Pages

Banner 468

Showing posts with label Users and Groups with Windows 2003. Show all posts
Showing posts with label Users and Groups with Windows 2003. Show all posts
Thursday, 8 August 2013

Adding a Windows XP computer to a Windows Server 2003 domain

0 comments
 
Preface:
This is basically the same procedure as the Windows 2000 tutorial.  Some things to note about adding a Windows XP computer to a domain are the following:
  • You need Windows XP Professional to join a XP computer to a domain.  Home can't be used fully for this
  • You will loose the "fancy" log on screen and you will receive the "classic" log on screen instead.  This is for security and cannot be changed, unless you revert to workgroup mode
  • You will loose the "Fast User Switching".  This cannot be restored, except by reverting back to workgroup mode.
Method:
Click Start, right click "My Computer" and click "Properties"
Go to the "Computer Name" tab and click "Change..."
Select the "Domain" radio button then put in your domain name, not including the . extension (in my example I used the domain "hello.test" but when joining the computer to a domain, I will only type "hello")
Press "OK".  Then you will be presented with a user name and password prompt.  Enter the user name and password of a Domain Administrator
Press "OK" and after a minute or two you will receive a message welcoming you to the domain.  Then you will receive a message telling you that a reboot is required, click "OK" to that, and the properties window.  Then click "Yes" when you are prompted to reboot.
And we're finished.  You have just learnt how to add a Windows XP computer to a Windows Server 2003 domain
Additive:
After the XP computer boots to Control-Alt-Delete you may need to change it from logging onto itself (which will use the local info) to logging onto the domain.  To do this, press Ctrl-Alt-Del, then the "Options >>>" button on the log on screen.  Then select the domain from the drop-down box
After that you can log on using domain credentials
Readmore...
Wednesday, 7 August 2013

Configuring Domain Group Policy for Windows 2003

0 comments
 
Windows 2003 Group Policies allow the administrators to manage a group of people accessing a resource efficiently. The group policies can be used to control both the users and computers.
They give better productivity to administrators and save their time by allowing them to manage all the users and computers centrally in just one go.
The group policies are of two types, Local Group Policy and Domain-based Group Policy. As the name suggests, the Local Group Policies allow the local administrator to manage all the users of a computer to access the resources and features available on the computer. For example an administrator can remove the use of Run command from the start menu. This will ensure that the users will not find Run command on that computer.
The Domain-based Group Policies on the other hand allow the domain/enterprise administrators to manage all the users and the computers of a domain/ forest centrally. They can define the settings and the allowed actions for users and computers across sites, domains, and OUs through group policies.
There are more than 2000 pre-created group policy settings available in Windows Server 2003/ Windows XP. A default group policy already exists. You only need to modify it by setting values of different policy settings according to your specific requirements. You can also create new group policies to meet your specific business requirements. The group policies allow you to implement:
  • Registry based settings: Allows you to create a policy to administer operating system components and applications.
  • Security settings: Allows you to set security options for users and computers to restrict them to run files based on path, hash, publisher criteria, or URL zone.
  • Software restrictions: Allows you to create a policy that would restrict users to run unwanted applications and protect computers against virus and hacking attack.
  • Software distribution and installation: Allows you to either assign or publish software application to domain users centrally with the help of a group policy.
  • Automation of tasks using computer and User Scripts
  • Roaming user profiles: Allow mobile users to see a familiar and consistent desktop environment on all the computers of the domain by storing their profile centrally on a server.
  • Internet Explorer maintenance: Allow administrators to manage the IE settings of the user's computers in a domain by setting the security zones, privacy settings, and other parameters centrally with the help of group policy.

Configuring a Domain-Based Group Policy
Just as you used group policy editor to create a local computer policy, to create a domain-based group policy you need to use Active Users and Computers snap-in from where you can open the GPMC .
Follow the steps below to create a domain-based group policy
1. Select Active Directory Users and Computers tool from the Administrative Tools.
2. Expand Active Directory Users and Computers node, as shown below.
3. Right-click the domain name and select Properties from the menu that appears.
tk-windows-gp-domain-1
The properties window of the domain appears.

