Get in Touch

Course Outline

1. Introduction

  • Overview of Active Directory Domain Services (AD DS)
  • Course goals and expected learning outcomes
  • The function of Active Directory within enterprise ecosystems for government
  • Description of the training laboratory environment
  • Key terminology and foundational concepts in Active Directory

2. Overview of Active Directory Features and Architecture

  • Structural components of Active Directory
  • Distinction between logical and physical structures
  • Domains, Trees, and Forests
  • Organizational Units (OUs)
  • Domain Controllers and Global Catalog services
  • Flexible Single Master Operations (FSMO) roles
  • Sites and Subnets configuration
  • DNS integration with Active Directory
  • Active Directory partitions and database architecture

3. Overview of Identity Management Solutions and Concepts

  • Fundamentals of Identity and Access Management (IAM)
  • Distinctions between authentication and authorization
  • Kerberos authentication protocol
  • NTLM authentication protocol
  • Single Sign-On (SSO) mechanisms
  • Role-Based Access Control (RBAC)
  • Identity lifecycle management processes
  • Concepts related to hybrid identity environments for government

4. Setting up Active Directory

  • Strategic planning for Active Directory deployment
  • Installation of Active Directory Domain Services
  • Promotion of servers to Domain Controller status
  • Establishment of new forests and domains
  • Installation and configuration of DNS services
  • Verification of installation integrity
  • Deployment best practices for government operations

5. Implementing Active Directory Domain Services

  • Creation and structure of Organizational Units
  • Administration of users, groups, and computers
  • User account management procedures
  • Group scopes and group types
  • Delegation of administrative privileges
  • Management of service accounts
  • Domain membership for computer systems

6. Configuring and Managing Replication

  • Principles of Active Directory replication
  • Multi-master replication mechanisms
  • Replication topology design
  • Knowledge Consistency Checker (KCC) functionality
  • Sites and replication scheduling
  • Troubleshooting replication errors
  • Monitoring replication health status

7. Implementing and Managing Group Policy

  • Group Policy architecture overview
  • Creation of Group Policy Objects (GPOs)
  • GPO linking procedures
  • Group Policy inheritance models
  • Loopback processing configuration
  • Administrative Templates management
  • Software deployment via GPO
  • Folder Redirection implementation
  • Application of security policies
  • Password and account lockout policy settings
  • Troubleshooting Group Policy issues

8. Implementing a Certification Authority (CA) Hierarchy

  • Introduction to Public Key Infrastructure (PKI)
  • Architecture of Certificate Services
  • Root and Subordinate Certification Authorities
  • Installation of Active Directory Certificate Services
  • Design of CA hierarchy structures
  • Certificate template management
  • Auto-enrollment configurations

9. Managing Certificates

  • Certificate lifecycle management processes
  • Issuance of certificates
  • Certificate renewal procedures
  • Certificate revocation protocols
  • Certificate Revocation Lists (CRLs)
  • Online Certificate Status Protocol (OCSP)
  • Management of certificate templates
  • Troubleshooting certificate-related issues for government networks

10. Implementing and Administering Active Directory Federation Services (AD FS)

  • Introduction to federation services
  • Architecture of AD FS
  • Claims-based authentication models
  • Installation of AD FS
  • Configuration of trust relationships
  • Implementation of Single Sign-On
  • Integration of external applications
  • Monitoring and troubleshooting AD FS for government use

11. Enabling Data Access

  • Access control principles
  • NTFS permissions structure
  • Shared folder permissions
  • Evaluation of effective permissions
  • Access-Based Enumeration features
  • Dynamic Access Control implementation
  • File Classification Infrastructure
  • Auditing of file access events for government compliance

12. Securing Active Directory Domain Services

  • Security best practices for Active Directory
  • Administrative security models
  • Tiered administration strategies
  • Privileged Access Management (PAM)
  • Securing Domain Controllers in government environments
  • Password policy configurations
  • Fine-Grained Password Policies
  • Account lockout policies
  • Auditing and monitoring requirements
  • Backup and recovery considerations for critical infrastructure

13. Implementing and Managing Rights Management Services (RMS)

  • Introduction to Active Directory Rights Management Services
  • RMS architecture
  • Installation of AD RMS
  • Protection of sensitive documents in government systems
  • Information protection policies
  • Integration with Microsoft Office applications
  • Management of user access rights

14. Implementing Microsoft Entra ID (formerly Azure Active Directory)

  • Introduction to Microsoft Entra ID
  • Cloud identity concepts for federal use
  • Hybrid identity architecture
  • Microsoft Entra Connect configuration
  • Password Hash Synchronization
  • Pass-through Authentication methods
  • Federation with AD FS
  • Overview of Conditional Access policies
  • Identity synchronization processes
  • Management of cloud-based identities for government agencies

15. Integrating Active Directory with OpenLDAP

  • Fundamentals of LDAP protocol
  • Active Directory LDAP support capabilities
  • Overview of OpenLDAP
  • Methods for identity synchronization
  • Authentication integration strategies
  • Common interoperability scenarios for government systems
  • Security considerations in LDAP integration
  • Troubleshooting LDAP connectivity issues

16. Monitoring Active Directory

  • Overview of monitoring tools
  • Utilization of Event Viewer
  • Performance Monitor application
  • Active Directory Administrative Center
  • Use of PowerShell for monitoring tasks in government operations
  • Replication monitoring procedures
  • System health checks
  • Auditing of system changes
  • Performance optimization techniques

17. Troubleshooting

  • Resolution of user logon issues
  • DNS-related problem resolution
  • Replication failure diagnostics
  • Group Policy troubleshooting methods
  • Authentication issue resolution for government networks
  • Certificate-related problem diagnosis
  • Domain Controller health assessments
  • Use of diagnostic tools (dcdiag, repadmin, nltest, gpresult)
  • Backup and recovery procedures for federal systems
  • Disaster recovery scenarios planning

18. Summary and Conclusion

  • Review of key technical concepts
  • Best practices for Active Directory administration in government sectors
  • Security recommendations for federal agencies
  • Operational maintenance checklist for persistent compliance
  • Additional Microsoft resources and official documentation references
  • Questions and answers session
  • Final hands-on review and laboratory wrap-up

Requirements

  • Proficiency in system administration tasks
  • Operational knowledge of the Windows Server environment

Target Audience

  • System administrators requiring specialized tools for government operations
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories