ADAC and Course Intro
In this video, we'll introduce this course, which is adjunct to the core material shown below as the foundation.
Knowledge Check
What is the primary use of the Active Directory Administrative Center?
Navigate ADAC
Navigation of ADAC might take a little getting used to if you're accustomed to Active Directory Users and Computers (ADUC). However, you'll find that it is more feature-rich and more details are surfaced in the UI compared to ADUC.
Knowledge Check
Which of the following are features of the Active Directory Administrative Center (ADAC) compared to Active Directory Users and Computers (ADUC)? (Choose three)
Active Directory Recycle Bin
Although you can enable and use the AD Recycle Bin from PowerShell, it is much easier to both enable the recycle bin and recover objects using ADAC.
Knowledge Check
Active Directory Recycle Bin operates retroactively - it can recover tombstoned objects deleted prior to its activation.
Fine-Grained Password Policy
Typically, passwords are set via the Default Domain Policy as a GPO setting. However, you may have certain users or groups that require differing requirements than the rest of the organization. That's why we have fine-grained password policy.
Knowledge Check
Why might it be necessary to configure a fine-grained password policy?
Bulk Operations and PowerShell
You can do many of the same bulk operations in ADAC as you can do in ADUC, but the fact that all actions in ADAC are actually PowerShell-backed functions, it can be very handy to use the PowerShell actions as the basis for other actions.
Knowledge Check
PowerShell actions shown in ADAC can be used as the basis for similar PowerShell actions you want to perform, such as in a script that you want to write.
Validation
For this validation, launch the lab that appears below. The goal is mainly for your to experiment with what ADAC is capable of and how it can make the Administrator's tasks easier. So you are free to roam around and see what's there, but I'd also like you to try doing a few of the tasks below.
- Enable the Active Directory Recycle bin
- Locate any user account
- Identify the current update sequence number (USN) of the account
(under "More Information" for the account) - Delete the account
- Recover the deleted account from the Active Directory Recycle bin
- Locate the new USN of the account
- Create a fine-grained password policy
- Apply it to a specific user account
- Bulk add a few user accounts to a department (e.g., IT, Sales, etc.)
- Peruse the actions you have taken as shown in Windows PowerShell History
View Transcript
ADAC and Course Intro
0:00All right, so as we get started in this particular course,
0:03I want to point out first of all that this,
0:05as well as a few others that I have not recorded yet,
0:08are going to be add-ons to the original core material.
0:12That course is called Windows Server Administration
0:16Core Infrastructure for Enterprise IT.
0:19Yes, it's a long title and I had to look off screen
0:21to remember how to say the whole thing.
0:23I'll try to remember to link that down below here somewhere.
0:26The reason why I bring this up
0:27is because this whole course,
0:30starting with the core course that I just mentioned,
0:32is designed to bring someone from a beginning level
0:35of a server administration
0:37into a little bit of a higher level.
0:39So maybe, for example,
0:41you've been working the help desk for a while,
0:42you're kind of ready to get off the help desk,
0:45but you don't have a lot of server experience yet.
0:47Well, that's what this course is for, okay?
0:49So that core course is for you.
0:51And then this course,
0:53which revolves more around Active Directory topics,
0:56is going to get you a long way towards server administration.
1:01So again, I want to point out that these are all fundamentals.
1:06And even though everyone talks about the cloud and AI
1:09and everything going in that direction,
1:12you're always going to have some degree
1:15of local servers to administer.
1:17I just don't see a way around that.
1:19And even if you do move mostly towards the cloud,
1:22those servers are also very often going to be
1:25Windows Server 2025
1:26or whatever the next version of server is.
1:29So fundamental knowledge about servers
1:32is going to be critical to all of that
1:34and on-premises or not on-premises, okay?
1:37So that having been said,
1:39let's move here into the first portion
1:42of this particular course,
1:44which is going to revolve around
1:46Active Directory Administrative Center.
1:49So how do you actually get to that
1:50and what's it used for?
1:51Well, it's primarily used to manage the objects
1:54within Active Directory.
1:55It is largely a replacement
1:57for Active Directory Users and Computers
2:00or ADUC or ADUC,
2:02as we sometimes call it as well.
2:04And you can still use that by the way.
2:06That's kind of the old school MMC-based tool
2:10that we would use.
2:10Actually, I'll show it to you.
2:11It's pinned right down here on my taskbar area.
2:14And this is what the original looked like.
2:16Now, also I'll point out
2:18that in the original core course
2:20that I mentioned earlier,
2:22we talked about this a little bit already, okay?
2:23But I'm kind of reestablishing some context here
2:26in case you haven't seen that course
2:28or you don't really even want to go into that course.
2:31I still recommend it.
2:32But if you want to just jump right in here
2:34to the Active Directory stuff,
2:35well, here we are, okay?
2:36So this is how I used to administer
2:39Active Directory for decades, okay?
2:42Active Directory Users and Computers.
2:44In fact, maybe it's my age.
2:47Maybe I'm a little resistant to change
2:48like a lot of other folks are.
2:50So moving over to
2:51Active Directory Administrative Center,
2:54I'll use it sometimes
2:56and sometimes I won't, okay?
2:57Sometimes I just kind of still gravitate back
3:00towards this old method right here.
3:02And so if you wanted to edit a user,
3:04for example, you double-click on it,
3:05you get this kind of tabbed interface and everything.
3:08And the whole thing, you know,
3:09the MMC console whole UI
3:13and way of doing things is a little bit
3:15year 2000-ish, okay?
3:17Which makes sense because that's when Windows,
3:20as we currently know it,
3:21came out anyway.
3:23However, we want to move on
3:25into more modern ways of doing things.
3:27So with that, we'll move into
3:30Active Directory Administrative Center.
3:32And, you know,
3:33Microsoft has changed a lot of different things,
3:34including even their Start menu here.
3:37So you just aren't going to find it right here
3:39when you first click the Start menu.
3:40You're going to need to go to All
3:42and then you can go down here
3:44to Windows Tools, okay?
3:46Once you're in that,
3:47it really just opens up this window
3:49and there it is,
3:49Active Directory Administrative Center.
3:51Which I've also pinned to my taskbar area.
3:54You can see it's already down there.
3:56Otherwise, it would say Pin To,
3:57but I have the option to unpin it.
4:00So anyway, it's already there.
4:02And I will point out,
4:03even though Microsoft calls this
4:05the more modern way of doing things
4:07and, you know, a little bit more up-to-date and all,
4:10it's actually been around for several years.
4:12And this is my opinion.
4:15Microsoft has never been known for the best UIs.
4:19That's why we have the macOS, okay?
4:21And a lot of the Linux operating systems as well
4:24have really appealing
4:25and easy-to-navigate UI nowadays.
4:29But Microsoft still has whatever this is, okay?
4:33Now, apart from that little minor jab
4:35against Microsoft for their UIs,
4:38let's get a look at this and what it is.
4:40And it is still a value.
4:41I don't mean to put it down entirely.
4:43So we start off with the Overview page here.
4:46And the first thing that we have here
4:47is a little tile that says Learn More.
4:49And these are just links
4:51to different places you can go
4:52to learn more about different functions
4:55within this particular tool.
4:57So if you're just trying to access
4:58some more information,
5:00that's where you would want to go.
5:01But most of what we'll be doing
5:02is really over here on the left.
5:04Now, also I'll point out,
5:06yours is not going to look like mine
5:07if you have one already.
5:09So by the way,
5:11we'll have a Playground Lab
5:13attached to this particular course,
5:15which is just a couple of servers,
5:17a couple of clients.
5:18And you can use that to poke around in here,
5:22administer something,
5:24figure something out.
5:25Just kind of, it's a playground, right?
5:27It's just a place for you
5:28to experiment on your own.
5:30And don't worry about breaking anything
5:32because all you have to do
5:33is to reset the lab
5:35and it'll go back to the way it was
5:37when you first started to work with it.
5:39I'll also include labs
5:41throughout this course in various parts
5:43so that you can get
5:45some hands-on experience there as well.
5:46Because you don't want to mess with this
5:48in a production environment.
5:50You want to be able to experiment with things
5:52and play around with things
5:53without an impact in the real world.
5:56Now, the other reason why
5:57mine might not look like yours
5:59is because most of what we'll see here,
6:01first of all, let me show you this.
6:03See these two little things
6:05you can click on?
6:05I don't even know what you would really call those.
6:07But we're currently in the list view.
6:09With the list view,
6:10it'll show you the most recently accessed portions
6:14of the UI that you have visited.
6:17There's not really a graceful way to reset this.
6:20You can delete a specific folder
6:23in I think it's app data folder.
6:25It's kind of clunky and awkward
6:27and you don't really just want to do that all the time.
6:29I thought about doing that here
6:30because I wanted to kind of start
6:31with a clean environment.
6:32But on the other hand,
6:33you're going to see this fill up
6:34as you use it anyway.
6:36The other thing you can do though
6:38is you can go over here to the tree view
6:40and that's a little bit more hierarchical
6:42in what you're accustomed to seeing.
6:44So here we're seeing a lot of
6:45the different same hierarchies you might see
6:48in Active Directory users and computers
6:50and stuff like that.
6:50Okay.
6:51So it might just be a little bit more familiar for you
6:54and something you might want to access that way.
6:57All right.
6:58So that is an introduction
7:00to how this whole thing works.
7:01If I click on, for example,
7:03the domain right here
7:04and I've only got one domain,
7:06but you may also have multiple domains
7:07in your environment.
7:09We also get a little bit of a hierarchy here.
7:11I just don't think it's as navigable
7:13as the tree view.
7:15But Microsoft seems to really like us
7:17to use this view.
7:18All right.
7:19So when we get into the next video,
7:21we'll start to explore some more specifics
7:23about this whole UI
7:24and how to make it work to your advantage.
Navigate ADAC
0:00All right. So we got started in our last video
0:02by taking a look at Active Directory Administrative Center.
0:05We saw a little bit about
0:07the navigation basics there, but not a lot.
0:09We saw that we can open that from the Server Manager tools.
0:12Notice that I also did pin mine to
0:15the taskbar area because I expect to be able to use it a lot,
0:19and I don't want to have to fish for it every time I want to use it.
0:21You can also add navigation nodes
0:24for the various domains that you might have.
0:26So in a forested environment,
0:27this will be a little bit easier than
0:29Active Directory Users and Computers
0:30because the focus there is on a single domain,
0:33whereas in a forested environment with multiple domains,
0:36you have a little bit better navigability there.
0:38Now, I only have the one domain of nuggetlab.com
0:41for our particular labs and all of that stuff,
0:43so that's all we're going to really be working with here.
0:45You also have a couple of different views.
0:46First of all, there's the tree view for
0:48the basic containers themselves, organizational units,
0:51all the other containers, stuff like that.
0:53Then the default view here would be the one we saw in
0:56our previous video where it's a list view,
0:59and that's, again, also usable for just listing the objects.
1:04Now, it's a little bit of a six one, half dozen of the other.
1:07You pick whichever one you're more comfortable with,
1:10and there's not really a right answer to choose
1:13one or the other in every instance anyway.
1:15It depends on what kind of objects you're trying to access.
1:19We'll look at all this here in a moment.
1:20There's also the preview pane for the details.
1:24I will say this as well about
1:26ADAC as opposed to Active Directory Users and Computers,
1:30you get more information in the same screen,
1:34if you will, than you do with Active Directory Users and Computers.
1:38That's one of the things that's very useful in terms of making
1:42something more navigable is to just have more information.
1:47That's one of the good advantages there.
1:49You can also globally search across a forest,
1:52which again would include multiple other domains there.
1:56I'm going to go ahead and open up again
1:57Active Directory Administrative Center.
1:59Let's just take a look first of all.
2:00Now, again, remember all this stuff right up here is just educational.
2:03Let's just, if you want to go to
2:04Microsoft's web page about various things.
2:07But you can see right from the beginning here that we have
2:10more usability here because what do administrators frequently do?
2:15Well, frequently, we have to change somebody's password, don't we?
2:19They'll probably always be doing that,
2:20whether you're on a help desk,
2:22whether you're further up in IT.
