Beruflich Dokumente
Kultur Dokumente
w w t . w c e n h c o r o . p o c . n i
Module Overview
Create Computers and Join the Domain Administer Computer Objects and Accounts
w w t . w c e n h c o r o . p o c . n i
w w t . w c e n h c o r o . p o c . n i
1ou must be a member of the local Administrators group on the computer to change its domain or wor group membership A computer object should e2ist in the directory service
)f it does not already e2ist! you must also have permission to create a computer account in domain
w w t . w c e n h c o r o . p o c . n i
Client computers
"ypically subdivided by region
Divide O's based first on administration! then to facilitate configuration with 3roup Policy
w w t . w c e n h c o r o . p o c . n i
Computer .ame and Computer .ame 6Pre4Windows 89997 should be the same 'ser or group bo2 delegates permissions to the specified account to join the computer to the domain
w w t . w c e n h c o r o . p o c . n i
w w t . w c e n h c o r o . p o c . n i
Delegate to appropriate groups the permission to create computer objects in the appropriate O's
,D)-D+
)mport 6create7! modify! or e2port computer accounts
w w t . w c e n h c o r o . p o c . n i
D(Add
Create computer accounts and set initial properties
.etDom
Create computer accounts Join machines to domain
Export
C(*D+;e2e
w w t . w c e n h c o r o . p o c . n i
csvde i -f filename [-k] -i< )mport 6default mode is e2port7 4 < Continue past errors 6such as Object Already +2ists7
)nclude userAccountControl column 6set to =9>?7 and sAMAccount.ame column 6set to computername@7
Export
w w t . w c e n h c o r o . p o c . n i
dn: CN=FILE25,O =File, O =!ervers, "C=c#n$#s#,"C=c#m c%&n'e$(pe: &dd #)*ec$Cl&ss: $#p #)*ec$Cl&ss: pers#n #)*ec$Cl&ss: #r'&ni+&$i#n&l,ers#n #)*ec$Cl&ss: -ser #)*ec$Cl&ss: c#mp-$er cn: FILE25 -ser.cc#-n$C#n$r#l: /012 s.3.cc#-n$N&me: FILE254
w w t . w c e n h c o r o . p o c . n i
)n Active Directory Module for Power(hell! use< .ew4ADComputer 4(amAccount.ame D+(E"OP:8F GPath HO'IClient Computers!DCIcontoso!DCIcomJ
w w t . w c e n h c o r o . p o c . n i
Computer Accounts and (ecure Channel #ecogni&e Computer Account Problems #eset a Computer Account #ename a Computer Disable and +nable a Computer Delete and #ecycle Computer Accounts
w w t . w c e n h c o r o . p o c . n i
Managed 5y
,in to user who is the primary user of the computer ,in to group that is responsible for the computer 6servers7
Member Of
3roups< 3roup Policy filtering! software deployment
dsmod computer NComputerDNN O4desc NDescriptionNP O4loc NLocationNP )n Power(hell! use< (et4ADComputer cmdlet
Move a Computer
'sing Active Directory 'sers and Computers
Drag and drop
w w t . w c e n h c o r o . p o c . n i
-newname .ew.ame< 'sed to rename a computer 4newparent ParentD.< 'sed to move a computer to the O' specified by ParentD.
w w t . w c e n h c o r o . p o c . n i
w w t . w c e n h c o r o . p o c . n i
w w t . w c e n h c o r o . p o c . n i
D(ModR
dsmod computer ComputerDN !reset
.etDom
ne$d#m rese$ MachineName 5d#m&in DomainName 5 serO UserName 5,&ss6#rdO 7Password 8 9:
.,"est
nl$es$ 5server:Ser"erName 5sc=rese$:"O3.IN>DomainController
#ename a Computer
'se (ystem Properties of the computer to rename the computer and its account correctly
w w t . w c e n h c o r o . p o c . n i
.etDom
ne$d#m ren&mec#mp-$er MachineName 5Ne6N&me:NewName [5 serO:LocalUsername] [5,&ss6#rdO:7LocalPassword89: ] [5 ser":DomainUsername] [5,&ss6#rd":7DomainPassword89: ] [5!ec-re,&ss6#rd,r#mp$] [5;E<##$[:TimeInSeconds] ]
Windows Power(hell< #e.ame4Computer 5e cautious of the impact that renaming can have on services and on certificates associated with computerJs name
w w t . w c e n h c o r o . p o c . n i
D(Mod
dsm#d c#mp-$er ComputerDN -dis&)led (es dsm#d c#mp-$er ComputerDN -dis&)led n#
w w t . w c e n h c o r o . p o c . n i
w w t . w c e n h c o r o . p o c . n i
w w t . w c e n h c o r o . p o c . n i
F;
"ransfer the blob file with domain information to client computer system hard drive
BLOB Win7
=; M;
djoin Sre$uestODJ Sloadfile des top:8F;t2t Swindowspath W(ystem#ootW 6Slocalos7 #estart the client computer