็†ฑ้–€ๅˆ†้กž
 ่ผ‰ๅ…ฅไธญ…
็›ฎ้Œ„

๐Ÿ›ก Windows AD Domain Controller ๆžถ่จญๆ•™ๅญธ(ๅซ PowerShell ่‡ชๅ‹•ๅŒ–)

    ๐Ÿ›ก Windows AD Domain Controller ๆžถ่จญๆ•™ๅญธ(ๅซ PowerShell ่‡ชๅ‹•ๅŒ–)

    Active Directory(AD)ๆ˜ฏไผๆฅญ็’ฐๅขƒไธญๆœ€ๆ ธๅฟƒ็š„่บซๅˆ†็ฎก็†็ณป็ตฑ。 ๆœฌ็ฏ‡ๅฐ‡ไปฅ GUI + PowerShell ็š„ๆ–นๅผๅฎŒๆ•ด็คบ็ฏ„ๅฆ‚ไฝ•ๆžถ่จญ Domain Controller(DC),ๅŒ…ๅซ AD DS ่ง’่‰ฒๅฎ‰่ฃ、Domain ๅปบ็ซ‹、OU ่จญ่จˆๅŽŸๅ‰‡、Group Policy ็ฎก็†่ˆ‡ๅธธ่ฆ‹็ถญ้‹ๆŒ‡ไปค。 ็„ก่ซ–ๆ˜ฏๅฐๅž‹่พฆๅ…ฌๅฎคๆˆ–ๅคงๅž‹ไผๆฅญ,ๆœฌ็ฏ‡็š†ๅฏไฝœ็‚บๆจ™ๆบ–่ฆๅŠƒๆŒ‡ๅ—。

    ๐Ÿ“Œ ไธ€、็’ฐๅขƒ้œ€ๆฑ‚่ˆ‡็‰ˆๆœฌๅปบ่ญฐ

    • Windows Server 2019 / 2022(ๅปบ่ญฐ)
    • ๅ›บๅฎš IP(้ฟๅ… Dynamic IP ๅฐŽ่‡ด DNS ๅˆ†่ฃ‚)
    • ่‡ณๅฐ‘ 4 GB RAM(ๅปบ่ญฐ 8 GB)
    • ็ฃ็ขŸ่‡ณๅฐ‘ 60 GB
    • ็ถฒ่ทฏๅฏๆญฃๅธธ้‹ไฝœ,DNS ๆŒ‡ๅ‘่‡ช่บซ(DC ๆžถ่จญๅพŒๆœƒ่‡ชๅ‹•่จญๅฎš)

    ๐Ÿงฑ ไบŒ、Active Directory ๆžถๆง‹ๅฟซ้€Ÿ็†่งฃ

    • Domain:ไผๆฅญ่บซไปฝ็ฎก็†็š„้‚่ผฏ้‚Š็•Œ
    • Domain Controller:่ฒ ่ฒฌ่บซไปฝ้ฉ—่ญ‰、ๆŽˆๆฌŠ、็ฎก็†็‰ฉไปถ
    • OU(็ต„็น”ๅ–ฎไฝ):็ฎก็†็พค็ต„、ไฝฟ็”จ่€…、้›ป่…ฆ็š„ๅฎนๅ™จ
    • Group Policy(GPO):ๅฅ—็”จๅฎ‰ๅ…จๆ€ง่ˆ‡่จญๅฎš็š„็ญ–็•ฅไธญๅฟƒ

    ๐Ÿ–ฅ️ ไธ‰、GUI ๆ“ไฝœ:ๅฎ‰่ฃ AD DS ่ˆ‡ๅปบ็ซ‹ Domain

    1️⃣ ๅฎ‰่ฃ AD Domain Services

    Server Manager → Add Roles and Features
    → Roles → Active Directory Domain Services(AD DS)
    → Install
    

