Friday, 5 December 2008

Networking Week 8

Managing Users in Server 2003:

This week we looked at adding users and user groups in the windows server 2003 active directory domain. We also looked at system admin controls to prevent miss use of company computer equipment and limiting access periods to the company resources.  And finally we looked at ensuring that the company Terms of Service agreement is reviewed and agreed upon with all computer use.

The first activity we looked at was adding user accounts to the Active directory environment this is done by the manage your server window, then select manage users, computers for the active directory controller. Left click the domain name from the left pane of the screen that opens, then left click on the users tab below that. Next select an area in the right pane of the screen and right click then select new user from the drop down menus, You will then need to fill in the user details including the name of the user and of course a log in or username and password for the user. A small amount of configuration can be done here on the password allowing the user to configure the own password, not allowing the user to change the password, disable the account and Allow the account to never expire.

The rest of the configuration for user accounts can be found in the properties of each individual account by right clicking and selecting properties then the according tab such as setting a time limit for logon or usage can be done here, limiting the computers by IP address that user is allowed to log in on and many other fine tuning settings.

Setting up a user group is done in cases where many users have or will need the same permission's to the same areas of the server, this is done again by heading to the manage your server page then open the active directory users settings. select the domain name again and then users , from here right click on the right pane of the window and select new then select group, Type in the name for the group like sales etc then add user accounts to the members tab.

The active directory settings area can also be used to fine tune the log in of users on client machines and any remote log ins also. This is done by right clicking on the domain name in the settings page of active directory users and computers then select properties, select the group policy tab and select the default domain policy then edit, now select windows settings from the left side of the page and then security settings from here you can configure things like user account password rules or lockout policies.  You can also select local policies under the security policy on the left pane of the screen and then select security policies from here you can input many details including the log in message users will be prompted with at login these could include the IT usage policies. I have included a picture of this area as it can be confusing with all the similar setting areas but each has a different use and outcome.

Server2003 Security Policies

No comments: