Lo2 - Lesson 2 Active Directory Objects
Lo2 - Lesson 2 Active Directory Objects
Lo2 - Lesson 2 Active Directory Objects
What’s New
Active directory (AD) is not going to work solely without its objects, Objects are everything live
under AD. As stated in (Information sheet: Active Directory) objects are the following, Users
and groups, services (i.e. Emails), resources such printers, shared folders.
What is It?
What is an OU?
An Organization Unit is a container that holds AD Object like User Accounts, Computer
Accounts, and Groups. (See Figure 1)
We’ll start off building a few Organization Units so our Users and Computer Accounts will
have a place to live.
1. Start by opening up your Server Manager, then expand the Roles section. (See Figure 3)
PERFORMANCE TASK
Organizational Unit’s keep your object organized and are used to control what users and
computers can and can’t do.
Groups are active directory objects that allow you to provide and deny access to resources
like printer folder. Groups are residing in organizational unit.
3. At this point you should be able to see your domain. In our example we are using the
itsmeismael domain. Go ahead and expand your domain (click the + sign). (See Figure 7)
6. We now have a new Organizational Unit in our Active Directory called CSS Students. (See
Figure 10)
1. After creating an Organizational Unit in your Active Directory, you are ready to create your
first group. Go ahead and select your OU and then right-click in the blank area. Next, point to
New and then select Group. (See Figure 11)
2. The next step is to name your Group, select the group scope and then select the group
type. In this example we are going to name our group CSS User. We are also going to
leave the default selections for group scope is Global, and group type is Security > click
OK. (See Figure 12)
USER ACCOUNTS
it allows users to access network resources.
2. In the empty area, right-click select New and click User. You can also right-click the OU
and click New and select User to create a new user account. (See Figure 14)
3. New Object dialog box will open as shown below. You can fill in the user information like
first name, last name etc. As you can see below, there are two user login names. The first
User logon name is also called User Principal Name (UPN) superUser@itsmeismael.com
which is email like name that can be used to login to domain joined computers. Second
user logon name (pre-Windows 2000) also called SamAccountName can also be used by
user to login to domain-joined computers in the form itsmeismael\superUser. After
entering the user details, click Next. (See Figure 15)
4. Enter password for the user. You can choose various options as shown below. Once you
are done, click Next. (See Figure 16)
What I Can Do
Performance Objective: Given are the following materials, you should be able to install active
directory. Allotted time 30 minutes.
Supplies/Materials:
Steps/Procedure:
4. Create a group
Where:
Group name = CSS Group
Add your newly created domain users inside the group
Total Points
Total Items
References
“How to Install Active Directory On Windows Server 2008 R2”. Accessed March 30, 2022,
https://www.howtogeek.com/99323/installing-active-directory-on-server-2008-r2/
“Active Directory Objects” Ismael Manic Balana. Accessed July 7, 2019,
http://cssnctwo.weebly.com/active-directory-objects
“A delegation for this DNS server cannot be created because the authoritative parent zone
cannot be found or it does not run Windows DNS server”. Accessed March 30, 2022,
https://docs.microsoft.com/en-us/archive/blogs/activedirectoryua/a-delegation-for-this-dns-
server-cannot-be-created-because-the-authoritative-parent-zone-cannot-be-found-or-it-
does-not-run-windows-dns-server
“Create User Account in Server 2012 Domain Controller”. Accessed March 30, 2022,
https://www.mustbegeek.com/create-user-account-in-server-2012-domain-controller/