    2️⃣ Promote ๆˆ Domain Controller

    Server Manager → ไธŠๆ–น้€š็Ÿฅๆ——ๆจ™ → Promote this server to a domain controller
    → Add a new forest
    → Domain Name:corp.local(ไพไผๆฅญ้œ€ๆฑ‚่‡ช่จ‚)
    → DSRM ๅฏ†็ขผ(้œ€ๅฆฅๅ–„ไฟๅญ˜)
    → Install
    
    PC ๅฐ‡่‡ชๅ‹•้‡ๆ–ฐๅ•Ÿๅ‹•,ไน‹ๅพŒๅณๅฏไฝฟ็”จ AD Domain Controller ๅŠŸ่ƒฝ。

    ๐Ÿ’ป ๅ››、PowerShell ่‡ชๅ‹•ๅŒ–ๆžถ่จญ Domain(ๅฎŒๆ•ด่…ณๆœฌ)

    ไปฅไธ‹็‚บๆœ€ๅฎŒๆ•ด็‰ˆๆœฌ,้ฉๅˆ่‡ชๅ‹•ๅŒ–้ƒจ็ฝฒ่ˆ‡ๅคง้‡ Server ไฝˆๅปบ。

    1️⃣ ๅฎ‰่ฃ AD DS ่ง’่‰ฒ

    Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
    

    2️⃣ ๅปบ็ซ‹ๆ–ฐ Domain

    Import-Module ADDSDeployment
    
    Install-ADDSForest `
      -DomainName "corp.local" `
      -DomainNetbiosName "CORP" `
      -SafeModeAdministratorPassword (ConvertTo-SecureString "YourP@ssw0rd" -AsPlainText -Force) `
      -InstallDns `
      -Force
    
    ⚠️ ๅŸท่กŒๅพŒไผบๆœๅ™จๆœƒ่‡ชๅ‹•้‡้–‹ๆฉŸ。

    ๐Ÿ“ ไบ”、ไผๆฅญ็ดš OU(็ต„็น”ๅ–ฎไฝ)ๆจ™ๆบ–ๆžถๆง‹

    ๅปบ่ญฐไผๆฅญ้ตๅพชๆœ€ๅธธ่ฆ‹็š„ 4 ๅฑค็ดš:

    corp.local
    ├── _Admins
    ├── _Groups
    ├── _Servers
    ├── _Workstations
    └── _Users
    

    PowerShell ๅปบ็ซ‹ OU(ๅฎŒๆ•ดๅฏๅŸท่กŒ)

    New-ADOrganizationalUnit -Name "_Servers" -Path "DC=corp,DC=local"
    New-ADOrganizationalUnit -Name "_Users"   -Path "DC=corp,DC=local"
    New-ADOrganizationalUnit -Name "_Groups"  -Path "DC=corp,DC=local"
    New-ADOrganizationalUnit -Name "_Admins"  -Path "DC=corp,DC=local"
    

    ๐Ÿ‘ฅ ๅ…ญ、ๅปบ็ซ‹ไฝฟ็”จ่€…่ˆ‡็พค็ต„(GUI ่ˆ‡ PowerShell)

    1️⃣ GUI ๅปบ็ซ‹ไฝฟ็”จ่€…

    Active Directory Users and Computers(ADUC)
    → ๅณ้ต OU → New → User
    

    2️⃣ PowerShell ๅปบ็ซ‹ไฝฟ็”จ่€…

    New-ADUser `
      -Name "John Doe" `
      -SamAccountName "jdoe" `
      -UserPrincipalName "jdoe@corp.local" `
      -Path "OU=_Users,DC=corp,DC=local" `
      -AccountPassword (ConvertTo-SecureString "P@ssw0rd!" -AsPlainText -Force) `
      -Enabled $true
    

    3️⃣ ๅปบ็ซ‹็พค็ต„

    New-ADGroup `
      -Name "IT-Admins" `
      -GroupScope Global `
      -Path "OU=_Groups,DC=corp,DC=local"
    

