Lo2 - Lesson 2 Active Directory Objects

Download as pdf or txt
Download as pdf or txt
You are on page 1of 12

What I Need to Know

After reading this MODULE, STUDENT(S) MUST be able to:


 Understand what are differences between OU, Users and Groups.
 Create organizational unit and groups in active directory users and computers
 Create users accounts
 In active directory users and groups

What’s New
Active directory (AD) is not going to work solely without its objects, Objects are everything live
under AD. As stated in (Information sheet: Active Directory) objects are the following, Users
and groups, services (i.e. Emails), resources such printers, shared folders.

Lesson ACTIVE DIRECTORY OBJECTS


2 (OU, Users and Groups)

What is It?

What is an OU?
An Organization Unit is a container that holds AD Object like User Accounts, Computer
Accounts, and Groups. (See Figure 1)

Figure 1: Organization Units


Organization Units help to keep your objects organized but also are used to control what
your users can and can’t do (among other things)

We’ll start off building a few Organization Units so our Users and Computer Accounts will
have a place to live.

You can organize Organization Units:


 Geographically
 By function (Departments. etc.)
 But remember to KISS as much as you’re able to! Keep it Simple, Sysadmin. (See
Figure 2)

Figure 2: Organizational Units

Creating an Organizational Unit (OU)

1. Start by opening up your Server Manager, then expand the Roles section. (See Figure 3)

PERFORMANCE TASK

See Figure 4: Forest root domain


Computer accounts
 Allow AD to keep track and control the computers in your network. A computer without
an Account in AD can’t access the network –it’s security measure.
 It resides in OU’s which allow you to install software to all machines in OU at once.
 When you are going to join a computer in your domain (you’ll need Admin level
credentials)
 A computer account is automatically created in AD.

Organizational Unit (OU) vs Groups

Organizational Unit’s keep your object organized and are used to control what users and
computers can and can’t do.
Groups are active directory objects that allow you to provide and deny access to resources
like printer folder. Groups are residing in organizational unit.

CREATING ORGANIZATIONAL UNIT


1. Open server manager (See Figure 5)

Figure 5: Server Manager


2. Expand the Active Directory Domain Services (click the + sign ) section > click on
Active Directory Users and Computers. (See Figure 6)

Figure 6: Active Directory Users and Computers

3. At this point you should be able to see your domain. In our example we are using the
itsmeismael domain. Go ahead and expand your domain (click the + sign). (See Figure 7)

Figure 7: Expanded Domain


4. Now we need to create an Organizational Unit for a group to live in. In this example we are
going to create an OU for our CSS Students. To create a new Organization Unit, right-click
on your domain name, point to the New option and then select Organizational Unit. (See
Figure 8)

Figure 8: Select Organizational Unit


5. Type the name of your OU and make sure that the box is checked next to Protect container
from accidental deletion. When done, click OK. (See Figure 9)

Figure 9: Type the name of your Organizational Unit (OU)

6. We now have a new Organizational Unit in our Active Directory called CSS Students. (See
Figure 10)

Figure 10: Active Directory


CREATING A NEW GROUP

1. After creating an Organizational Unit in your Active Directory, you are ready to create your
first group. Go ahead and select your OU and then right-click in the blank area. Next, point to
New and then select Group. (See Figure 11)

Figure 11: Creating first group

2. The next step is to name your Group, select the group scope and then select the group
type. In this example we are going to name our group CSS User. We are also going to
leave the default selections for group scope is Global, and group type is Security > click
OK. (See Figure 12)

Figure 12: Naming your Group


3. Our new group has been created! (See Figure 13)

Figure 13: A new group has been created.

USER ACCOUNTS
 it allows users to access network resources.

Creating an account using Server Manager


1. Open Server Manager open Roles click Open Active Directory Users and expand the
domain name (itsmeismael.com). Select the Organization Unit (CS Students) where you
want to create the new user account. (See Figure 14)

Figure 14: Selecting a group and creating a new user

2. In the empty area, right-click select New and click User. You can also right-click the OU
and click New and select User to create a new user account. (See Figure 14)

3. New Object dialog box will open as shown below. You can fill in the user information like
first name, last name etc. As you can see below, there are two user login names. The first
User logon name is also called User Principal Name (UPN) superUser@itsmeismael.com
which is email like name that can be used to login to domain joined computers. Second
user logon name (pre-Windows 2000) also called SamAccountName can also be used by
user to login to domain-joined computers in the form itsmeismael\superUser. After
entering the user details, click Next. (See Figure 15)

Figure 15: New Object-User

4. Enter password for the user. You can choose various options as shown below. Once you
are done, click Next. (See Figure 16)

Figure 16: Enter password for the new user.


5. View the summary then click Finish. (See Figure 17)

Figure 17: Summary

What I Can Do

Title: Install active directory

Performance Objective: Given are the following materials, you should be able to install active
directory. Allotted time 30 minutes.

Assessment Method: Demonstration, Observation

Supplies/Materials:

Equipment: Computer with Windows Server 2008 R2

Prerequisites: Installed and configured active directory

Steps/Procedure:

1. Read Lesson Installing Active Directory

2. Create an Organizational Unit


Where:
Name of Organizational Unit(s) = CSS Students
3.Create two domain users
Where:
Name of first user =Your full name, Logon username = WirelessClient Name of second
user = Your full name, Logon username = Wired Client Set the password as
_admin@123 for both users

4. Create a group
Where:
Group name = CSS Group
Add your newly created domain users inside the group

Assessment Method: Demonstration, Observation

Performance Criteria Checklist

Learner’s Name: Date:


During the performance of the task, did you consider the following criteria?

Grade Point Equivalent

Criteria Yes Highest Possible Score = 5 No

Lowest Possible Score = 0


Did the trainee….
1. Created an organizational unit
according to the specific given task?
2. Created two domain users according to
job requirements?
3. Set up the group for domain users
according to specific instruction?
4. Performed and followed completely the
given tasks?
5. Observed and performed 5S and
occupational health and safety?

Total Points

Total Items

Signature of the Learner

Signature of the Trainer


Grade Point Equivalent
The table shows the equivalent points that are used and show how they are calculated to
determine the grade point average (GPA), or index.
The highest equivalent points that trainer can give is 5 points per criterion and the lowest is
O. If the trainee/learner accumulates scores with below two (2) grade point equivalent, she/he
needs to retake the whole given task.

Grade Point Equivalent Explanation


5 Excellent
4 Very Good
3 Good
2 Average
1 Poor

References

“How to Install Active Directory On Windows Server 2008 R2”. Accessed March 30, 2022,
https://www.howtogeek.com/99323/installing-active-directory-on-server-2008-r2/
“Active Directory Objects” Ismael Manic Balana. Accessed July 7, 2019,
http://cssnctwo.weebly.com/active-directory-objects

“A delegation for this DNS server cannot be created because the authoritative parent zone
cannot be found or it does not run Windows DNS server”. Accessed March 30, 2022,
https://docs.microsoft.com/en-us/archive/blogs/activedirectoryua/a-delegation-for-this-dns-
server-cannot-be-created-because-the-authoritative-parent-zone-cannot-be-found-or-it-
does-not-run-windows-dns-server

“Create User Account in Server 2012 Domain Controller”. Accessed March 30, 2022,
https://www.mustbegeek.com/create-user-account-in-server-2012-domain-controller/

You might also like