Active Directory: Procedures
Active Directory: Procedures
Procedures
Change Management Process
Account Management (create, disable, delete actions)
Creating and Deploying GPOs
Group Management
Patch Management
Change Initiation
Change that can impact Active Directory and its community can be initiated by three different
groups and with expected impacts that range from significant to limited (or none).
Stakeholders
General Guidelines
Change Management requires uniform processes no matter which group initiates a change. The
process will differ based on urgency and expected impact, but not by the group that initiates the
change. CCM will be enforced at the root level of the domain or when an action requires
Domain Admin privileges.
When approval or advice is required, the announcement must indicate what changes will be
made, why the changes are being made, potential impact to IT staff and end users, and how much
time the changes are expected to take.
Notification requires a very short one or two sentence description (maintenance on domain
controllers will take place at X for period of Y hours). Notification is not needed for planned
outages published on the Web site (normal weekend maintenance for example).
In the event that a change takes longer than expected, the AD-Notify mail list must be
immediately notified with the new completion time
Workstation Info
1. Workstations in the LBL forest should be configured to turn off DDNS registration. This
may be enforced by a domain GPO in the future and should not be blocked at the OUs
2. LBL naming standards are recommended for computer account names. The standard is to
combine the UID of the primary person using the machine, followed by a dash, followed
by a workstation operating system identifier, and finally the last two digits of the DOE
number. The workstation identifiers are x for Windows XP, w for Windows 2000, and n
for Windows NT 4. e.g. cwnelson-x44 or cwnelson-w39
3. It is recommended that you wait 30 minutes after creating and deleting a computer
account before attempting to create a new computer account with the same name
Top
Group Management
Best Practices
Try to use global groups to organize the users in your OUs into groups
Try to use domain local groups to assign permissions to resources
CCM
More words on when CCM takes effect and when it does not?
These rules apply to all changes to the Domain Controllers (DCs) in the LBL domain, including
but not limited to the registry, file system permissions, network settings, security settings, virus
definition updates, patching, directory services changes, group policy settings, etc. However,
good judgment must be used in order to identify which CCM category the specific changes apply
to.
Top
Overview
The IT division manages an institutional Windows Server Update Service (WSUS). The purpose
of the WSUS server is to facilitate patching of Windows computers in the LBNL environment.
Participation in the WSUS server is optional, but widely deployed and the default for computers
in AD.
The overarching philosophy is to replicate the patches Microsoft delivers via the LBNL WSUS
server (E.g., security patches, office patches, and non-critical patches). The WSUS service adds
the ability to monitor and verify the patch status as well as stop the deployment of a problem
patch.
Patch Approval
Patch approval is done by a collaborative team (WSUS team) from IT User Support, IT
Infrastructure, and CPP. This team meets monthly on the second Tuesday of the month (e.g.
Microsoft Patch Tuesday) to release patches. IT User support management is responsible for
approving patches but delegates this authority to the WSUS team.
The WSUS team first reviews the patches to identify any high priority patches that may require
CPP to scan and isolate. The team then briefly reviews the function of each patch and releases
them to all clients. The team also performs a brief review of WSUS to ensure patches are
applying correctly. The team also runs the Cleanup Wizard to remove outdated patches and
computers that have not contacted WSUS in more than 30 days. The patch approval process
takes less than 30 minutes per month.
Patch Problems
The WSUS team releases all WSUS patches at the same time as Microsoft. The WSUS team
will unapprove a patch in the event the patch is creating significant disruption or causing
significant problems in the LBNL environment. Unapproval is reserved for when a patch causes
problems in the LBNL environment. We specifically try to avoid unapproval based upon
Internet discussions alone. IT User support (Charlie Verboom) is responsible for decide when
patches are unapproved.
IT-WSUS3
This is the GPO recommended for most systems. This GPO will configure WSUS to download
the patches and install them at 10:00AM. If anyone is logged into the system, they will be
prompted to reboot every hour, but never forcible rebooted. If no one is logged into the
computer, it will reboot.
IT-WSUS3-NotifyOnly
This is the GPO recommended for servers and instrumentation computers. A person must do
installation and reboot; the WSUS policy only prompts for download and reboot. This GPO
simply tracks the patch status.