System Admin Manual
System Admin Manual
LABMANUAL
INDEX
2
Windows Server 2008 - System Administration
3
Windows Server 2008 - System Administration
Pre-requisites:
4
Windows Server 2008 - System Administration
5
Windows Server 2008 - System Administration
6
Windows Server 2008 - System Administration
7
Windows Server 2008 - System Administration
9. Leave the Product Key blank, and click Next. (Product key can be entered later.)
8
Windows Server 2008 - System Administration
9
Windows Server 2008 - System Administration
10
Windows Server 2008 - System Administration
16. Enter the size for the partition, and click Apply.
11
Windows Server 2008 - System Administration
12
Windows Server 2008 - System Administration
13
Windows Server 2008 - System Administration
21. Click OK, (User’s password must be changed before logging on the first time.)
22. Enter the New Password and Confirm the password and Press Enter.
14
Windows Server 2008 - System Administration
15
Windows Server 2008 - System Administration
16
Windows Server 2008 - System Administration
Pre-requisites:
17
Windows Server 2008 - System Administration
18
Windows Server 2008 - System Administration
19
Windows Server 2008 - System Administration
20
Windows Server 2008 - System Administration
21
Windows Server 2008 - System Administration
22
Windows Server 2008 - System Administration
13. Enter the size for the partition, and click Apply.
23
Windows Server 2008 - System Administration
24
Windows Server 2008 - System Administration
18. Enter the User Name and verify the Computer Name, click Next.
25
Windows Server 2008 - System Administration
26
Windows Server 2008 - System Administration
27
Windows Server 2008 - System Administration
24. Finally Operating System is installed and the User has logged in.
28
Windows Server 2008 - System Administration
29
Windows Server 2008 - System Administration
4. Enter User Name (User1) and set Password, Confirm Password and click Create.
Verification:
30
Windows Server 2008 - System Administration
ACTIVE DIRECTORY
Pre-requisites:
1. A Computer with Windows Server 2008 Operating System and connected in the
network.
SYS1
MICROSOFT.COM
SYS1
Domain Controller
IP Address 10.0.0.1
31
Windows Server 2008 - System Administration
2. In the Network and Sharing Center window select Manage Network Connections
32
Windows Server 2008 - System Administration
33
Windows Server 2008 - System Administration
6. Select Use the following IP address and enter the IP address and click Subnet
mask, it will be entered automatically and select Use the following DNS Server
addresses and enter the Preferred DNS Server address and Click OK, and OK.
8. Select Private Network and click Next Close and verify for Network discovery
and File sharing options are on.
34
Windows Server 2008 - System Administration
35
Windows Server 2008 - System Administration
36
Windows Server 2008 - System Administration
8. Enter the DNS Domain Name (Ex: MICROSOFT.COM) and click Next.
37
Windows Server 2008 - System Administration
9. Select the Forest Functional Level (Windows 2000) and click Next.
10. Select the Domain Functional Level (Windows 2000 Native) and click Next.
38
Windows Server 2008 - System Administration
13. On Database and log locations page, accept the default locations and click Next.
39
Windows Server 2008 - System Administration
14. On Directory Services Restore Mode Administrator Password page, enter the
password and confirm password and click Next.
15. On Summary page, review the Options you selected and Next.
40
Windows Server 2008 - System Administration
16. The Active Directory Installation starts and check box Reboot on Completion.
17. Computer restarts after the Installation of Active Directory Domain Services.
Verification:
2. In Computer Name, domain, and workgroup settings verify for the domain
name MICROSOFT.COM.
41
Windows Server 2008 - System Administration
Pre-requisites:
SYS1 SYS2
MICROSOFT.COM
SYS1 SYS2
42
Windows Server 2008 - System Administration
2. Right click Computer Icon and click Properties and click Change settings.
43
Windows Server 2008 - System Administration
5. Enter the user name Administrator and his Password, click OK.
6. Welcome Message appears indicating that the computer was successful in joining
the Domain.
7. Click OK and click Close to close the System Properties dialog box. It will ask for
restart, click Yes.
Verification:
2. Click Computer Name, domain, and workgroup settings and verify for the
Domain Name MICROSOFT.COM.
44
Windows Server 2008 - System Administration
2. Right click Computer and click Properties and click Change settings.
5. Enter the user name Administrator and his Password, click OK.
45
Windows Server 2008 - System Administration
6. Welcome Message appears indicating that the computer was successful in joining
the Domain, click OK.