2:24This is just stuff that we have to do all the time.
2:26I do find it interesting though,
2:28Microsoft did try to,
2:31when Active Directory first came out years ago,
2:33they tried to steer us all towards
2:36user principal names which look like e-mail addresses.
2:40So it might be phoenixusers01 at nuggetlab.com,
2:43phoenixusers08 at nuggetlab.com, something like that.
2:47Here, however, it seems like they just want you to use
2:50the old method here where you just enter in
2:54the flat name of the domain in the pre-Windows 2000 method.
2:58So it would be just like this, nuggetlab,
3:01backslash, and then the name of the user.
3:04Let's say phoenixusers08 here.
3:06Not case-sensitive, of course.
3:07So then I would just enter in the new password.
3:10This is just, again,
3:12an area where ADAC is very handy
3:14because it puts right to the beginning here,
3:16right in the first page that we access,
3:19the ability to do something like change that password
3:22without having to fish for that account.
3:24Because this account, it could be buried under five,
3:27six, 10 different organizational units
3:30in terms of its whole hierarchy.
3:33So it makes it a lot easier to navigate that way.
3:36Then you would just enter in the password and choose
3:38whether the user has to change
3:40the password of the next logon or not.
3:41If it's been locked,
3:42you can unlock the account.
3:44Mine hasn't been, so there's no sense in selecting that.
3:46It won't let me anyway.
3:48And then I simply click Apply.
3:50Bam, that's it.
3:51I didn't have to fish for the account.
3:53I didn't have to drill down through all kinds of hierarchies.
3:56It just does that right away right there.
3:58Also, this is a global search.
4:00Now, this again will help me to search an entire forest.
4:03Again, I only have the single domain,
4:05but imagine a organization that has a forest root
4:11and then, I don't know, six, eight,
4:1210 different subdomains underneath that.
4:15They kind of branch out underneath it
4:17in a tree-like structure.
4:19Well, that's a lot of click-through
4:21to get to what you want to find.
4:23But I'm just looking for, let's say, a specific user account.
4:26Let's make a Tucson user 05 or 04 and press Enter.
4:31Bam, it just finds it right there.
4:33Again, prevents me from having to drill down
4:36through an entire hierarchy
4:38or to fish for the right domain, all that kind of stuff.
4:42And of course, from here, I have other options,
4:45which we're not gonna investigate all of this right now.
4:47I think most of those are pretty well self-explanatory,
4:50but there they all are regardless, okay?
4:52All right, so again, very, very handy way
4:56to be able to manage things like our accounts.
4:59Now, don't fear.
5:00If you do like to just kind of navigate
5:02your way through things, you can still do that.
5:04So if I expand this little arrow right here,
5:06click the little arrow right there,
5:08then it will give me the opportunity
5:09to expand out other things.
5:12So for example, I was at Phoenix Users.
5:15Now, since I was there recently, it pops up down here.
5:18Anything that I've accessed recently
5:20will show up down here.
5:22Tucson Users, Phoenix Users, and so forth.
5:24But if I have something else that I access frequently,
5:27like Phoenix Desktops, I don't actually have any right now,
5:30but if I did, I could pin that,
5:33and then now it'll appear right here,
5:35and it's a pinned item.
5:37Again, for easy access in the future.
5:40Oh, I guess I have desktops after all.
5:41I got four of them, in fact.
5:43If I want to unpin it,
5:44I simply click the little pin button again,
5:46and it unpins it, but it does still show up right here.
5:49Why?
5:49Because remember, it was used most recently.
5:51Now, a couple of other things I'll point out
5:53just briefly here,
5:54but we will get into that in a different course.
5:57It's also adjunct to this course,
5:59and that would be this dynamic access control
6:01and authentication.
6:02These are simply additional ways
6:05to secure your environment.
6:07So for example, the dynamic access control
6:10takes us way beyond just things like NTFS ACLs,
6:13access control lists,
6:14where you can give someone read access,
6:17change permissions,
6:19all the different kinds of permissions
6:21that you can apply there.
6:22Well, this takes it beyond that even,
6:25and allows you to say, yes, they can access it,
6:28but they also have to be a member of,
6:29I don't know, a certain department.
6:32So they have to be a member of IT,
6:34a member of HR, a member of sales, whatever.
6:37And one of the advantages of that as well
6:40is that you can create a security group
6:44for those users as well,
6:45like the sales users, all that kind of stuff.
6:47But sometimes we don't need to get that granular,
6:50or we want to just apply a specific property
6:53of a user's account for it to check against
6:55to see if they should access this.
6:57It has some similarities to simply
6:59creating a new security group
7:01and dropping the user in that security group,
7:02but it's a little bit more granular here as well.
7:05Now, let me go back to one of our users.
7:06Let me go to one of the Tucson users here,
7:08Tucson user seven, let's say.
7:10I don't know if you saw it,
7:11but just notice that as I parked here for just a moment,
7:14it popped up Tucson users right up here
7:16at the top of the list.
7:18Because again, I'm using it recently here.
7:20He's gonna ask a little summary.
7:22Most of the accounts that I've created here
7:23are just for lab purposes.
7:25So all of the details have not been filled out,
7:27like the office that they're in,
7:29or their email or webpage, all that kind of stuff.
7:32All right, I just filled in enough to create the accounts.
7:35By the way, these were all created in my previous course,
7:40the core, the server core course, using a script.
7:44And as you can see here,
7:44the only two actual requirements by the red little,
7:47I guess, mauve colored little asterisk right there
7:51are the full name of the user, which I have right there,
7:54and the SAM account name,
7:56which is another way to describe the domain backslash
8:00username, this whole format right here.
8:03And there you have that.
8:05But again, one of the efficiencies that we have here
8:07is that everything is, or not everything,
8:09but most things that we want to access
8:11are in the same UI right here,
8:13as opposed to something like ADUC,
8:16where we would have to click between various tabs
8:18and kind of fish for things a little bit more.
8:20Anyway, I'll leave that to you to further explore
8:22if you like.
8:23Notice another thing we have here
8:25is that there's a more information item
8:28that we see down here.
