Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Mastering Active Directory
Mastering Active Directory

Mastering Active Directory: Understand the Core Functionalities of Active Directory Services Using Microsoft Server 2016 and PowerShell

eBook
€8.99 €39.99
Paperback
€48.99
Subscription
Free Trial
Renews at €18.99p/m

What do you get with eBook?

Product feature icon Instant access to your Digital eBook purchase
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
OR
Modal Close icon
Payment Processing...
tick Completed

Billing Address

Table of content icon View table of contents Preview book icon Preview Book

Mastering Active Directory

Active Directory Domain Services 2016

Microsoft Active Directory Domain Services (AD DS) have been in the industry for more than 15 years now. The first Microsoft AD version was released with Windows Server 2000. After that, with each and every Microsoft Server release, a new AD DS version was released too. Those changes improved the functions, security, manageability, and reliability of identity infrastructures.

Each and every time Microsoft releases a new version of their software, IT engineers, IT professionals, and administrators rush to figure out what is new in it. It's good practice to be on top of industrial trends. At the time I started writing this book, there weren't many resources available to explain the new features of AD DS 2016.

Microsoft released AD DS 2016 at a very interesting time technologically. As I stated in the previous chapter, today's...

AD DS 2016 features

AD DS improvements apply to its forest and domain functional levels. Upgrading the operating system or adding domain controllers that run Windows Server 2016 to an existing AD infrastructure isn't going to upgrade the forest and domain functional levels. In order to use or test these new AD DS 2016 features, you need to have the forest and domain function levels set to Windows Server 2016. The minimum forest and domain functional levels you can run on your identity infrastructure depend on the lowest domain controller version running.

For example, if you have a Windows Server 2008 domain controller in your infrastructure, even if you add a Windows Server 2016 domain controller, the domain and forest functional levels need to be maintained as Windows Server 2008 until the last Windows Server 2008 domain controller is removed from the infrastructure.

...

Privileged Access Management

Privileged Access Management (PAM) is one of the most-discussed topics in presentations, tech shows, IT forums, IT groups, blogs, and meetings in the past few years (since 2014) when it comes to identity management. It has become a trending topic, especially after the Windows Server 2016 preview releases. In 2016, I traveled to several cities in several countries and found myself involved in many presentations and discussions about PAM.

First of all, this is not a feature you can enable with a few clicks. It is a combination of many technologies and methodologies that come together and make a workflow or, in other words, way of living for administrators. AD DS 2016 includes features and capabilities supporting PAM in the infrastructure, but it is not the only thing it has. This is one of the greatest challenges I see about this new way of thinking...

Time-based group memberships

In the previous section, I explained PAM features in the new AD DS 2016. Time-based group membership is a part of that broader topic. It allows administrators to assign temporary group membership, which is expressed by a time-to-live (TTL) value. This value will be added to the Kerberos ticket. It is also called the expiring links feature. When a user is assigned to a temporary group membership, their login Kerberos ticket-granting ticket (TGT) lifetime will be equal to the lowest TTL value they have. For example, let's assume you grant temporary group membership to user A to be a member of the Domain Admin group. It is only valid for 60 minutes. But the user logs in 50 minutes after the original assignment and only has 10 minutes left to be a member of the Domain Admin group. Based on this, the domain controller will issue a TGT valid only for...

Microsoft Passport

The most common way of protecting access to a system or resources is to introduce authentication and authorization processes. This is exactly what AD does as well. When a user logs in to a domain-joined device, AD first authenticates the user to see whether they're the user they claim to be. Once authentication is successful, it then checks what the user is allowed to do (authorization). To do that, we use usernames and passwords. This is what all identity infrastructure attackers are after. They need some kind of username and password to get into the system. Passwords are a rather weak authentication method. They are breakable, and it's just a matter of time and methods used. As a solution, organizations are tightening password policies, but when they are forcibly made complex, more and more people start to write down. I have seen a few people who...

Active Directory Federation Services improvements

Active Directory Federation Services (AD FS) allows the sharing of identities among trusted business partners (federated) with minimum identity infrastructure changes. AD FS 2016 added many new features to protect federated environments with rising identity infrastructure threats. In Chapter 13, Active Directory Federation Services, I will explain AD FS in detail. Right now, I am going to summarize the shiny new features it has.

In the previous section about Microsoft Passport, I explained why the traditional username/password method is no longer an option against modern identity threats. This is applicable to federated environments as well. Most federated environments use MFA as another layer of security, but we still use usernames and passwords for the initial authentication process. AD FS 2016 supports three new methods to authenticate...

Time sync improvements

Time accuracy is important for AD infrastructures to maintain Kerberos authentication between users and domain controllers. Currently, the time accuracy between two parties should be less than 5 minutes. In an AD environment, domain members sync time with domain controllers (PDC or domain controller in the root forest or a domain controller with the good time server (GTIMESERV) flag) to maintain accurate time across the environment.

But sometimes, this doesn't work as expected. Virtual servers sync time with their hosts, which can cause accuracy issues. Depending on the network topology, the reply packets for time requests can take longer to reach the requester. This also can cause accuracy issues between the DC and client. Mobile devices and laptops may not connect with the domain very often, which can also lead to time accuracy issues.

