Introduction |
|
xvii | |
|
|
1 | (78) |
|
|
2 | (1) |
|
Assessing the Technical Environment |
|
|
2 | (1) |
|
|
3 | (31) |
|
Components Used in the Logical Design of Active Directory |
|
|
3 | (6) |
|
|
9 | (3) |
|
|
12 | (3) |
|
Formulating New Candidate Models |
|
|
15 | (1) |
|
|
16 | (1) |
|
Identifying Existing Service Levels |
|
|
17 | (3) |
|
Identifying Service Levels Requiring Change |
|
|
20 | (1) |
|
Hardware and Software Deployments |
|
|
21 | (1) |
|
Performing a Hardware Inventory |
|
|
21 | (1) |
|
Analyzing Hardware Requirements |
|
|
22 | (2) |
|
Performing a Software Inventory |
|
|
24 | (1) |
|
Analyzing Software Requirements |
|
|
25 | (1) |
|
|
26 | (1) |
|
Identifying Current Interoperability Instances |
|
|
26 | (7) |
|
Assessing Additional Active Directory Interoperability Requirements |
|
|
33 | (1) |
|
Assessing the Current Server Infrastructure |
|
|
34 | (14) |
|
|
34 | (1) |
|
Identifying Existing Windows Domain Installations |
|
|
34 | (2) |
|
Identifying the Current Domain Models |
|
|
36 | (5) |
|
Comparing Models with Your Envisaged Design |
|
|
41 | (4) |
|
|
45 | (2) |
|
Documenting Existing Infrastructure Locations |
|
|
47 | (1) |
|
|
48 | (1) |
|
|
48 | (10) |
|
Analyzing the Existing Namespaces |
|
|
50 | (1) |
|
Documenting All Namespaces |
|
|
51 | (1) |
|
Identifying and Providing Remediation for Potential Issues |
|
|
52 | (2) |
|
Assessing the DNS Infrastructure |
|
|
54 | (1) |
|
Document DNS Server Locations |
|
|
54 | (1) |
|
Analyzing Zone Configuration and Transfers |
|
|
55 | (1) |
|
Identifying Supportability for Active Directory |
|
|
56 | (1) |
|
Assessing BIND Implementations |
|
|
57 | (1) |
|
Identifying Non-Supported Aspects |
|
|
57 | (1) |
|
Assessing the Physical Network |
|
|
58 | (7) |
|
|
58 | (1) |
|
Developing Tools and Methods to Interrogate the Network |
|
|
59 | (1) |
|
Collating Routes, Links, and Bandwidths |
|
|
60 | (1) |
|
|
60 | (1) |
|
|
61 | (1) |
|
Documenting Site and Subnet Boundaries |
|
|
61 | (1) |
|
Drawing the Routes, Links, and Bandwidths Map |
|
|
62 | (1) |
|
Analyzing Network Performance |
|
|
63 | (1) |
|
Documenting Current Baselines |
|
|
63 | (1) |
|
Identifying Issues and Constraints |
|
|
64 | (1) |
|
Assessing the Impact of Proposed Designs |
|
|
65 | (5) |
|
Looking at the Existing Infrastructure |
|
|
65 | (1) |
|
|
65 | (1) |
|
|
66 | (1) |
|
|
66 | (1) |
|
Determining Interoperability |
|
|
66 | (1) |
|
Other Network Operating Systems |
|
|
66 | (1) |
|
|
67 | (1) |
|
Examining the Physical Network |
|
|
68 | (1) |
|
|
68 | (1) |
|
|
69 | (1) |
|
Summary of Exam Objectives |
|
|
70 | (1) |
|
Exam Objectives Fast Track |
|
|
71 | (2) |
|
Exam Objectives Frequently Asked Questions |
|
|
73 | (1) |
|
|
74 | (3) |
|
SelfTest Quick Answer Key |
|
|
77 | (2) |
|
Developing the Active Directory Infrastructure Design |
|
|
79 | (76) |
|
|
80 | (1) |
|
Assessing and Designing the Administrative Model |
|
|
80 | (6) |
|
Service Administrators and Data Administrators |
|
|
81 | (1) |
|
The Role of the Service Administrator |
|
|
82 | (1) |
|
The Role of the Data Administrator |
|
|
82 | (1) |
|
Understanding Isolation and Autonomy |
|
|
83 | (1) |
|
|
84 | (1) |
|
|
85 | (1) |
|
