Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Mastering Active Directory
Mastering Active Directory

Mastering Active Directory: Understand the Core Functionalities of Active Directory Services Using Microsoft Server 2016 and PowerShell

eBook
€8.99 €39.99
Paperback
€48.99
Subscription
Free Trial
Renews at €18.99p/m

What do you get with Print?

Product feature icon Instant access to your digital eBook copy whilst your Print order is Shipped
Product feature icon Paperback book shipped to your preferred address
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
OR
Modal Close icon
Payment Processing...
tick Completed

Shipping Address

Billing Address

Shipping Methods
Table of content icon View table of contents Preview book icon Preview Book

Mastering Active Directory

Active Directory Domain Services 2016

Microsoft Active Directory Domain Services (AD DS) have been in the industry for more than 15 years now. The first Microsoft AD version was released with Windows Server 2000. After that, with each and every Microsoft Server release, a new AD DS version was released too. Those changes improved the functions, security, manageability, and reliability of identity infrastructures.

Each and every time Microsoft releases a new version of their software, IT engineers, IT professionals, and administrators rush to figure out what is new in it. It's good practice to be on top of industrial trends. At the time I started writing this book, there weren't many resources available to explain the new features of AD DS 2016.

Microsoft released AD DS 2016 at a very interesting time technologically. As I stated in the previous chapter, today's...

AD DS 2016 features

AD DS improvements apply to its forest and domain functional levels. Upgrading the operating system or adding domain controllers that run Windows Server 2016 to an existing AD infrastructure isn't going to upgrade the forest and domain functional levels. In order to use or test these new AD DS 2016 features, you need to have the forest and domain function levels set to Windows Server 2016. The minimum forest and domain functional levels you can run on your identity infrastructure depend on the lowest domain controller version running.

For example, if you have a Windows Server 2008 domain controller in your infrastructure, even if you add a Windows Server 2016 domain controller, the domain and forest functional levels need to be maintained as Windows Server 2008 until the last Windows Server 2008 domain controller is removed from the infrastructure.

...

Privileged Access Management

Privileged Access Management (PAM) is one of the most-discussed topics in presentations, tech shows, IT forums, IT groups, blogs, and meetings in the past few years (since 2014) when it comes to identity management. It has become a trending topic, especially after the Windows Server 2016 preview releases. In 2016, I traveled to several cities in several countries and found myself involved in many presentations and discussions about PAM.

First of all, this is not a feature you can enable with a few clicks. It is a combination of many technologies and methodologies that come together and make a workflow or, in other words, way of living for administrators. AD DS 2016 includes features and capabilities supporting PAM in the infrastructure, but it is not the only thing it has. This is one of the greatest challenges I see about this new way of thinking...

Time-based group memberships

In the previous section, I explained PAM features in the new AD DS 2016. Time-based group membership is a part of that broader topic. It allows administrators to assign temporary group membership, which is expressed by a time-to-live (TTL) value. This value will be added to the Kerberos ticket. It is also called the expiring links feature. When a user is assigned to a temporary group membership, their login Kerberos ticket-granting ticket (TGT) lifetime will be equal to the lowest TTL value they have. For example, let's assume you grant temporary group membership to user A to be a member of the Domain Admin group. It is only valid for 60 minutes. But the user logs in 50 minutes after the original assignment and only has 10 minutes left to be a member of the Domain Admin group. Based on this, the domain controller will issue a TGT valid only for...

Microsoft Passport

The most common way of protecting access to a system or resources is to introduce authentication and authorization processes. This is exactly what AD does as well. When a user logs in to a domain-joined device, AD first authenticates the user to see whether they're the user they claim to be. Once authentication is successful, it then checks what the user is allowed to do (authorization). To do that, we use usernames and passwords. This is what all identity infrastructure attackers are after. They need some kind of username and password to get into the system. Passwords are a rather weak authentication method. They are breakable, and it's just a matter of time and methods used. As a solution, organizations are tightening password policies, but when they are forcibly made complex, more and more people start to write down. I have seen a few people who...