7. Click OK click OK and click Close to close the System Properties dialog box. It
will ask for restart, click Yes.
Verification:
2. Click Computer Name, domain, and workgroup settings and verify for the
Domain Name MICROSOFT.COM.
46
Windows Server 2008 - System Administration
3. In the console tree, expand your domain MICROSOFT.COM, and then Right Click
Users Container, select New User.
47
Windows Server 2008 - System Administration
4. Specify the First name, and User Logon name and then click Next.
5. Enter the Password and Confirm Password for the User account, click Next.
6. Review the configuration settings for the User Account and then click Finish.
Verification:
48
Windows Server 2008 - System Administration
49
Windows Server 2008 - System Administration
50
Windows Server 2008 - System Administration
6. Change the length value from (7 to 0) and click Apply and OK.
51
Windows Server 2008 - System Administration
9. Click Start Run and Type GPUPDATE and It refreshes the policy changes.
Verification:
1. Go to Active Directory Users and Computers and Create a User with any
Password or without any Password.
52
Windows Server 2008 - System Administration
53
Windows Server 2008 - System Administration
5. Click Add User or Group Click Browse Enter the User name Click OK.
54
Windows Server 2008 - System Administration
55
Windows Server 2008 - System Administration
56
Windows Server 2008 - System Administration
Verification:
1. Enter the password for user (User1) wrongly for 2 times while logging in and the
user account will be locked.
57
Windows Server 2008 - System Administration
Verification:
58
Windows Server 2008 - System Administration
PERMISSIONS
Pre-requisites:
SYS1 SYS2
MICROSOFT.COM
SYS1 SYS2
59
Windows Server 2008 - System Administration
2. Right Click the folder (DATA) and Select Properties and Click Security tab click
Advanced tab Click Edit Clear the box on “Include inherit permissions from
this objects parent.
60
Windows Server 2008 - System Administration
61
Windows Server 2008 - System Administration
3. Select the drop down arrow mark and select Find enter the User name (User1)
click OK select the User(User1)and assign Permissions (Ex: Co-Owner) click
Share click Done.
62
Windows Server 2008 - System Administration
Verification:
Access the Shared folder
1. Logon to Member Server or Client as User (User1) Open Network.
63
Windows Server 2008 - System Administration
Verification:
1. Disconnect or Disable the Network connection, and try to access the shared
folders from network and only Sales folder will be visible and accessible.
64
Windows Server 2008 - System Administration
2. Open the SALES folder & make some modifications (Create some files in it).
3. Then connect or Enable the Network connection, then Right Click the shared
folder & click Sync.
65
Windows Server 2008 - System Administration
66
Windows Server 2008 - System Administration
5. Click Enable Offline Files click OK Click Yes to restart the system.
Verification:
1. Disconnect or Disable the Network connection, and try to access the Shared
Folders from network and only SALES folder will be visible and accessible.
2. Access the SALES folder & make some modifications (Create some files in it).
3. Connect or Enable the Network connection, then Right Click the shared folder &
click Sync.
4. Modifications will be updated on the shared folder (In the server).
67
Windows Server 2008 - System Administration
PROFILES
Pre-requisites:
SYS1 SYS2
MICROSOFT.COM
SYS1 SYS2
68
Windows Server 2008 - System Administration
2. Go to Active Directory Users and Computers and create Users (Ex:a1, a2).
Verification:
69
Windows Server 2008 - System Administration
5. Create some files on desktop and go to C: drive Open Users Open the user
profile(a1) folder open desktop folder verify for the files created on Desktop.
70
Windows Server 2008 - System Administration
Example: \\SYS1\roam\a1.
Verification:
1. Login as user a1 on Client or Member Server and create some files on the
Desktop.
2. Then Right click Computer Icon and Click Properties and Select Advanced System
Settings.
71
Windows Server 2008 - System Administration
5. Logoff this user (a1)& login on another computer with the same user (a1), we can
see the files which we have created on first computer.
72
Windows Server 2008 - System Administration
6. Click Advanced.
73
Windows Server 2008 - System Administration
8. Click Edit.
74
Windows Server 2008 - System Administration
9. Select Administrators and check the box Replace owner on sub containers and
objects, click Apply and Yes OK OK OK.