Time accuracy...

Summary

In this chapter, we looked at the new features and enhancements that come with AD DS 2016. One of the biggest improvements was Microsoft's new approach toward privilege access management. This is not just a feature that can be enabled via AD DS and is just part of the border solution. It helps protect identity infrastructures from adversaries as traditional techniques and technologies are no longer valid with rising threats. We also saw the new types of advanced authentication methods allowed by AD DS. Typical username/password combinations are the weaker option with current infrastructure-security challenges. AD FS 2016 also has additional security enhancements to protect identities in a federated environment. Last but not least, we saw the improvements made to time synchronization to maintain time accuracy across the AD domain.

In the next chapter, we are going...

Left arrow icon Right arrow icon
Download code icon Download Code

Key benefits

  • •Manage your Active Directory services for Windows Server 2016 effectively
  • •Automate administrative tasks in Active Directory using PowerShell
  • •Manage your organization’s network with ease

Description

Active Directory is a centralized and standardized system that automates networked management of user data, security, and distributed resources and enables interoperation with other directories. If you are aware of Active Directory basics and want to gain expertise in it, this book is perfect for you. We will quickly go through the architecture and fundamentals of Active Directory and then dive deep into the core components, such as forests, domains, sites, trust relationships, OU, objects, attributes, DNS, and replication. We will then move on to AD schemas, global catalogs, LDAP, RODC, RMS, certificate authorities, group policies, and security best practices, which will help you gain a better understanding of objects and components and how they can be used effectively. We will also cover AD Domain Services and Federation Services for Windows Server 2016 and all their new features. Last but not least, you will learn how to manage your identity infrastructure for a hybrid-cloud setup. All this will help you design, plan, deploy, manage operations on, and troubleshoot your enterprise identity infrastructure in a secure, effective manner. Furthermore, I will guide you through automating administrative tasks using PowerShell cmdlets. Toward the end of the book, we will cover best practices and troubleshooting techniques that can be used to improve security and performance in an identity infrastructure.

Who is this book for?

If you are an Active Directory administrator, system administrator, or network professional who has basic knowledge of Active Directory and are looking to gain expertise in this topic, this is the book for you.

What you will learn

  • •Explore the new features in Active Directory Domain Service 2016
  • •Automate AD tasks with PowerShell
  • •Get to know the advanced functionalities of the schema
  • •Learn about Flexible Single Master Operation (FSMO) roles and their placement
  • •Install and migrate Active directory from older versions to Active Directory 2016
  • •Manage Active Directory objects using different tools and techniques
  • •Manage users, groups, and devices effectively
  • •Design your OU structure in the best way
  • •Audit and monitor Active Directory
  • •Integrate Azure with Active Directory for a hybrid setup

Product Details

Country selected
Publication date, Length, Edition, Language, ISBN-13
Publication date : Jun 30, 2017
Length: 742 pages
Edition : 1st
Language : English
ISBN-13 : 9781787283077
Vendor :
Microsoft

What do you get with eBook?

Product feature icon Instant access to your Digital eBook purchase
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
OR
Modal Close icon
Payment Processing...
tick Completed

Billing Address

Product Details

Publication date : Jun 30, 2017
Length: 742 pages
Edition : 1st
Language : English
ISBN-13 : 9781787283077
Vendor :
Microsoft

Packt Subscriptions

See our plans and pricing
Modal Close icon
€18.99 billed monthly
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Simple pricing, no contract
€189.99 billed annually
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just €5 each
Feature tick icon Exclusive print discounts
€264.99 billed in 18 months
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just €5 each
Feature tick icon Exclusive print discounts

Frequently bought together


Stars icon
Total 135.97
Windows Server 2016 Automation with PowerShell Cookbook
€49.99
Mastering Windows PowerShell Scripting (Second Edition)
€36.99
Mastering Active Directory
€48.99
Total 135.97 Stars icon
Banner background image

Table of Contents

19 Chapters
Active Directory Fundamentals Chevron down icon Chevron up icon
Active Directory Domain Services 2016 Chevron down icon Chevron up icon
Designing Active Directory Infrastructure Chevron down icon Chevron up icon
Active Directory Domain Name System Chevron down icon Chevron up icon
Placing Operations Master Roles Chevron down icon Chevron up icon
Migrating to Active Directory 2016 Chevron down icon Chevron up icon
Managing Active Directory Objects Chevron down icon Chevron up icon
Managing Users, Groups, and Devices Chevron down icon Chevron up icon
Designing the OU Structure Chevron down icon Chevron up icon
Managing Group Policies Chevron down icon Chevron up icon
Active Directory Services Chevron down icon Chevron up icon
Active Directory Certificate Services Chevron down icon Chevron up icon
Active Directory Federation Services Chevron down icon Chevron up icon
Active Directory Rights Management Services Chevron down icon Chevron up icon
Active Directory Security Best Practices Chevron down icon Chevron up icon
Advanced AD Management with PowerShell Chevron down icon Chevron up icon
Azure Active Directory Hybrid Setup Chevron down icon Chevron up icon
Active Directory Audit and Monitoring Chevron down icon Chevron up icon
Active Directory Troubleshooting Chevron down icon Chevron up icon

