tirsdag 16. oktober 2012

How to setup Active Directory in Windows Server 2012


Overview

Windows Server 2012 provides advancements to every area of IT services, and that certainly includes Active Directory. Whether you're looking to take advantage of Dynamic Access Control, begin virtualizing your Active Directory infrastructure, or start using one of the other amazing features that Windows Server 2012 Active Directory offers, it all begins with getting a Windows Server 2012 added as a domain controller.

What Happened to dcpromo?

Similar to previous versions of Windows Server, you start the process of making a server into a domain controller by adding the Active Directory Domain Services roles to your computer. However, in Windows Server 2012, you do not run dcpromo to promote your server to a domain controller. In Windows Server 2012, dcpromo has been deprecated.
So what replaces dcpromo in Windows Server 2012? There are now two ways to promote your server to a DC. The first option is to use PowerShell. This provides the ability to script the process, save the script, or batch the process out to multiple servers. The second option is a task made available in Server Manager that can be run to begin the promotion wizard.



Who Can Install Active Directory on Windows Server 2012?

If you are going to be creating the first domain in a new forest, log on as the local Administrator. If you're adding a new domain in an existing forest, be a member of the Enterprise Admins group for the forest you're going to join. To add a new domain controller to an existing domain, be a member of the Domain Admins group.
Once you're logged into the server with the correct account, you'll next add the Active Directory Domain Services feature to your server. You can install the Active Directory Services feature on to Windows Server 2012 by both PowerShell and Server Manager.
The fastest method of installing features in Windows Server 2012 is with PowerShell; let's take a look at the steps needed to accomplish this.

Install Active Directory Domain Services on Windows Server 2012 with PowerShell

Add-WindowsFeature -name ad-domain-services -IncludeManagementTools
It doesn't get any easier than that, but in case you want to do it the hard way, I'll show you how to add the Active Directory feature to your Windows Server 2012 using Server Manager, too.


Install Active Directory Domain Services on Windows Server 2012 with Server Manager

  1. Open Server Manager, then select Manage and click on "Add Roles and Features"
  2. Click Next on the "Before you begin" window
  3. Select Role-based or feature-based installation and then click Next
  4. Click Select a server from the server pool, click the name of the server to install Active Directory Domain Services to, and then click Next (If you wanted to install this on a remote server, you have to first create a server group containing the remote server)
  5. Click Active Directory Domain Services. When the Add Roles and Features Wizard dialog box opens, select Add Features, then Next
  6. On the Active Directory Domain Services page, review the information and then click Next
  7. On the Confirm installation selections page, click Install
  8. On the Results page, verify Installation succeeded, and click Promote this server to a domain controller to start the Active Directory Domain Services Configuration Wizard
The nice part about using the Server Manager method is that it takes you directly into running the Active Directory Domain Services Configuration Wizard, which is the utility which replaced the deprecated dcpromo.
Now that you've installed the features, you will need to promote the server into a domain controller.


How to Promote a Server to a Domain Controller in Windows Server 2012 with Server Manager

