Active Directory
ABC is a company which is located in Melbourne. It wants to store its files in a secured manner, with file server. The files can be accessed by the user who have appropriate permissions for access. Hence, this company needs a LAN connection at the main branch.There are three departments in the company namely Finance, Marketing and Finance.The main goal of this department is to have their own OU. To setup a secured LAN connection for this company, it must implement certain technologies in their LAN. Centralized authentication will be provided for the users. Roaming profiles will be created for the users. DHCP server will provide IP address for all the computers and IIS server will be implemented for the network.
CentralizedUser Authentication
Active Directory
Active directory domain services (ADDS) has the role of server, for the windows and the R2operating system. In order to have a centralized and a secure management it provides a distributed directory service(“Active Directory Services”, 2017).
Install Active Directory
- As an initial step, go to the task bar, open the server manager.
- From the server manager’s dashboard choose àAdd roles and features.
- Go to installation type screen àrole-based or features-based installationà(“Centralized user authentication”, 2017).
- The roles are considered to set the server and there are additional functionalities available.
- Current server is pickedby default. Click on the next option to move on to the Server Roles tab.
- Now for the next step, check on the next option, active directory domain. Notice willbe displayed to explain certainextra role services.
- If it requires installation, then add services has to be clicked.
- More number of options are available, which includes the services of the certificates and thereare the services that are present in the light weight directory services.
- But, it must be installed earlier.
- Next, have a glance and the go for select optional features for the purpose of installation.
- Then place the check box and the select the desired one. Click on the Nextoption.
- Review it on the top and then select the clickoption.
- Review installation and click on Confirm installation from the selection
- Start the remote registry service.
- Before the server is promoted to the domain controller, start the remote registry service (“Client/Server Environment”, 2017).
- Click the Start option and then select the option Control Panel.
- Under the option services, right-click on the remote registrythen check out the properties
- After doing that, from the *Startup type: **, select àautomatic.
- From the service statusàselectstart.
- Finally, the remote registry service begins.
- Configure the Active directory.
- If it is your first step, then from the task baràopen server manager.
- By selecting the notifications icon, open the notifications pane from the top of the server Manager. From the notification on configuring ADDSàclick on “Promote this server to a domain controller”
- By configuration of deployment tabàadd a new forest. Inthe root domain name field, insert the root domain nameàclick on next(Costantini, 2017).
- Now select the domain and then the forest functional level, and finally give input in the provided password fields for Directory Services Restore Mode (DSRM).
- The DSRM password is utilizedduring the process of booting the Domain Controller into the recovery mode.
- The selected one has many good features and also contains the server editor.
- Now, have a glance at warning on the DNS Options tabàselect next.
- Give the confirmation or enter a NetBIOS nameàclick on the nextoption.
- Mention the Database location, Log files, and SYSVOL foldersà
- Review the configuration options àclick on next option.
- The system makes sure to check whether all therequired prerequisites are installed on the system before they are moved forward. Once the check is accomplished move on to installation part.
- In windows server 2012 R2, Active Directory Services will be installed(Ferrill, 2017).
This profile is created in three different methods as follows,
- Local Profile
- Roaming Profile
- Mandatory profile
Local Profile
Local profile is also call as a user profile. Initially, it creates automatically when the user logs into the computer. User data is stored in the hard drive of the system. If the user changes anything from their account, then it gets changed automatically(“How to set up a local area network (LAN)”, 2017).
Mandatory Profile
Mandatory profile allows read only permission. It stores all the user data in the server. This profile is stored in the server. It downloads the file, every time when the user logsin to the computer. If the users log off the system, then their profile will not be updated. Only the administrator can make any changes.
Roaming Profile
Roaming profile is created by the administrator and is saved in the server. This profile is available when the users log on to any system, in the network. If user makes any changes in the file, then it will be replicated in the entire profile which is saved in the server and the computer(“Roaming User Profiles (Windows)”, 2017). From roaming profile, the user can access their computer and files from any system in the network.
Configuration of Roaming Profile
Here let’s see, how to create roaming profile in Active Domain Directory Service (ADDS).
For creating profile, in server “C” create a new folder as profile, then place this folder with everyone in the network(“How to: Enable Internet Information Services (IIS)”, 2017).
- In sharing: check the network path and copy it.
