Creating and Managing Active Directory Groups and Organizational Units (Ous)
Creating and Managing Active Directory Groups and Organizational Units (Ous)
LAB 3
CREATING AND
MANAGING ACTIVE
DIRECTORY GROUPS
AND ORGANIZATIONAL
UNITS (OUS)
Table 3-1
Computers required for Lab 3
Computer Operating System Computer Name
Server (VM 1) Windows Server 2016 LON-DC1
In addition to the computers, you will also require the software listed in Table 3-2 to
complete Lab 3.
Table 3-2
Software required for Lab 3
Software Location
Lab 3 student worksheet Lab03_worksheet.docx (provided by instructor)
SCENARIO
2. On the LON-DC1 computer, using Server Manager, click Tools > Active Directory
Users and Computers. The Active Directory Users and Computers console appears.
3. In the left pane, right-click the Adatum.com node and choose New > Organizational
Unit.
4. In the New Object – Organizational Unit Wizard, in the Name text box, type
Engineering, as shown in Figure 3-1.
Figure 3-1
The New Object – Organizational Unit Wizard
5. Click OK.
7. In the Active Directory Administrative Center console, in the left pane, select the
Adatum (local) node. Then in the Tasks pane, under Adatum (local) section, select New
> Organizational Unit.
70-742 Identity with Windows Server 2016
8. In the Create Organizational Unit dialog box (see Figure 3-2), in the Name text box, type
Projects and then click OK.
Figure 3-2
The Create Organizational Unit dialog box
9. Click the Start button and then click the Windows PowerShell tile.
10. In the Administrator: Windows PowerShell window, at the command prompt, type New-
ADOrganizationalUnit –Name HR and press Enter.
11. In the Active Directory Users and Computers console, press F5 to refresh list of
organizational units.
12. Take a screen shot of the adatum.com domain in the Active Directory Users and
Computers console, showing the OU objects you created, by pressing Alt+PrtScr, and
then paste the resulting image into the Lab03_worksheet file in the page provided by
pressing Ctrl+V.
70-742 Identity with Windows Server 2016
13. Right-click the Projects OU, and click Delete. When you are prompted to confirm this
action, click Yes.
15. In the Sales OU, double-click the Abbie Parsons user account.
18. Take a screen shot of the adatum.com domain in the Active Directory Users and
Computers console by pressing Alt+PrtScr, and then paste the resulting image into the
Lab03_worksheet file in the page provided by pressing Ctrl+V.
70-742 Identity with Windows Server 2016
19. In the Sales OU, double-click the Abbie Parsons user account.
21. Close the Abbie Parsons Properties dialog box by clicking OK.
24. Deselect the Protect object from accidental deletion option and then click OK.
25. Right-click the Projects organizational unit and choose Delete. When you are asked
prompted to confirm this action, click Yes.
70-742 Identity with Windows Server 2016
26. In the Sales OU, right-click Abbie Parsons and choose Move.
27. In the Move dialog box, click HR and then click OK.
29. Take a screen shot of the HR OU in the Active Directory Users and Computers console
by pressing Alt+PrtScr, and then paste the resulting image into the Lab03_worksheet file
in the page provided by pressing Ctrl+V.
30. Right-click the Abbie Parsons user account and then click Move.
31. In the Move dialog box, select Sales and then click OK.
Mindset Since the early days of the Microsoft Server operating system,
administrators used groups to manage network permissions. Groups
enable you to assign permissions to multiple users simultaneously. A
group can be defined as a list of user or computer accounts that
functions as a security principal, in much the same way that a user
70-742 Identity with Windows Server 2016
does.
Completion time 30 minutes
1. On LON-DC1, in the Active Directory Users and Computers console, select the HR OU
you created in Exercise 3.1.
2. Right-click the HR OU and choose click New > Group. The New Object - Group
dialog box appears (see Figure 3-3).
Figure 3-3
The New Object – Group Wizard
4. Under Group scope, select the Domain local option. Answer the following question and
then click OK. The new group object appears in the HR OU.
5. Take a screen shot of the HR OU in the Active Directory Users and Computers console
by pressing Alt+PrtScr and then paste the resulting image into the Lab03_worksheet
file in the page provided by pressing Ctrl+V.
6. If Active Directory Administrative Center is not open, using Server Manager, click
Tools > Active Directory Administrative Center.
7. In the Active Directory Administrative Center console, click the Adatum (local) node in
the left pane and, in the center pane, double-click the HR OU.
8. In the Tasks right pane, in the HR section, click New > Group. The Create Group
dialog box appears, as shown in Figure 3-4.
70-742 Identity with Windows Server 2016
Figure 3-4
Adding a group in Active Directory Administrative Center
10. Under Group scope, select Domain local, answer the following question, and then click
OK. The new group appears in the HR OU.
11. In Active Directory Users and Computers, with the HR OU highlighted, in the center
tab, click the white space/blank space of the HR OU and then press F5.
12. Take a screen shot of the HR OU in the Active Directory Users and Computers console
by pressing Alt+PrtScr and then paste the resulting image into the Lab03_worksheet
file in the page provided by pressing Ctrl+V.
70-742 Identity with Windows Server 2016
16. In the Select Users, Contacts, Computers, Service Accounts, or Groups dialog box, in
the Enter the object names to select text box, type Adam Hobbs and click OK.
20. In the Beth Burke Properties dialog box, click Member Of.
22. In the Select Groups dialog box, in the Enter the object names to select, type HR
Printing and then click OK.
23. Close the Beth Burke Properties dialog box by clicking OK.
24. Go to the HR OU and double-click HR Printing. Then click the Members tab.
70-742 Identity with Windows Server 2016
25. Take a screen shot of the HR Printing Properties dialog box in the Active Directory
Users and Computers console by pressing Alt+PrtScr and then paste the resulting
image into the Lab03_worksheet file in the page provided by pressing Ctrl+V.
30. In the Select Users, Contacts, Computers, Service Accounts, or Groups dialog box, in
the Enter the object names to select text box, type HR Printing and then click OK.
31. In the Members section, double-click HR Printing and then click the Members tab.
33. Close the Backup Manager Properties dialog box by clicking OK.
1. On LON-DC1, in the Active Directory Users and Computers console, right-click the
HR OU and choose Delegate Control.
4. In the Select Users, Computers, or Groups dialog box, in the Enter the object names to
select box, type Backup Manager and click OK. Then click Next. The Tasks to
delegate page appears, as shown in Figure 3-5.
70-742 Identity with Windows Server 2016
Figure 3-5
The Delegation of Control Wizard
5. In the Delegate the following common tasks list, select the following check boxes and
then click Next:
6. The Completing the Delegation of Control Wizard page appears. Scroll to the bottom.
7. Take a screen shot of the Delegation of Control Wizard by pressing Alt+PrtScr and
then paste the resulting image into the Lab03_worksheet file in the page provided by
pressing Ctrl+V.
8. Click Finish.
70-742 Identity with Windows Server 2016
11. In the HR Properties dialog box, in the Group or user names section, scroll down and
click Backup Manager.
13. Take a screen shot of the Advanced Security Settings for HR dialog box by pressing
Alt+PrtScr and then paste the resulting image into the Lab03_worksheet file in the page
provided by pressing Ctrl+V.
70-742 Identity with Windows Server 2016
14. Close the Advanced Security Settings for HR dialog box by clicking OK.
End of lab.