10. Now open the folder a1 you can find some folders & files.
11. Select NTUSER.DAT file and rename to NTUSER.MAN, click Yes Yes.
75
Windows Server 2008 - System Administration
Note: NTUSER.DAT file is an operating system protected hidden file, it will not be
visible directly, if it is not visible, then open computer iconclick on Tools
TabSelect Folder options select View Tab select Show Hidden Files and
Folders Clear the check box Hide extensions for Known File Types Clear the
Check box Hide protected Operating system Files click Yes click OK.
12. After renaming it go back to the folder a1, Right Click a1Properties.
13. Select the Security tab Edit Add the User a1 and check Allow Full control,
click Apply and OK.
14. Click Advanced tab Edit Check the box Replace all existing inheritable
permissions on all descendants with inheritable permissions from this object.
76
Windows Server 2008 - System Administration
15. Click Apply, it will ask do you wish to continue, Click YES and OK.
77
Windows Server 2008 - System Administration
78
Windows Server 2008 - System Administration
3. Check box the box Enable quota management, and check the box Deny disk
space to users exceeding quota limit.
4. Click Quota Entries click Quota New Quota Entry…
5. Enter the User Name (a1) and Click Check names, click OK.
79
Windows Server 2008 - System Administration
6. Select Limit disk space to and enter the quota limit for a1Click OKClose.
80
Windows Server 2008 - System Administration
Pre-requisites:
SYS1 SYS2
MICROSOFT.COM
SYS1 SYS2
81
Windows Server 2008 - System Administration
82
Windows Server 2008 - System Administration
5. Welcome to the Active Directory Installation Wizard page appears, click Next.
83
Windows Server 2008 - System Administration
84
Windows Server 2008 - System Administration
85
Windows Server 2008 - System Administration
12. Verify for DNS server and Global Catalog check boxes, and click Next.
14. On Database and log locations page, accept the default locations and click Next.
86
Windows Server 2008 - System Administration
16. On Summary page, review the Options you selected, and clickNext.
87
Windows Server 2008 - System Administration
17. After the Active Directory Installation wizard is completed, then click FINISH.
88
Windows Server 2008 - System Administration
Pre-requisites:
SYS1
MICROSOFT.COM
SYS3
MCITP.MICROSOFT.COM
SYS1 SYS3
89
Windows Server 2008 - System Administration
90
Windows Server 2008 - System Administration
5. Welcome to the Active Directory Installation Wizard page appears, click Next.
91
Windows Server 2008 - System Administration
7. Select Existing Forest, Create a new domain in an existing forest click Next.
8. Enter the Forest Domain Name (Ex: MICROSOFT.COM) and click Set.
92
Windows Server 2008 - System Administration
10. Click Browse and Select the Parent Domain Name (MICROSOFT.COM).
93
Windows Server 2008 - System Administration
12. Select the Domain Functional Level (Windows 2000 Native) and click NEXT.
94
Windows Server 2008 - System Administration
14. Verify for DNS Server check box and click Next.
95
Windows Server 2008 - System Administration
17. On Directory Services Restore Mode Administrator Password page, enter the
password and confirm password and click Next.
18. On Summary page, review the Options you selected and Click Next.
96
Windows Server 2008 - System Administration
20. After the Active Directory Installation wizard is completed, then click FINISH.
97
Windows Server 2008 - System Administration
Pre-requisites:
SYS1
SYS4
MICROSOFT.COM
MCTS.COM
SYS1 SYS4
98
Windows Server 2008 - System Administration
99
Windows Server 2008 - System Administration
5. Welcome to the Active Directory Installation Wizard page appears, check the
box Use advanced mode installation and click Next.
100
Windows Server 2008 - System Administration
7. Select Existing Forest, Select Create a new domain in an existing forest and
check the box Create a new domain tree root instead of a new child domain,
click Next.
8. Enter the Forest Domain Name (Ex: MICROSOFT.com) and click Set.
101
Windows Server 2008 - System Administration
9. Enter Administrator, Password, Domain Name (DC Credentials) and click OK and
click Next.
10. Enter the New Domain Tree Name(Ex:MCTS.COM) and click Next.
102
Windows Server 2008 - System Administration
11. On NetBIOS Domain name page, Domain NetBIOS Name appears, click Next.
12. Select the Domain Functional Level (Windows 2000 Native) and click Next.
103
Windows Server 2008 - System Administration
14. Verify for DNS Server and Global catalog check box and click Next.
104
Windows Server 2008 - System Administration
16. On Database and log locations page, accept the default locations, click Next.
17. Select Use this specific domain controller and select SYS1.MICROSOFT.COM
click Next.