Active Directory Federation Services improvements

Active Directory Federation Services (AD FS) allows the sharing of identities among trusted business partners (federated) with minimum identity infrastructure changes. AD FS 2016 added many new features to protect federated environments with rising identity infrastructure threats. In Chapter 13, Active Directory Federation Services, I will explain AD FS in detail. Right now, I am going to summarize the shiny new features it has.

In the previous section about Microsoft Passport, I explained why the traditional username/password method is no longer an option against modern identity threats. This is applicable to federated environments as well. Most federated environments use MFA as another layer of security, but we still use usernames and passwords for the initial authentication process. AD FS 2016 supports three new methods to authenticate...

Time sync improvements

Time accuracy is important for AD infrastructures to maintain Kerberos authentication between users and domain controllers. Currently, the time accuracy between two parties should be less than 5 minutes. In an AD environment, domain members sync time with domain controllers (PDC or domain controller in the root forest or a domain controller with the good time server (GTIMESERV) flag) to maintain accurate time across the environment.

But sometimes, this doesn't work as expected. Virtual servers sync time with their hosts, which can cause accuracy issues. Depending on the network topology, the reply packets for time requests can take longer to reach the requester. This also can cause accuracy issues between the DC and client. Mobile devices and laptops may not connect with the domain very often, which can also lead to time accuracy issues.

Time accuracy...

Summary

In this chapter, we looked at the new features and enhancements that come with AD DS 2016. One of the biggest improvements was Microsoft's new approach toward privilege access management. This is not just a feature that can be enabled via AD DS and is just part of the border solution. It helps protect identity infrastructures from adversaries as traditional techniques and technologies are no longer valid with rising threats. We also saw the new types of advanced authentication methods allowed by AD DS. Typical username/password combinations are the weaker option with current infrastructure-security challenges. AD FS 2016 also has additional security enhancements to protect identities in a federated environment. Last but not least, we saw the improvements made to time synchronization to maintain time accuracy across the AD domain.

In the next chapter, we are going...

Left arrow icon Right arrow icon
Download code icon Download Code

Key benefits

  • •Manage your Active Directory services for Windows Server 2016 effectively
  • •Automate administrative tasks in Active Directory using PowerShell
  • •Manage your organization’s network with ease

Description

Active Directory is a centralized and standardized system that automates networked management of user data, security, and distributed resources and enables interoperation with other directories. If you are aware of Active Directory basics and want to gain expertise in it, this book is perfect for you. We will quickly go through the architecture and fundamentals of Active Directory and then dive deep into the core components, such as forests, domains, sites, trust relationships, OU, objects, attributes, DNS, and replication. We will then move on to AD schemas, global catalogs, LDAP, RODC, RMS, certificate authorities, group policies, and security best practices, which will help you gain a better understanding of objects and components and how they can be used effectively. We will also cover AD Domain Services and Federation Services for Windows Server 2016 and all their new features. Last but not least, you will learn how to manage your identity infrastructure for a hybrid-cloud setup. All this will help you design, plan, deploy, manage operations on, and troubleshoot your enterprise identity infrastructure in a secure, effective manner. Furthermore, I will guide you through automating administrative tasks using PowerShell cmdlets. Toward the end of the book, we will cover best practices and troubleshooting techniques that can be used to improve security and performance in an identity infrastructure.

Who is this book for?

If you are an Active Directory administrator, system administrator, or network professional who has basic knowledge of Active Directory and are looking to gain expertise in this topic, this is the book for you.

What you will learn

  • •Explore the new features in Active Directory Domain Service 2016
  • •Automate AD tasks with PowerShell
  • •Get to know the advanced functionalities of the schema
  • •Learn about Flexible Single Master Operation (FSMO) roles and their placement
  • •Install and migrate Active directory from older versions to Active Directory 2016
  • •Manage Active Directory objects using different tools and techniques
  • •Manage users, groups, and devices effectively
  • •Design your OU structure in the best way
  • •Audit and monitor Active Directory
  • •Integrate Azure with Active Directory for a hybrid setup
Estimated delivery fee Deliver to Ireland

Premium delivery 7 - 10 business days

€23.95
(Includes tracking information)

Product Details

Country selected
Publication date, Length, Edition, Language, ISBN-13
Publication date : Jun 30, 2017
Length: 742 pages
Edition : 1st
Language : English
ISBN-13 : 9781787289352
Vendor :
Microsoft
Languages :

What do you get with Print?

