Copyrighted Material
Total Page:16
File Type:pdf, Size:1020Kb
Index Note to the reader: Throughout this index boldfaced page numbers indicate primary discussions of a topic. Italicized page numbers indicate illustrations. Active Directory-integrated zones, 178–179 Symbols & Numbers Active Directory Lightweight Directory % Processor Time counter, 103 Services, 224 802.1x enforcement, in NAP, 196–197 Active Directory Rights Management Services (AD RMS), 224 Active Directory Users and Computers (ADUC), 209, 210 AD CS (Active Directory Certificate Services), A 217–220 A (host) records, 180, 204 AD DS. See Active Directory Domain Services AAAA (host) records, 180, 204 (AD DS) Account logon events, auditing, 387, 411 AD FS (Active Directory Federation Services), 225 account management, auditing, 387 AD LDS (Active Directory Lightweight Directory Account Operators group, 228 Services), 224 acknowledge packets in DHCP, 160 AD RMS (Active Directory Rights Management actions, for tasks, 121–122 Services), 224 activating Windows Server 2008, 24–25 Add Roles Wizard, 11 Active Directory, 25–34 Select Server Roles page, 53 auditing capabilities, 387 for Terminal Services, 339 auditing detailed events, 388–389 /Add switch, for WDSUtil command, 51 backup and recovery, 230–240 administrative templates, language specific, 264 backup process, 232–235 Administrator account, 226 restoring, 235–240 Administrators (domain controller) group, database 227–228 read-only copy, 15 Administrators (local machine) group, 227 volume containing, 231 adminpak.msi file, 132 elements, 26, 26–29 .adml files, 264 listing shared printers in, 331 .admx files, 264 replication, DNS zone transfers in, 178 ADUC (Active Directory Users and Computers), rights and permissions, 225–230 209, 210 server editions for server roles, 4 alias (CNAME) record, 183 Windows Server 2008 editions support Allowed RODC Password Replication Group, for, 40 216, 229 Active Directory Certificate Services (AD CS), Apache web server, 6, 354 217–220 APIPA (automatic private IP address), 160 Active Directory DiagnosticsCOPYRIGHTED template, 103 AppCmd MATERIAL command-line tool, 431 Active Directory Domain Services (AD DS), 25, application pools, in SharePoint services, 323 209–211 Application server, Server editions for, 4 adding role, 31–33 applications installing, 32 Group Policy for provisioning, 260–262 publishing printer in, 308–309 installing on Terminal Server, 341–342 schema, 27 limiting CPU and memory use by, 123 tools, 33–34 virtual server for hosting, 83 Active Directory Federation Services (AD FS), 225 Applications and Services Logs, 112 93157book.indd 467 8/7/08 4:07:01 PM 468 /Approve switch – calendars /Approve switch, for WDSUtil command, 52 Baseline Properties dialog box, 106, 107 ASP.NET applications, 354 basic images, 48 IIS and, 355, 355 Basic template, for data collector sets, 103 .aspx file extension, 355 batch files. See scripts asset management, SCCM for, 146 batch timeout, 114 assigning applications, 261–262 bcdedit (Boot Configuration Data Editor), 60 document activation and, 260 to restart domain controller, 237 asymmetric encryption, 380 BIOS, BitLocker requirements, 371 attributes, in global catalog, 27 BitLocker Drive Encryption, 8, 40, 370–378, 410 auditing, 387–392 adding feature, 371–372, 372 detailed Active Directory events, 388–389 enabling on non-TPM systems, 376–377 enabling, 411 and Encrypting File System, 379 enabling for Directory Service Access, multifactor authentication with, 377 389–391 partition configuration for, 373–375 object access, 391–392 recovery mode, 378 auditpol command-line tool, 389, 411 requirements, 371 Authenticated Users group, permissions for starting system with, 377 GPO, 253 Block Policy Inheritance, in Group Policy, authentication, 399 246–247 with private keys, 218 blogs, 322 RADIUS server for centralized, 401 Boot Configuration Data Editor (bcdedit), 60 at remote office, 16 to restart domain controller, 237 of servers, on Remote Desktop boot images, 46–48 Connection, 130 for WDS, 55 by VPN servers, 195 Boot Images container, in WDS, 61 Authentication Header (AH), in IPSec packet, 402 boot volume, 230 authoritative restore, 240, 272 bootable WinRE disk, creating, 437 of Active Directory, 236–237 booting from installation CD, 437 need for, 238 BOOTP (Bootstrap Protocol), 45 authorization, RADIUS server for broadcasts for DHCP, 168 centralized, 401 boot.wim file, 46 auto-cast transmissions, 68–69 Broadcast method, for name resolution, 175 autoenrollment, 223 broadcast packets, for DHCP, 160, 168 automatic private IP address (APIPA), 160 business continuity planning, 414 Automatic Updates, 136 failover clustering, 424, 424–428 autonomous mode, for WSUS servers, 138, 139 requirements, 425–426 fault tolerance for disks, 418–423 for print device, 308 