Please enable JavaScript.
Coggle requires JavaScript to display documents.
Active Directory Domain Service (Share Permission Fact(Secure FAT)…
Active Directory Domain Service
Network Architecture
Work-group is a peer to peer network
One password for each user on every computer they access
Every PC that shares a resources act as a server
Every PC that access a shared resource act as a client
Usually limited to 10 member
Domain Controller(Not # DNS)
Resources can be everywhere on the network
Domain controller
authenticate user
and computer account
Domain controller
authorize
to resources
Account
User- must have an account when log into window network
Benefit
1.User Account => Control Access
2.Add Password => Increase in Authentication
3.Access list allow system to authorize user access
4.User Account => Unique (SID) => inside (Access Token)
Computer - in a domain mus t have a computer account
Share Permission Fact(Secure FAT)
Everyone group is automatically assigned the read permission
Apply only to user coming through the network
This is the only way to secure FAT
(File allocation table)
control all the file/folder and FAT 32 volumes
Specify the maximum number of user
Basic Share Permission (see in lecture note)
Security Permission
A part of the NTFS file system
Change with each object type
Access Control List
When a user tried to access an Object(e.g) file, folder , print in the SID will compare it access token with the ACD in (DaCL)
Active Directory
Is a Database to stored detail to an Account
Used To: Control
Who can Access these object
Who can Manage these object
Domain Terminology
3 Main Level:
A Forest: Is a collection of AD DS domains that are bound by automatically created
two-way trust
relationship
A Domain is a logical administrative unite that is the home for user ,computers and other objects
A Tree: is a collection of AD DS domains that share a common root domain and have a contiguous namespace
A Organisational Unit(OU) is a container with a domain that organised user, computers and other OUs.
Group Scope
Global: Used to group user and computer account from the local domain
Domain Local: Used to provide access to resources in the local domain
Universal: used to group Global groups from multiple domains