4. Click the Group Policy tab.
5. The Group Policy tab appears with a Default Domain Policy already created in it, as shown in here:
tk-windows-gp-domain-2

You can edit the Default Domain Policy or create a new policy. However, it is not recommended to modify the Default Domain Policy for regular settings.
We will select to create a new policy instead. Click New to create a new group policy or group policy object. A new group policy object appears below the Default Domain Policy in the Group Policy tab, as shown below:
tk-windows-gp-domain-3

Once you rename this group policy, you can either double-click on it, or select it and click Edit.
You'll next be presented with the Group Policy Object Editor from where you can select the changes you wish to apply to the specific Group Policy:
tk-windows-gp-domain-4

In this example, we have selected to Remove Run menu from Start Menu as shown above. Double-click on the selected setting and the properties of the settings will appear. Select Enabled to enable this setting. Clicking on Explain will provide plenty of additional information to help you understand the effects of this setting.
tk-windows-gp-domain-5
When done, click on OK to save the new setting.
Similarly you can set other settings for the policy. After setting all the desired options, close the Group Policy Object editor . You new group policy will take effect.
Readmore...

How To Create an Active Directory Server in Windows Server 2003

0 comments
 

Creating the Active Directory

After you have installed Windows Server 2003 on a stand-alone server, run the Active Directory Wizard to create the new Active Directory forest or domain, and then convert the Windows Server 2003 computer into the first domain controller in the forest. To convert a Windows Server 2003 computer into the first domain controller in the forest, follow these steps:
  1. Insert the Windows Server 2003 CD-ROM into your computer's CD-ROM or DVD-ROM drive.
  2. Click Start, click Run, and then type dcpromo.
  3. Click OK to start the Active Directory Installation Wizard, and then click Next.
  4. Click Domain controller for a new domain, and then click Next.
  5. Click Domain in a new forest, and then click Next.
  6. Specify the full DNS name for the new domain. Note that because this procedure is for a laboratory environment and you are not integrating this environment into your existing DNS infrastructure, you can use something generic, such as mycompany.local, for this setting. Click Next.
  7. Accept the default domain NetBIOS name (this is "mycompany" if you used the suggestion in step 6). Click Next.
  8. Set the database and log file location to the default setting of the c:\winnt\ntds folder, and then click Next.
  9. Set the Sysvol folder location to the default setting of the c:\winnt\sysvol folder, and then click Next.
  10. Click Install and configure the DNS server on this computer, and then click Next.
  11. Click Permissions compatible only with Windows 2000 or Windows Server 2003 servers or operating systems, and then click Next.
  12. Because this is a laboratory environment, leave the password for the Directory Services Restore Mode Administrator blank. Note that in a full production environment, this password is set by using a secure password format. Click Next.
  13. Review and confirm the options that you selected, and then click Next.
  14. The installation of Active Directory proceeds. Note that this operation may take several minutes.
  15. When you are prompted, restart the computer. After the computer restarts, confirm that the Domain Name System (DNS) service location records for the new domain controller have been created. To confirm that the DNS service location records have been created, follow these steps:
    1. Click Start, point to Administrative Tools, and then click DNS to start the DNS Administrator Console.
    2. Expand the server name, expand Forward Lookup Zones, and then expand the domain.
    3. Verify that the _msdcs, _sites, _tcp, and _udp folders are present. These folders and the service location records they contain are critical to Active Directory and Windows Server 2003 operations.

