download.microsoft.com/documents/hk/technet... · transfer back all the fsmo roles 8. apply any...

86

Upload: others

Post on 21-Sep-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 2: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 3: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 4: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 5: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Session Objectives and Takeaways

Page 6: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Session Objectives and Takeaways

Page 7: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 8: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 9: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Active Directory Forest

Schema

Master

Infrastructure

Master

Step1:

run: ADPREP /ForestPrep

Step 2:

run: ADPREP /DomainPrep (each domain)

run: ADPREP /DomainPrep /GPPrep (each

domain)

run: ADPREP /DomainPrep /RODCPREP

(optional, depends on using RODC or not)

Step 3: Install Fresh or

Upgrade

WS 2008 R2

Domain

Controller

Page 10: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 11: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 12: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 13: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 14: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 15: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 16: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 17: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 18: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 19: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 20: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 21: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Demote the original DC gracefully and disconnect from network

Fresh install a Windows server 2008 R2 on a new hardware

Rename to the original name and join to domain

Promote to Windows server 2008 R2 DC

Transfer back all the FSMO roles

Page 22: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Demote the original DC gracefully and disconnect from network

Fresh install a Windows server 2008 R2 on a new hardware

Rename to the original name and join to domain

Promote to Windows server 2008 R2 DC

Transfer back all the FSMO roles

8. Apply any registry key / DC hardening keys that used before

Page 23: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Demote the original DC gracefully and disconnect from network

Fresh install a Windows server 2008 R2 on a new hardware

Rename to the original name and join to domain

Promote to Windows server 2008 R2 DC

Transfer back all the FSMO roles

8. Apply any registry key / DC hardening keys that used before

9. Upgrade DC one by one

Page 24: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Demote the original DC gracefully and disconnect from network

Fresh install a Windows server 2008 R2 on a new hardware

Rename to the original name and join to domain

Promote to Windows server 2008 R2 DC

Transfer back all the FSMO roles

8. Apply any registry key / DC hardening keys that used before

9. Upgrade DC one by one

10. Change domain and forest functional mode

Page 25: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Considerations

netsh

Printbrm.exe

CA backup and restore

Page 26: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

New Domain Functional Level

Page 27: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

New Forest Functional Level

Page 28: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 29: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

DES Encryption For Kerberos

Page 30: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

DES Encryption For Kerberos

Page 31: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

DES Encryption For Kerberos

Page 32: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Encryption Criteria for Kerberos

Role O.S Supported encryption level for Kerberos

DC Windows 2003 RC4 and DES

Client Windows XP DES and RC4

Resource Server Non Windows Kerberos Server DES

Page 33: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

DES Encryption is Disabled – So, what?

Role O.S Supported encryption level for

Kerberos

DC Windows 2003 RC4 and DES

Client Windows 7 AES and RC4

Resource Server Non Windows Kerberos

Server

DES

Page 34: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Authoritative Restore of the Krbtgt

Page 35: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Authoritative Restore of the Krbtgt

Page 36: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Authoritative Restore of the Krbtgt

Page 37: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Authoritative Restore of the Krbtgt

Page 38: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Invalid FSMO Role Holder

Page 39: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Invalid FSMO Role Holder

Page 40: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Invalid FSMO Role Holder

Page 41: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Invalid FSMO Role Holder

Page 42: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

LDAP Query Policy Hard Limits

Page 43: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

LDAP Query Policy Hard Limits

Page 44: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

LDAP Query Policy Hard Limits

Page 45: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

LDAP Query Policy Hard Limits

Page 46: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

LDAP Query Policy Hard Limits

http://support.microsoft.com/kb/2009267

Page 47: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

NT4 Crypto

Page 48: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Dynamic Port Range

Page 49: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Dynamic Port Range

Page 50: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Dynamic Port Range

Page 51: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Miscellaneous

Page 52: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Considerations before Upgrade

Page 53: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Considerations before Upgrade

Page 54: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 55: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Benefits

Page 56: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Branch office….

Page 57: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Features

Page 58: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

58

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch

Page 59: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

59

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch

1. AS_Req sent to RODC

(request for TGT)

1

Page 60: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

60

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch 2. RODC: Looks in DB: "I

don't have the users

password "

1. AS_Req sent to RODC

(request for TGT)

1

2

Page 61: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

61

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch 2. RODC: Looks in DB: "I

don't have the users

password "

3. Forwards Request to a

writeable DC

1. AS_Req sent to RODC

(request for TGT)

1

2

3

Page 62: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

62

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch 2. RODC: Looks in DB: "I

don't have the users

password "

3. Forwards Request to a

writeable DC

4. Writeable DC

authenticates request

1. AS_Req sent to RODC

(request for TGT)

1

2

3

4

Page 63: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

63

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch 2. RODC: Looks in DB: "I

don't have the users

password "

3. Forwards Request to a

writeable DC

4. Writeable DC

authenticates request

5. Returns authentication

response and TGT back to

the RODC

1. AS_Req sent to RODC

(request for TGT)

1

2

3

4

5

Page 64: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

64

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch 2. RODC: Looks in DB: "I

don't have the users

password "

3. Forwards Request to a

writeable DC

4. Writeable DC

authenticates request

5. Returns authentication

response and TGT back to

the RODC

1. AS_Req sent to RODC

(request for TGT)

1

2

3

4

5

6

6. RODC gives TGT to User

and Queues a replication

request for the password

6

Page 65: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Authentication and Client Operations