8:30And again, we get more granularity
8:32in all of these details down here.
8:34I tried to make the native view of this
8:37in a little bit bigger font as much as I can,
8:39but it is all just kind of famously very small.
8:43So I will zoom in whenever it makes sense
8:46to make it more visible.
8:47But again, so for example, here's the canonical name
8:49where it shows us kind of the breadcrumbs, if you will,
8:52to be able to access the location of that user
8:54using forward slashes.
8:56The alternative to that would be the distinguished name,
8:59which would name it something like
9:02OU equals Tucson users,
9:04OU equals Tucson,
9:06OU equals AZ,
9:08domain component equals com,
9:10and domain component equals Nugget Lab,
9:11that kind of stuff.
9:12Now, I haven't actually used this account.
9:14That's why it says it's never logged on.
9:16Let me try to find an account that has been logged on
9:18at one time or another,
9:20get a little bit better look at that.
9:21For that, I'll go into Phoenix.
9:23I think I've used my admin account recently here.
9:25So let's go to phoenixadmin01.
9:28And we can see here again,
9:29if I go down to more information,
9:32that yes, indeed, we have had more logons here.
9:35In fact, I've had 87 logons with this test account.
9:39When it was created, when it was modified,
9:41also we even have a bad password count,
9:43which by the way,
9:45if you have entered in the wrong password
9:47a couple of times,
9:48and then you log on and you say,
9:49oh, yeah, you know what?
9:50Now I remember the password.
9:51And you entered in correctly,
9:52then it clears this and resets it back to zero.
9:55So this will only show a number down at the bottom there
9:58if someone has logged in with the wrong path
10:01or tried to log on with the wrong password,
10:04and were never successful.
10:05Again, we also see additional details down here.
10:08I won't exhaust all of this.
10:10I'll just leave that to you.
10:11But you see a lot of the other additional items there
10:14that are also very handy,
10:15such as the SID,
10:16which is a unique identifier for each user account.
10:20Anytime I make a change to this account,
10:22it'll also change the update sequence number.
10:25This is how it is able to keep track
10:28of what's changed in an account
10:31or any other Active Directory object,
10:33and thereby can also synchronize it
10:34with other domain controllers that we have.
10:36So if another domain controller looks at this,
10:38and let's say that it's a current update sequence number
10:42was 12,000, what is that?
10:44No, 122,930.
10:49Then it will say, oh, well, this one's 934.
10:52Therefore it must be more current.
10:53So I'll need to pull down whatever has changed
10:56from this account, probably like a password change
10:58or group membership or something like that.
11:00So again, more data that we can work with,
11:02and it's a little bit more accessible
11:04than what we had in Active Directory users and computers.
Active Directory Recycle Bin
0:00All right. So one of the problems that we sometimes have in Active Directory is that
0:04even experienced administrators can make mistakes, right? I mean, we're all human,
0:08and sometimes something gets deleted that we really shouldn't have deleted
0:12and can have a pretty big impact. Now, there is the Active Directory Recycle Bin,
0:16which as the name implies, is similar to what you would get with the Recycle Bin that's on
0:20your desktop. So if you delete a spreadsheet and you want to get it back, it's in the Recycle Bin.
0:24Just retrieve it. That's all you got to do, right? Similarly, we can now do that in Active
0:29Directory as well. I think this came out in, I want to say 2008, Server 2008. It might have been
0:34R2. Because prior to that time, we did not have a way to recover these objects. You could recover
0:40them, but it would have to be done through an actual recovery, a backup and restore operation,
0:48okay? And it got to be kind of messy at times as well. So Recycle Bin is a cleaner way to do this
0:54to recover an accidental deletion of an object. It could be a simple user account. It could be
1:02an organizational unit. It could be a parent organizational unit like this with multiple
1:08other organizational units and users and other kinds of accounts and all kinds of things,
1:14computer objects, all kinds of things. There could be thousands and thousands of accounts
1:20and objects underneath this parent. So if you delete that parent, you lose all of this,
1:24right? Devastating when that could happen, all right? Now, there's not really a lot of
1:31anecdotal evidence for this because when organizations have a deletion like that,
1:37they don't like to advertise that or brag about it. Oh yeah, we deleted this
1:42organizational unit and lost thousands of user accounts at the same time.
1:46Isn't that hilarious? So organizations don't like to publicize that. Nevertheless,
1:51I think you know that it happens and it can have a devastating effect because this is what's going
1:55to happen. All the users, and by the way, computer accounts if they're in those OUs,
2:01well, they can no longer log in. They effectively become a nobody, okay? As far as Active Directory
2:07is concerned, you don't exist anymore and your computer doesn't exist either. This could also
2:14affect, of course, various applications you need to use because most applications
2:19have to have some kind of an authentication involved with them. And especially I'm thinking
2:23of things like a web app or something like that that might depend upon Active Directory for some
2:28kind of authentication to occur there. Another thing that would happen is you're no longer
2:33subjected to group policy objects. Well, because of the fact that you don't exist anymore,
2:39a group policy object won't apply to you either. It could be security settings that now disappear
2:43as well. So there's a lot of cascading effects that can happen here when you have an accidental
2:51deletion like this. And in addition, if you do not have the Active Directory Recycle been enabled,
2:57and I'll show you how to do this coming up, then what objects get deleted, they become what we
3:02call tombstone and then there's a time limitation on tombstone objects. So a tombstone object is
3:09pretty much like a car that's had the engine removed. It's not really worth much anymore.
3:16What happens is those tombstone objects have all of their attributes stripped, group memberships,
3:24any of the other attributes that are part of that account. To recover that account then could take
3:30hours or sometimes days. It depends on the size of the organization and the availability and
3:36recoverability of your backups. And even with the backup, it's kind of a mess. So what do we
3:42do with this? Well, when we do have a recovery that we can do with the Recycle Bin, we can get back
3:47most of the common objects that you would want to recover that get deleted. Things like user
3:52accounts, groups, organizational units, and child organizational units like this.
3:58Some things to keep in mind and some limitations are it's not retroactive. So for example,
4:03before we started recording, do I have it? I have it here. Yeah. I ran this, well, it's kind of a
4:09long to scroll all the way up. So this is what I ran right here down at the bottom. I just wanted
4:14to see if there were any objects that were deleted. Okay. So I ran this PowerShell command,
4:19let get AD object. The filter is, is deleted true. And I want to show those deleted objects.
4:26And then this is what it dumped out. These are all a bunch of things that I've deleted. I don't
4:30even remember what all of them are, but I did delete one thing recently, and that was Tucson
4:34user 10. Okay. Now again, this is really just what we call a tombstone object. So it's really not
4:42very useful just to recover that account in any other way than to use a restore operation from a
4:50previous backup that was made of Active Directory. A better way to do it though, is to use the Active
4:56Directory Recycler. But now there is a way to enable this apart from Active Directory
5:01Administrative Center. We've had this before we had Active Directory Administrative Center,
5:06and you could enable this from Active Directory, excuse me, from PowerShell. This is irreversible
5:12by the way. So once you enable it, you can't disable it. Although I don't know why you'd want
5:15to. So first thing you have to do is to import module Active Directory. If it's not already
5:20present, I think I already had it, but I went in and ran it anyway and nothing seemed to happen.
5:25So I think I already had it. Anyway, then I wanted to enable an AD optional feature,
5:30and then there's a backtick here. In PowerShell, a backtick means that I can press return and add
5:38additional parameters or options to the PowerShell commandlet. Otherwise, all of these things,
5:44next to these double arrows, all of these things would be on one line all the way over here.
5:48I probably could have done it in this case, but sometimes it runs way over the edge of the
5:53border of the window, and I guess it'll be a little bit hard to read. But anyway, what we're
5:57enabling is the Recycle Bin feature. It is a forest-wide option, so bear that in mind. You
6:03don't do that on only a single domain. It's an entire forest and all of its child domains,
6:08if there are any. And then you would target it to whatever the root domain is. In my case,
6:13it's nuggetlab.com. I'm going to control C to get out of that because I don't want to actually
6:17press enter, accidentally press enter, because I don't want to do it that way. What I'd rather do
6:22is to go here in Active Directory Administrative Center and simply choose Enable Recycle Bin.
6:29Are you sure you want to perform this action? Once you've done it, it cannot be disabled. Kabam,
6:34and it is now done. Now, do bear aware of this message here. It's been enabled for this forest,
6:41but in an enterprise environment with lots of domain controllers and child domains and all
6:44that kind of stuff, it may not function reliably until all domain controllers in the forest
6:51have replicated. This can take hours. If you're a large global organization,
6:55it's probably going to be hours, maybe even days before it completely propagates throughout your
7:01entire forest. Just bear that in mind. Now, once that's been done, I also need to refresh this.
7:06I'm actually just going to close it and open it up again after a couple of seconds here.
7:11And then now, once I go into Nugget Lab here, I should see deleted objects. Now,
7:16I don't have anything there, even though you saw that I had a TucsonUser10, I think it was,
7:24had been deleted. But remember, that was a tombstone to objects. Let me delete another
7:27object. Let me go to a different Tucson user. So I'll select TucsonUser9, and I'll delete that
7:33object. You want to delete that object? Yes. Now, I'll go back to deleted objects, and there you go.
7:39There's TucsonUser09. Restoring it is quite simple. Notice that over on the right,
7:44I have a couple of options there. Restore, restore to, locate the parent, properties.
7:50That might be handy because I might not be sure that that's the right account that I want to
7:55recover. So I can right-click on it, look at its properties. I don't even really have anything in
7:59there, so there's not much to show because these are just kind of emptied out accounts. I can
8:03restore it to a different location. So I can decide, you know what, that user has moved anyway,
8:10they've moved to Phoenix, and I'm going to have to change their name anyhow. So I'm going to put
8:15PhoenixUsers. I could do that if I want. I can also locate the parent, and that will tell me
8:21where they were located. Here you can see we are now in TucsonUsers, and if I go to the tree view,
8:28we'll see that a little bit more explicitly right here. I'm glad I thought of that because I don't
8:32think I ever actually showed you the difference between these. Maybe I did, but I forgot. But
8:36anyway, just two different ways to look at the objects. Actually, I did. I think I remember
8:40right now, and now I'm going to just restore it. Bam, it is now restored to TucsonUsers,
8:46and there is TucsonUser09. Now, this might be a good time to show something else as well.
8:53If I go down here, if I double-click on the account, and now I go down here to more information,
8:58we'll see here that the update sequence number is quite high, 143, is that right?
9:05Yeah, 143,582. Every time you make a change to an account, it increments that. By the way,
9:11it doesn't usually increment it by just one. It's usually kind of significant,
9:16but it was first created. It was 25,049. Now, why am I pointing that out? Because when you restore
9:25an object, it has to increment the update sequence number by quite a lot in order to guarantee that
9:31it can properly replicate to any other domain controllers. There are instances in which,
9:37just imagine if we only incremented it by one number, so 143,581, 582, 583, like that.
9:46Well, in the time that it took me to delete that object in the first place, another administrator
9:51on a different domain controller may have changed something about that account, changed group
9:54membership, password, whatever. But when they change it, it also increments it.
10:00So they may have beaten me to the punch where they're already at 143,583 when I restore this.
10:08Well, that makes my object that's been restored look old. Therefore, anything that they did with
10:14it, we could overwrite this one. It gets to be kind of messy because you can start to get into
10:19some collisions and stuff like that. So that's why it increments it by a kind of a high number.
10:24Now, as an example, let's look at TucsonUser08, which I created at the same time I created
10:29TucsonUser09. And if I look at that one and go to more information, notice that here,
10:35it is a significantly lower update sequence number. So usually, it increments it by at least
10:40100,000. And that just helps to guarantee that in the synchronization process with other domain
10:46controllers, it's not going to accidentally look as if that's old information. The same would
10:52happen, by the way, if we did a directory services restore mode restore, which is a special kind of
10:58restore you can do from a Active Directory backup. When you restore it, it's called directory
11:02services restore. It does a similar thing, increments it by quite a lot. Now, I kind of
11:07got off track here. So again, it's not retroactive. That's what I was showing you there with
11:12the TucsonUser10 account. I really can't get that back from the recycle bin. There are other
11:17ways to do it, but not through the recycle bin. However, you saw me recover the TucsonUser09
11:21account because that was in the recycle bin. When you delete an account, it normally has a 180-day
11:28tombstone lifetime. And that's just to keep the object present. Even though all the attributes
11:35have been stripped out, this is without the recycle bin, it keeps the object around just
11:39kind of as a husk, just a shell of what the account used to be but without any attributes. Why?
11:45Because it needs to reflect the fact that on this domain controller here, I had a user account
11:51that we 86ed, we deleted. Sounds kind of fatal, but anyway, we delete that account. Well, we have
11:58another domain controller over here in some other continent or whatever. If we were to delete that
12:04user account and leave no trace whatsoever of that account, this other domain controller would still
12:10have that account. And then we would have a real synchronization issue here that would be all broken
12:16because we insist the account still exists. We insist that the account was deleted. What's going
12:22to happen? Okay. It just causes some Active Directory issues there that you really don't
12:26want to tangle with, believe me. So really, we have these tombstoned objects where they're tombstone
12:32because we need to use a garbage collection process to notify the other domain controllers
12:36that the object is actually deleted. And remember, the attributes will be stripped.
12:41So that's why we need a recycle bin because we want to get the attributes back as well. Otherwise,
12:46you might as well just recreate the account or use directory services restore mode to get that
12:51account back, which is a little bit messier, but doable. If there are nested OUs, well,
12:57this can get complicated. Okay. It doesn't have to be. So if I have an organizational unit here
13:02and another one here and another one here, let's say, if I deleted this top level OU,
13:08it will also delete the child, the children OUs and any of their contents, any of their objects.
13:14But if I recover that OU, then in turn, it should also recover using the recycle bin,
13:21all of these other child OUs and their contents. But if we messed it up and we deleted this,
13:30which in turn deleted this and which in turn deleted this and all the objects,
13:33if we only recovered this child OU, maybe we didn't realize that the parents were also deleted.
13:40So we recovered only this child, then it causes, again, kind of a problem because kind of this
13:47phantom organizational unit that doesn't really have a connection to its parents. I'll get into
13:53all the details with that, but again, it can get kind of messy there. And you may have to go to
13:58a more manual process to recover those. You'd have to recover manually the parents,
14:04the other objects, all that kind of stuff. And if it's a complex restoration where you have a lot
14:08going on with it, you probably need to go back to PowerShell instead of using the Active Directory
14:13Recycle Bin directly in ADAC. Although, ADAC is definitely the easiest way to go.
Fine-Grained Password Policy
0:01All right, so here I've got my virtual machines running.
0:04This is what I've been using for the whole course, really.
0:07And there's a server here, actually a workstation,
0:09I should say, a Win11-01.
0:12It's got all the administrative tools on it.
0:14It would be something that an administrator would use.
0:17Most of us don't actually sit at a server.
0:20We sit at a workstation,
0:21and then we have these server tools installed there
0:24that allow us to remotely connect to our servers.
0:26But as you can imagine,
0:28even though it's just a lowly workstation,
0:30pretty security sensitive
0:31because of who's logging onto it, right?
0:33So for example, I'm gonna log on as phoenixadmin09, okay?
0:38And the password is something very, very secretive.
0:42As you can see right here, capital P at sign SSW0RD, okay?
0:48Not bad for a lab environment or whatever like that.
0:51I've really dumbed down our password policy
0:54just to make things easy
0:56and it's not a production environment.
0:58Of course, in production, we wouldn't wanna do that.
1:00Nevertheless, this might not be the best
1:02for an administrative account.
1:03Maybe phoenixadmin09,
1:05maybe they're a highly specific account
1:09that's an enterprise admin and a domain admin
1:11and all that kind of stuff.
1:12And we wanna lock that account down
1:15or we can apply this to an entire security group
1:18of administrators, for example.
1:20But anyway, you can see that I logged in just fine
1:23with that stupid password.
1:24Also here, I've gone back
1:25to Active Directory Administrative Center
1:28and let's go to phoenixadmin09 and I'll double click there.
1:31We'll see that if I click member of,
1:33sure enough, they're a member of domain admins,
1:34enterprise admins.
1:36That's a pretty weak password
1:38for somebody with that level of privilege.
1:40Even if it would be for other reasons,
1:42perfectly acceptable for my receptionist and my salespeople
1:46and other kind of generic users
1:49that we have in the cubicle farm.
1:51Not for this person though.
1:52So how can I tighten this up a little
1:55and make sure that we have good security here?
1:57Well, I can go back up here to the Nugget Lab local.
2:01And again, I can do this from the tree view
2:02or from the list view either way.
2:05And I'm gonna go down here to system
2:08and then there's this password settings container, okay?
2:11So once I double click that,
2:12I am now in the password settings container.
2:16If we take a look at the group policy management console,
2:19I'm gonna put a push pin in that for right now.
2:22I'm just gonna go to the group policy management console,
2:25gpmc.msc and take a look at our password policy,
2:29which is in the default password policy right here.
2:31That's where it is by default.
2:33Give me the default domain policy.
2:35And I'm gonna click on edit there.
2:36And if we click on the computer configuration policies,
2:40Windows settings, security settings, account policies,
2:44and then password policy,
2:46I could really dumb all of this down.
2:48And in fact, I'm gonna do that.
2:49Strip all of this stuff out.
2:51Some will be able to reset their passwords immediately.
2:55You can also, for some of these,
2:56just specify not to define the policy setting.
2:58That would be just as good there, okay?
3:01Password length, we'll just say
3:02even zero characters will be fine.
3:04Oops, I must've clicked too soon for that.
3:07There we go.
3:07Zero characters, no complexities required.
3:11I'll even disable that, okay?
3:13And so this is a really a horrible password setting, okay?
3:18And I'm exaggerating things a little bit here.
3:19You wouldn't do this in a production environment.
3:21But my point is, yeah,
3:23I could create an administrative account right now
3:26with these weak requirements for a password
3:29that might not be acceptable in any other context.