Assessing and Defining the Forest Design |
|
|
86 | (15) |
|
|
86 | (1) |
|
|
87 | (1) |
|
|
87 | (1) |
|
|
88 | (1) |
|
|
88 | (1) |
|
|
89 | (1) |
|
|
89 | (1) |
|
|
89 | (1) |
|
Externally Facing Environments |
|
|
90 | (1) |
|
|
90 | (1) |
|
The Service Provider Model |
|
|
91 | (1) |
|
The Restricted Access Model |
|
|
92 | (1) |
|
|
93 | (1) |
|
|
94 | (2) |
|
|
96 | (1) |
|
|
96 | (2) |
|
Ownership, Accountability, and Change Management |
|
|
98 | (1) |
|
|
98 | (1) |
|
|
98 | (1) |
|
|
99 | (2) |
|
Assessing and Creating the Domain Design |
|
|
101 | (18) |
|
|
101 | (1) |
|
|
101 | (1) |
|
|
102 | (1) |
|
|
103 | (1) |
|
|
104 | (1) |
|
|
104 | (1) |
|
|
105 | (1) |
|
|
106 | (1) |
|
The Dedicated Root Domain |
|
|
106 | (1) |
|
Using a Dedicated Root Domain |
|
|
106 | (2) |
|
|
108 | (2) |
|
|
110 | (2) |
|
|
112 | (2) |
|
Comparing Trees with Domains |
|
|
114 | (1) |
|
|
114 | (1) |
|
|
115 | (2) |
|
|
117 | (1) |
|
Ownership and Responsibilities |
|
|
118 | (1) |
|
|
119 | (11) |
|
|
120 | (1) |
|
Delegation and Admin Models |
|
|
120 | (2) |
|
|
122 | (2) |
|
|
124 | (2) |
|
|
126 | (1) |
|
|
126 | (1) |
|
|
127 | (1) |
|
|
128 | (2) |
|
|
130 | (1) |
|
Developing the Replication Design |
|
|
130 | (17) |
|
|
131 | (1) |
|
|
131 | (1) |
|
|
132 | (1) |
|
|
132 | (1) |
|
|
132 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
134 | (1) |
|
|
134 | (1) |
|
|
135 | (1) |
|
Automatic Connection Objects |
|
|
135 | (1) |
|
Manual Connection Objects |
|
|
136 | (1) |
|
|
136 | (1) |
|
Knowledge Consistency Checker (KCC) |
|
|
137 | (1) |
|
Inter Site Topology Generator and Bridgehead Servers |
|
|
138 | (2) |
|
|
140 | (1) |
|
File Replication System (FRS) |
|
|
141 | (1) |
|
|
141 | (1) |
|
|
141 | (1) |
|
|
141 | (1) |
|
|
142 | (1) |
|
|
143 | (1) |
|
|
143 | (1) |
|
|
144 | (1) |
|
|
145 | (2) |
|
Summary of Exam Objectives |
|
|
147 | (1) |
|
Exam Objectives Fast Track |
|
|
147 | (2) |
|
Exam Objectives Frequently Asked Questions |
|
|
149 | (1) |
|
|
150 | (4) |
|
SelfTest Quick Answer Key |
|
|
154 | (1) |
|
Developing the Network Services Design |
|
|
155 | (62) |
|
|
156 | (1) |
|
Developing the Network Services Infrastructure Designs |
|
|
156 | (51) |
|
|
157 | (2) |
|
|
159 | (8) |
|
|
167 | (16) |
|
|
183 | (1) |
|
|
184 | (3) |
|
|
187 | (1) |
|
|
188 | (1) |
|
|
189 | (1) |
|
|
189 | (2) |
|
|
191 | (4) |
|
|
195 | (5) |
|
Integration with Existing Deployments |
|
|
200 | (1) |
|
Developing Remote Access Strategy |
|
|
200 | (1) |
|
|
201 | (2) |
|
Integrating with Existing Deployments |
|
|
203 | (4) |
|
Summary of Exam Objectives |
|
|
207 | (1) |
|
Exam Objectives Fast Track |
|
|
208 | (1) |
|
Exam Objectives Frequently Asked Questions |
|
|
209 | (1) |
|
|
210 | (6) |
|
SelfTest Quick Answer Key |
|
|
216 | (1) |
|
Designing the Logical Components |
|
|
217 | (100) |
|
|
218 | (1) |
|
|
218 | (10) |
|
|
219 | (1) |
|
|
219 | (1) |
|
|
219 | (1) |
|
Understanding the Scope of the Standards |
|
|
220 | (1) |
|
|
221 | (1) |
|
|
222 | (1) |
|
|
222 | (1) |
|
What Should You Standardize? |
|
|
222 | (1) |
|
|
223 | (1) |
|
|
224 | (1) |
|
|
225 | (2) |
|
|
227 | (1) |
|
Defining the Forest Structure, Hierarchy, and Naming Strategy |
|
|
228 | (15) |
|
|
228 | (1) |
|
|
229 | (2) |
