Manage Access to an Active Directory Environment Due 11:30 15 December.
The desktop and laptop are authorized for use by the store manager, President Kathy Kudler ,and the president’s administrative assistant.
The printer/scanner/fax machine is authorized for use by the store employees where it is located, as well as President Kathy Kudler and the president’s administrative assistant.
The director of store operations can use any equipment in any location.
Design group objects to implement group policies to manage access to these resources. Document the group design using the following table:
|
Name |
Membership |
Type |
Scope |
Permissions |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
During your work on the network operating system, you become concerned about threats such as disk failures, administrative errors, natural disasters, and the impact of unauthorized changes to data.
How do you plan to recover from these types of loss of current AD DS and other critical information?
What utilities might you investigate to help accomplish your plan?
(Examples of above assignment below – do not plagiarize)
· The desktop and laptop are authorized for use by the store manager, President Kathy Kudler ,and the president’s administrative assistant.
· The printer/scanner/fax machine is authorized for use by the store employees where it is located, as well as President Kathy Kudler and the president’s administrative assistant.
· The director of store operations can use any equipment in any location. Design group objects to implement group policies to manage access to these resources. Document the group design using the following table:
|
Name |
Membership |
Type |
Scope |
Permissions |
|
Director |
Management |
Security Group |
Universal |
Enterprise Admin |
|
President/Administrative Assistant |
Management |
Security Group |
Global |
Group Policy Creator/Owner |
|
Store Manager |
Management |
Security Group |
Local |
Domain User |
|
GenEmployee |
GenUser |
Security Group |
Local |
Print Operator |
|
|
|
|
|
|
Group Policies are designed with the platform of the forest consisting of the following domain structure:
· kudler.com – main
· loc X. kudler.com – sub – X= location number eg: 1,2,3,4 etc….
Each scope is given access per domain forest. Local users would be constrained to a local machine(s) within each specific domain location. Global users would have access to the entirety of each given domain and the Universal scope would allow access to the entire forest of domains.
Permissions allowed are based on default permission settings for these groups:
· Enterprise Admins - Members in the Enterprise Admins group are given absolute full permissions to perform any actions in the entire forest. This encompasses functions such as managing the trust relationships and adding domains to the trees and forests.
· Domain Users - The Domain Users group generally contains all of current user accounts for the declared domain. This group is given basic permissions to resources and data that do not need higher levels of security.
· Group Policy Creator Owners - Group Policy Creator Owners group are all able to create/modify Group Policy settings for objects in the domain. This gives them the ability to enable security settings on OUs (and any of the objects that they contain).
· Print Operators - By default, members of the Print Operators group are granted permissions to administer all of the printers in a domain. This also includes common functions like changing the priority of print jobs in queue and removing items from the active print queue.
All of the users at Kudler Fine Foods are organized into groups and assigned permissions based on the following model of assignment:
( OU ) ( OU ) ( OU ) ( GROUPS ) ( USERS )
AD Disaster Recovery Strategy
Kudler Fine Foods needs a Disaster Recovery process in case of theft, fire, flood etc. There are a few tools we will need to put in place in order to protect the integrity of the system structure and data. Windows 2008 Server contains (WSB) Windows Server Backup tool which is a GUI based component. By default, it is NOT installed as a feature. Using the Server Management Console we will install the WSB as well as the basic CLI support tools. Using the WSB, we will create a system backup of AD structure and data. Along with the AD backup, we WSB to create a system state backup along with a (BMR) Bare Metal Restore. All of the backups will be stored on disk in a fire-proof safe as well as moved off-site to a secure data vault location. The BRM feature will allow the Kudler Systems Administrators to easily create a mirror running image of the existing system and duplicate it on a fresh piece of hardware such as a new server out-of-the-box.
References
Hester, M., & Henley, C. (2010). Windows 2008 Server R2 Administration . : Sybex.
Mar-Elia, D. (2010). Windows Server 2008 R2 and Windows 7 Group Policy. (cover story). Windows IT Pro, 16(6), 23.
Another example:
Example Table 1. User Groups
|
Name |
Membership |
Type |
Scope |
Permissions |
|
LaJollaPrinters |
LaJollaEmployees, Execs, LaJollaStoreMgmt |
Security Group |
La Jolla OU |
|
|
EncinitasPrinters |
EncinitasEmployees, Execs, EncinitasStoreMgmt |
Security Group |
Encinitas OU |
|
|
DelMarPrinters |
DelMarEmployees, Execs, DelMarStoreMgmt |
Security Group |
Del Mar OU |
|
|
Execs |
Kathy Kudler, Dir of Store Ops, Admin Assistant |
Security Group |
Global |
Print, Cancel Jobs, Logon |
|
LaJollaComputers |
Execs, LaJollaStoreMgmt |
Security Group |
La Jolla OU |
Logon |
|
EncinitasComputers |
Execs, DelMarStoreMgmt |
Security Group |
Encinitas OU |
Logon |
|
DelMarComputers |
Execs, DelMarStoreMgmt |
Security Group |
Del Mar OU |
Logon |
|
|
|
|
|
|
|
Name |
Membership |
Type |
Scope |
Permissions |
|
Kathy Kudler |
President |
Security |
Global Group |
All systems/all locations |
|
Admin Assist |
President |
Security |
Global Group |
All systems/all locations |
|
Director of SO |
President |
Security |
Global Group |
All systems/all locations |
|
Manager La Jolla |
La Jolla |
Security |
Domain Local Group |
All La Jolla systems |
|
Employees La Jolla |
La Jolla |
Security |
Domain Local Group |
Printer/scanner/fax machine |
|
Manager Del Mar |
Del Mar |
Security |
Domain Local Group |
All Del Mar systems |
|
Employees Del Mar |
Del Mar |
Security |
Domain Local Group |
Printer/scanner/fax machine |
|
Manager Encinitas |
Encinitas |
Security |
Domain Local Group |
All Encinitas systems |
|
Employees Encinitas |
Encinitas |
Security |
Domain Local Group |
Printer/scanner/fax machine |