DESKTOP

Outlining AD DS Changes in Windows Server 2012 (part 2) : Restarting AD DS on a Domain Controller, Implementing Multiple Password Policies per Domain

10/11/2013 7:26:31 PM

4. Restarting AD DS on a Domain Controller

Windows Server 2008 originally introduced new capabilities to start or stop directory services running on a DC without having to shut it down. This enables administrators to perform maintenance or recovery on the Active Directory database without having to reboot into Directory Services Restore Mode. This feature is also present in Windows Server 2012 DCs.

In addition to allowing for maintenance and recovery, turning off the DC functionality on an AD DC essentially turns that DC into a member server, allowing for a server to be quickly brought out of DC mode if necessary. In addition, with RODCs, Microsoft has removed the need for local administrators on the DC to have Domain Admin rights as well, which improves overall security in places where administration of the DC server is required but full Domain Admin rights are not needed.

To take a Windows Server 2012 DC offline, follow these steps:

1. Open up the Services MMC (Start, All Programs, Administrative Tools, Services).

2. From the Services MMC, select the Active Directory Domain Services service, as shown in Figure 3. Right-click it and choose Stop.

Image

Figure 3.. Restarting AD DS on a Domain Controller

3. When prompted that stopping AD DS will stop other associated services such as DNS, DFS, Kerberos, and Intersite Messaging, choose Yes to continue.

4. To restart AD DS, right-click the AD DS service and choose Start.

5. Implementing Multiple Password Policies per Domain

Another Windows Server 2008 addition to AD DS is the ability to implement granular password policies across a single domain. Previously, this was only an option with third-party password-change utilities installed on the DCs in a forest. With Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012, administrators can define which users have more complex password policies and which will be able to use more lenient policies.

You need to understand a few key points about this technology before implementing it, as follows:

• Domain mode must be set to Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012 level.

• Fine-grained password policies always win over a domain password policy.

• Password policies can be applied to groups, but they must be global security groups.

• Fine-grained password policies applied to a user always win over settings applied to a group.

• The Password Settings objects (PSOs) are stored in the Password Settings Container in AD (that is, CN=Password Settings Container,CN=System,DC=companyabc,DC=com).

• Only one set of password policies can apply to a user. If multiple password policies are applied, the policy with the lower-number precedence wins.

To create a custom password policy for a specific user, a PSO must be created using ADAC, an improvement over Windows Server 2008 and Windows Server 2008 R2, which required creation of the PSOs using ADSIEdit.

To create a new PSO, open ADAC and follow these steps:

1. Navigate to domain root - System - Passwords Settings Container.

2. Under Tasks, select New - Password Settings.

3. Enter the information into the dialog box, shown in Figure 4, using Table 1 as a reference.

Image

Figure 4.. Creating a PSO.

Table 1. PSO Attributes

Image
Image

4. Click OK to finalize the creation of the PSO.

Other  
  •  Windows Server 2012 : Understanding AD DS Replication, Outlining the Role of DNS in AD DS
  •  Settings Breakdown for Windows Server 2008 and Windows Vista : Policies (part 6) - Administrative Templates
  •  Settings Breakdown for Windows Server 2008 and Windows Vista : Policies (part 5) - Security Settings - Public Key Policies, Software Restriction Policies
  •  Settings Breakdown for Windows Server 2008 and Windows Vista : Policies (part 4) - Security Settings - Wired Network, Windows Firewall with Advanced Security
  •  Settings Breakdown for Windows Server 2008 and Windows Vista : Policies (part 3) - Security Settings - Restricted Groups, System Services, Registry
  •  Settings Breakdown for Windows Server 2008 and Windows Vista : Policies (part 2) - Security Settings - Account Policies, Local Policies
  •  Settings Breakdown for Windows Server 2008 and Windows Vista : Policies (part 1) - Software Settings
  •  Windows 8 : Managing Application Virtualization and Run Levels (part 2) - Setting Run Levels, Optimizing Virtualization and Installation Prompting for Elevation
  •  Windows 8 : Managing Application Virtualization and Run Levels (part 1) - Application Access Tokens and Location Virtualization, Application Integrity and Run Levels
  •  Windows 8 : Installing and Maintaining Applications - Managing Desktop Apps
  •  
    Top 10
    Extending LINQ to Objects : Writing a Single Element Operator (part 2) - Building the RandomElement Operator
    Extending LINQ to Objects : Writing a Single Element Operator (part 1) - Building Our Own Last Operator
    3 Tips for Maintaining Your Cell Phone Battery (part 2) - Discharge Smart, Use Smart
    3 Tips for Maintaining Your Cell Phone Battery (part 1) - Charge Smart
    OPEL MERIVA : Making a grand entrance
    FORD MONDEO 2.0 ECOBOOST : Modern Mondeo
    BMW 650i COUPE : Sexy retooling of BMW's 6-series
    BMW 120d; M135i - Finely tuned
    PHP Tutorials : Storing Images in MySQL with PHP (part 2) - Creating the HTML, Inserting the Image into MySQL
    PHP Tutorials : Storing Images in MySQL with PHP (part 1) - Why store binary files in MySQL using PHP?
    REVIEW
    - First look: Apple Watch

    - 3 Tips for Maintaining Your Cell Phone Battery (part 1)

    - 3 Tips for Maintaining Your Cell Phone Battery (part 2)
    VIDEO TUTORIAL
    - How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 1)

    - How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 2)

    - How to create your first Swimlane Diagram or Cross-Functional Flowchart Diagram by using Microsoft Visio 2010 (Part 3)
    Popular Tags
    Microsoft Access Microsoft Excel Microsoft OneNote Microsoft PowerPoint Microsoft Project Microsoft Visio Microsoft Word Active Directory Biztalk Exchange Server Microsoft LynC Server Microsoft Dynamic Sharepoint Sql Server Windows Server 2008 Windows Server 2012 Windows 7 Windows 8 Adobe Indesign Adobe Flash Professional Dreamweaver Adobe Illustrator Adobe After Effects Adobe Photoshop Adobe Fireworks Adobe Flash Catalyst Corel Painter X CorelDRAW X5 CorelDraw 10 QuarkXPress 8 windows Phone 7 windows Phone 8 BlackBerry Android Ipad Iphone iOS