Active Directory

  Home  Networking  Active Directory


“Active Directory Interview Questions and Answers will guide us now that Active Directory is a technology created by Microsoft that provides a variety of network services, including LDAP-like directory services, Kerberos-based authentication, DNS-based naming and other network information, Central location for network administration and delegation, Information security and single sign-on for user access to networked based resources so learn more by this Active Directory Interview Questions Answer”



146 Active Directory Questions And Answers

81⟩ Define Replication in Active Directory?

Site streamlines replication of directory information and reduces replication traffic.

Site membership is determined differently for domain controllers and clients. A client determines it is in when it is turned on, so its site location will often be dynamically updated. A domain controller's site location is established by which site its Server object belongs to in the directory, so its site location will be consistent unless the domain controller's Server object is intentionally moved to a different site.

 151 views

82⟩ Define the global catalog key directory roles?

When a user logs on to the network, the global catalog provides universal group membership information for the account sending the logon request to the domain controller. If there is only one domain controller in the domain, the domain controller and the global catalog are the same server. If there are multiple domain controllers in the network, the global catalog is hosted on the domain controller configured as such. If a global catalog is not available when a user initiates a network logon process, the user is only able to log on to the local computer.

 142 views

83⟩ What is the role of Global Catalog Server in a Domain?

By default, a global catalog is created automatically on the initial domain controller in the forest. It stores a full replica of all objects in the directory for its host domain and a partial replica of all objects contained in the directory of every other domain in the forest. The replica is partial because it stores some, but not all, of the property values for every object in the forest.

 152 views

84⟩ Suppose if a user is a member of the Domain Admins group, Did he able to log on to the network even when a global catalog is not available?

The global catalog is designed to respond to queries about objects anywhere in the forest with maximum speed and minimum network traffic. Because a single global catalog contains information about objects in all domains in the forest, a query about an object can be resolved by a global catalog in the domain in which the query is initiated. Thus, finding information in the directory does not produce unnecessary query traffic across domain

boundaries.

You can optionally configure any domain controller to host a global catalog, based on your organization's requirements for servicing logon requests and search queries. After additional domain controllers are installed in the domain, you can change the default location of the global catalog to another domain controller using Active Directory Sites and Services.

 185 views

85⟩ Do you know why GC and infrastructure master should not be on the same server?

The infrastructure master is responsible for updating references from objects in its domain to objects in other domains. The infrastructure master compares its data with that of a global catalog. Global catalogs receive regular updates for objects in all domains through replication, so the global catalog's data will always be up-to-date. If the infrastructure master finds data that is out-of-date, it requests the updated data from a global catalog. The infrastructure master then replicates that updated data to the other domain controllers in the domain.

★ If the infrastructure master and global catalog are on the same domain controller, the infrastructure master will not function. The infrastructure master will never find data that is out of date, so will never replicate any changes to the other domain controllers in the domain.

★ If all of the domain controllers in a domain are also hosting the global catalog, all of the domain controllers will have the current data and it does not matter which domain controller holds the infrastructure master role.

 152 views

88⟩ Define Forest-Wide operations master roles?

Every Active Directory forest must have the following roles:

★ Schema master

★ Domain naming master

There can be only one schema master and one domain naming master for the entire forest.

 157 views

89⟩ Define Domain-Wide operations master roles?

Every domain in the forest must have the following roles:

★ Relative ID master

★ Primary DC (PDC) emulator

★ Infrastructure master

Each domain in the forest can have only one RID master, PDC Emulator, and Infrastructure Master.

 148 views

90⟩ Define Relative ID master role?

The RID master allocates pool of relative IDs to each DC in its domain. Whenever a DC creates a user, group, or computer object, it assigns a unique security ID to that object. The security ID consists of a domain security ID (that is the same for all security IDs created in the domain), and a relative ID that is unique for each security ID created in the domain. To move an object between domains (using Movetree.exe), you must initiate the move on the DC acting as the relative ID master of the domain that currently contains the object.

 168 views

91⟩ Define PDC emulator role?

For pre-W2K clients, the PDC emulator acts as a Windows NT PDC. It processes password changes from clients and replicates updates to the BDCs.

In native-mode, the PDC emulator receives preferential replication of password changes performed by other DCs in the domain. If a password was recently changed, that change takes time to replicate to every DC in the domain. If a logon authentication fails at another DC due to a bad password, that DC will forward the authentication request to the PDC emulator before rejecting the log on attempt.

 151 views

92⟩ Define the Infrastructure master role?

The infrastructure master is responsible for updating the group-to-user references whenever the members of groups are renamed or changed. At any time, there can be only one DC acting as the infrastructure master in each domain. When you rename or move a member of a group (and that member resides in a different domain from the group), the group may temporarily appear not to contain that member. The infrastructure master of the group's domain is responsible for updating the group so it knows the new name or location of the member. The infrastructure master distributes the update via multi-master replication.

There is no compromise to security during the time between the member rename and the group update. Only an administrator looking at that particular group membership would notice the temporary inconsistency.

 149 views

93⟩ Define the single master operations?

Active Directory supports multi-master replication of the directory data between all DCs in the domain. Some changes are impractical to perform in multi-master fashion, so only one DC, called the operations master, accepts requests for such changes. Because the operations master roles can be moved to other DCs within the domain or forest, these roles are sometimes referred to as Flexible Single Master Operations. In any Active Directory there are five operations master roles. Some roles must appear in every forest. Other roles must appear in every domain in the forest.

 159 views

94⟩ List the FSMO roles?

★ Schema master

★ Domain naming master

★ RID master

★ PDC emulator

★ Infrastructure daemon

 182 views

95⟩ Describe the Infrastructure FSMO role?

When an object in one domain is referenced by another object in another domain, it represents the reference by the GUID, the SID (for references to security principals), and the DN of the object being referenced. The infrastructure FSMO role holder is the DC responsible for updating an object's SID and distinguished name in a cross-domain object reference.

 146 views

96⟩ How to place the FSMO roles?

★ Place the RID and PDC emulator roles on the same domain controller. Good communication from the PDC to the RID master is desirable as down-level clients and applications target the PDC, making it a large consumer of RIDs.

★ As a general rule, the infrastructure master should be located on a non-global catalog server that has a direct connection object to some global catalog in the forest, preferably in the same Active Directory site.

 203 views

97⟩ How to responding operations master failures?

Some of the operations master roles are crucial to the operation of your network. Others can be unavailable for quite some time before their absence becomes a problem If an operations master is not available due to computer failure or network problems, you can seize the operations master role.

In general, seizing an operations master role is a drastic step that should be considered only if the current operations master will never be available again.

 166 views

98⟩ How to create a container to list printers in Active Directory?

To create a Printers container in which to list your printers in Active Directory:

1) Click Start, point to Programs, point to Windows 2000 Support Tools, point to Tools, and then click ADSI Edit.

2) Expand Domain NC [Domain Name], and then click DC=Domain, DC=com.

3) On the Action menu, point to New, and then click Object.

4) In the Select a class box, click container, and then click Next.

5) In the Value box, type Printers, and then click Next.

6) Click Finish.

A CN=Printers container appears in the right pane of ADSI Edit.

1) Right-click CN=Printers, and then click Properties.

2) Click the Attributes tab.

3) In the Select a property to view box, click "show In Advanced View Only", and then click Clear.

4) In the Edit Attribute box, type false, click Set, and then click OK.

5) Quit ADSI Edit.

6) Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers. The Printers container that you created appears in the list of directory objects.

7) On the View menu, click Advanced Features.

8) On the View menu, click Users, Groups, and Computers as containers.

9) Move the printers that you want to the Printers container.

10) Quit Active Directory Users and Computers.

 151 views

99⟩ How to publish a printer in AD?

1) Log on to the computer as an administrator.

2) Click Start, point to Settings, and then click Printers.

3) In the Printers folder, right-click the printer that you want to publish in Active Directory, and then click Properties.

4) Click the Sharing tab, click Share As, and then either type a share name or accept the default name. Use only letters and numbers; do not use spaces, punctuation, or special characters.

5) Click to select the List in the Directory check box, and then click OK.

6) Close the Printers folder.

 145 views

100⟩ How to configure an authoritative time server in Windows 2000?

Windows includes the W32Time time service tool that is required by the Kerberos authentication protocol. The purpose of the Time service is to ensure that all computers that are running Windows 2000 in an organization use a common time.

Windows-based computers use the following hierarchy by default:

• All client PCs and member servers nominate the authenticating DC as their in-bound time Server.

• DCs may nominate the PDC operations master as their in-bound time partner but may use a parent DC based on stratum numbering.

• All PDC operations masters follow the hierarchy of domains in the selection of their inbound time partner.

PDC operations master at the root of the forest becomes authoritative for the organization. This PDC can be configured to recognize an external Simple Network Time Protocol (SNTP) time server as authoritative by using the following net time command:

Net time /setsntp: server_list

To reset the local computer's time against the authoritative time server for the domain:

Net time /domain_name /set

Net stop w32time

W32tm -once

Net start w32time

SNTP defaults to using UDP port 123. If this port is not open to the Internet, you cannot synchronize your server to Internet SNTP servers. Administrators can also configure an internal time server as authoritative by using the net time command. If the administrator directs the command to the operations master, it may be necessary to reboot the server for the changes to take effect.

 176 views