Praise for the First Edition
“Trust me on this one...if you’re an Active Directory engineer or architect, this is the book you need. It’s the companion that’s going to help you keep your job if you’re up in the middle of the night trying to understand how something works or why it’s not working. It’s truly an amazing book.”
—Scott Rachui, MCSE and Senior Active Directory Engineer, author of MCSE Exchange Server 5.5 for Dummies
“This is the best book on Windows 2000 that I have read and one of the best computer books I have ever read. The most unique quality is the excellent explanation of how to use scripting to maximize your results and minimize your effort. This book is especially well suited to the enterprise audience that has to deploy many servers (100+) and not just 1-10. If you have even a small bit of programming experience, you will really appreciate the in-depth explanations of Windows 2000 under the covers.”
—Eric Chipko
“Wow!! I love this book. I’d trade all my books covering Active Directory for this book in a second. The material is covered at a depth that I haven’t seen in any other book—and I’ve looked at most of them. The material is presented in a straightforward manner that doesn’t put you to sleep. An NT4 administrator could easily read this book and become an expert at Active Directory. I especially appreciated the chapter on Active Directory security.”Praise for the Second Edition
—Brian Arkills, author of LDAP Directories Explained
“If you are committed and really desire to know what makes Active Directory tick—and with it the backbone of the latest, and greatest, generation of Windows Network Operating Systems—then there is no better guide to get you there than this book. Inside Active Directory has no equal in the breadth, depth, and scope of its value to a technical practitioner.”
—Rick Kingslan, Microsoft MVP, Directory Services
“Kouti and Seitsonen provide excellent coverage of topics a lot of people have difficulty understanding and setting up properly. This book supplies you with sound background theory so you can understand these concepts and at the same time gives just the right amount of detail to actually accomplish what you are trying to do.”
—Harold McFarland, Editor, Readers Preference Reviews
“The style of this book is very appealing. It gives sufficient detail for the experienced administrator and explains what is happening ’behind the scenes’ at each step, which is extremely helpful when problems arise. An excellent read and an essential component for any skilled administrator!”
—Jeff Dunkelberger, Solutions Architect
“An outstanding refresh of an already great book, Inside Active Directory, Second Edition, should be in the toolbox of any serious Active Directory administrator, architect, or developer. Inside Active Directory is one of the five books I refer to on a weekly basis. Thanks to the authors for all their hard work and dedication.”
—Joe Richards, Microsoft MVP, Windows Server/Active Directory
The most practical, comprehensive, and highly praised guide to Active Directory has now been fully updated for Windows Server 2003. The second edition of Inside Active Directory: A System Administrator’s Guide offers a definitive reference to the design, architecture, installation, and management of Active Directory, the cornerstone technology within Windows 2000 and Windows Server 2003 distributed networks. This new edition—based on the final release software of Windows Server 2003—emphasizes security and covers all the new features, including enhancements in replication and Group Policy, forest trusts, functional levels, and working with dynamic objects.
Inside this core reference, you’ll find practical strategies for managing Active Directory, along with detailed instructions for efficiently administering your entire network operating environment. You will find detailed coverage of the following:
This is an indispensable reference for anyone working with Active Directory. Network operating system novices will gain a solid understanding of Active Directory, while administrators experienced in NT, NetWare, or UNIX will learn how to utilize their current skills in Active Directory. Experienced Windows 2000/Windows Server 2003 professionals will pick up advanced techniques, and developers will benefit strongly from the architecture topics.
"synopsis" may belong to another edition of this title.
Sakari Kouti, M.S. (Tech), is a senior trainer and consultant for Sovelto, the leading training company in Finland. He started working with networks in 1986 and his articles have appeared in Windows NT Magazine (now Windows and .NET Magazine). Sakari was one of the first MCSEs in the world back in 1994.
Mika Seitsonen is a senior trainer at Sovelto. His network experience spans more than ten years, and he was one of the first MCSE: Security on Microsoft Windows Server 2003 certified persons in the world. Mika was awarded MVP—Directory Services in 2004 and holds an M.S. (Tech) from University of Nottingham (U.K.) and Lappeenranta University of Technology (Finland).
During the seven years that Windows NT was sold before Active Directory shipped as part of Windows 2000 (and consequently, as part of Windows Server 2003), administrators didn’t need to learn practically anything new, at least about the core operating system features. User and group management, domains and domain models, and resource management had been the same in all Windows NT versions.
With the introduction of Active Directory, that all changed. There is a huge difference in managing Windows networks over the old NT administration model. Therefore, Active Directory will require quite a lot of study on the part of NT professionals.
Despite some administrative wizards in the user interface and the new Microsoft Management Console (MMC) administration interface, implementing and administering Active Directory requires probably more learning, testing, piloting, and planning than Windows NT required.
About This Book
This book is an implementer’s and administrator’s guide to Active Directory. Throughout the book, you will learn the workings, architecture, administration, and planning of Active Directory. Depending on your needs, however, you don’t have to read this book from cover to cover, as we describe later in this preface.
The first version of Active Directory was included in Windows 2000 (AD2000, as we call it), and the second version is included in Windows Server 2003 (AD2003, as we call it). The first edition of this book covered AD2000, and this second edition covers primarily AD2003, but secondarily also AD2000.
The following list evaluates the appropriateness of this book for a number of potential audiences.
For all target audiences, it is possible that you are not interested in all the advanced topics in this book, so you are free to skip any of them.
We believe that this book has the following strengths.
We have divided the book into three parts.
We’ll now present a short summary of each chapter. Mika wrote Chapter 2 and Chapter 7, and Sakari wrote the remaining chapters.