    ๐Ÿ“Œ ไธƒ、Group Policy(GPO)ๅธธ่ฆ‹ๆ‡‰็”จ

    GPO ๆŽงๅˆถไผๆฅญ้›ป่…ฆ็š„่จญๅฎš,ๅŒ…ๅซ:

    • ๅฏ†็ขผ็ญ–็•ฅ(Password Policy)
    • ็™ปๅ…ฅ/็™ปๅ‡บ่…ณๆœฌ
    • ๆกŒ้ข้™ๅˆถ
    • ้˜ฒ็ซ็‰†่ฆๅ‰‡
    • USB ๅฐ้Ž–

    PowerShell ๅปบ็ซ‹ GPO

    New-GPO -Name "Workstation-Security"
    

    ้€ฃ็ต GPO ่‡ณ็‰นๅฎš OU

    New-GPLink -Name "Workstation-Security" -Target "OU=_Workstations,DC=corp,DC=local"
    

    ๐Ÿ›  ๅ…ซ、Domain Controller ๅธธ่ฆ‹็ถญ้‹ๆŒ‡ไปค

    1️⃣ ๅฅๅบทๆชขๆŸฅ

    dcdiag /v
    

    2️⃣ ่ค‡ๅฏซ็‹€ๆ…‹

    repadmin /replsummary
    repadmin /showrepl
    

    3️⃣ DNS ้‡ๆ–ฐ่ผ‰ๅ…ฅ

    ipconfig /registerdns
    

    4️⃣ ๆ‰€ๆœ‰็™ปๅ…ฅ็ด€้Œ„ๆŸฅ่ฉข

    Get-EventLog -LogName Security -InstanceId 4624
    

    ๐Ÿงญ ไน、ๅปบ่ญฐๅฎŒๆ•ด AD ๆžถๆง‹ๆต็จ‹(ๆ–ฐๆ‰‹ไนŸ้ฉ็”จ)

    1. ๅ›บๅฎš IP → ๆ›ดๆ–ฐ็ณป็ตฑ → ๅฎ‰่ฃ AD DS
    2. Promote ๆˆ Domain Controller
    3. ่จญ่จˆ OU、ๅปบ็ซ‹ไฝฟ็”จ่€…/็พค็ต„
    4. ่จญๅฎš GPO(ๅฏ†็ขผ、่ฃ็ฝฎ、ๆกŒ้ขๆ”ฟ็ญ–)
    5. ้€ฒ่กŒ dcdiag、repadmin ๅฅๅบทๆชขๆŸฅ
    6. ๅฎšๆœŸๅ‚™ไปฝ AD(System State Backup)
    

    ๐Ÿ“˜ ็ต่ชž

    Active Directory ๆ˜ฏไผๆฅญ็ถฒ่ทฏ็š„ไธญๅฟƒ,ๅคงๅคšๆ•ธ Windows ๆœๅ‹™้ƒฝไพ่ณดๅฎƒ。 ๆœฌ็ฏ‡ๆไพ›ๆžถ่จญ、OU ๆžถๆง‹、็พค็ต„่ˆ‡ GPO ่จญๅฎš、PowerShell ่‡ชๅ‹•ๅŒ–็ญ‰ๅฎŒๆ•ดๆ“ไฝœๆต็จ‹。 ่‹ฅไฝ ๆญฃๅœจ่ฆๅŠƒไผๆฅญ AD ๆžถๆง‹,ๆญค็ฏ‡ๅฏไฝœ็‚บๅฎŒๆ•ด็š„ๅฐŽๅ…ฅ่ˆ‡็ถญ่ญทๆŒ‡ๅ—。


    ๐Ÿ”— ๅปถไผธ้–ฑ่ฎ€

    — WWFandy・Windows ไผๆฅญๆžถๆง‹็ญ†่จ˜

    ๐Ÿ”— ๅˆ†ไบซ้€™็ฏ‡ LINE Facebook X

    ๆฒ’ๆœ‰็•™่จ€:

    ๅผต่ฒผ็•™่จ€

    ๅญ—็ดš