B network load balancing, 428–431, 429 requirements, 430–431 backdoor, for data retrieval, 386 Windows Server Backup feature, 431–436 backup Business Desktop Deployment (BDD), 437 of Active Directory, 230–240 creating, 79–80 of file servers, 276 of Group Policy objects, 263–264 of Server Core critical volumes, 235 C Windows Server Backup feature, 431–436 CA. See certification authorities (CA) Backup Domain Controllers (BDCs), 28 cache, for passwords on RODC, 215 Backup Operators group, 228 calculated stability index, 101 baseline image, custom image as, 48 calendars, in SharePoint services, 322 93157book.indd 468 8/7/08 4:07:01 PM capture images – Data Recovery Agent 469 capture images, 47 Computer Configuration node in Group case sensitivity, and DNS names, 172 Policy, 241 CDs, copying EFS certificate to, 383 disabling, 252–253, 253 Certificate Manager, 384, 384 computer image deployment, 65–70 certificate revocation list (CRL), 218, 219 device management, 65–67 certificates, 217–218 prestaging computers, 65 for EFS, 380–381 Computer Management tool, creating shares with, backup, 382–383 282–284 importing, 384–385 conditions, for tasks, 122, 123 certification authorities (CA), 217, 218, confidentiality, 399 221–223 configuration information, in data collector enterprise, 222–223 set, 103 stand-alone, 222 context for task, 121 change management, 146 Contributor permission level, 289, 330 Change permissions, for shares, 289 control, OU for delegating, 210, 211–213 checksums, 399 Control Panel child domain, in Active Directory, 26 for accessing programs, 261 client computers BitLocker availability from, 372, 372 compliance with security policies, 192–193 Control Panel Wizard, 341 components, 13 /Convert switch, for WDSUtil command, 51 configuring for offline files, 295–296 /Copy switch, for WDSUtil command, 51 configuring to use WSUS, 138–145 counters, in Performance Monitor, 98 nondomain clients, 144–145 Create a Basic Task Wizard, 118, 118 configuring WDS server to respond to, Create a Shared Folder Wizard, 282–284, 283 65–67, 66 Create Quota page, 298 controlling patch deployment to, 134 Credential Security Support Provider (CredSSP) dynamic update settings, 189, 189 protocol, 77, 92, 338 health check for, 400 Critical event in log, 113 requirements for WDS, 50 critical volumes Client (Respond Only) Group Policy setting, for backup, 232–234 IPSec, 403 on Server Core, 235 client-side targeting, 155 in Windows Server 2008, 230–231 on WSUS server, 143–144, 144 CRL (certificate revocation list), 218, 219 ClusPrep, 426 cscript command, 75, 122 cmdlets, 13 custom images, 48 CNAME (alias) record, 183, 205 creating and capturing, 59–61 Co-owner permission level, 289, 330 custom views, for logs, 111–112 collector, for event subscriptions, 113 collector initiated event subscriptions, 114, 154 command-line tools. See also Server Core D AppCmd, 431 DAC (Discretionary Access Control) model, 286 auditpol, 389, 411 DACL (discretionary access control lists), 390 dfsrmig.exe, 316 data collector set templates, 100 gpupdate, 247 data collector sets, 97, 103–111 /Force, 271 creating from template, 106–108 for scripts, 11–12 reports from, 109, 109–111, 110 WinRM, 114, 154, 431, 447 running, 104 command prompt, in Windows Recovery data decryption field (DDF), 380 Environment, 437 Data Recovery Agent, 385–386 Common Criteria Evaluation Assurance Level 4+ vs. Key Recovery Agent, 386 (EAL 4+), 397 93157book.indd 469 8/7/08 4:07:02 PM 470 Datacenter edition of Windows Server 2008 – drivers Datacenter edition of Windows Server 2008, 3 disks hardware requirements, 18 fault tolerance for, 418–423 virtual server licensing, 85 storage solutions, 421–423 virtual servers on, 8 terminology, 422 DCPromo tool, 29–30, 40, 213 displaying message when attaching tasks, 119 DDF (data decryption field), 380 distributed environment, WSUS in, 138, 139 default domain controllers policy, 241 Distributed File System (DFS), 310–321, 331 default domain policy, 241 creating replication group, 318 default gateway, 169 namespaces to organize content, 311, default groups, in Users container, 227 311–312 Delegation of Control Wizard, 210, 213, 271 replication, 313–316, 332 Delete Catalog command (Wbadmin), 434 and WSUS, 316 /Delete switch, for WDSUtil command, 52 DMZ (demilitarized zone), 347, 393, 393 Delete Systemstatebackup command DNS. See Domain Name System (DNS) (Wbadmin), 434 DNS Manager console, 176, 176 deleting reports from data collector sets, 110 creating new NS record in, 183 demilitarized zone (DMZ), 347, 393, 393 DNSAdmins group, 205, 229 Denied RODC Password Replication Group, documents, usage rights of, 224 216, 230 Domain Admins group, 204, 226, 227, 330 Deny permission, 287 and GPO creation, 256 Deployment Server service, in WDS, 52 domain-based namespaces, vs. stand-alone,