Manage Access to an Active Directory Environment Due 11:30 15 December.

profilesapper55
week_3_chart_example_060413.docx

Assume for this assignment that Kudler Fine Foods is running Windows Server® 2008 R2. The company has three locations, each overseen by a store manager. Each store manager has access to a desktop, a laptop, and a printer/scanner/fax machine. This equipment is authorized for use according to the following rules:

The desktop and laptop are authorized for use by the store manager, President Kathy Kudler ,and the president’s administrative assistant.

The printer/scanner/fax machine is authorized for use by the store employees where it is located, as well as President Kathy Kudler and the president’s administrative assistant.

The director of store operations can use any equipment in any location.

Design group objects to implement group policies to manage access to these resources. Document the group design using the following table:

Name

Membership

Type

Scope

Permissions

During your work on the network operating system, you become concerned about threats such as disk failures, administrative errors, natural disasters, and the impact of unauthorized changes to data.

How do you plan to recover from these types of loss of current AD DS and other critical information?

What utilities might you investigate to help accomplish your plan?

(Examples of above assignment below – do not plagiarize)

 

·         The desktop and laptop are authorized for use by the store manager, President Kathy Kudler ,and the president’s administrative assistant.

·         The printer/scanner/fax machine is authorized for use by the store employees where it is located, as well as President Kathy Kudler and the president’s administrative assistant.

·         The director of store operations can use any equipment in any location. Design group objects to implement group policies to manage access to these resources. Document the group design using the following table:

 

Name

Membership

Type

Scope

Permissions

 Director

 Management

 Security Group

 Universal

 Enterprise Admin

 President/Administrative Assistant

 Management

Security Group

 Global

 Group Policy Creator/Owner

 Store Manager

 Management

 Security Group

 Local

 Domain User

 GenEmployee

 GenUser

Security Group

 Local

 Print Operator

Group Policies are designed with the platform of the forest consisting of the following domain structure:

· kudler.com – main

· loc X. kudler.com – sub – X= location number eg: 1,2,3,4 etc….

Each scope is given access per domain forest. Local users would be constrained to a local machine(s) within each specific domain location. Global users would have access to the entirety of each given domain and the Universal scope would allow access to the entire forest of domains.

Permissions allowed are based on default permission settings for these groups:

· Enterprise Admins - Members in the Enterprise Admins group are given absolute full permissions to perform any actions in the entire forest. This encompasses functions such as managing the trust relationships and adding domains to the trees and forests.

· Domain Users - The Domain Users group generally contains all of current user accounts for the declared domain. This group is given basic permissions to resources and data that do not need higher levels of security.

· Group Policy Creator Owners - Group Policy Creator Owners group are all able to create/modify Group Policy settings for objects in the domain. This gives them the ability to enable security settings on OUs (and any of the objects that they contain).

· Print Operators - By default, members of the Print Operators group are granted permissions to administer all of the printers in a domain. This also includes common functions like changing the priority of print jobs in queue and removing items from the active print queue.

All of the users at Kudler Fine Foods are organized into groups and assigned permissions based on the following model of assignment:

( OU ) ( OU ) ( OU ) ( GROUPS ) ( USERS )

AD Disaster Recovery Strategy

Kudler Fine Foods needs a Disaster Recovery process in case of theft, fire, flood etc. There are a few tools we will need to put in place in order to protect the integrity of the system structure and data. Windows 2008 Server contains (WSB) Windows Server Backup tool which is a GUI based component. By default, it is NOT installed as a feature. Using the Server Management Console we will install the WSB as well as the basic CLI support tools. Using the WSB, we will create a system backup of AD structure and data. Along with the AD backup, we WSB to create a system state backup along with a (BMR) Bare Metal Restore. All of the backups will be stored on disk in a fire-proof safe as well as moved off-site to a secure data vault location. The BRM feature will allow the Kudler Systems Administrators to easily create a mirror running image of the existing system and duplicate it on a fresh piece of hardware such as a new server out-of-the-box.

References

Hester, M., & Henley, C. (2010). Windows 2008 Server R2 Administration . : Sybex.

Mar-Elia, D. (2010). Windows Server 2008 R2 and Windows 7 Group Policy. (cover story). Windows IT Pro, 16(6), 23.

Another example:

Example Table 1. User Groups

Name

Membership

Type

Scope

Permissions

 LaJollaPrinters

 LaJollaEmployees, Execs, LaJollaStoreMgmt

Security Group

La Jolla OU

Print

EncinitasPrinters

EncinitasEmployees, Execs, EncinitasStoreMgmt

Security Group

Encinitas OU

Print

 DelMarPrinters

 DelMarEmployees, Execs, DelMarStoreMgmt

Security Group

Del Mar OU

Print

 Execs

 Kathy Kudler, Dir of Store Ops, Admin Assistant

Security Group

Global

Print, Cancel Jobs, Logon

 LaJollaComputers

Execs, LaJollaStoreMgmt

Security Group

La Jolla OU

Logon

EncinitasComputers

Execs, DelMarStoreMgmt

Security Group

Encinitas OU

Logon

 DelMarComputers

Execs, DelMarStoreMgmt

Security Group

Del Mar OU

Logon

Name

Membership

Type

Scope

Permissions

Kathy Kudler

President

Security

Global Group

All systems/all locations

Admin Assist

President

Security

Global Group

All systems/all locations

Director of SO

President

Security

Global Group

All systems/all locations

Manager La Jolla

La Jolla

Security

Domain Local Group

All La Jolla systems

Employees La Jolla

La Jolla

Security

Domain Local Group

Printer/scanner/fax machine

Manager Del Mar

Del Mar

Security

Domain Local Group

All Del Mar systems

Employees Del Mar

Del Mar

Security

Domain Local Group

Printer/scanner/fax machine

Manager Encinitas

Encinitas

Security

Domain Local Group

All Encinitas systems

Employees Encinitas

Encinitas

Security

Domain Local Group

Printer/scanner/fax machine