Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Introduction
- Introduction to Active Directory Domain Services (AD DS)
- Course objectives and expected learning outcomes
- The role of Active Directory in enterprise settings
- Overview of the training lab setup
- Key terminology and concepts related to Active Directory
2. Active Directory Features and Architecture Overview
- Active Directory architecture
- Distinguishing logical from physical structures
- Domains, Trees, and Forests
- Organizational Units (OUs)
- Domain Controllers and the Global Catalog
- Flexible Single Master Operations (FSMO) roles
- Sites and Subnets
- DNS integration with Active Directory
- Active Directory partitions and database architecture
3. Identity Management Solutions and Concepts Overview
- Fundamentals of Identity and Access Management (IAM)
- Differences between Authentication and Authorization
- Kerberos authentication mechanism
- NTLM authentication mechanism
- Single Sign-On (SSO)
- Role-Based Access Control (RBAC)
- Identity lifecycle management
- Hybrid identity concepts
4. Setting Up Active Directory
- Planning an Active Directory deployment
- Installing Active Directory Domain Services
- Upgrading a server to a Domain Controller
- Creating a new forest and domain
- Installing and configuring DNS
- Verifying the installation
- Deployment best practices
5. Implementing Active Directory Domain Services
- Creating Organizational Units
- Administering users, groups, and computers
- User account management
- Group scopes and group types
- Delegating administrative control
- Managing service accounts
- Joining computers to the domain
6. Configuring and Managing Replication
- Active Directory replication principles
- Multi-master replication model
- Replication topology
- Knowledge Consistency Checker (KCC)
- Sites and replication scheduling
- Troubleshooting replication issues
- Monitoring replication health
7. Implementing and Managing Group Policy
- Group Policy architecture
- Creating Group Policy Objects (GPOs)
- Linking GPOs
- Group Policy inheritance behavior
- Loopback processing
- Administrative Templates
- Software deployment via GPO
- Folder Redirection
- Security policies
- Password and account lockout policies
- Troubleshooting Group Policy issues
8. Implementing a Certification Authority (CA) Hierarchy
- Introduction to Public Key Infrastructure (PKI)
- Certificate Services architecture
- Root and Subordinate Certification Authorities
- Installing Active Directory Certificate Services
- Designing a CA hierarchy
- Certificate templates
- Auto-enrollment processes
9. Managing Certificates
- Certificate lifecycle management
- Issuing certificates
- Certificate renewal procedures
- Certificate revocation processes
- Certificate Revocation Lists (CRLs)
- Online Certificate Status Protocol (OCSP)
- Managing certificate templates
- Troubleshooting certificate issues
10. Implementing and Administering Active Directory Federation Services (AD FS)
- Introduction to federation services
- AD FS architecture
- Claims-based authentication
- Installing AD FS
- Configuring trust relationships
- Implementing Single Sign-On
- Integrating external applications
- Monitoring and troubleshooting AD FS
11. Enabling Data Access
- Access control concepts
- NTFS permissions
- Shared folder permissions
- Calculating Effective permissions
- Access-Based Enumeration
- Dynamic Access Control
- File Classification Infrastructure
- Auditing file access events
12. Securing Active Directory Domain Services
- Security best practices for Active Directory
- Administrative security model
- Tiered administration approach
- Privileged Access Management (PAM)
- Securing Domain Controllers
- Password policies
- Fine-Grained Password Policies
- Account lockout policies
- Auditing and monitoring strategies
- Backup and recovery considerations
13. Implementing and Managing Rights Management Services (RMS)
- Introduction to Active Directory Rights Management Services
- RMS architecture
- Installing AD RMS
- Protecting sensitive documents
- Information protection policies
- Integration with Microsoft Office
- Managing user access rights
14. Implementing Microsoft Entra ID (formerly Azure Active Directory)
- Introduction to Microsoft Entra ID
- Cloud identity concepts
- Hybrid identity architecture
- Microsoft Entra Connect
- Password Hash Synchronization
- Pass-through Authentication
- Federation with AD FS
- Conditional Access overview
- Identity synchronization processes
- Managing cloud identities
15. Integrating Active Directory with OpenLDAP
- LDAP fundamentals
- Active Directory LDAP support
- OpenLDAP overview
- Identity synchronization methods
- Authentication integration techniques
- Common interoperability scenarios
- Security considerations
- Troubleshooting LDAP connectivity issues
16. Monitoring Active Directory
- Monitoring tools available
- Using Event Viewer
- Utilizing Performance Monitor
- Active Directory Administrative Center
- PowerShell for monitoring tasks
- Replication monitoring techniques
- Conducting health checks
- Auditing changes in the directory
- Performance optimization strategies
17. Troubleshooting
- Addressing user logon issues
- Resolving DNS-related problems
- Investigating replication failures
- Troubleshooting Group Policy issues
- Handling authentication issues
- Addressing certificate-related problems
- Checking Domain Controller health
- Using diagnostic tools (dcdiag, repadmin, nltest, gpresult)
- Backup and recovery procedures
- Disaster recovery scenarios
18. Summary and Conclusion
- Review of key concepts covered
- Best practices for Active Directory administration
- Security recommendations
- Operational maintenance checklist
- Additional Microsoft resources and documentation
- Questions and answers session
- Final hands-on review and lab wrap-up
Requirements
- Experience in system administration
- Background working with Windows Server
Target Audience
- System administrators
21 Hours
Testimonials (2)
Defenitely the 90% HandsOn-Training and the Revisions of the Activities i had to do during the Training. The Traing was intense, due to i was the only member. But i learned a lot and Chris answered every single question i had. I would defenitly recommend this course.
Sebastian - Artweger GmbH und Co KG
Course - Active Directory for Admins
I learned a lot and gained knowledge can use at my work!