Customer reviews

Top Reviews
Rating distribution
Full star icon Full star icon Full star icon Full star icon Half star icon 4.4
(10 Ratings)
5 star 70%
4 star 10%
3 star 10%
2 star 10%
1 star 0%
Filter icon Filter
Top Reviews

Filter reviews by




Joseph Faries II Oct 19, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
Love it
Amazon Verified review Amazon
Johary G Aug 29, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
It took me two weeks of heavy reading to tackle this copious book of about 700 pages. I wanted to read it in the first place because i felt like I was in need of upgrading my AD skills to the 21st century. This book does just that for me and I really thank the author for putting so much efforts in getting this work done. Kuddos to you my fellow.This book is packed with examples, especially in PowerShell. If someone needed to get his hands dirty, here we go. You will be well served ah ah ah ah..... OH i like this book. Thanks again for putting your talent to the service of others.I did notice a few typos and things the like, but this book is so good that the benefits overpowered these little distraction. There are not that many of them, so.Best regards
Amazon Verified review Amazon
Angela Smith May 14, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
One of the better technology related books I've read. Author uses a lot of examples to make topics easier to understand and remember.
Amazon Verified review Amazon
Peter Dec 07, 2018
Full star icon Full star icon Full star icon Full star icon Full star icon 5
I highly recommend this book. Very clear and informative. The seller ships very quickly.
Amazon Verified review Amazon
Nagesh Suresh Shanbhag Jul 18, 2019
Full star icon Full star icon Full star icon Full star icon Full star icon 5
Nice and Excellent 👍... Very help ful to clear concept of Active directory
Amazon Verified review Amazon
Get free access to Packt library with over 7500+ books and video courses for 7 days!
Start Free Trial

FAQs

How do I buy and download an eBook? Chevron down icon Chevron up icon

Where there is an eBook version of a title available, you can buy it from the book details for that title. Add either the standalone eBook or the eBook and print book bundle to your shopping cart. Your eBook will show in your cart as a product on its own. After completing checkout and payment in the normal way, you will receive your receipt on the screen containing a link to a personalised PDF download file. This link will remain active for 30 days. You can download backup copies of the file by logging in to your account at any time.

If you already have Adobe reader installed, then clicking on the link will download and open the PDF file directly. If you don't, then save the PDF file on your machine and download the Reader to view it.

Please Note: Packt eBooks are non-returnable and non-refundable.

Packt eBook and Licensing When you buy an eBook from Packt Publishing, completing your purchase means you accept the terms of our licence agreement. Please read the full text of the agreement. In it we have tried to balance the need for the ebook to be usable for you the reader with our needs to protect the rights of us as Publishers and of our authors. In summary, the agreement says:

  • You may make copies of your eBook for your own use onto any machine
  • You may not pass copies of the eBook on to anyone else
How can I make a purchase on your website? Chevron down icon Chevron up icon

If you want to purchase a video course, eBook or Bundle (Print+eBook) please follow below steps:

  1. Register on our website using your email address and the password.
  2. Search for the title by name or ISBN using the search option.
  3. Select the title you want to purchase.
  4. Choose the format you wish to purchase the title in; if you order the Print Book, you get a free eBook copy of the same title. 
  5. Proceed with the checkout process (payment to be made using Credit Card, Debit Cart, or PayPal)
Where can I access support around an eBook? Chevron down icon Chevron up icon
  • If you experience a problem with using or installing Adobe Reader, the contact Adobe directly.
  • To view the errata for the book, see www.packtpub.com/support and view the pages for the title you have.
  • To view your account details or to download a new copy of the book go to www.packtpub.com/account
  • To contact us directly if a problem is not resolved, use www.packtpub.com/contact-us
What eBook formats do Packt support? Chevron down icon Chevron up icon

Our eBooks are currently available in a variety of formats such as PDF and ePubs. In the future, this may well change with trends and development in technology, but please note that our PDFs are not Adobe eBook Reader format, which has greater restrictions on security.

You will need to use Adobe Reader v9 or later in order to read Packt's PDF eBooks.

What are the benefits of eBooks? Chevron down icon Chevron up icon
  • You can get the information you need immediately
  • You can easily take them with you on a laptop
  • You can download them an unlimited number of times
  • You can print them out
  • They are copy-paste enabled
  • They are searchable
  • There is no password protection
  • They are lower price than print
  • They save resources and space
What is an eBook? Chevron down icon Chevron up icon

Packt eBooks are a complete electronic version of the print edition, available in PDF and ePub formats. Every piece of content down to the page numbering is the same. Because we save the costs of printing and shipping the book to you, we are able to offer eBooks at a lower cost than print editions.

When you have purchased an eBook, simply login to your account and click on the link in Your Download Area. We recommend you saving the file to your hard drive before opening it.

For optimal viewing of our eBooks, we recommend you download and install the free Adobe Reader version 9.