Monday, July 11, 2011

IT Leadership: Active Directory

OK, So I thought today would be an easy, lazy Monday. Wrong. What could possibly go wrong when both John and I have worked with Active Directory numerous times? Perhaps not the back end of AD, but worked with, nevertheless.

Yesterday, I had gone in and discovered that our File Manager network issue had been resolved by the fixes I entered on Friday during coffee break. I had turned network discovery on on the workstations and disabled IPv6. I had also changed the workgroup name to match the server. I wish I had had time to check on this before leaving Lethbridge Friday, perhaps I wouldn't have dreamt in octets.

Our task today was to add the Role - Active Directory Services. This seemed easy enough, we went to our Initial Configuration tasks and chose Add Role, AD Services. When this was completed we were prompted to run the dcpromo.exe which was embedded in the installation wizard. We chose to add a domain controller in an existing forest. Our domain name was network5769.local. We did have some difficulty authenticating this service. What we discovered was that our DNS on the server's network adapter had changed to Lethbridge's. Of course, the Lethbridge router was not going to authenticate our domain. When we changed the DNS to the 192.168.181.50 (Lyle's) and 192.168.10.50 (our switch), we were up and authenticated in no time.

Our next tasks were to join our workstations to the domain. Both John and I were "old-hands" at this.
1. Right-click on My Computer
2. Properties
3. Computer name, domain and workgroup settings. Click change settings.
4. To rename this computer or change its domain or workgroup, click Change.
5. Click on the radial button, Domain and enter network 5769.local
6. Restart

Secondly, we needed to create four containers or OU within our school.
1. Computers
2. Students
3. Teachers
4. Groups

To do this we right-clicked on our school container and chose Create, New OU and labelled the OUs appropriately.

The next step was to move our two workstations in the Computers container within our school. This we could accomplish using drag and drop.

We next created two Students - student.lobo and student.lefebvre. We did this by right-clicking on the Students Container and Create New, user.

We used the same procedure and same naming protocol for the two teachers.

Our next step was to create two groups - teacher and student. We used the same procedure as above - right click on the group container and Create New, group.

After we had created our two groups, we needed to ensure that our two students became members of these groups. To do this we double clicked on the user, clicked on the Members of tab and Added studentJS. There is a shortcut to do this. If you cannot remember the exact name of the group policy, you can type the first few letters and click on the far right FIND link. It will show up with all policies beginning with that search criteria. Then simply highlight the proper choice and click add.

We ensured that our two teachers were members of the teachers group and the two students belonged to the student group. A cross-reference check of this was to go to the group policy and check members.

It looked, in theory, like we were good to go. However, things never seem to work out when that clock hits the magic hour of 11:30 am. Our workstations would not log on to our Active Directory. Err...

To fix this problem, we had to delete our four users and recreate them. We then added our group policies again. For whatever reason, this worked!

I think my partner may have been a little paranoid, he tried logging in again at the end of our school day. And...it worked!

Our references we used for the installation were:
Amaya, Nelson. (n.d.). How to install active directory on Server 2008 [Web log post]. Retrieved from http://forevergeeks.com/how-to-install-active-directory-on-windows-2008
Hall, Aaron. (n.d.). Setup Active Directory (Server 2008). Aaronhall.net: someday, bringing goodThings2Life will become a paradigm. Retrieved from http://www.aaronhall.net/support-active-directory-2008#
McLoughlin, N. (2008, February 26). Install active directory domain services for windows server 2008 [Web log post]. Retrieved from http://itsolutionsdirect.com/installing-active-directory-domain-services-for-windows-server-2008/151/

No comments:

Post a Comment