๐ก Windows AD Domain Controller ๆถ่จญๆๅญธ(ๅซ PowerShell ่ชๅๅ)
Active Directory(AD)ๆฏไผๆฅญ็ฐๅขไธญๆๆ ธๅฟ็่บซๅ็ฎก็็ณป็ตฑ。 ๆฌ็ฏๅฐไปฅ GUI + PowerShell ็ๆนๅผๅฎๆด็คบ็ฏๅฆไฝๆถ่จญ Domain Controller(DC),ๅ ๅซ AD DS ่ง่ฒๅฎ่ฃ、Domain ๅปบ็ซ、OU ่จญ่จๅๅ、Group Policy ็ฎก็่ๅธธ่ฆ็ถญ้ๆไปค。 ็ก่ซๆฏๅฐๅ่พฆๅ ฌๅฎคๆๅคงๅไผๆฅญ,ๆฌ็ฏ็ๅฏไฝ็บๆจๆบ่ฆๅๆๅ。
๐ ไธ、็ฐๅข้ๆฑ่็ๆฌๅปบ่ญฐ
- Windows Server 2019 / 2022(ๅปบ่ญฐ)
- ๅบๅฎ IP(้ฟๅ Dynamic IP ๅฐ่ด DNS ๅ่ฃ)
- ่ณๅฐ 4 GB RAM(ๅปบ่ญฐ 8 GB)
- ็ฃ็ข่ณๅฐ 60 GB
- ็ถฒ่ทฏๅฏๆญฃๅธธ้ไฝ,DNS ๆๅ่ช่บซ(DC ๆถ่จญๅพๆ่ชๅ่จญๅฎ)
๐งฑ ไบ、Active Directory ๆถๆงๅฟซ้็่งฃ
- Domain:ไผๆฅญ่บซไปฝ็ฎก็็้่ผฏ้็
- Domain Controller:่ฒ ่ฒฌ่บซไปฝ้ฉ่ญ、ๆๆฌ、็ฎก็็ฉไปถ
- OU(็ต็นๅฎไฝ):็ฎก็็พค็ต、ไฝฟ็จ่ 、้ป่ ฆ็ๅฎนๅจ
- Group Policy(GPO):ๅฅ็จๅฎๅ จๆง่่จญๅฎ็็ญ็ฅไธญๅฟ
๐ฅ️ ไธ、GUI ๆไฝ:ๅฎ่ฃ AD DS ่ๅปบ็ซ Domain
1️⃣ ๅฎ่ฃ AD Domain Services
Server Manager → Add Roles and Features
→ Roles → Active Directory Domain Services(AD DS)
→ Install
2️⃣ Promote ๆ Domain Controller
Server Manager → ไธๆน้็ฅๆๆจ → Promote this server to a domain controller
→ Add a new forest
→ Domain Name:corp.local(ไพไผๆฅญ้ๆฑ่ช่จ)
→ DSRM ๅฏ็ขผ(้ๅฆฅๅไฟๅญ)
→ Install
PC ๅฐ่ชๅ้ๆฐๅๅ,ไนๅพๅณๅฏไฝฟ็จ AD Domain Controller ๅ่ฝ。
๐ป ๅ、PowerShell ่ชๅๅๆถ่จญ Domain(ๅฎๆด่ ณๆฌ)
ไปฅไธ็บๆๅฎๆด็ๆฌ,้ฉๅ่ชๅๅ้จ็ฝฒ่ๅคง้ Server ไฝๅปบ。
1️⃣ ๅฎ่ฃ AD DS ่ง่ฒ
Install-WindowsFeature AD-Domain-Services -IncludeManagementTools
2️⃣ ๅปบ็ซๆฐ Domain
Import-Module ADDSDeployment
Install-ADDSForest `
-DomainName "corp.local" `
-DomainNetbiosName "CORP" `
-SafeModeAdministratorPassword (ConvertTo-SecureString "YourP@ssw0rd" -AsPlainText -Force) `
-InstallDns `
-Force
⚠️ ๅท่กๅพไผบๆๅจๆ่ชๅ้้ๆฉ。
๐ ไบ、ไผๆฅญ็ด OU(็ต็นๅฎไฝ)ๆจๆบๆถๆง
ๅปบ่ญฐไผๆฅญ้ตๅพชๆๅธธ่ฆ็ 4 ๅฑค็ด:
corp.local
├── _Admins
├── _Groups
├── _Servers
├── _Workstations
└── _Users
PowerShell ๅปบ็ซ OU(ๅฎๆดๅฏๅท่ก)
New-ADOrganizationalUnit -Name "_Servers" -Path "DC=corp,DC=local"
New-ADOrganizationalUnit -Name "_Users" -Path "DC=corp,DC=local"
New-ADOrganizationalUnit -Name "_Groups" -Path "DC=corp,DC=local"
New-ADOrganizationalUnit -Name "_Admins" -Path "DC=corp,DC=local"
๐ฅ ๅ ญ、ๅปบ็ซไฝฟ็จ่ ่็พค็ต(GUI ่ PowerShell)
1️⃣ GUI ๅปบ็ซไฝฟ็จ่
Active Directory Users and Computers(ADUC)
→ ๅณ้ต OU → New → User
2️⃣ PowerShell ๅปบ็ซไฝฟ็จ่
New-ADUser `
-Name "John Doe" `
-SamAccountName "jdoe" `
-UserPrincipalName "jdoe@corp.local" `
-Path "OU=_Users,DC=corp,DC=local" `
-AccountPassword (ConvertTo-SecureString "P@ssw0rd!" -AsPlainText -Force) `
-Enabled $true
3️⃣ ๅปบ็ซ็พค็ต
New-ADGroup `
-Name "IT-Admins" `
-GroupScope Global `
-Path "OU=_Groups,DC=corp,DC=local"
๐ ไธ、Group Policy(GPO)ๅธธ่ฆๆ็จ
GPO ๆงๅถไผๆฅญ้ป่ ฆ็่จญๅฎ,ๅ ๅซ:
- ๅฏ็ขผ็ญ็ฅ(Password Policy)
- ็ปๅ ฅ/็ปๅบ่ ณๆฌ
- ๆก้ข้ๅถ
- ้ฒ็ซ็่ฆๅ
- USB ๅฐ้
PowerShell ๅปบ็ซ GPO
New-GPO -Name "Workstation-Security"
้ฃ็ต GPO ่ณ็นๅฎ OU
New-GPLink -Name "Workstation-Security" -Target "OU=_Workstations,DC=corp,DC=local"
๐ ๅ ซ、Domain Controller ๅธธ่ฆ็ถญ้ๆไปค
1️⃣ ๅฅๅบทๆชขๆฅ
dcdiag /v
2️⃣ ่คๅฏซ็ๆ
repadmin /replsummary
repadmin /showrepl
3️⃣ DNS ้ๆฐ่ผๅ ฅ
ipconfig /registerdns
4️⃣ ๆๆ็ปๅ ฅ็ด้ๆฅ่ฉข
Get-EventLog -LogName Security -InstanceId 4624
๐งญ ไน、ๅปบ่ญฐๅฎๆด AD ๆถๆงๆต็จ(ๆฐๆไน้ฉ็จ)
1. ๅบๅฎ IP → ๆดๆฐ็ณป็ตฑ → ๅฎ่ฃ AD DS 2. Promote ๆ Domain Controller 3. ่จญ่จ OU、ๅปบ็ซไฝฟ็จ่ /็พค็ต 4. ่จญๅฎ GPO(ๅฏ็ขผ、่ฃ็ฝฎ、ๆก้ขๆฟ็ญ) 5. ้ฒ่ก dcdiag、repadmin ๅฅๅบทๆชขๆฅ 6. ๅฎๆๅไปฝ AD(System State Backup)
๐ ็ต่ช
Active Directory ๆฏไผๆฅญ็ถฒ่ทฏ็ไธญๅฟ,ๅคงๅคๆธ Windows ๆๅ้ฝไพ่ณดๅฎ。 ๆฌ็ฏๆไพๆถ่จญ、OU ๆถๆง、็พค็ต่ GPO ่จญๅฎ、PowerShell ่ชๅๅ็ญๅฎๆดๆไฝๆต็จ。 ่ฅไฝ ๆญฃๅจ่ฆๅไผๆฅญ AD ๆถๆง,ๆญค็ฏๅฏไฝ็บๅฎๆด็ๅฐๅ ฅ่็ถญ่ญทๆๅ。
๐ ๅปถไผธ้ฑ่ฎ
- Windows Update ๆทฑๅบฆ่งฃๆ:USOClient、WaaS、WSUS ่ก็บๅทฎ็ฐ
- PowerShell ๅปบ็ฝฎไผๆฅญๆชๆกๅไบซ็ฐๅข
- Windows DNS Server ๆถ่จญๅฎๆดๆๅ
- Windows DHCP Server ๅฎๆดๆถ่จญๆๅ
— WWFandy・Windows ไผๆฅญๆถๆง็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