Adding Users and Computers to the Active Directory Domain

After the new Active Directory domain is established, create a user account in that domain to use as an administrative account. When that user is added to the appropriate security groups, use that account to add computers to the domain.
  1. To create a new user, follow these steps:
    1. Click Start, point to Administrative Tools, and then click Active Directory Users and Computers to start the Active Directory Users and Computers console.
    2. Click the domain name that you created, and then expand the contents.
    3. Right-click Users, point to New, and then click User.
    4. Type the first name, last name, and user logon name of the new user, and then click Next.
    5. Type a new password, confirm the password, and then click to select one of the following check boxes:

      • Users must change password at next logon (recommended for most users)
      • User cannot change password
      • Password never expires
      • Account is disabled
      Click Next.
    6. Review the information that you provided, and if everything is correct, click Finish.
  2. After you create the new user, give this user account membership in a group that permits that user to perform administrative tasks. Because this is a laboratory environment that you are in control of, you can give this user account full administrative access by making it a member of the Schema, Enterprise, and Domain administrators groups. To add the account to the Schema, Enterprise, and Domain administrators groups, follow these steps:
    1. On the Active Directory Users and Computers console, right-click the new account that you created, and then click Properties.
    2. Click the Member Of tab, and then click Add.
    3. In the Select Groups dialog box, specify a group, and then click OK to add the groups that you want to the list.
    4. Repeat the selection process for each group in which the user needs account membership.
    5. Click OK to finish.
  3. The final step in this process is to add a member server to the domain. This process also applies to workstations. To add a computer to the domain, follow these steps:
    1. Log on to the computer that you want to add to the domain.
    2. Right-click My Computer, and then click Properties.
    3. Click the Computer Name tab, and then click Change.
    4. In the Computer Name Changes dialog box, click Domain under Member Of, and then type the domain name. Click OK.
    5. When you are prompted, type the user name and password of the account that you previously created, and then click OK.

      A message that welcomes you to the domain is generated.
    6. Click OK to return to the Computer Name tab, and then click OK to finish.
    7. Restart the computer if you are prompted to do so.

Troubleshooting

You Cannot Open the Active Directory Snap-ins

After you have completed the installation of Active Directory, you may not be able to start the Active Directory Users and Computers snap-in, and you may receive an error message that indicates that no authority can be contacted for authentication. This can occur if DNS is not correctly configured. To resolve this issue, verify that the zones on your DNS server are configured correctly and that your DNS server has authority for the zone that contains the Active Directory domain name. If the zones appear to be correct and the server has authority for the domain, try to start the Active Directory Users and Computers snap-in again. If you receive the same error message, use the DCPROMO utility to remove Active Directory, restart the computer, and then reinstall Active Directory.
Readmore...

Configuring permissions and groups (Windows Server 2003 domain controller)

0 comments
 

Configuring permissions and groups (Windows Server 2003 domain controller)

If Microsoft Windows Server 2003 is a domain controller, you must complete these tasks to configure users and groups to access IBM® InfoSphere® Information Server. This configuration is required only for the engine tier computer and is only applicable to the users of the operating system where the engine tier components are installed.

Procedure

Because you cannot add the built-in authenticated users group to a group that you create in steps 2 and 3, you might prefer to skip steps 2 and 3 and use the authenticated users group directly.
  1. Log in to Microsoft Windows Server 2003 as an administrator.
  2. Configure the server to allow local users to log in.
    1. Click Start > Control Panel > Administrative Tools > Domain Security Policy.
    2. In the Domain Security Policy window, expand Local Policies > User Rights Assignment to display the policies.
    3. In the Domain Security window, click the Allow log on Locally policy, and click Actions > Properties.
    4. In the Allow log on Locally Properties window, click Add User or Group.
    5. Click Browse.
    6. In the Select Users, Computers, or Groups window, click Advanced and then click Find Now.
    7. In the search results, click Authenticated Users, and then click OK three times to return to the Domain Security Policy window.
    8. Close the Domain Security Policy window.
  3. Create a group.
    1. Click Start > Control Panel > Administrative Tools > Active Directory and Computers.
    2. In the Active Directory and Computers window, click Users in the current domain.
    3. In the window that opens, click Action > New Group.
    4. In the New Group window, type the name for the group.
    5. Leave Group scope as Global and Group type as Security.
    6. Click OK
  4. Add users to the group.
    1. In the Users in the current domain window, click the name of the group that you want to add users to, and click OK. Authenticated users are not available.
    2. Click Action > Properties.
    3. In the Properties window, click the Members tab, and then click Add.
    4. In the window that opens, click Advanced, and then click Find Now.
    5. Click the names of users that you want to add to the group, and then click OK. Authenticated users are not available.
    6. Click OK two times to save your results and to return to the Active Directory and Computers window.
    7. Close the Active Directory and Computers window.
  5. Set permissions on the server folder.
    1. In Windows Explorer, locate the server folder. The default location is c:\IBM\InformationServer\Server.
    2. Click File > Properties.
    3. In the Properties window, click the Security tab, and click Add.
    4. In the Select Users, Computers, or Groups window, click Locations.
    5. In the window that opens, click Advanced, and then click Find Now.
    6. Click the name of the group that you want to set permissions for.
    7. Click OK, and then click OK again.
    8. Click the name of the group that you want to set permissions for.
    9. In the Permissions list, locate Modify.
    10. Click Write in the Allow column for this item, and click OK.
    11. If you receive a message to confirm your changes, confirm by clicking Apply changes to this folder, subfolders and files.
Readmore...

Creating Windows Users and Groups with Windows 2003

0 comments
 

User Accounts

In Windows Server 2003 computers there are two types of user accounts. These types are local and domain user accounts. The local user accounts are the single user accounts that are locally created on a Windows Server 2003 computer to allow a user to log on to a local computer. The local user accounts are stored in Security Accounts Manager (SAM) database locally on the hard disk. The local user accounts allow you to access local resources on a computer
On the other hand the domain user accounts are created on domain controllers and are saved in Active Directory. These accounts allow to you access resources anywhere on the network. On a Windows Server 2003 computer, which is a member of a domain, you need a local user account to log in locally on the computer and a domain user account to log in to the domain. Although you can have a same login and password for both the accounts, they are still entirely different account types.
You become a local administrator on your computer automatically because local computer account is created when a server is created. A domain administrator can be local administrator on all the member computers of the domain because by default the domain administrators are added to the local administrators group of the computers that belong to the domain.
This article discusses about creating local as well as domain user accounts, creating groups and then adding members to groups.
Creating a Local User Account
To create a local user account, you need to:
1. Log on as Administrator, or as a user of local administrator group or Account Operators local group in the domain.
2. Open Administrative Tools in the Control Panel and then click Computer Management, as shown in Figure 1.

tk-windows-user-groups-1
Figure 1

3. Click Users folder under Local Users and Groups node, as shown in Figure 2.
tk-windows-user-groups-2
Figure 2

4. Right-click Users and then click New User in the menu that appears, as shown in Figure 3:
tk-windows-user-groups-3
Figure 3

The New User dialog box appears as shown below in Figure 4.
5. Provide the User name and the Password for the user in their respective fields.
6. Select the desired password settings requirement.
Select User must change password at next logon option if you want the user to change the password when the user first logs into computer. Select User cannot change password option if you do not want the user to change the password. Select Password never expires option if you do not want the password to become obsolete after a number of days. Select Account is disabled to disable this user account.
7. Click Create , and then click Close:
tk-windows-user-groups-4
 Figure 4


The user account will appear on clicking Users node under Local Users and Groups on the right panel of the window.
You can now associate the user to a group. To associate the user to a group, you need to:
8. Click Users folder under Local Users and Groups node.
9. Right-click the user and then select Properties from the menu that appears, as shown in Figure 5:
tk-windows-user-groups-5
 Figure 5

The Properties dialog box of the user account appears, as shown in Figure 6:
10. Click Member of tab.

The group(s) with which the user is currently associated appears.

