Re: New to Active Directory



So how does the login process work? When users try to login to their
computers, do they have to log into the domain? Are they able to login
locally?

Thanks.


Paul Bergson wrote:
There are no local accounts needed in Windows desktops, when you
authenticate to the domain you are logged on locally with your domain
credentials. All permissions provide to the user are assigned via their
domain credentials.

Microsoft is a multimaster environment, similar to Netware. All replication
is handled to and from each other via definitions of inter and intra site
replication. This is all handled hands off and you usually want to keep it
that way unless you have large numbers of DC's in many locations.

The DC's don;t manage anything other than the access control to resources
through security. Kerberos is used to provide Ticket Granting Tickets to
resources that reside in the domain. If you have the proper credentials you
are given the authorization to use the object, service, etc... Permissions
are assigned usually by domain groups, thereby as users come and go you only
change group membership of the group instead of going to the object and
adding and deleting users.

I would recommend you go out and purchase some books specifically on AD, in
particular there is an MVP (Joe Richard's) who spends a lot of time in here
and has written a book that would be of great value to you.

The link below will bring you to the info to the book

http://www.amazon.com/gp/product/0596101732/qid=1152907154/sr=1-1/ref=sr_1_1/104-4656207-8740720?s=books&v=glance&n=283155


--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

<rzaleski@xxxxxxxxx> wrote in message
news:1152904576.213423.17660@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I have experience using Novell NetWare. I am currently learning how to
use Active Directory. I am looking for a good beginner's tutorial.
Everything I have searched for has been too advanced. I have a few
questions.

1. A user will have a local workstation username/password. When they
connect to Active Directory, how does the local workstation
username/password sync with the Active Directory username/password?
2. In an Active Directory environment one (or I assume many) computers
can be domain controllers. Do these replicate to each other? Do these
servers manage all other servers/users/printers, etc?

Thanks.


.



Relevant Pages

  • Re: users are not able to log into windows 2000 domain
    ... Re-join the computers to the domain. ... > I had active directory and the server crashed, ... > network computers if I try to login, ... > domain admins and the login works now. ...
    (microsoft.public.win2000.active_directory)
  • Re: local rights when logging into a domain
    ... this for about 200 computers. ... >Login as administrator of the domain on the pc, ... >Choose the user from the active directory then Next...It ...
    (microsoft.public.win2000.security)
  • Re: Is_Member problem : Does user belong to custom Group
    ... In active directory: 1 - Created in Active directory a Windows group named ... 'MyDomainName/MyApplReadOnly' as Login Name and the same as User ... We can create a ROLE in the database and add the users. ...
    (microsoft.public.sqlserver.security)
  • Re: Go directly to limited login
    ... > These computers have a limited login, ... > they use these public-access computers. ... > login, which is used only by staff. ... You can leave the password box blank if your account does ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Is_Member problem : Does user belong to custom Group
    ... - Added in Security/Logins the windows Group 'MyDomainName/MyApplReadOnly' referred as type 'Windows Group' with Defaultdatabase 'Master' ... Then configured the database Role Membership of this user by setting db_datareader and db_denydatawriter to true. ... for the current user returns 0 although he is referred in active directory as someone belonging to the the windows group Mydomainname\MyapplReadOnly ... There is a login, there is a user that mapped to the Login ...
    (microsoft.public.sqlserver.security)