Product feature icon Instant access to your digital eBook copy whilst your Print order is Shipped
Product feature icon Paperback book shipped to your preferred address
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
OR
Modal Close icon
Payment Processing...
tick Completed

Shipping Address

Billing Address

Shipping Methods
Estimated delivery fee Deliver to Ireland

Premium delivery 7 - 10 business days

€23.95
(Includes tracking information)

Product Details

Publication date : Jun 30, 2017
Length: 742 pages
Edition : 1st
Language : English
ISBN-13 : 9781787289352
Vendor :
Microsoft
Languages :

Packt Subscriptions

See our plans and pricing
Modal Close icon
€18.99 billed monthly
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Simple pricing, no contract
€189.99 billed annually
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just €5 each
Feature tick icon Exclusive print discounts
€264.99 billed in 18 months
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just €5 each
Feature tick icon Exclusive print discounts

Frequently bought together


Stars icon
Total 135.97
Windows Server 2016 Automation with PowerShell Cookbook
€49.99
Mastering Windows PowerShell Scripting (Second Edition)
€36.99
Mastering Active Directory
€48.99
Total 135.97 Stars icon
Banner background image

Table of Contents

19 Chapters
Active Directory Fundamentals Chevron down icon Chevron up icon
Active Directory Domain Services 2016 Chevron down icon Chevron up icon
Designing Active Directory Infrastructure Chevron down icon Chevron up icon
Active Directory Domain Name System Chevron down icon Chevron up icon
Placing Operations Master Roles Chevron down icon Chevron up icon
Migrating to Active Directory 2016 Chevron down icon Chevron up icon
Managing Active Directory Objects Chevron down icon Chevron up icon
Managing Users, Groups, and Devices Chevron down icon Chevron up icon
Designing the OU Structure Chevron down icon Chevron up icon
Managing Group Policies Chevron down icon Chevron up icon
Active Directory Services Chevron down icon Chevron up icon
Active Directory Certificate Services Chevron down icon Chevron up icon
Active Directory Federation Services Chevron down icon Chevron up icon
Active Directory Rights Management Services Chevron down icon Chevron up icon
Active Directory Security Best Practices Chevron down icon Chevron up icon
Advanced AD Management with PowerShell Chevron down icon Chevron up icon
Azure Active Directory Hybrid Setup Chevron down icon Chevron up icon
Active Directory Audit and Monitoring Chevron down icon Chevron up icon
Active Directory Troubleshooting Chevron down icon Chevron up icon

Customer reviews

Top Reviews
Rating distribution
Full star icon Full star icon Full star icon Full star icon Half star icon 4.4
(10 Ratings)
5 star 70%
4 star 10%
3 star 10%
2 star 10%
1 star 0%
Filter icon Filter
Top Reviews

Filter reviews by




Joseph Faries II Oct 19, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
Love it
Amazon Verified review Amazon
Johary G Aug 29, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
It took me two weeks of heavy reading to tackle this copious book of about 700 pages. I wanted to read it in the first place because i felt like I was in need of upgrading my AD skills to the 21st century. This book does just that for me and I really thank the author for putting so much efforts in getting this work done. Kuddos to you my fellow.This book is packed with examples, especially in PowerShell. If someone needed to get his hands dirty, here we go. You will be well served ah ah ah ah..... OH i like this book. Thanks again for putting your talent to the service of others.I did notice a few typos and things the like, but this book is so good that the benefits overpowered these little distraction. There are not that many of them, so.Best regards
Amazon Verified review Amazon
Angela Smith May 14, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
One of the better technology related books I've read. Author uses a lot of examples to make topics easier to understand and remember.
Amazon Verified review Amazon
Peter Dec 07, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
I highly recommend this book. Very clear and informative. The seller ships very quickly.
Amazon Verified review Amazon
Nagesh Suresh Shanbhag Jul 18, 2019
Full star icon Full star icon Full star icon Full star icon Full star icon 5
Nice and Excellent 👍... Very help ful to clear concept of Active directory
Amazon Verified review Amazon
Get free access to Packt library with over 7500+ books and video courses for 7 days!
Start Free Trial

FAQs

What is the delivery time and cost of print book? Chevron down icon Chevron up icon

Shipping Details

USA:

'

Economy: Delivery to most addresses in the US within 10-15 business days

Premium: Trackable Delivery to most addresses in the US within 3-8 business days

UK:

Economy: Delivery to most addresses in the U.K. within 7-9 business days.
Shipments are not trackable

Premium: Trackable delivery to most addresses in the U.K. within 3-4 business days!
Add one extra business day for deliveries to Northern Ireland and Scottish Highlands and islands

EU:

Premium: Trackable delivery to most EU destinations within 4-9 business days.

Australia:

Economy: Can deliver to P. O. Boxes and private residences.
Trackable service with delivery to addresses in Australia only.
Delivery time ranges from 7-9 business days for VIC and 8-10 business days for Interstate metro
Delivery time is up to 15 business days for remote areas of WA, NT & QLD.

Premium: Delivery to addresses in Australia only
Trackable delivery to most P. O. Boxes and private residences in Australia within 4-5 days based on the distance to a destination following dispatch.

India:

Premium: Delivery to most Indian addresses within 5-6 business days

Rest of the World:

Premium: Countries in the American continent: Trackable delivery to most countries within 4-7 business days

Asia:

Premium: Delivery to most Asian addresses within 5-9 business days

Disclaimer:
All orders received before 5 PM U.K time would start printing from the next business day. So the estimated delivery times start from the next day as well. Orders received after 5 PM U.K time (in our internal systems) on a business day or anytime on the weekend will begin printing the second to next business day. For example, an order placed at 11 AM today will begin printing tomorrow, whereas an order placed at 9 PM tonight will begin printing the day after tomorrow.


Unfortunately, due to several restrictions, we are unable to ship to the following countries:

  1. Afghanistan
  2. American Samoa
  3. Belarus
  4. Brunei Darussalam
  5. Central African Republic
  6. The Democratic Republic of Congo
  7. Eritrea
  8. Guinea-bissau
  9. Iran
  10. Lebanon
  11. Libiya Arab Jamahriya
  12. Somalia
  13. Sudan
  14. Russian Federation
  15. Syrian Arab Republic
  16. Ukraine
  17. Venezuela
What is custom duty/charge? Chevron down icon Chevron up icon

Customs duty are charges levied on goods when they cross international borders. It is a tax that is imposed on imported goods. These duties are charged by special authorities and bodies created by local governments and are meant to protect local industries, economies, and businesses.

Do I have to pay customs charges for the print book order? Chevron down icon Chevron up icon

The orders shipped to the countries that are listed under EU27 will not bear custom charges. They are paid by Packt as part of the order.

List of EU27 countries: www.gov.uk/eu-eea:

A custom duty or localized taxes may be applicable on the shipment and would be charged by the recipient country outside of the EU27 which should be paid by the customer and these duties are not included in the shipping charges been charged on the order.

How do I know my custom duty charges? Chevron down icon Chevron up icon

The amount of duty payable varies greatly depending on the imported goods, the country of origin and several other factors like the total invoice amount or dimensions like weight, and other such criteria applicable in your country.

For example:

  • If you live in Mexico, and the declared value of your ordered items is over $ 50, for you to receive a package, you will have to pay additional import tax of 19% which will be $ 9.50 to the courier service.
  • Whereas if you live in Turkey, and the declared value of your ordered items is over € 22, for you to receive a package, you will have to pay additional import tax of 18% which will be € 3.96 to the courier service.
How can I cancel my order? Chevron down icon Chevron up icon

Cancellation Policy for Published Printed Books:

You can cancel any order within 1 hour of placing the order. Simply contact customercare@packt.com with your order details or payment transaction id. If your order has already started the shipment process, we will do our best to stop it. However, if it is already on the way to you then when you receive it, you can contact us at customercare@packt.com using the returns and refund process.

Please understand that Packt Publishing cannot provide refunds or cancel any order except for the cases described in our Return Policy (i.e. Packt Publishing agrees to replace your printed book because it arrives damaged or material defect in book), Packt Publishing will not accept returns.