- For Adding Admin:
Installation of Active Directory
In Client PC: In profile folder à properties à security à edit à add àAdmin à check name of admin à Admin built-in account à ok à select accountàFull control à apply à ok.
- Then log off the client.
- Then Open Server: check the shared folder named as profile.
Go to Tool in server: Click AD User and Computer à Click Demo user à Profile: in profile paste the path of the shared folder.
For creating Share Open server manageràshareà create new share.
Creating a New Share Profile
Click on new share wizard à select profile à select SME Share –Quick (This profile will create in short time). Then, click on the next option.
Select share location: select server name then click on the next option.
In Share Name: enter the profile name and click on the next option.
Then click next à go to Permissions à Select the user name and give full access àNext
Advanced Security setting: Open advanced setting for roaming profile à click permission à Then click on add option.
For adding entry profile à select advanced permission àclick ok.
Form conforming Profile: check the detail and next.
Result of creating profile is shown here.
Open ADDS à extend saved queries àthen it displays the user name.
Roaming profiles in Active directory of windows server 2012 R2 will be done.
The IP addresses from a DHCP Servermust be retrieved for all the computers.The DHCP is a network protocol. It assigns IP address to a computer.It defines range of numbers.It is a client or server protocol, which automatically provides internet protocol host along with the IP address(“Using DHCP to Assign IP Addresses to Devices”, 2017).
Benefits of DHCP
The DHCP provides some benefits such as:
- Reliableconfiguration of IP address.
- DHCP increases the configuration errors with manual IP address configuration like,
- Typographical errors
- Addresses the conflicts.
- Reliable IP address configuration
- The centralized and automated TCP/IP configuration are supported.
- It defines TCP/IP configuration from a central location.
- It assigns a wide range of extra TCP/IP configuration.
Use of DHCP
- It provides valid TCP/IP address configuration parameters.
- It allows single IP address configuration(“Installing and Configuring DHCP role on Windows Server 2012”, 2017).
DHCP Installation Procedures
Click server manager then choose àadd roles and features.
Select àrole-based or feature-based installation
It shows system name and IP address and then click on the next button.
Click next button then start the feature installation.
Launch the DHCP post-install configuration.
Open the authorization page.
Open the summary page.
Check the post deployment configuration.
DHCP MMC launch point.
DHCP Server will be installed.
The company must also host a website. Thus, it requires a separate IIS server. IIS is an extensible web server which Microsoft has created (“Install Active Directory on Windows Server 2012”, 2017). It helps HTTP, HTTPS, FTP, FTPS, SMTP and NNTP. IIS is a collection of web services and it communicates with the software like Microsoft share point, Microsoft visual studio.NET, along with web distributed authoring and versioning.The IIS application uses HTML page. It serves HTML webpages and dynamic webpages. It supports some security features as follows:
- Mapping of Client certificate.
- Security for IP
- Request the filtering
- The authorization of URL.
Local Profile
Select Web Server(IIS) in the Server Roles page(“Installing IIS 8.5 on Windows Server 2012 R2”, 2017).
To install the IIS Management Console click on Add Features in the Add Roles and go to Features wizard. Uncheck, Include management tools when you no need to install the Management Console. Then, click on Continue option(“What is Internet Information Services (IIS)? – Definition from WhatIs.com”, 2017).
- From the Server Roles page, click on the Next button (“Internet Authentication Service and Centralized Management”, 2017).
- Identify the features that yourequire to install on the Features page. Then click on the Next button. Whatever features are needed, it can be selected automatically by IIS.
- Click on Next button, on the Web Server Role(IIS) page.
- If you need any extra role services to install. Select those services on the Role Services page(“Internet Information Services Security Journal”, 2017).
When a particular role service is selected, it needs another role features or services, so a separate page is opened that specifies the role services that are required to be installed. Leave the Include management tools. To add the needed role services or features click on Add Features.
Click on the next option, on the Roles Services page after completing the process of adding the required role services.
Check on the role services and features which are selected on the Confirmation page. To provide an immediate effect on settings, restart the destination server. If required select the option, restart the destination server automatically. Save the configuration by selecting Export configuration settings, then move to Save As dialog box. The file name should be entered in the appropriate area and then click on the save button. Click on the Install button on the Confirmation page, when you are ready to begin the process of installation.
When the Installation Progress page gets displayed, you can close the window without affecting the tasks that are running. If you want to open the page again or to view task status click on the present notifications in the notification area.