|
|
231 | (1) |
|
Internal versus External Names |
|
|
232 | (1) |
|
|
233 | (4) |
|
|
237 | (1) |
|
|
238 | (1) |
|
Assessing and Defining a Migration Path |
|
|
238 | (1) |
|
|
238 | (3) |
|
|
241 | (1) |
|
Migrating to Pristine Environment |
|
|
242 | (1) |
|
Defining Authentication Mechanisms |
|
|
243 | (11) |
|
|
243 | (1) |
|
|
243 | (1) |
|
|
244 | (5) |
|
|
249 | (1) |
|
|
250 | (3) |
|
|
253 | (1) |
|
|
253 | (1) |
|
Designing the Organizational Unit Model |
|
|
254 | (9) |
|
|
255 | (1) |
|
|
255 | (1) |
|
|
256 | (1) |
|
Delegating by Object Type |
|
|
256 | (1) |
|
|
257 | (1) |
|
|
258 | (1) |
|
|
258 | (1) |
|
|
259 | (3) |
|
|
262 | (1) |
|
Defining the Group Policy Object Approach |
|
|
263 | (16) |
|
|
263 | (2) |
|
|
265 | (1) |
|
What Do We Hope to Achieve? |
|
|
266 | (1) |
|
How Many and Where Applied? |
|
|
266 | (1) |
|
Delegating the Group Policy |
|
|
267 | (1) |
|
|
268 | (1) |
|
|
269 | (4) |
|
Mandatory Policy Settings |
|
|
273 | (1) |
|
|
274 | (2) |
|
Designing Strategies for Account Policies |
|
|
276 | (1) |
|
The Default Domain Controllers Policy |
|
|
277 | (1) |
|
|
278 | (1) |
|
|
278 | (1) |
|
|
279 | (1) |
|
Exploring Groups and Roles |
|
|
279 | (6) |
|
|
279 | (1) |
|
|
279 | (2) |
|
Administrative Access Groups |
|
|
281 | (1) |
|
|
281 | (1) |
|
|
282 | (2) |
|
Creating and Managing Roles |
|
|
284 | (1) |
|
Defining Replication Topology |
|
|
285 | (13) |
|
|
286 | (1) |
|
|
286 | (1) |
|
Identifying Active Directory Sites and Subnets |
|
|
286 | (9) |
|
Selecting a Replication Topology |
|
|
295 | (2) |
|
Creating a Replication Diagram |
|
|
297 | (1) |
|
Summary of Exam Objectives |
|
|
298 | (2) |
|
Exam Objectives Fast Track |
|
|
300 | (3) |
|
Exam Objectives Frequently Asked Questions |
|
|
303 | (4) |
|
|
307 | (8) |
|
SelfTest Quick Answer Key |
|
|
315 | (2) |
|
|
317 | (66) |
|
|
318 | (1) |
|
|
318 | (43) |
|
|
319 | (5) |
|
Active Directory Hosting the Only DNS Namespace |
|
|
324 | (2) |
|
Active Directory Hosting Its Own DNS Namespace |
|
|
326 | (1) |
|
Active Directory Within an Existing DNS Implementation |
|
|
327 | (1) |
|
|
328 | (2) |
|
|
330 | (1) |
|
|
331 | (2) |
|
Identifying DNS Record Requirements |
|
|
333 | (6) |
|
Identify Zone Requirements |
|
|
339 | (1) |
|
|
340 | (4) |
|
Active Directory Integrated versus Primary Zones |
|
|
344 | (2) |
|
Storing Zones in Application Partitions |
|
|
346 | (2) |
|
|
348 | (9) |
|
|
357 | (3) |
|
Interoperability with WINS and DHCP |
|
|
360 | (1) |
|
Understanding WINS Design |
|
|
361 | (11) |
|
|
362 | (1) |
|
Ensuring Unique NetBIOS Names |
|
|
362 | (1) |
|
WINS Topologies and Replication across the Enterprise |
|
|
363 | (1) |
|
|
364 | (1) |
|
|
364 | (1) |
|
|
364 | (4) |
|
Advanced WINS Optimization |
|
|
368 | (4) |
|
Summary of Exam Objectives |
|
|
372 | (1) |
|
Exam Objectives Fast Track |
|
|
373 | (1) |
|
Exam Objectives Frequently Asked Questions |
|
|
374 | (2) |
|
|
376 | (5) |
|
SelfTest Quick Answer Key |
|
|
381 | (2) |
|
Remote Access and Address Management |
|
|
383 | (78) |
|
|
384 | (1) |
|
Remote Access Service Servers |
|
|
384 | (46) |
|
|
386 | (1) |
|
Identifying Remote Access Users, Machines, and Locations |
|
|
386 | (1) |
|
