Top Banner
Module 3: Managing User Accounts
20

User Management

Jan 11, 2016

Download

Documents

Book of Active Directory Services
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: User Management

Module 3: Managing User Accounts

Page 2: User Management

Creating User Accounts

What Is a User Account?

Names Associated with Domain User Accounts

Guidelines for Creating a User Account Naming Convention

User Account Placement in a Hierarchy

User Account Password Options

When to Require or Restrict Password Changes

Tools to Create User Accounts

Best Practices for Creating User Accounts

Page 3: User Management

What Is a User Account?

Multimedia: Types of User Accounts

Domain user accounts (stored in Active Directory)

Local user accounts (stored on local computer)

Windows Server 2003 Domain

Page 4: User Management

Names Associated with Domain User Accounts

Name Example

User logon name Tadams

Pre-Windows 2000 logon name

contoso\Tadams

User principal logon name

[email protected]

LDAP distinguished name

CN=terry adams,ou=sales,dc=contoso,dc=msft

LDAP relative distinguished name

CN=terry adams

Page 5: User Management

Guidelines for Creating a User Account Naming Convention

A convention for naming user accounts should accommodate:

Employees with identical names

Different types of employees, such as temporary or contract employees

Page 6: User Management

User Account Placement in a Hierarchy

Geopolitical Design

Users

North America

Users

South America

Business Design

Users

Accounting

Users

Sales

Page 7: User Management

User Account Password Options

Account options Description

User must change password at next logon

Users must change their passwords the next time they log on to the network

User cannot change password

Users do not have the permissions to change their own password

Password never expires

Users’ passwords will not expire and do not need to be changed

Account is disabled

Users cannot log on by using the selected account

Page 8: User Management

When to Require or Restrict Password Changes

Option Use this option when you:

Require

password

changes

Create new domain accounts

Reset passwords

Restrict password changes

Create local and domain service accounts

Page 9: User Management

Tools to Create User Accounts

Tools available to create user accounts

Active Directory Users and Computers

Command-line utilities

Dsadd

Net user

Batch utilities

CSVDE

LDIFDE

Computer Management MMC to create local users

Page 10: User Management

Best Practices for Creating User Accounts

Best practices for creating local user accounts

Limit the number of people who can log on locally

Best practices for creating domain user accounts

Disable any account that will not be used immediately

Require users to change their passwords the first time that they log on

Do not use the Users container for ordinary user accounts

Rename the Administrator account

Use strong passwords

Page 11: User Management

When to Modify User Account Properties

Modify user account properties to:

Make it easier to use search capabilities to find users

Match a company’s organizational hierarchy

Determine the group membership of a user account

Page 12: User Management

Properties Associated with User Accounts

The Properties dialog box for a user account contains:

Page 13: User Management

Renaming a User Account

The Rename User dialog box

Page 14: User Management

Creating a User Account Template

What Is a User Account Template?

What Properties Are in a Template?

Guidelines for Creating User Account Templates

Practice: Creating a User Account Template

Page 15: User Management

What Is a User Account Template?

Employs a user account with properties meeting common user requirements

Makes creating user accounts with standardized configurations more efficient

User Account

Template

Page 16: User Management

What Properties Are in a Template?

Tab Properties copied

Address All properties except Street Address

Account All properties except Logon Name

ProfileAll properties except Profile path and Home folderreflect new user’s logon name

Organization All properties except Title

Member Of All properties

Page 17: User Management

Guidelines for Creating User Account Templates

Create a separate classification for each department

Create a separate group for short-term and temporary employees

Set user account expiration dates for short-term and temporary employees

Disable the account template

Identify the account template

Page 18: User Management

Why Enable or Disable User Accounts?

Scenarios for disabling accounts

User takes a leave of absence

Creating accounts that will not be used immediately

Tools available for disabling or enabling accounts

Active Directory Users and Computers

Dsmod command

Page 19: User Management

What Are Locked-Out User Accounts?

Account lockout thresholds:

Define the number of failed logon attempts

Prevent hackers from guessing user passwords

Logon failures can occur:

At the logon screen

At a screen saver protected by a password

When accessing network resources

Page 20: User Management

When to Reset User Passwords

Reset a password when a user forgets his or her password

After the local user’s password has been reset, the user can no longer access some types of information