imageAfter installing the Active Directory Domain Services feature on your server, you can promote the server to a domain controller. If you have just finished the feature installation, the AD DS Configuration Wizard begins automatically.
However, if the feature installation has already been closed, you can start the Active Directory Domain Services Configuration Window by clicking the Tasks icon along the top of Server Manager.
  1. Choose your Deployment Configuration.
    • To install a domain controller to an existing domain, specify the domain name.
    • To install a new domain in existing forest, choose "Child" or "Tree" domain, then browse for forest structure.
    • To install a new forest, specify the new forest name.
    • Then click Next.
  2. Choose your Domain Controller Options.
    • To create a new forest or domain, select the functional levels, click Domain Name System (DNS) server, specify the Directory Services Restore Mode password, and then click Next.
    • To add a DC to a domain, choose Domain Name System (DNS) server, Global Catalog (GC), or Read Only Domain Controller (RODC) as needed, choose the site name, and type the Directory Services Restore Mode password and then click Next.
  3. If installing a DNS Server, you may need to Update DNS delegation. To update, enter credentials with permission to create DNS delegation records in the parent DNS zone. (To help determine if you need to update DNS delegation, see the Microsoft TechNet article Understanding Zone Delegation. For more information on any errors that may be generated by updating DNS delegation, see DNS Options.
  4. If installing a Read Only Domain Controller (RODC), specify the group that will manage the RODC. Add or remove accounts to the Allowed or Denied password replication groups. Click Next.
  5. On the Additional Options page, choose one of the following options:
    • To create a new domain, type or verify the NetBIOS name of the domain.
    • To add a DC to a domain, select a domain controller to replicate the AD DS installation data from (or the wizard can select "any").
  6. Specify where the directories for the Active Directory database, the log files, and the SYSVOL folder will be. Click Next.
    Warning: Do not attempt to store any of the above on a Resilient File System data volume.
  7. You may need to specify alternate credentials to run adprep on the Preparation Options page.
  8. If you want to reuse these steps again, click View Script, and copy the text of the PowerShell script.
  9. Verify your server was successfully promoted on the results page, then click Close.
A reboot is required and it happens automatically by default.
You can also automate this process with PowerShell.

How to Promote a Server to a Domain Controller in Windows Server 2012 with PowerShell

There are three PowerShell cmdlets, which coincide with the three deployment options:
Install-ADDSDomainControllerCreates a new domain controller in an existing domain
Install-ADDSDomain Creates a new domain in an existing forest
Install-ADDSForest Creates a new forest

How to Add a Domain Controller using PowerShell

To use Install-ADDSDomainController, only three things are required:
  • domain name - which must be passed through the DomainName parameter
  • credentials - that are in the Domain Admins group of the domain
  • Directory Services Restore Mode password - which can either be passed through the SafeModeAdministratorPassword parameter, or it can be provided when prompted.
There are many more optional parameters that can be used, which specify everything from where to find the installation media, to whether or not to reboot when it's completed.
The simplest example of this is:
Install-ADDSDomainController "mydomain.local"

How to Add a Domain Forest using PowerShell

To use Install-ADDSDomain, you must also specify the parent domain name. Just as when using PowerShell to add a domain controller, you may either supply the Directory Services Restore Mode password in the cmdlet, or provide it when prompted.
This is an example of how to create a new domain in a forest with PowerShell:
Install-ADDSDomain  -NewDomainName  mychildn  `
-ParentDomainName mydomain.local; `
-InstallDNS `
-CreateDNSDelegation `
-DomainMode Win8 `
-ReplicationSourceDC  dc0.mydomain.local
Note: The ` character is used to continue the command on the next line


How to Add a New Forest with PowerShell

To use Install-ADDSForest, all that needs to be provided is the forest name. A prompt will allow the Directory Services Restore Mode password to be entered, and DNS is installed by default during a forest installation.
An example of this would be:
Install-ADDSForest "mydomain.local"
Or you could be more specific:
Install-ADDSForest –DomainName mydomain.loca  `
 -CreateDNSDelegation  `
 -DomainMode Win8   `
 -ForestMode Win8 

Conclusion

Though Windows Server 2012 removes the dcpromo that system engineers have been using since 2000, they have not removed the functionality. If a GUI is preferred by an active directory engineer, they may still have much of the look and feel provided through Server Manager. If a script or a command line interface is preferred, new cmdlets in PowerShell provide all of the flexibility of the GUI, with the added benefit or scalability and reusability.



søndag 15. april 2012

Cannelloni - En smak av Italia




Ingredienser:

12 Cannellonirør La Collezione Barilla
Fyll:
320 g kyllingfilet
160 g ricottaost
60 g parmesanost
1 revet gulrot
1 hakket løk
120 g hakkede valnøtter
½ dl hvitvin
20 g smør
salt og nykvernet pepper
Hvit saus:
9 dl melk
50 g smør
1 dl mel
salt
1 klype muskatnøtt
100 g spinat

Fremgangsmåte:

Fyll:
Stek revet gulrot og hakket løk i en panne. Tilsett strimlet kylling, og smak til med pepper og salt. Tilsett hvitvin og la det koke til vinen er fordampet. Ha i grovhakkede valnøttkjerner og stek i 5 minutter. Hell alt sammen over i en bolle og bland godt.
La blandingen kjølne før du tilsetter ricottaost og revet parmesan. Fyll Cannellonirørene med blandingen, det gjøres enklest med en kakesprøyte.
Hvit saus:
Smelt smøret i en gryte, tilsett melet og en skvett melk. Det er viktig å røre hele tiden så sausen ikke klumper seg. Spe forsiktig i resten av melken. Tilsett spinat, muskatnøtt og salt, og gi det hele et oppkok. Smør en ovnsform, og dekk bunnen med et lag hvit saus. Legg i de fylte Cannellonirørene, og dekk over med et nytt lag hvit saus.
Gratineres i ovnen på 200 C i 35 minutter. Server og nyt!

søndag 4. mars 2012

Gründer, jammen ikke lett

Det å være gründer er jammen ikke lett..Men så er det vel sånn at hadde det vært lett så hadde vel alle gjort det.
Jeg anser meg vel selv som gründer typen, men om jeg ER en gründer det får vel andre bedømme.

Men nå har det seg slik at jeg stadig kommer opp med nye ideer om hvordan jeg skal gjøre nye ting eller hvordan jeg kan gjøre gamle ting annerledes. Det er ikke alltid at man trenger å finne opp hjulet på nytt, men man skal jo også være forsiktig med å ikke kopiere helt en ting også...(Har dessverre brent meg på det ja) Men se på Bjørn Kjoos f.eks. Han fant ikke opp flyselskapene, ideen hans var ikke ny. Vi hadde jo flyselskap før det. Men han gjorde det annerledes. Gjorde en variasjon og gjorde det til noe utrolig stort. Mer eller mindre det samme med Idar Vollvik. Han startet jo ikke det første mobilselskapet, men han gjorde det billigere på en bra måte som gjorde at det ble stort...Nå er vel kansje ikke Vollvik noe videre forbilde på det han gjorde senere, for å klare å rote bort så mye penger på tull er vel ikke akkurat noen god prestasjon....

Men selv om jeg stadig kommer opp med nye ideer, så er det jo langt fra at alle blir noe av for å si det sånn. Jeg tror jeg kommer opp med bortimot 10-12 nye ideer hver uke i snitt. Mange eller de fleste blir vel forkastet, men noen holder jeg fast ved, prøver å videre utvikle, for så å kaste det igjen...Men så tror jeg jo selv at det bare er ett tidsspørsmål før jeg kommer opp med det virkelig store....Klart noen ny Zuckerberg går jeg ikke rundt og tror jeg skal bli. Men det trenger jeg ikke heller. Jeg vil bare komme opp med noe som jeg selv kan være stolt av å ha gjort...Så får vi se da hva det blir :)

søndag 12. februar 2012

Morsdag, Farsdag og valentines day

Må man virkelig ha 3 felles dager i året for å hedre og vise det til de mennesker man er glad i, eller er dette nok ett påfunn fra handelsstanden for å få folk til å kjøpe mer gaver. Jeg synes virkelig det er triste greier....Hva med å vise de sammen personene det hele året....Hvorfor har vi ikke da en barnsdag, en sønnsdag, dattersdag. Skal ikke disse få en oppmerksomhet....Ikke minst, tenk på alle de som ikke har en mor eller far lenger....Hvorfor påminne de hva de ikke har lenger med en dag hvor alle hilser til sine kjære.

Det føles jo mye mer uekte å få oppmerksomhet på en dag som alle andre får oppmerksomhet fordi alle har påminnet deg denne dagen. Tenk hvor mye mer det hadde betydd hvis man fikk denne oppmerksomheten fra sine kjære på en Onsdag midt i mai, eller en tirsdag i oktober.....

Ja ja, vi lar oss styre av markedskreftene så dette forundrer meg ikke.