Assessing and Defining a Remote Access Method |
|
|
387 | (4) |
|
Assessing and Defining the Authentication Requirements |
|
|
391 | (6) |
|
|
397 | (13) |
|
Active Directory Implications |
|
|
410 | (1) |
|
Defining Security Policies |
|
|
411 | (11) |
|
Identifying an Authentication and Accounting Strategy |
|
|
422 | (2) |
|
Defining the Audit Strategy |
|
|
424 | (6) |
|
IP Address Management and DHCP |
|
|
430 | (19) |
|
|
443 | (1) |
|
DHCP Security Considerations |
|
|
444 | (3) |
|
DNS Integration and Client Interoperability |
|
|
447 | (2) |
|
Summary of Exam Objectives |
|
|
449 | (1) |
|
Exam Objectives Fast Track |
|
|
449 | (2) |
|
Exam Objectives Frequently Asked Questions |
|
|
451 | (1) |
|
|
452 | (8) |
|
SelfTest Quick Answer Key |
|
|
460 | (1) |
|
Service Sizing and Placement |
|
|
461 | (68) |
|
|
462 | (1) |
|
|
462 | (16) |
|
|
463 | (1) |
|
|
464 | (3) |
|
Self--Sufficient Locations |
|
|
467 | (1) |
|
|
468 | (1) |
|
|
469 | (1) |
|
|
470 | (1) |
|
Active Directory Aware Applications |
|
|
471 | (1) |
|
|
471 | (1) |
|
|
472 | (1) |
|
Developing a Service Placement Algorithm |
|
|
472 | (5) |
|
|
477 | (1) |
|
|
478 | (42) |
|
|
478 | (1) |
|
|
479 | (6) |
|
Application Directory Partitions |
|
|
485 | (1) |
|
Domain Controller Sizing and Specification |
|
|
485 | (1) |
|
|
485 | (3) |
|
|
488 | (2) |
|
|
490 | (8) |
|
Global Catalog Server Sizing and Specification |
|
|
498 | (1) |
|
|
499 | (1) |
|
|
499 | (3) |
|
|
502 | (1) |
|
|
502 | (1) |
|
Flexible Single Master Operations Roles |
|
|
503 | (1) |
|
|
503 | (7) |
|
|
510 | (3) |
|
|
513 | (7) |
|
Summary of Exam Objectives |
|
|
520 | (1) |
|
Exam Objectives Fast Track |
|
|
521 | (1) |
|
Exam Objectives Frequently Asked Questions |
|
|
522 | (2) |
|
|
524 | (4) |
|
SelfTest Quick Answer Key |
|
|
528 | (1) |
|
|
529 | (40) |
|
|
530 | (1) |
|
|
530 | (19) |
|
|
530 | (3) |
|
|
533 | (1) |
|
Segmenting the Intranet from the Internet |
|
|
534 | (1) |
|
Network Topology Definitions |
|
|
535 | (1) |
|
|
536 | (1) |
|
|
537 | (1) |
|
|
538 | (1) |
|
Segmenting the Organization into Subnets |
|
|
539 | (1) |
|
|
539 | (6) |
|
|
545 | (2) |
|
|
547 | (2) |
|
Designing Requirements for Remote Access Infrastructures |
|
|
549 | (7) |
|
|
550 | (1) |
|
|
550 | (2) |
|
|
552 | (1) |
|
Intranet Authentication Requirements |
|
|
553 | (1) |
|
|
553 | (1) |
|
|
554 | (1) |
|
|
555 | (1) |
|
Determining Sizing and Availability of Remote Access Infrastructure |
|
|
556 | (3) |
|
Sizing Remote Access Components |
|
|
556 | (1) |
|
Placing Remote Access Components |
|
|
556 | (2) |
|
Providing Scalability, Availability, and Failover |
|
|
558 | (1) |
|
Summary of Exam Objectives |
|
|
559 | (1) |
|
Exam Objectives Fast Track |
|
|
560 | (2) |
|
Exam Objectives Frequently Asked Questions |
|
|
562 | (1) |
|
|
563 | (5) |
|
SelfTest Quick Answer Key |
|
|
568 | (1) |
|
|
569 | (62) |
|
|
570 | (5) |
|
Developing the Active Directory Infrastructure Design |
|
|
575 | (5) |
|
Developing the Network Services Design |
|
|
580 | (9) |
|
Designing the Logical Components |
|
|
589 | (11) |
|
|
600 | (6) |
|
Remote Access and Address Management |
|
|
606 | (11) |
|
Service Sizing and Placement |
|
|
617 | (6) |
|
|
623 | (8) |
Index |
|
631 | |