PLAN ACTIVE DIRECTORY TESTOUT SERVER PRO 2016 IDENTITY

  • Slides: 24
Download presentation
PLAN ACTIVE DIRECTORY TESTOUT SERVER PRO 2016: IDENTITY

PLAN ACTIVE DIRECTORY TESTOUT SERVER PRO 2016: IDENTITY

Manage Active Directory replication. Configure intrasite replication. Configure intersite replication. TESTOUT SERVER PRO 2016:

Manage Active Directory replication. Configure intrasite replication. Configure intersite replication. TESTOUT SERVER PRO 2016: IDENTITY

Site Link Bridgehead Server Connection Site Link Cost Distributed File System (DFS) File Replication

Site Link Bridgehead Server Connection Site Link Cost Distributed File System (DFS) File Replication Service (FRS) TESTOUT SERVER PRO 2016: IDENTITY

Site Link Bridge: A collection of two or more site links that can be

Site Link Bridge: A collection of two or more site links that can be grouped as a single logical link. Bridgehead Server: A domain controller in a site that replicates with domain controllers in other sites. Connection: A logical communication channel between domain controllers. Site Link Cost: A number assigned to a site link that identifies the overall relative cost of using that site link. The cost is used to select the optimal path between sites when more than one path exists. TESTOUT SERVER PRO 2016: IDENTITY

Distributed File System (DFS): A set of client and server services that allow an

Distributed File System (DFS): A set of client and server services that allow an organization using Microsoft Windows servers to organize many distributed SMB file shares into a distributed file system. File Replication Service (FRS): Used for replicating the Distributed File System folder (SYSVOL) for Microsoft Server preceding Windows Server 2008 R 2. TESTOUT SERVER PRO 2016: IDENTITY

IP site links: Support all types of replication. Must allow RPC traffic through firewall

IP site links: Support all types of replication. Must allow RPC traffic through firewall to replicate. Are used in nearly all cases (99. 9%). SMTP site links: Are used between sites without reliable, persistent links. Have several drawbacks: Only transfers schema, configuration, and application partition data. Do not transfer domain data. Require an Enterprise Certification Authority and an SMTP server at each end of the link. TESTOUT SERVER PRO 2016: IDENTITY

An arbitrary number used to favor faster connections. Slower connections are avoided by using

An arbitrary number used to favor faster connections. Slower connections are avoided by using a higher cost number. Active Directory always chooses the least cumulative cost. TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

Define when Active Directory replication can occur. May be set to avoid replication during

Define when Active Directory replication can occur. May be set to avoid replication during peak traffic of limited bandwidth. TESTOUT SERVER PRO 2016: IDENTITY

Define when Active Directory replication can occur. May be set to avoid replication during

Define when Active Directory replication can occur. May be set to avoid replication during peak traffic of limited bandwidth. Should overlap between sites with no direct connections. TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

Determines how often to replicate Active Directory. Has a default value of 180 minutes

Determines how often to replicate Active Directory. Has a default value of 180 minutes (3 hours). Has a valid range of 15 to 10, 080 minutes. Increases traffic and lowers latency if it is lowered. Decreases traffic and increases latency if it is increased. TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

Replication between two or more domain controllers located in the same site. Completed by

Replication between two or more domain controllers located in the same site. Completed by Knowledge Consistency Checker (KCC). Runs every 15 minutes by default. Chooses replication partners according to the rule of three. Rule of Three 1 TESTOUT SERVER PRO 2016: IDENTITY 2 3

Replication between two or more domain controllers located in the same site. Completed by

Replication between two or more domain controllers located in the same site. Completed by Knowledge Consistency Checker (KCC). Runs every 15 minutes by default. Chooses replication partners according to the rule of three. Creates automatic connection objects. Stops creating automatic connections if manual connection objects are created. TESTOUT SERVER PRO 2016: IDENTITY

Replication that occurs between sites. Replication occurs only between bridgehead servers. The ISTG selects

Replication that occurs between sites. Replication occurs only between bridgehead servers. The ISTG selects the bridgehead servers. Updates between bridgehead servers use intersite. Updates from bridgehead servers to other domain controllers uses intrasite. Bridgehead Servers Intrasite Site B t In ite s er Site A Intrasite Bridgehead server can be manually assigned. If manually assigned, ISTG will stop designating bridgehead servers for the site. If manually assigned, Microsoft suggests selecting at least two preferred bridgehead servers. TESTOUT SERVER PRO 2016: IDENTITY

Repadmin can be used to: View the replication topology. Troubleshoot logon issues and replication

Repadmin can be used to: View the replication topology. Troubleshoot logon issues and replication problems. Force all domain controllers to replicate with all other domain controllers: repadmin /syncall Verify replication: repadmin /showrepl TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

TESTOUT SERVER PRO 2016: IDENTITY

Do the following labs: 2. 3. 5 Configure Intrasite Replication 2. 3. 6 Configure

Do the following labs: 2. 3. 5 Configure Intrasite Replication 2. 3. 6 Configure Intersite Replication TESTOUT SERVER PRO 2016: IDENTITY

What types of trusts are enabled by default for site link bridges? How do

What types of trusts are enabled by default for site link bridges? How do you establish bidirectional communications between domain controllers? How does intrasite replication differ from intersite replication? What are the different ways you can force replication? What are three ways you force a certain path between sites for replication? What is the process for migrating from FRS replication to DFS replication when the domain is at Windows Server 2003 functional level? During which migration stages are you able to roll back the migration? TESTOUT SERVER PRO 2016: IDENTITY