105
Windows Server 2008 - System Administration
19. On Summary page, review the Options you selected and Click Next.
106
Windows Server 2008 - System Administration
21. After the Active Directory Installation wizard is completed, click FINISH.
107
Windows Server 2008 - System Administration
Pre-requisites:
SYS1 SYS2
MICROSOFT.COM
SYS1 SYS2
108
Windows Server 2008 - System Administration
109
Windows Server 2008 - System Administration
110
Windows Server 2008 - System Administration
8. Type: Quit
111
Windows Server 2008 - System Administration
112
Windows Server 2008 - System Administration
113
Windows Server 2008 - System Administration
114
Windows Server 2008 - System Administration
115
Windows Server 2008 - System Administration
Verification:
1. Type Net accounts and Press Enter
2. Computer role of Domain Controller will be converted to Backup and Additional
Domain Controller will be converted to Primary.
116
Windows Server 2008 - System Administration
117
Windows Server 2008 - System Administration
118
Windows Server 2008 - System Administration
9. Type: Quit
119
Windows Server 2008 - System Administration
120
Windows Server 2008 - System Administration
121
Windows Server 2008 - System Administration
122
Windows Server 2008 - System Administration
123
Windows Server 2008 - System Administration
Verification:
1. Type Net accounts and Press Enter
2. Computer role of Additional Domain Controller will be converted to Primary.
124
Windows Server 2008 - System Administration
GROUP POLICIES
Pre-requisites:
SYS1 SYS2
MICROSOFT.COM
SYS1 SYS2
125
Windows Server 2008 - System Administration
126
Windows Server 2008 - System Administration
3. Enter the name for OU (Ex: Sales1) and (for lab) uncheck Protect container from
accidental deletion and click OK.
127
Windows Server 2008 - System Administration
2. Right click OU (Sales1) Create a GPO in this domain and Link it here.
3. Enter any name to GPO Link (Ex: Remove Computer Icon) and click OK.
128
Windows Server 2008 - System Administration
129
Windows Server 2008 - System Administration
Verification:
1. Logon to client system as Sales1ou user (s1) and verify the changes because of
the policy.
130
Windows Server 2008 - System Administration
2. Right click Domain name (MICROSOFT.COM) and select Create a GPO in this
domain and Link it here.
131
Windows Server 2008 - System Administration
3. Enter New GPO Link name Ex: Remove Network Icon and click OK.
4. Select the Created GPO Right Click Created GPO Select Edit.
5. In the Group Policy Management editor window, Go to User Configuration
Policies Administrative Templates Desktop
6. Select a policy (Hide Network Icon on desktop) right side of the screen, Right
Click and select Properties.
132
Windows Server 2008 - System Administration
Verification:
1. Login as User (S1) to Client or Member Server and Verify for the changes.
133
Windows Server 2008 - System Administration
Verification:
1. Login as a user to Client or Member Server, and Verify for the changes.
134
Windows Server 2008 - System Administration
2. Click Next.
135
Windows Server 2008 - System Administration
4. Select User and click Browse enter the Username (S1)click OK and Next.
136
Windows Server 2008 - System Administration
5. Select the site (Default-First-site-Name) and check skip to final page, click Next.
137
Windows Server 2008 - System Administration
2. Click Next.
138
Windows Server 2008 - System Administration
4. Check the Box Create, delete and manage user accounts and Next.
5. Click Finish.
Verification:
1. Log on to D.C as User (User1), Start Run Dsa.msc Create User in OU.
139
Windows Server 2008 - System Administration
140
Windows Server 2008 - System Administration
6. Click Desktop Open Network Open SYS1 (Server name containing shared
folder).
141
Windows Server 2008 - System Administration
142
Windows Server 2008 - System Administration
Verification:
1. Go to Member Server and login as user1.
2. Start Settings Control Panel Double click Program and Features.
3. Click Install a Program from the Network Select the Application and Install
143
Windows Server 2008 - System Administration
144
Windows Server 2008 - System Administration
7. Click Add.
8. Enter the UNC path for the Script in the shared folder
\\SYS1\Userscripts\logon.vbe and click OK Apply and OK.
