Tuesday, March 5, 2024

2024-02 - Active Directory AD8 - Subdomains

We have created user accounts for our IT employees.  Before adding the other users, we need to create a structure of departments and sub-departments for our company.

Use the RSAT tools to create a structure of Organizational Units (OUs) for other departments in our fictional organization.  Departments may include, but are not limited to:


Marketing

Financial

Human Resources

Administration

Operations

Information Technology

Janitorial

If this domain is going to be used for various company campuses (such as the morning and afternoon classes), it might be good to create an OU for each of these campuses.  If that is the case, only create subdomains for the campus you are overseeing and leave the other campus IT to do their own.


Okay so here's the deal as I understand it, unless I am just really bad at reading instructions...I think it says to do something with RSAT. I could be wrong, seriously, I have been wrong before, like, nearly every time I read instructions. Or take them. I pretty much can't do anything as it is clearly said to do haha. So, RSAT here I think we go. I looked up a Youtube video by searching access directory RSAT, and I clicked a video called IT Support Basics LAB... something something and started watching. It took me a few minutes of watching this guy just sit there wasting time doing nothing on a silent video and moving his mouse and windows around as if he was gesticulating and then I realized he is probably talking and for some reason I just can't here it. Turned on subtitles, he was speaking a lot. Probably would be useful to hear. This'll go faster. I switched my audio back to my laptop because I was using a second screen that was acting like it ad speakers but didn't and my laptop was confused I guess. 

Then the guy said something about needing to get RSAT 2. I just went along with this. Watch, my instructor is about to roll by and say, wo wo, wait what are you doing, 2 is for launching nukes or something, whatever you do don't use that. So RSAT 2 here we, lets blast off. 

The guy navigated to his start menu and went Apps and Features, and I thought, that's strange, you would only go there if you were uninstalling a program...or...if you were using that one feature to, yeah that's what he's doing. I've only gone there one time to install something so...yeah. 

I went to the start menu, apps & features didn't show up because I stupidly didn't right click on the start button, so  typed apps & features and it came up, I clicked, it came up, the video said to click on "Optional Features", a button located above the scroll menu for installed programs, but I found two different buttons in that location than the video was talking about, instead of optional features and app exception aliases, I found Manage Optional Features and Manage App Execution Aliases. His says the same thing but without the manage part. Maybe its just a windows update thing. 

I clicked on it and selected add a feature and it presented a dialogue box saying Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item. I pressed okay because it wasn't actually stopping me from doing anything as far as I could tell. There were a few little weird things like this with our Proxmox server so I just ignored it. Later I'm probably going to say something like, "and then Doug walked by and said I was doing ti wrong". 

When the Add A Feature window loaded, there were no features listed. 

I asked around in class as Doug was busy. Zack said he didn't know anything and so I said I would try that, thanks. 

That didn't work so I asked Jack, one of my class friends that came in at the same time as me. He came over, he had done some of the earlier Access Directory projects so I thought maybe there was a chance he knew. He said to google why the list wasn't populating. I did that. I read a post that among other things, said that you must have an administrator account. I went to the cmd and typed "netplwiz", and a window popped up saying I am the administrator. So that's not the problem. I also went to check what version of windows we had, thought I would find it in the system window, and quickly discovered a possible reason, this copy of windows server 2019 on Proxmox does not have a valid windows key. So I figured that was probably the reason. 

Doug gave me a few seconds and told me to google what RSAT stands for, and when I did that, he added, that should get you started. 

Apparently RSAT is Remote Server Administration tools, and allows you to remotely manage server roles and features. 

Okay so from now on I google what acroyms mean and my difficulties troubleshooting are over? I just thought of a funny quote I had heard a few times but I didn't hear the whole quote, looked it up and it was from Full Metal Jacket, nope, a little too unsafe for work. 

The rest of the explanation for RSAT said that RSAT is a Windows application that uses snap-ins to tremotely manage the roles and features running on windows server. So I googled "how to install snapins windows server 2019". 

Okay now shut up for a second because I have to actually do what it says now and there's only fifty five minutes of class left and I really haven't actually accomplished anything yet. 

