1. 丹 C働NG TH C T P QU N TR H TH NG V M NG
MY TNH
BU I 1 : ACTIVE DIRECTORY (AD)
1. C叩c kh叩i ni m :
a. Server 単 c l p (Standalone server) : M t m叩y t鱈nh ci 単 t h 単i u hnh MS Windows
2003 l n 単 u ti棚n 単動 c g i l server 単 c l p.
b. Server thnh vi棚n (Member server) : M t m叩y t鱈nh ci 単 t h 単i u hnh MS Windows
2003 nh動ng kh担ng ph i l b 単i u khi n mi n, c坦 th tham gia vo m t mi n.
c. B 単i u khi n mi n (Domain controller) : M叩y t鱈nh th c thi MS Windows 2003 Server
ci 単 t Active Directory.
2. Ci 単 t Active Directory (AD) :
Sinh vi棚n th c hi n ci 単 t Active Directory theo h動 ng d n minh h a nh動 sau :
B動 c 1 : Click StartRun. Nh p l nh dcpromo. Click OK.
1
2. B動 c 2 : Xu t hi n h p tho i cho m ng ci 単 t AD. Click Next.
B動 c 3 : H p tho i th担ng b叩o s t動董ng th鱈ch c a h 単i u hnh. Click Next.
2
3. B動 c 4 : Ci 単 t B 単i u khi n mi n cho m t mi n m i. Click Next.
B動 c 5 : Ci 単 t mi n trong r ng mi n m i. Click Next.
3
4. B動 c 6 : 丹 t t棚n mi n 単 y 単 DNS cho mi n
B動 c 7 : T棚n NetBIOS c a mi n
4
6. B動 c 9 : N董i l動u tr Shared System Volume
B動 c 10 : Ci 単 t v c u h狸nh DNS server tr棚n b 単i u khi n mi n v thi t l p lm DNS
server ch鱈nh.
6
7. B動 c 11 : Ch cho ph辿p t動董ng th鱈ch v i c叩c h 単i u hnh Windows 2000 v Windows 2003
m kh担ng t動董ng th鱈ch v i c叩c h 単i u hnh tr動 c 単坦 (Windows NT)
B動 c 12 : Thi t l p password cho ti kho n qu n tr l動u tr d ch v danh b
7
8. B動 c 13 : T ng h p c叩c th担ng tin 単達 l a ch n
B動 c 14 : B t 単 u qu叩 tr狸nh ci 単 t Active Directory
8
9. B動 c 15 : 丹ang th c hi n ci 単 t DNS server
B動 c 16 : Qu叩 tr狸nh ci 単 t Active Directoy hon thnh
9
10. B動 c 17 : Kh i 単 ng b 単i u khi n mi n. Click Restart Now
3. T o 丹董n v t ch c (Organizational Unit - OU), ti kho n ng動 i d湛ng (User
Account), nh坦m (Group)
a. T o 単董n v t ch c
丹ng nh p vo b 単i u khi n b ng ti kho n Administrator.
Click StartProgramsAdministrative ToolsActive Directory Users and
Computers. Click tr叩i chu t ch n t棚n mi n ctu.edu.vn. Click ph i chu t ch n
NewOrganizational Unit. L n l動 t t o ra 3 単董n v t ch c Sales, Marketing,
Production.
b. T o ti kho n ng動 i d湛ng trong c叩c 単董n v t ch c
Trong OU Sales l n l動 t t o 2 ti kho n ng動 i d湛ng nh動 sau : Click tr叩i chu t
ch n Sales. Click ph i chu t Sales ch n NewUser. Nh p c叩c th担ng tin c a ti
kho n ng動 i d湛ng l n l動 t nh動 sau :
10
11. First Name Phan
Last Name Chu Trinh
Full Name Phan Chu Trinh
User logon name pctrinh
Password 1234@abcd
B d u ch n trong 担 check box : User must change password at next logon.
First Name Doan
Last Name Thi Diem
Full Name Doan Thi Diem
User logon name dtdiem
Password 1234@abcd
B d u ch n trong 担 check box : User must change password at next logon.
Trong OU Marketing l n l動 t t o 2 ti kho n ng動 i d湛ng v i th担ng tin c a ti
kho n ng動 i d湛ng l n l動 t nh動 sau :
First Name Tran
Last Name Hung Dao
Full Name Tran Hung Dao
User logon name thdao
Password 1234@abcd
B d u ch n trong 担 check box : User must change password at next logon.
First Name Ho
Last Name Xuan Huong
Full Name Ho Xuan Huong
User logon name hxhuong
Password 1234@abcd
B d u ch n trong 担 check box : User must change password at next logon.
Trong OU Prodcution l n l動 t t o 2 ti kho n ng動 i d湛ng v i th担ng tin c a ti
kho n ng動 i d湛ng l n l動 t nh動 sau :
First Name Nguyen
Last Name Trai
Full Name Nguyen Trai
User logon name ntrai
Password 1234@abcd
B d u ch n trong 担 check box : User must change password at next logon.
11
12. First Name Hai
Last Name Ba Trung
Full Name Hai Ba Trung
User logon name hbtrung
Password 1234@abcd
B d u ch n trong 担 check box : User must change password at next logon.
c. T o nh坦m ng動 i d湛ng (Group)
Chuy n ch 単 ho t 単 ng c a b 単i u khi n mi n sang ch 単 Native
Mode.
Click ph i t棚n mi n ctu.edu.vn. Ch n Raise Domain Functional Level
Ch n Windows Server 2003. Click Raise.
12
13. H p tho i th担ng b叩o vi c thay 単 i m c ch c nng c a mi n. Ch n OK.
H p tho i th担ng b叩o thay 単 i m c ch c nng c a mi n thnh c担ng. Ch n
OK.
Kh叩i ni m : Nh坦m (Group)
Thay v狸 c p quy n truy c p cho t ng ti kho n ng動 i d湛ng truy c p ti
nguy棚n, nh qu n tr s t o ra c叩c lo i nh坦m ng動 i d湛ng. Sau 単坦 単動a c叩c
ti kho n ng動 i d湛ng lm thnh vi棚n c a nh坦m. Sau 単坦 c p quy n truy c p
cho nh坦m.
Chi n l動 c s d ng nh坦m : c坦 c叩c lo i nh坦m ph bi n trong mi n MS
Windows 2003 Server : Global group, Domain Local Group, Universal
Group.
Nh qu n tr th動 ng t o ra nh坦m Global group, sau 単坦 単動a ti kho n ng動 i
d湛ng lm thnh vi棚n c a Global Group. Sau 単坦 単動a Global Group lm
thnh vi棚n c a nh坦m Domain Local Group. G叩n quy n truy c p ti nguy棚n
cho Domain Group.
T o nh坦m Global GAllUser
13
14. Click ph i chu t t棚n mi n ctu.deu.vn, ch n NewGroup
Group name : GAllUser
Group scope : Global
Group type : Security
T o nh坦m Global
Click ph i chu t t棚n mi n ctu.deu.vn, ch n NewGroup
Group name : DLResource
Group scope : Domain local
Group type : Security
14
15. 丹動a nh坦m GAllUser lm thnh vi棚n c a nh坦m DLResource :
Double click nh坦m DLResource. Ch n tab Members, click n炭t Add, click
n炭t Advancedclick n炭t Find Now, click ch n GAllUser, clik OK, click
OK.
15