What is your returns and refunds policy? Chevron down icon Chevron up icon

Return Policy:

We want you to be happy with your purchase from Packtpub.com. We will not hassle you with returning print books to us. If the print book you receive from us is incorrect, damaged, doesn't work or is unacceptably late, please contact Customer Relations Team on customercare@packt.com with the order number and issue details as explained below:

  1. If you ordered (eBook, Video or Print Book) incorrectly or accidentally, please contact Customer Relations Team on customercare@packt.com within one hour of placing the order and we will replace/refund you the item cost.
  2. Sadly, if your eBook or Video file is faulty or a fault occurs during the eBook or Video being made available to you, i.e. during download then you should contact Customer Relations Team within 14 days of purchase on customercare@packt.com who will be able to resolve this issue for you.
  3. You will have a choice of replacement or refund of the problem items.(damaged, defective or incorrect)
  4. Once Customer Care Team confirms that you will be refunded, you should receive the refund within 10 to 12 working days.
  5. If you are only requesting a refund of one book from a multiple order, then we will refund you the appropriate single item.
  6. Where the items were shipped under a free shipping offer, there will be no shipping costs to refund.

On the off chance your printed book arrives damaged, with book material defect, contact our Customer Relation Team on customercare@packt.com within 14 days of receipt of the book with appropriate evidence of damage and we will work with you to secure a replacement copy, if necessary. Please note that each printed book you order from us is individually made by Packt's professional book-printing partner which is on a print-on-demand basis.

What tax is charged? Chevron down icon Chevron up icon

Currently, no tax is charged on the purchase of any print book (subject to change based on the laws and regulations). A localized VAT fee is charged only to our European and UK customers on eBooks, Video and subscriptions that they buy. GST is charged to Indian customers for eBooks and video purchases.

What payment methods can I use? Chevron down icon Chevron up icon

You can pay with the following card types:

  1. Visa Debit
  2. Visa Credit
  3. MasterCard
  4. PayPal
What is the delivery time and cost of print books? Chevron down icon Chevron up icon

Shipping Details

USA:

'

Economy: Delivery to most addresses in the US within 10-15 business days

Premium: Trackable Delivery to most addresses in the US within 3-8 business days

UK:

Economy: Delivery to most addresses in the U.K. within 7-9 business days.
Shipments are not trackable

Premium: Trackable delivery to most addresses in the U.K. within 3-4 business days!
Add one extra business day for deliveries to Northern Ireland and Scottish Highlands and islands

EU:

Premium: Trackable delivery to most EU destinations within 4-9 business days.

Australia:

Economy: Can deliver to P. O. Boxes and private residences.
Trackable service with delivery to addresses in Australia only.
Delivery time ranges from 7-9 business days for VIC and 8-10 business days for Interstate metro
Delivery time is up to 15 business days for remote areas of WA, NT & QLD.

Premium: Delivery to addresses in Australia only
Trackable delivery to most P. O. Boxes and private residences in Australia within 4-5 days based on the distance to a destination following dispatch.

India:

Premium: Delivery to most Indian addresses within 5-6 business days

Rest of the World:

Premium: Countries in the American continent: Trackable delivery to most countries within 4-7 business days

Asia:

Premium: Delivery to most Asian addresses within 5-9 business days

Disclaimer:
All orders received before 5 PM U.K time would start printing from the next business day. So the estimated delivery times start from the next day as well. Orders received after 5 PM U.K time (in our internal systems) on a business day or anytime on the weekend will begin printing the second to next business day. For example, an order placed at 11 AM today will begin printing tomorrow, whereas an order placed at 9 PM tonight will begin printing the day after tomorrow.


Unfortunately, due to several restrictions, we are unable to ship to the following countries:

  1. Afghanistan
  2. American Samoa
  3. Belarus
  4. Brunei Darussalam
  5. Central African Republic
  6. The Democratic Republic of Congo
  7. Eritrea
  8. Guinea-bissau
  9. Iran
  10. Lebanon
  11. Libiya Arab Jamahriya
  12. Somalia
  13. Sudan
  14. Russian Federation
  15. Syrian Arab Republic
  16. Ukraine
  17. Venezuela