Chapter 1: Active Directory: The Big Picture
Before going into detail, we give you a general picture of Active Directory. After you learn the concepts introduced in this chapter, you can skip freely some later chapters that you might not be interested in. However, we encourage you to browse through the table of contents of any such chapter to make sure that you are not going to unintentionally miss anything important.Chapter 2: Active Directory Installation
In this chapter, we explain how to install Active Directory. We also describe the post-installation tasks, as well as how to automate and troubleshoot installation.Chapter 3: Managing OUs, Users, and Groups
Once you have an Active Directory domain up and running, one obvious task is to create a user account for each user and plan how to enhance user administration by using groups and organizational units (OUs). This chapter looks at managing OUs, users, contacts, groups, and computer objects, and covers some related topics.Chapter 4: Securing Active Directory
Active Directory has an access control mechanism that enables you to define who can read or modify what information in Active Directory. In this chapter, we explain the concepts and architecture of access control, as well as how to manage permissions in various scenarios.Chapter 5: Sites and Replication
For Active Directory to work efficiently when your network spans multiple geographic locations, you must plan and implement the physical structure and define it in Active Directory itself. In this chapter, we describe the concepts, management, and advanced topics of the physical structure. Some of the content is also relevant for a company with just one site.Chapter 6: Domains and Forests
Active Directory has several levels of hierarchies that you can use to implement an effective logical structure for your company network. In this chapter, we discuss whether you should use one or many domains and one or many forests, and how you should plan and manage that logical structure. We also revisit the physical structure, because it somewhat overlaps with the logical structure. In addition, we explain the anatomy of LDAP searches.Chapter 7: Group Policy
Active Directory has an extensive management architecture called “Group Policy.” You can use Group Policy to manage various aspects of Active Directory objects—for example, user desktop and server security settings. Some of the largest changes to Active Directory day-to-day management come in the form of Group Policy tools. In addition to these tools, you learn the architecture, inheritance, and processing of Group Policy in this chapter.Chapter 8: Active Directory Schema
This chapter examines the Active Directory data model and how it is enforced by the rules of the schema. After reading this chapter, you’ll better understand how Active Directory works behind the scenes, and you’ll also gain knowledge that you can use if you are going to extend the schema.Chapter 9: Extending the Schema
One of Active Directory’s advantages over Windows NT is that you can extend the Active Directory schema, either to accommodate directory-enabled applications or for some administrative purpose. In this chapter, we explain the considerations for extensions and describe the process itself.Chapter 10: Administration Scripts: Concepts
By downloading scripts from the Internet or writing your own scripts and executing them, you can greatly enhance and automate administration. In this chapter, we explain how to get started with technologies such as Windows Script Host (WSH), VBScript, and Active Directory Service Interfaces (ADSI).Chapter 11: Administration Scripts: Examples
In this chapter, we present over 50 sample scripts along with their explanations. Outputs of many of the scripts provide some architectural information about Active Directory, and you can run those scripts without understanding what they do on each line. Therefore, you can use these scripts not only for various administrative tasks, but also to gain more knowledge about Active Directory. This chapter also introduces some additional scripting concepts, such as ActiveX Data Objects (ADO), between the sample scripts"About this title" may belong to another edition of this title.
Shipping:
FREE
Within U.S.A.
Seller: ZBK Books, Carlstadt, NJ, U.S.A.
Condition: good. Used book in good and clean conditions. Pages and cover are intact. Limited notes marks and highlighting may be present. May show signs of normal shelf wear and bends on edges. Item may be missing CDs or access codes. May include library marks. Fast Shipping. Seller Inventory # ZWM.JDB8
Quantity: 1 available
Seller: ThriftBooks-Atlanta, AUSTELL, GA, U.S.A.
Paperback. Condition: As New. No Jacket. Pages are clean and are not marred by notes or folds of any kind. ~ ThriftBooks: Read More, Spend Less 3.9. Seller Inventory # G0321228480I2N00
Quantity: 1 available
Seller: ThriftBooks-Dallas, Dallas, TX, U.S.A.
Paperback. Condition: Very Good. No Jacket. May have limited writing in cover pages. Pages are unmarked. ~ ThriftBooks: Read More, Spend Less 3.9. Seller Inventory # G0321228480I4N00
Quantity: 1 available
Seller: Blue Vase Books, Interlochen, MI, U.S.A.
Condition: good. The item shows wear from consistent use, but it remains in good condition and works perfectly. All pages and cover are intact including the dust cover, if applicable . Spine may show signs of wear. Pages may include limited notes and highlighting. May NOT include discs, access code or other supplemental materials. Seller Inventory # BVV.0321228480.G
Quantity: 1 available
Seller: Book Haven, Wellington, WLG, New Zealand
Paperback. Condition: Good. The most comprehensive, practical, and highly praised book on Active Directory is now fully updated for Windows Server 2003 A System Administrator's Guide (2nd Edition) (Microsoft Windows Server System Series). Heavy. 1248 pages. Seller Inventory # 1509369
Quantity: 1 available
Seller: Grumpys Fine Books, Tijeras, NM, U.S.A.
Paperback. Condition: very good. little wear and tear. Seller Inventory # Grumpy0321228480
Quantity: 1 available
Seller: Grumpys Fine Books, Tijeras, NM, U.S.A.
Paperback. Condition: new. Prompt service guaranteed. Seller Inventory # Clean0321228480
Quantity: 1 available
Seller: OM Books, Sevilla, SE, Spain
Condition: usado - bueno. Seller Inventory # 9780321228482
Quantity: 1 available