Introduction to Windows Server 2019 - Active Directory and GPOs (Notes)

0.0(0)
studied byStudied by 0 people
full-widthCall with Kai
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/57

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering key AD DS, forest/domain, replication, FSMO roles, and Group Policy concepts from the notes.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

58 Terms

1
New cards

Active Directory Domain Services (AD DS)

The principal security engine of Windows Server responsible for authentication of users/devices and the infrastructure for identity, access control, and resource permissions.

2
New cards

Identity

A representation of each user, device, application, or service; a set of data that uniquely describes an object.

3
New cards

Authentication

The process of verifying the identity of a user, computer, group, device, service, or process.

4
New cards

Authorization

The process of granting or validating permissions for a service, application, or subject after authentication.

5
New cards

Stand-Alone Authentication (Workgroup)

A local configuration where each computer maintains its own trusted identities in a SAM database.

6
New cards

Security Accounts Manager (SAM)

The local credential store that holds users and groups for stand-alone Windows systems.

7
New cards

Join a Domain

The process by which a computer authenticates to an AD DS domain, often using a domain account for sign-in.

8
New cards

AD DS Objects

Entities in AD DS such as users, groups, and computers that are stored in the directory.

9
New cards

User Object

An AD DS object representing a user, with sign-in credentials and attributes describing the user.

10
New cards

Group Object

An AD DS object representing a collection of users or computers used to simplify permissions and administration.

11
New cards

Group Types

Two types of groups in AD DS: Security Groups and Distribution Groups.

12
New cards

Security Groups

Groups used to grant permissions and access control to resources.

13
New cards

Distribution Groups

Groups used for mail distribution; not typically used for access control.

14
New cards

Group Scopes

Defines the range of a group's permissions and membership within AD DS.

15
New cards

Local

A group scope limited to the local computer.

16
New cards

Domain-local

A group scope that applies permissions within a single domain.

17
New cards

Global

A group scope whose members come from one domain and can be used to grant permissions within the same domain (and across trusted domains when appropriate).

18
New cards

Universal

A group scope whose membership can include users from any domain in the forest and can grant access across domains.

19
New cards

Computer Object

An AD DS object that represents a computer, used to manage the computer’s access to resources.

20
New cards

Computers Container

The default container in which computers reside when joined to a domain.

21
New cards

Organizational Unit (OU)

A container within a domain used to group objects and link GPOs; supports delegation and administrative delegation.

22
New cards

AD Built-In Containers

Default containers in AD DS (e.g., Domain, Computers, Users, Domain Controllers, Built-in) used for object storage and permissions.

23
New cards

Forest

A logical container that groups one or more domains and stores authentication and directory data across the forest.

24
New cards

Domain

A group of computers within a forest that shares common policies and authentication boundaries.

25
New cards

Domain Controllers

Servers that host AD DS data (NTDS.dit) and SYSVOL; run Kerberos/KDC services for authentication.

26
New cards

Kerberos

Authentication protocol used by AD DS to provide ticket-based authentication within the domain.

27
New cards

Key Distribution Center (KDC)

A component of Kerberos that issues tickets to clients for access to services.

28
New cards

Global Catalog

A partial, read-only replica of the forest’s directory used to speed cross-domain searches.

29
New cards

Schema

Defines all object classes and attributes that AD DS uses to store data; replicated across the forest.

30
New cards

Schema Master

FSMO role holder responsible for schema updates; changes replicate to other domain controllers.

31
New cards

Domain Naming Master

FSMO role holder responsible for adding/removing domains in a forest.

32
New cards

RID Master

FSMO role holder that allocates security identifiers (SIDs) to new objects.

33
New cards

Infrastructure Master

FSMO role holder that updates cross-domain object references and group memberships.

34
New cards

PDC Emulator

FSMO role holder providing NT4 backward compatibility, time synchronization, and password management.

35
New cards

FSMO

Flexible Single Master Operations; set of single-master roles in AD DS (Schema Master, Domain Naming Master, RID Master, Infrastructure Master, PDC Emulator).

36
New cards

Transfers

Moving an FSMO role from one Domain Controller to another when planned.

37
New cards

Seizure

Taking ownership of an FSMO role when the current holder cannot be reached.

38
New cards

AD DS Replication

Multi-master replication of AD DS data so changes propagate to all domain controllers.

39
New cards

Partitions

Logical divisions of AD DS data used for efficient replication and organization.

40
New cards

Domain Partition

Partition that holds domain data; replicated within the domain.

41
New cards

Schema Partition

Partition that holds schema-related data; replicated to all domain controllers in the forest.

42
New cards

Configuration Partition

Partition that stores topology and replication information.

43
New cards

Application Directory Partition

Partition used by applications to store directory data; not used for standard user objects.

44
New cards

Sign-in Process

Computer authenticates with AD DS during startup by locating a domain controller via DNS and LSA handles the authentication.

45
New cards

DNS lookup

DNS query used to locate domain controllers for authentication and sign-in.

46
New cards

Local Security Authority (LSA)

Component on the domain controller that manages the actual authentication process.

47
New cards

Group Policy Object (GPO)

A container for policy settings applied to users and computers within AD DS.

48
New cards

GPO Storage: GPC and GPT

GPO data stored in Group Policy Container (GPC) metadata and Group Policy Template (GPT) settings.

49
New cards

GPC

Group Policy Container; stores GPO metadata in AD DS.

50
New cards

GPT

Group Policy Template; stores the actual policy settings (registry-based).

51
New cards

GPO Scope and Inheritance

Defines which users/computers a GPO applies to and how policies flow through OUs.

52
New cards

Domain-Based Group Policies

GPOs created in AD DS and linked to domains or OUs for domain-wide management.

53
New cards

Local GPO

Group Policy stored on a local computer, not in AD DS.

54
New cards

Default Domain Policy

Default GPO created with AD DS for domain-wide settings.

55
New cards

Default Domain Controllers Policy

Default GPO created for Domain Controllers to apply specific settings.

56
New cards

Administrative Templates

Policy settings stored in AD DS that modify registry keys; include User-related and Computer-related templates.

57
New cards

User-related settings

Administrative template settings that apply to users.

58
New cards

Computer-related settings

Administrative template settings that apply to computers.

Explore top flashcards

latin vocab stage 40
Updated 999d ago
flashcards Flashcards (22)
Synonyms
Updated 45d ago
flashcards Flashcards (206)
DECA58
Updated 395d ago
flashcards Flashcards (58)
all of bio (Q)
Updated 1030d ago
flashcards Flashcards (463)
Urinate Sis! Pt 1
Updated 156d ago
flashcards Flashcards (23)
latin vocab stage 40
Updated 999d ago
flashcards Flashcards (22)
Synonyms
Updated 45d ago
flashcards Flashcards (206)
DECA58
Updated 395d ago
flashcards Flashcards (58)
all of bio (Q)
Updated 1030d ago
flashcards Flashcards (463)
Urinate Sis! Pt 1
Updated 156d ago
flashcards Flashcards (23)