3:33So here in the password settings container,
3:36I need to set up a new password settings
3:37for my Phoenix Admin 09.
3:39And again, it could also be for a group.
3:41But I'll just say domain and enterprise admins.
3:45Then you'll also enter in a precedence.
3:48This is a little bit hard to describe,
3:49but you can actually have multiple levels
3:52of these passwords policies, password settings, okay?
3:56And you can set a number here.
3:58This is a little bit arbitrary.
3:59So I can say the number 10, okay?
4:02Now, if somebody is subject to both this policy
4:07and based on something like maybe group membership,
4:10they are also subject to a different
4:12password settings policy.
4:14Then whichever one has the lowest number
4:17would take precedence.
4:18So if there's another one that this user is also a part of,
4:22it applies to them in a couple of different ways,
4:25but the other policies are level nine instead of 10,
4:29like you see right here,
4:30then that other policy would take precedence.
4:33On the other hand, if there was another one
4:34that was, say, precedence number 11,
4:37then this one would win over there, okay?
4:40Now here you can see I'm setting up more requirements there.
4:45Let's say it's a minimum password policy of 10.
4:47You know, all of this is already more secure
4:49than our dumbed down policy,
4:50which I configured in the group policy management console.
4:54Password history of 24, must meet complexity.
4:58There's also this, by the way,
5:00protect from accidental deletion.
5:02We didn't use to have this
5:03when Active Directory first came out,
5:04but now it applies to a lot of different kinds
5:06of sensitive objects, user accounts even,
5:09organizational units, groups.
5:12Prevent things from being accidentally deleted.
5:16Minimum password age of one
5:18and enforce maximum password age of 42.
5:22Notice that we can also enforce an account lockout policy,
5:25which I didn't have before.
5:26So I can say, number of failed logon attempts allowed.
5:29Let's just say two.
5:31Oops, my alarm's going off.
5:32Sorry, hold on.
5:33Now I can't remember what I set it for.
5:34Was I supposed to be taking a nap right now?
5:37Maybe I should pause the screen and take a nap.
5:39Anyway, gosh, how old am I?
5:42Supposed to take a nap before they serve me my applesauce.
5:45So since it's a security sensitive account,
5:48you want to only allow two failed logon attempts.
5:51Maybe they fat fingered a logon.
5:52Maybe they remembered the logon incorrectly,
5:55the password that is.
5:56And since it's so sensitive, they only get two chances.
5:59After two failed logon attempts, it will lock that account
6:02and we'll have to find another administrator to unlock it.
6:05Or we can wait 30 minutes
6:08and then it would reset itself,
6:10but we'd have to wait 30 minutes of not being productive
6:13and sitting in the break room
6:14and gossiping about other employees and stuff like that.
6:18They probably locked themselves out on purpose.
6:20Okay, and similarly again here,
6:22the account is locked out for 30 minutes there.
6:24So sensitive admins, high security requirements.
6:31I'm just making stuff up.
6:32Okay, now we also have to decide who this applies to.
6:36So then I can add in, wherever I want this to apply,
6:40you'll have a good business reasons for doing this,
6:42but it's probably gonna be some kind of sensitive group
6:45like, I don't know, CEOs,
6:47or in this case, since it's IT related,
6:49let's say domain admins.
6:51So I'll just put in here domain admins, okay?
6:53And I'll just check the names and it checks out, okay?
6:56Click okay, and then there it is, okay?
6:58So I will now apply to all domain admins
7:01will have these password requirements
7:03if I wanted it to be that way.
7:05In my case, I really don't
7:06because I wanna keep my stupid passwords
7:09for demonstration purposes
7:11to make it easier for me to log in.
7:12Yes, it's all about what's easier for me, people.
7:15So we'll click on add here
7:16and I'll just gonna specify that one user,
7:18PhoenixAdmin09, I think it was.
7:21Yep, there they are, click okay.
7:23And now this specific policy
7:26will only apply to that one user.
7:30Now, believe me,
7:31I'm gonna pause here for a moment and talk about this.
7:33This has been the source of a lot of strife and arguments
7:38and darn near coronary heart attacks.
7:41I've seen in person, by the way.
7:43Yes, I've been right in the middle of these arguments.
7:45I did some consulting
7:47for a large defense contractor years ago now.
7:51And if I named them, you would know them right away.
7:53I had two administrators behind me.
7:56I was sitting at the desk
7:57and we were talking about this
7:58because we were talking about
8:00rearranging their whole Active Directory structure.
8:03And I had two administrators behind me
8:05while I was sitting at the keyboard,
8:07arguing back and forth.
8:08I can feel the spit flying back and forth here.
8:11And the guy on my right,
8:13he'd taken me to dinner the night before.
8:15And he was saying that I bought him a steak dinner,
8:19but I didn't realize until he started eating.
8:21He says, I'm not supposed to be eating this
8:22because I've got very serious heart issues.
8:25And the doctor doesn't want me to eat,
8:27I don't know, red meat or something, I don't know.
8:31It shows you how healthy I am.
8:32Anyway, so I knew that this guy on my right
8:35was very susceptible to a heart attack.
8:37And he is in this screaming match
8:39with this other administrator behind me
8:41all over things like these password policies.
8:44And they were also arguing about
8:46whether to consolidate into a single domain
8:48or multiple domains.
8:49At the time, this is years ago,
8:51they were arguing that,
8:52one of the administrators were arguing
8:53that they would have to have a separate domain
8:55because that's how we used to have to do this.
8:57In the past, if you had somebody
9:01that had separate password requirements,
9:03you had to put them in their own domain.
9:06So there were certain domains
9:08that only had a very small handful of accounts in them
9:11because those were the sensitive accounts.
9:14That's kind of a big set of overhead
9:17just for that one purpose.
9:19But who would you apply to?
9:20You know, IT admins, C-suite executives,
9:23CEOs, CFOs, CIOs, that sort of thing.
9:28People with different levels of security clearances,
9:30people who work on different sensitive projects,
9:33stuff like that, okay?
9:34So anyway, that was one example
9:36that I was telling you about with that defense contractor.
9:38I also ran into that with a large financial services firm
9:41that I was consulting for.