Says to install snap-ins you go to the MMC, which is the Microsoft Management Console. I am familiar with that, just did a few test questions on it in class like a month ago and so I did a quick research assignment and took notes to understand what it was. So I was familiar with it even if I didn't know how to use it with ease. I have seen it in the past and all that but never actually got accustomed to using it, barely knew it had a name. 

I went start button on windows 2019 and started typing mmc, and the group policy manager came up, in the mmc. But I don't want to change the group policy manager or use the group policy manager to start messing with something unrelated, I needed an empty console window. I followed the google instructions more carefully and it said to go to run, so I went start menu and typed run, the run app cane up, typed mmc, and then a blank MMC window came up, ready to do something new. Great! Went file > add / remove snap-ins > click add, click okay, save for future use. 

Well, that's all done. Thought for a second I was going to have to band over backwards to figure this out. 

I overheard Doug saying all his friends are moving to Texas, now he and his wife are getting lonely. I told Doug he can call me anytime, I'll pepper him with questions on how to do stuff. 

I realized I didn't google how to install RSAT so I then typed how to install RSAT snap-ins. I got a new thing saying to go to the server manager window, which sounded similar but was not the same as the Active Directory Administrative Center I had already opened up. Yeah, I mean, not at all similar I guess. I opened an app named Server Manager and a new thing with the Active Directory in it came up. 

It said to go to Manage at the top of the window and to the right, kind of backwards instead of being on the left > then go add roles and features > a wizard comes up, select ...

Well guess what, it's almost like I said something like this was going to happen. Doug came by and told me to search RSAT again, scroll down and select this one Microsoft troubleshoot page and showed me that in the instructions, it says to use RSAT Tools, and he had me scroll to a point on this Microsoft instruction page to what those RSAT tools included. A list showing AD DS and AD LDS tools include the following tools:  Active Directory Administrative Center, Active Directory Domains and Trusts, Active Directory Sites and Services, Active Directory Users and Computers, ADSI Edit, and Active Directory module for Windows PowerShell. 

He showed me that when I first started working, I actually saw these tools already when I went to the search button and typed active directory, and things including the Active Directory module for Windows PowerShell came up. Then he deleted that and typed users and the option to select Active Directory Users and Computers. A new window appeared that was basically an MMC console window but populated with the users and computers. 

He showed me that when my team and I last Thursday created a whole bunch of IT users in the IT OU or organizational Unit, all we needed to do since all those users were in the Information Technology OU, I just needed to create more OU's and name them accordingly: Marketing, Financial, Human resources, Operations, Administration, and Janitorial. 

I did that and at first I was right-clicking on the above selection in the side-panel that all these OU's were located in, and then selecting New > and selecting Organizational Units. A window would pop up for me to name and then by the time I got to the Operations OU, I decided to get creative and instead click on the Action button up top and left on the window and go New > Organizational Units > typed Operations and pressed enter. Then the Operations OU appeared as a sub folder or unit or whatever under the previous OU I created, Administration. I tried to delete it and was told I didn't have sufficient privileges to delete it. 

Doug said this was a great learning opportunity. He had me g to connect another OU just to show me something in the Window, and there was a checkbox under the place where you name the folder. This checkbox was for protecting containers from accidental deletion. 

Then he had me right click on the accidentally created OU so I can see how in the properties box, there were only three tabs including General, another that said COM something and then a third one. But then he had me go to the View option on the top left of the Console Window > check the option that says Advanced Features, and then go back to the options window for the mistakenly created OU and now all of the sudden there were a lot more tabs. Here there was a tab called Object, and in it was that same checkbox from earlier "Protect object from accidental deletion". Doug had me uncheck this box, hit okay and then delete it. 

He went on to say that everybody misses that but it's in a weird place, it is right in front of you and not at all in a place that's easy to find. 

Ticket done. He said I could close the ticket and mark it as resolved. 

This has been Truncat3d 00000000111100010100110______________end of line

No comments:

Post a Comment

2025-07-10 - Active Directory 5.0 - Group Policy Foundations: Understanding Domain Admins and User Accounts / Setting up Remote Access

  Why You Use TESTLAB\Administrator Across Multiple Machines — And Why You Need Separate Domain Users When you join a workstation to an Act...