Active Directory® Domain Services
Active Directory®
Domain Services (AD DS) server role ကိုအသံုးျပဳျခင္းေႀကာင္႔က်ြန္ေတာ္တို႔ဟာ user
and resource management ေတြအတြက္ a scalable, secure, and manageable
infrastructure ျပဳလုပ္ေပးနိုင္တယ္ေနာင္ျပီးေတာ႔ Microsoft® Exchange Server လို
directory-enabled applications ေတြကိုလည္းအေထာက္အပံလုပ္ေပးနိုင္တယ္။
AD DS က directory-enabled
applications ေတြဆီကရတဲ႔ network resources and application-specific data information
ေတြကို သိမ္းထားေပးတယ္ေနာက္ျပီး manages လည္းလုပ္လို႔ရတဲ႔ a distributed database
တစ္ခုကို provide လုပ္ေပးတယ္။ AD DS running လုပ္ေနတဲ႔ server ကို domain
controllerလို႔ေခၚပါတယ္. IT Administrators ေတြက a network ရဲ့ elements ေတြျဖစ္တဲ႔
users, computers, and other devices ေတြကို a hierarchical containment structure
တစ္ခုဖြ႔ဲစည္းတည္ေဆာက္ဖို႔ AD DS ကိုသံုးတယ္။ The hierarchical containment
structure မွာ the Active Directory forest ေတြ domains in the forest နဲ႔
organizational units (OUs) in each domain ပါတယ္. Network elements ေတြကို a hierarchical containment structure တစ္ခုအေနနဲ႔ Organize လုပ္ျခင္းက ေအာက္ပါ benefitsေတြရေစပါတယ္:
·
The
forest acts as a security boundary for an organization and defines the scope of
authority for administrators. By default, a forest contains a single domain, which is known as the
forest root domain.
·
Additional
domains can be created in the forest to provide partitioning of AD DS
data, which enables organizations to replicate data only where it is needed.
This makes it possible for AD DS to scale globally over a network that has
limited available bandwidth. An Active Directory domain also supports a
number of other core functions that are related to administration, including
network-wide user identity, authentication, and trust relationships.
·
OUs
simplify the delegation of authority to facilitate the management of large
numbers of objects. Through delegation, owners can transfer full or limited
authority over objects to other users or groups. Delegation is important
because it helps to distribute the management of large numbers of objects to a
number of people who are trusted to perform management tasks.
Security အေနနဲ႔ကေတာ႔ AD DS က logon authentication and access
control ေတြနဲ႔ resources in the directoryေတြကို ထိန္းခ်ဳပ္ထားတယ္. A single
network logon မွာဆိုရင္ administrators ေတြက သူတို႔ network မွာရွိတဲ႔ directory
data and organization ေတြအကုန္လံုး ကို manage လုပ္နိုင္တယ္. Authorized network
users ေတြကေတာ႔ a single network logon နဲ႔ပဲ network ထဲမွာရွိတဲ႔ resources ေတြကိုပဲသံုးနိုင္တယ္။
Policy-based administration eases the management of even the most complex
network.Additional AD DS features include the following:
·
A
set of rules, the schema, that defines the classes of objects and attributes
that are contained in the directory, the constraints and limits on instances of
these objects, and the format of their names.
·
A
global catalog that contains information about every object in the directory.
Users and administrators can use the global catalog to find directory
information, regardless of which domain in the directory actually contains the
data.
·
A
query and index mechanism, so that objects and their properties can be
published and found by network users or applications.
·
A
replication service that distributes directory data across a network. All
writable domain controllers in a domain participate in replication and contain
a complete copy of all directory information for their domain. Any change to
directory data is replicated to all domain controllers in the domain.
·
Operations
master roles (also known as flexible single master operations or FSMO). Domain
controllers that hold operations master roles are designated to perform
specific tasks to ensure consistency and eliminate conflicting entries in the
directory.
Requirements
for running Active Directory Domain Services
ADDS အတြက္လိုအပ္တဲ႔ Requirements ေတြကေတာ႔ေအာက္ပါအတိုင္းျဖစ္ပါတယ္
Requirement
|
Description
|
TCP/IP
|
TCP/IP and DNS server ေတြအတြက္ IP
addresses ေတြေပးရမယ္.
|
NTFS
|
Active Directory Domain Services (AD DS) ကို
install လုပ္မယ္ drive Partition က NTFS format ျဖစ္ေနရမယ္။Local Drive လည္းျဖစ္ရမယ္
|
Credentials
|
A new AD DS forest လုပ္ဖို႔ local
Administrator နဲ႔ login ထားမွရမယ္။ An additional domain controller တစ္ခုကို an
existing domain မွာ Add လုပ္မယ္ဆိုရင္လည္း က်ြန္ေတာ္တို႔က Domain Admins group
ရဲ႔ member ျဖစ္ေနရမယ္.
|
Domain Name System (DNS)
infrastructure
|
When you install AD DS, you can
include DNS server installation, if it is needed.
When you create a new domain, a
DNS delegation is created automatically during the installation process.
Creating a DNS delegation requires credentials that have permissions to
update the parent DNS zones.
|
Adprep
|
To add the first domain controller
that runs Windows Server 2012 to an existing Active Directory, adprep.exe
commands run automatically as needed. These commands have additional
credential and connectivity requirements.
|
Comments
Post a Comment