atentie ca numele userului si domeniul sunt case sensitive. Acestea trebuie puse in script exact asa cum apar in proprietatile userului:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/image.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2009/12/image_thumb.png" width="406" height="484" /></a> </p>
<p>Scriptul nu este bullet proof si e posibila sa existe cazuri in care sa nu detecteze tot. Pentru a-i imbunatati viteza am decis sa fac skip la OU-urile unde exista deja drepturi mostenite pentru acel user.</p>
<p>PS: Atentie ca scripturile postate aici sunt modificate de wordpress si anumite caractere trebuie modificate de mana cand faceti copy/paste la script.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/12/08/searching-for-delegated-rights-in-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Powershell Active Directory Module si Windows 2003 Domain Controllers</title>
		<link>http://www.winadmin.ro/2009/12/04/powershell-active-directory-module-si-windows-2003-domain-controllers/</link>
		<comments>http://www.winadmin.ro/2009/12/04/powershell-active-directory-module-si-windows-2003-domain-controllers/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 13:47:26 +0000</pubDate>
		<dc:creator>Sebi22</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Management and monitoring]]></category>
		<category><![CDATA[Windows Client]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Powershell]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=277</guid>
		<description><![CDATA[Mai intai, sa vedem ce este, pe scurt, Active Directory Module pentru Windows Powershell : este un (super, dupa parerea mea) new-feature inclus in Windows Server 2008 R2 si disponibil in Windows 7 dupa instalarea RSAT (Remote Server Administration Tools). Modulul cuprinde o serie de cmdlets utile pentru administrarea Active Directory. Initial, conditia necesara ca [...]]]></description>
			<content:encoded><![CDATA[<p>Mai intai, sa vedem ce este, pe scurt, Active Directory Module pentru Windows Powershell : este un (super, dupa parerea mea) new-feature inclus in Windows Server 2008 R2 si disponibil in Windows 7 dupa instalarea RSAT (Remote Server Administration Tools). Modulul cuprinde o serie de cmdlets utile pentru administrarea Active Directory.</p>
<p>Initial, conditia necesara ca sa poti utiliza acest modul era sa ai in organizatie cel putin un DC cu Windows 2008 R2, deoarece modul de conectare la Active Directory este prin intermediul Active Directory Web Services, alta noutate adusa de Windows 2008 R2, nedisponibil in versiunile anterioare.</p>
<p>Intre timp, s-au schimbat cerintele : ai nevoie doar de Windows 7 cu RSAT instalate si de cateva update-uri pe un DC care ruleaza Windows Server 2003 SP2, 2003 R2 SP2, 2008 sau 2008 SP2. Am testat intr-un mediu virtual cu un DC Windows 2003 R2 SP2 Standard Edition si o statie Windows 7 Enterprise si voi descrie in continuare procedura:</p>
<p>Am instalat urmatoarele pe DC:</p>
<p>- .NET Framework 3.5 cu SP1 <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=AB99342F-5D1A-413D-8319-81DA479AB0D7&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?FamilyID=AB99342F-5D1A-413D-8319-81DA479AB0D7&amp;displaylang=en</a></p>
<p>- Windows Management Framework Core for Windows Server 2003 (include Windows PowerShell 2.0 si Windows Remote Management 2.0)</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=f002462b-c8f2-417a-92a3-287f5f81407e&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?FamilyId=f002462b-c8f2-417a-92a3-287f5f81407e&amp;displaylang=en</a></p>
<p>- Hotfix-ul descris aici <a href="http://support.microsoft.com/kb/969166">http://support.microsoft.com/kb/969166</a> si care poate fi descarcat de aici <a href="http://connect.microsoft.com/VisualStudio/Downloads/DownloadDetails.aspx?DownloadID=20556">http://connect.microsoft.com/VisualStudio/Downloads/DownloadDetails.aspx?DownloadID=20556</a></p>
<p>- Hotfix-ul descris aici <a href="http://support.microsoft.com/kb/969429/en-us">http://support.microsoft.com/kb/969429/en-us</a> . Request download de aici <a href="http://support.microsoft.com/hotfix/KBHotfix.aspx?kbnum=969429&amp;kbln=en-us">http://support.microsoft.com/hotfix/KBHotfix.aspx?kbnum=969429&amp;kbln=en-us</a></p>
<p>Dupa restart :</p>
<p>- am instalat Active Directory Management Gateway Service, am ales versiunea pentru Windows 2003 x86. <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=008940c6-0296-4597-be3e-1d24c1cf0dda">http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=008940c6-0296-4597-be3e-1d24c1cf0dda</a></p>
<p>Pe o statie cu Windows 7 :</p>
<p>- am instalat Remote Server Administration Tools</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7d2f6ad7-656b-4313-a005-4e344e43997d&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?FamilyID=7d2f6ad7-656b-4313-a005-4e344e43997d&amp;displaylang=en</a></p>
<p>- am activat, din Control Panel, Programs and Features, Turn Windows features on or off, Remote Server Administration Tools, Role Administration Tools, AD and AD LDS Tools, Active Directory Module for Windows Powershell</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image002.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image002_thumb.jpg" border="0" alt="clip_image002" width="502" height="438" /></a></p>
<p>Dupa toate acestea, am trecut la faza de testare :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image004.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image004_thumb.jpg" border="0" alt="clip_image004" width="629" height="488" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image006.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image006_thumb.jpg" border="0" alt="clip_image006" width="627" height="523" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image008.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image008_thumb.jpg" border="0" alt="clip_image008" width="633" height="526" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image010.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image010_thumb.jpg" border="0" alt="clip_image010" width="637" height="236" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image012.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image012_thumb.jpg" border="0" alt="clip_image012" width="639" height="189" /></a></p>
<p>Deci functioneaza.</p>
<p>Si mai obtinem inca ceva odata cu instalarea Active Directory Web Services. Intram iar in Control Panel, Programs and Features, Turn Windows features on or off, Remote Server Administration Tools, Role Administration Tools, AD and AD LDS Tools, AD DS Tools,</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image014.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image014_thumb.jpg" border="0" alt="clip_image014" width="497" height="435" /></a></p>
<p>si avem si Active Directory Administrative Center, pe care il putem folosi pentru administrarea de la distanta a Active Directory, precum si pentru search dupa diverse obiecte si atribute :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image016.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image016_thumb.jpg" border="0" alt="clip_image016" width="643" height="345" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image018.jpg"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2009/12/clip_image018_thumb.jpg" border="0" alt="clip_image018" width="645" height="560" /></a></p>
<p>De retinut ca Active Directory Module nu poate fi importat direct pe DC-uri Windows Server 2003 sau 2008, administrarea se face doar de pe o statie cu Windows 7 cu RSAT sau cu Windows 2008 R2.</p>
<p>Spor la treaba.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2009/12/04/powershell-active-directory-module-si-windows-2003-domain-controllers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