Verification:
1. Go to Member Server and login as USER1 and verify for the Message.
145
Windows Server 2008 - System Administration
146
Windows Server 2008 - System Administration
147
Windows Server 2008 - System Administration
7. Select Basic Redirection, select Create a folder for each user under the root
path, click Browse select the shared folder from Network, \\SYS1\Folder
Redirection, click Apply and OK.
Verification:
148
Windows Server 2008 - System Administration
TRUST RELATIONSHIP
Pre-requisites:
SYS1 SYS2
MICROSOFT.COM IBM.COM
SYS1 SYS2
149
Windows Server 2008 - System Administration
4. Select Windows Server 2008 and click Raise click OK click OK.
150
Windows Server 2008 - System Administration
5. Right click Active Directory Domains and Trusts and Select Raise Forest
Functional Level.
6. Select Windows Server 2008 and click Raise click OK click OK.
Note: Repeat the Lab1on SYS2 (IBM.COM – Domain Controller) and Raise
Domain and Forest Functional Levels.
151
Windows Server 2008 - System Administration
152
Windows Server 2008 - System Administration
4. In Trust Name, enter name of other Forest IBM.COM and click Next.
153
Windows Server 2008 - System Administration
7. Select Both this domain and the specified domain and click Next.
154
Windows Server 2008 - System Administration
10. Select Forest-wide authentication for Specified Forest and click Next.
155
Windows Server 2008 - System Administration
13. Select Yes, confirm the outgoing trust and click Next.
14. Select Yes, confirm the incoming trust and click Next.
156
Windows Server 2008 - System Administration
Verification:
1. Try to Logon on to MICROSOFT.COM domain computers or IBM.COM domain
computers as other Domain Users.
Note: By default Users cannot log on to D.C.
1. Log in as MICROSOFT Administrator to MICROSOFT.COM D.C and allow IBM users
to log on to D.C using Domain Controller Security Policy in Group Policy
Management.(Allow Logon Locally Policy)
2. Similarly allow MICROSOFT.COM users to log on to IBM.COM D.C using Domain
Controller Security Policy of IBM.COM D.C.
157
Windows Server 2008 - System Administration
SYS1 SYS2
MICROSOFT.COM
SYS1 SYS2
158
Windows Server 2008 - System Administration
159
Windows Server 2008 - System Administration
160
Windows Server 2008 - System Administration
3. Enter the site name (USA) and select DEFAULT IP SITE LINK and click OK.
161
Windows Server 2008 - System Administration
162
Windows Server 2008 - System Administration
2. Enter the name (INDIA-USA Link), select INDIA and USA sites and click Add
click OK.
163
Windows Server 2008 - System Administration
164
Windows Server 2008 - System Administration
2. Raise Domain and Forest Functional Levels to Windows Server 2003 or 2008.
165
Windows Server 2008 - System Administration
6. Check the box Use advanced mode installation and click Next.
166
Windows Server 2008 - System Administration
167
Windows Server 2008 - System Administration
10. Select the Site (INDIA) for the Read-only Domain Controllers and click Next.
11. Verify the DNS, Global Catalog and Read-only Domain Controller (RODC)
checkboxes and click Next.
168
Windows Server 2008 - System Administration
13. Enter the User name (User1) and click OK and click Next.
169
Windows Server 2008 - System Administration
170
Windows Server 2008 - System Administration
17. To cache the user account password on RODC, Select the Users(User1, User2,
User3, User4, User5) Right click and select Add to a Group.
18. Enter the Group Name Allowed RODC Password Replication Group and click OK.
171
Windows Server 2008 - System Administration
172
Windows Server 2008 - System Administration
5. Welcome to the Active Directory Installation Wizard page appears, click Next.
173
Windows Server 2008 - System Administration
7. Select Existing forest and select Add a Domain Controller to an existing domain”
and click Next.
8. Enter the Forest Domain Name (Ex: MICROSOFT.com) and click Set.
9. Enter User1 and Password (User Credentials) and click OK, click Next.
174
Windows Server 2008 - System Administration
11. A warning appears indicating that the user account specified is not a member of
Administrators group, the installation may fail with an access denied error, click
YES. (Because the user account is having the permission to Install RODC.)
175
Windows Server 2008 - System Administration
13. On Database and log locations page, accept the default locations and click Next.
176
Windows Server 2008 - System Administration
15. On Summary page, review the Options you selected, and click Next.
16. After the Active Directory Installation wizard is completed, then click FINISH.
177
Windows Server 2008 - System Administration
Verification:
178