65

How it works: Password caching during first logon

Hub

`

Read Only DCHub Writable DC

Branch 2. RODC: Looks in DB: "I

don't have the users

password "

3. Forwards Request to a

writeable DC

4. Writeable DC

authenticates request

5. Returns authentication

response and TGT back to

the RODC

6. RODC gives TGT to User

and Queues a replication

request for the password

7) Hub DC checks

Password Replication

Policy to see if

Password can be

replicated

1. AS_Req sent to RODC

(request for TGT)

1

2

3

4

5

6

6

7

7

Note: At this point the user will have a hub signed TGT

Page 66: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Limitations

Page 67: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

RODC Considerations

Page 68: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Fine Grain Password Policy (FGPP)

Page 69: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Creating a Fine Grain Password Policy

Page 70: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

FGPP – Implementation Considerations

Page 71: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

FGPP – Defining Scope

Page 72: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

FGPP – Best Practices

Page 73: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Listens on port 9389

Advertised via DC Locator

nltest /dsgetdc:domain /ws

Active Directory Web Services

Page 74: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

AD Core

LDAP

S.DS.P / S.DS.AM / S.DS.AD

.NET

S

E

R

V

E

R

C

L

I

E

N

T

ADUC/ADSS/ADDT

WSH

ADSI

LDAP

MMC

GUI

DS RPC-Based Protocols

… DSR SAM

CLI

DS RPC-Based Protocols

… DSR SAM

Page 75: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

AD Core

LDAP

AD Web Services

S.DS.P / S.DS.AM / S.DS.AD

AD PowerShell MUX

WCF

.NET

WPF

.NET

.NET

S

E

R

V

E

R

C

L

I

E

N

T

WCF

.NET

AD Core

DS RPC-Based Protocols

… DSR SAM

AD Admin Center

GUI

BPA ADUC/ADSS/ADDT

WSH

ADSI

LDAP

MMC

GUI

DS RPC-Based Protocols

… DSR SAM

CLI

Page 76: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recycle Bin

Tombstone

Object

Recycled

Object

Deleted

Object

Windows Server 2008

No Recycle bin feature

Windows Server 2008 R2 with Recycle Bin enabled

Garbage

Collection

Garbage

Collection

Live

Object

Auth Restore

Delete

Delete

Undelete Deleted Object

Lifetime

180 Days

Tombstone

Lifetime

180 Days

Tombstone

Lifetime

180 Days

Live

Object

Page 77: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recovering Multiple Objects Deleted Objects container

A flat list of all objects in the Deleted state

DN is mangled, attributes preserved, lastKnownParent

Restore objects to live parent

Deleted objects must be restored to a live parent

Perform restore in top-down order

lastKnownParent and lastKnownRDN properties useful in rebuilding hierarchy

RDN over 128 chars truncated

\0ADEL:…

Page 78: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recovering Multiple Objects Deleted Objects container

A flat list of all objects in the Deleted state

DN is mangled, attributes preserved, lastKnownParent

Restore objects to live parent

Deleted objects must be restored to a live parent

Perform restore in top-down order

lastKnownParent and lastKnownRDN properties useful in rebuilding hierarchy

RDN over 128 chars truncated

Delete

\0ADEL:…

\0ADEL:…

\0ADEL:…

\0ADEL:…

\0ADEL:...

\0ADEL:…

Page 79: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recovering Multiple Objects Deleted Objects container

A flat list of all objects in the Deleted state

DN is mangled, attributes preserved, lastKnownParent

Restore objects to live parent

Deleted objects must be restored to a live parent

Perform restore in top-down order

lastKnownParent and lastKnownRDN properties useful in rebuilding hierarchy

RDN over 128 chars truncated

\0ADEL:…

\0ADEL:…

\0ADEL:…

\0ADEL:…

\0ADEL:...

\0ADEL:…

Page 80: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recovering Multiple Objects Deleted Objects container

A flat list of all objects in the Deleted state

DN is mangled, attributes preserved, lastKnownParent

Restore objects to live parent

Deleted objects must be restored to a live parent

Perform restore in top-down order

lastKnownParent and lastKnownRDN properties useful in rebuilding hierarchy

RDN over 128 chars truncated

\0ADEL:…

\0ADEL:…

\0ADEL:…

\0ADEL:…

\0ADEL:...

\0ADEL:…

Undelete

Page 81: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recovering Multiple Objects Deleted Objects container

A flat list of all objects in the Deleted state

DN is mangled, attributes preserved, lastKnownParent

Restore objects to live parent

Deleted objects must be restored to a live parent

Perform restore in top-down order

lastKnownParent and lastKnownRDN properties useful in rebuilding hierarchy

RDN over 128 chars truncated

\0ADEL:…

\0ADEL:…

Undelete

Page 82: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recovering Multiple Objects Deleted Objects container

A flat list of all objects in the Deleted state

DN is mangled, attributes preserved, lastKnownParent

Restore objects to live parent

Deleted objects must be restored to a live parent

Perform restore in top-down order

lastKnownParent and lastKnownRDN properties useful in rebuilding hierarchy

RDN over 128 chars truncated

\0ADEL:…

Page 83: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Recycle Bin Considerations

Page 84: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade

Key new features overview

Page 85: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade
Page 86: download.microsoft.com/documents/hk/technet... · Transfer back all the FSMO roles 8. Apply any registry key / DC hardening keys that used before 9. Upgrade