9:43They're kind of behind the scenes,
9:44you wouldn't know them if I named them,
9:46but they've got their tentacles
9:47in probably any financial organization
9:50that you will ever work with.
9:51Anyway, we're gonna do this just for Phoenix Admin 09,
9:55just to prove the point.
9:57Now I'm gonna switch over to that desktop
9:58and log that user out and back in again, okay?
10:02And by the way, what I'm using here is,
10:04you can see kind of in the background there,
10:06something from Sysinternals,
10:08and this is known as the Remote Desktop Connection Manager,
10:11and it just allows you to make remote desktop connections
10:13in one console instead of having separate windows
10:16for each connection.
10:17Anyhow, I'm logged back in now,
10:18and I just used that stupid password that I had before,
10:21capital P at sign SSWORD.
10:24Not the best password,
10:25but if I send a control alt delete there
10:28and change my password, I can enter in the old password,
10:32and the way the security policy is for all my other users,
10:35they could actually use a blank password.
10:38So I can try to submit that here,
10:40and it says it's unable to do so, why?
10:42Because the value does not meet
10:44the length, complexity, history, blah, blah, blah, okay?
10:46So it will not let me do that stupid weak password, okay?
10:50So there's my original password right there,
10:52I guess that's what it is.
10:54And you can see it right there.
10:55Now I have to make it something complicated and difficult.
10:59So I entered in a different password here,
11:01and you can see it right there.
11:03Still possibly a little bit easily guessable,
11:07but I had to enter this in, okay?
11:08It meets the complexity requirements,
11:10at least I think it does.
11:11And finally, I successfully changed the password,
11:13and we logged in, okay?
11:15So that only applied to that one user.
11:18Any of my other users could use a stupid password
11:20or a less secure password
11:22than what we set up for that one user.
11:25And that is the strength
11:27of using a fine-grained password policy.
11:29By the way, we don't really have it here
11:30because we don't need to,
11:32but you can also do all of this in PowerShell.
11:35It's just, why would you?
11:37You don't really set it in a lot of places,
11:40and it's just as easy or easier, really,
11:42to use the UI there in ADAC.
Bulk Operations and PowerShell
0:00Let's finish out here with a couple of simple items here,
0:03and one of those would be bulk operations.
0:06Now, we can actually do this as well
0:07in Active Directory users and computers,
0:09but just to finish it out here,
0:11we'll go with about Phoenix Admin 8-5 right here.
0:15With these several users right here,
0:18maybe we realized, I'm not sure we ever made them admins.
0:21I can right-click here and add them to a group,
0:25or maybe they're all disabled.
0:27I could disable them all and then enable them all,
0:30or maybe they're all locked out.
0:31I can unlock them all.
0:33I think you can see all those.
0:34Those are the options we have.
0:35I can also go to Properties if there's
0:38some other property we want to manage.
0:40Maybe they're all in the IT department.
0:43I would have to check that box and
0:45put them in the IT department.
0:47Now, likewise, I can also make them a member of a group here,
0:50but I'll just show you the different way to do that there.
0:52I'll just click, okay, now you can see if they're all in IT.
0:55I should probably do it for all those users.
0:56Anyway, now I can also add to a group in this way here as well,
1:00and I can make them domain admins.
1:03Not that I might necessarily want to do that all the time
1:06for a small organization to make so many domain admins,
1:09but I'm just showing you by way of
1:10demonstration what we're capable of doing right here.
1:13Now, notice also, we did show you this in
1:16the core course that I thought that's
1:18the basis of what I'm teaching here.
1:22But if I expand this out,
1:23remember, we also have this PowerShell history.
1:26For example, this last thing
1:28where I just changed their group membership,
1:30that's this last PowerShell cmdlet that we see.
1:34I can zoom in right down here at the bottom,
1:36set active directory groups at AD group.
1:39If I expand that out,
1:41we can copy all of that,
1:43go to a command prompt here, for example,
1:45or actually a PowerShell prompt,
1:47and I can paste that in here,
1:49and that would be the basis
1:50for some other script I want to do.
1:52Now, in this case,
1:53all those users that you can see here,
1:55Phoenix users, eight.
1:57Where's the other ones? Five, six.
1:59All the other ones that were in there, seven.
2:01You can't see the forest for the trees right now.
2:03But anyway, we see that in the identity,
2:05we added them all to domain admins.
2:08However, we see some other groups here,
2:11other users, what is it?
2:12Four, three, two.
2:14I don't think they're domain admins either.
2:16Let's confirm that first of all.
2:18These three right here,
2:19if I click on properties,
2:22and they're member of,
2:23yep, sure enough, they're just domain users.
2:25That would be easy enough to just add them into,
2:28using this add button over here on the right,
2:30to just add them in as domain admins.
2:33It's because I want to show you
2:35that we can also do this in PowerShell,
2:37using that as the basis, all of this right here,
2:41I can just change those accounts.
2:42So I haven't pressed enter yet,
2:44so I'm just going to go back over
2:46to each one of those accounts.
2:48What is it, two, three, and four?
2:49So I'll make that one two, three, and four.
2:55And all the rest of these I don't really need
2:56because they've already been added in.
2:58So I'll just select all the rest of those and delete them.
3:02And now I have Phoenix Admin four,
3:06Phoenix Admin three, Phoenix Admin two,
3:09and I think I did everything right.
3:11Then I'll just press enter here.
3:13And now if I go back into these accounts
3:15and go to their properties, member of,
3:18sure enough, they're all now domain admins here.
3:22So the point in showing you this
3:24is simply because I want you to understand
3:26that everything we do
3:28in Active Directory Administrative Center
3:30is backed by PowerShell.
3:33Any action you perform in here
3:34actually does a PowerShell cmdlet
3:38along with its various options and everything like that.
3:40And that's why it keeps a record of it all down here.
3:44Now it would be just as easy to use the UI
3:46for what I just demonstrated there.
3:47But if you have a more complicated situation
3:51and you need to use this as a basis for a script,
3:53for example, it's very easy to use this as your basis.
3:57And then you can just modify it
3:59for whatever script you might need.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year