Finally, click on the Task Details.
Check the details of successful installation on the Results page àClose button.
When you use the address of https://localhost check whether the default Web page is displayed or not. Then verify whether the Web server works when the web browser is opened(“Installing and Configuring DHCP role on Windows Server 2012”, 2017).
IIS installation is completed successfully.
Conclusion
In recent years, Windows server 2012 is used for different purposes. The centralized user authentication service is implemented with the active directory. Roaming profiles are implemented for the users at three level namely local profiles, roaming profiles and mandatory profiles. DHCP server is configured and it automatically provides IP address for all the systems. IIS server is installed and configured for IP security, authorization of URL and certificate mapping for the clients. Therefore, the overall process of setting up a secured LAN connection for the ABC Company in Melbourne is completed.
References
Active Directory Services. (2017). Technet.microsoft.com. Retrieved 2 June 2017, from https://technet.microsoft.com/en-us/library/dd578336(v=ws.10).aspx
Centralized user authentication. (2017). Dialogic.com. Retrieved 2 June 2017, from https://www.dialogic.com/webhelp/Vision/Release5.1/64-0400-04/centralized_user_authentication.htm
Client/Server Environment. (2017). CCM. Retrieved 2 June 2017, from https://ccm.net/contents/152-client-server-environment
Costantini, D. (2017). How to enable Roaming Profiles on Windows Server 2012 R2. The Solving. Retrieved 2 June 2017, from https://thesolving.com/server-room/how-to-enable-roaming-profiles-on-windows-server-2012-r2/
Ferrill, P. (2017). 10 excellent new features in Windows Server 2012 R2. InfoWorld. Retrieved 2 June 2017, from https://www.infoworld.com/article/2606748/microsoft-windows/108930-10-excellent-new-features-in-Windows-Server-2012-R2.html
How to set up a local area network (LAN). (2017). broadbandchoices.co.uk. Retrieved 2 June 2017, from https://www.broadbandchoices.co.uk/how-to/how-to-set-up-a-local-area-network
How to: Enable Internet Information Services (IIS). (2017). Msdn.microsoft.com. Retrieved 2 June 2017, from https://msdn.microsoft.com/en-us/library/ms181052(v=vs.80).aspx
Install Active Directory on Windows Server 2012. (2017). support.rackspace.com. Retrieved 2 June 2017, from from https://support.rackspace.com/how-to/installing-active-directory-on-windows-server-2012/
Installing and Configuring DHCP role on Windows Server 2012. (2017). Microsoft Windows DNS, DHCP and IPAM Team Blog. Retrieved 2 June 2017, from https://blogs.technet.microsoft.com/teamdhcp/2012/08/31/installing-and-configuring-dhcp-role-on-windows-server-2012/
Installing IIS 8.5 on Windows Server 2012 R2. (2017). Docs.microsoft.com. Retrieved 2 June 2017, from https://docs.microsoft.com/en-us/iis/install/installing-iis-85/installing-iis-85-on-windows-server-2012-r2
Internet Authentication Service and Centralized Management. (2017). Technet.microsoft.com. Retrieved 2 June 2017, from https://technet.microsoft.com/en-us/library/cc961340.aspx
Internet Information Services Security Journal. (2017). SearchWindowsServer. Retrieved 2 June 2017, from https://searchwindowsserver.techtarget.com/tutorial/Internet-Information-Services-Security-Journal
Roaming User Profiles (Windows). (2017). Msdn.microsoft.com. Retrieved 2 June 2017, from https://msdn.microsoft.com/en-us/library/windows/desktop/bb776897(v=vs.85).aspx
Using DHCP to Assign IP Addresses to Devices. (2017). Technet.microsoft.com. Retrieved 2 June 2017, from https://technet.microsoft.com/en-us/library/gg398275(v=ocs.14).aspx
What is Internet Information Services (IIS)? – Definition from WhatIs.com. (2017). SearchWindowsServer. Retrieved 2 June 2017, from https://searchwindowsserver.techtarget.com/definition/IIS
Installing and Configuring DHCP role on Windows Server 2012. (2017). Microsoft Windows DNS, DHCP and IPAM Team Blog. Retrieved 2 June 2017, from https://blogs.technet.microsoft.com/teamdhcp/2012/08/31/installing-and-configuring-dhcp-role-on-windows-server-2012/