11. Click Add.
tk-windows-user-groups-6
 Figure 6


The Select Groups dialog box appears, as shown in Figure 7.
12. Select the name of the group/object that you want the user to associate with from the Enter the object names to select field.
If the group/object names do not appear, you can click Advanced button to find them. Also if you want to choose different locations from the network or choose check the users available, then click Locations or Check Names buttons.
13. Click OK .
tk-windows-user-groups-7
Figure 7


The selected group will be associated with the user and will appear in the Properties window of the user, as shown in Figure 8:
tk-windows-user-groups-8
Figure 8

Creating a Domain User Account

The process of creating a domain user account is more or less similar to the process of creating a local user account. The only difference is a few different options in the same type of screens and a few steps more in between.
For example you need Active Directory Users and Computers MMC (Microsoft Management Console) to create domain account users instead of Local Users and Computers MMC. Also when you create a user in domain then a domain is associated with the user by default. However, you can change the domain if you want.
Besides all this, although, a domain user account can be created in the Users container, it is always better to create it in the desired Organization Unit (OU).
To create a domain user account follow the steps given below:
1. Log on as Administrator and open Active Directory Users and Computers MMC from the Administrative Tools in Control Panel, as shown in Figure 9.
2. Expand the OU in which you want to create a user, right-click the OU and select New->User from the menu that appears.
tk-windows-user-groups-9
 Figure 9

3. Alternatively, you can click on Action menu and select New->User from the menu that appears.
The New Object –User dialog box appears, as shown in Figure 10.
4. Provide the First name, Last name, and Full name in their respective fields.
5. Provide a unique logon name in User logon name field and then select a domain from the dropdown next to User logon name field if you want to change the domain name.
The domain and the user name that you have provided will appear in the User logon name (pre-Windows 2000) fields to ensure that user is allowed to log on to domain computers that are using earlier versions of Windows such as Windows NT.
tk-windows-user-groups-10
Figure 10
6. Click Next.

The second screen of New Object –User dialog box appears similar to Figure 4.
7. Provide the User name and the Password in their respective fields.
8. Select the desired password settings requirement:
Select User must change password at next logon option if you want the user to change the password when the user first logs into computer. Select User cannot change password option if you do not want the user to change the password. Select Password never expires option if you do not want the password to become obsolete after a number of days. Select Account is disabled to disable this user account.
9. Click Next.
10. Verify the user details that you had provided and click Finish on the third screen of New Object –User dialog box.
11. Follow the steps 9-13 mentioned in Creating a Local User Account section to associate a user to a group.

Creating Groups

Just like user accounts, the groups on a Windows Server 2003 computer are also of two types, the built in local groups and built in domain groups. The example of certain built in domain groups are: Account Operators, Administrators, Backup Operators, Network Configuration Operators, Performance Monitor Users, and Users. Similarly certain built in local groups are: Administrators, Users, Guests, and Backup operators.
The built in groups are created automatically when the operating system is installed and become a part of a domain. However, sometimes you need to create your own groups to meet your business requirements. The custom groups allow you limit the access of resources on a network to users as per your business requirements. To create custom groups in domain, you need to:
1. Log on as Administrator and open Active Directory Users and Computers MMC from the Administrative Tools in Control Panel, as shown in Figure 9.
2. Right-click the OU and select New->Group from the menu that appears.
The New Object –Group dialog box appears, as shown in Figure 10.
3. Provide the name of the group in the Group name field.
The group name that you have provided will appear in the Group name (pre-Windows 2000) field to ensure that group is functional on domain computers that are using earlier versions of Windows such as Windows NT.
4. Select the desired group scope of the group from the Group scope options.
If the Domain Local Scope is selected the members can come from any domain but the members can access resources only from the local domain.
If Global scope is selected then members can come only from local domain but can access resources in any domain.
If Universal scope is selected then members can come from any domain and members can access resources from any domain.
5. Select the group type from the Group Type options.
The group type can be Security or Distribution . The Security groups are only used to assign and gain permissions to access resources and Distribution groups are used for no-security related tasks such as sending emails to all the group members.
tk-windows-user-groups-11
Readmore...