Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

20411B-ENU-TrainerHandbook

.pdf
Скачиваний:
237
Добавлен:
01.05.2015
Размер:
16.48 Mб
Скачать

Administering Windows Server®2012

MCT

xi

 

Acknowledgments

Microsoft Learning wants to acknowledge and thank the following for their contribution toward developing this title. Their effort at various stages in the development has ensured that you have a good classroom experience.

Andrew J. Warren – Content Developer

USE

 

Andrew Warren has more than 25 years of experience in the IT industry, many of which he has spent teaching and writing. He has been involved as a subject matter expert for many of the Windows Server®

2008 courses, and the technical lead on a number of other courses. He also has been involved in developing TechNet sessions on Microsoft® Exchange Server 2007. Based in the United Kingdom, Andrew runs his own IT training and education consultancy.

Jason Kellington (Microsoft Certified Trainer (MCT), Microsoft Certified IT Professional (MCITP), and ONLY

Jason Kellington – Content Developer

Microsoft Certified Solutions Expert (MCSE) is a consultant, trainer, and author. He has experience working . with a wide range of Microsoft technologies, focusing on enterprise network infrastructure. Jason works in

several capacities with Microsoft. He is a content developer for Microsoft Learning courseware titles, a senior technical writer for Microsoft IT Showcase, and an author for Microsoft Press®.

Brian Desmond – Technical Reviewer

Brian Desmond is a Microsoft Most Valuable Professional (MVP) and consultant based out of Chicago,

Illinois. Brian focuses on Active Directory®, Exchange Server, and Identity Management projects for global enterprise customers. Brian is the author of Active Directory, 4th Edition (O’Reilly), and numerous articles in industry leading publications such as Windows IT Pro magazine. A frequent traveler, you can usually find Brian on the road speaking at conferences and visiting customers.

David Susemiehl – Content Developer

STUDENT

David Susemiehl has worked as consultant, trainer, and courseware developer since 1996. David has

 

extensive experience consulting on Microsoft Systems Management Server and Microsoft System Center

Configuration Manager 2007, as well as Active Directory, Exchange Server, and Terminal Server/Citrix

 

deployments. David has developed courseware development for Microsoft and Hewlett-Packard, and

 

delivered those courses successfully in Europe, Central America, and across North America. For the last

 

several years, David has been writing courseware for Microsoft Learning, and consulting on infrastructure

transitions in Michigan.

USE

 

PROHIBITED

xii Administering Windows Server® 2012

Contents

Module 1: Deploying and Maintaining Server Images

Lesson 1: Overview of Windows Deployment Services

1-2

Lesson 2: Implementing Deployment with Windows

 

Deployment Services

1-8

Lesson 3: Administering Windows Deployment Services

1-14

Lab: Using Windows Deployment Services to Deploy

 

Windows Server 2012

1-20

Module 2: Configuring and Troubleshooting Domain Name System

Lesson 1: Installing the DNS Server Role

2-2

Lesson 2: Configuring the DNS Server Role

2-8

Lesson 3: Configuring DNS Zones

2-14

Lesson 4: Configuring DNS Zone Transfers

2-19

Lesson 5: Managing and Troubleshooting DNS

2-22

Lab: Configuring and Troubleshooting DNS

2-30

Module 3: Maintaining Active Directory Domain Services

Lesson 1: Overview of AD DS

3-2

Lesson 2: Implementing Virtualized Domain Controllers

3-7

Lesson 3: Implementing Read-Only Domain Controllers

3-11

Lesson 4: Administering AD DS

3-15

Lesson 5: Managing the AD DS Database

3-23

Lab: Maintaining AD DS

3-32

Module 4: Managing User and Service Accounts

Lesson 1: Automating User Account Management

4-2

Lesson 2: Configuring Password-Policy and User-Account

 

Lockout Settings

4-7

Lesson 3: Configuring Managed Service Accounts

4-14

Lab: Managing User and Service Accounts

4-20

Module 5: Implementing a Group Policy Infrastructure

Lesson 1: Introducing Group Policy

5-2

Lesson 2: Implementing and Administering GPOs

5-10

Lesson 3: Group Policy Scope and Group Policy Processing

5-16

Lesson 4: Troubleshooting the Application of GPOs

5-31

Lab: Implementing a Group Policy Infrastructure

5-38

PROHIBITED USE STUDENT .ONLY USE MCT

 

Administering Windows Server®2012

Module 6: Managing User Desktops with Group Policy

 

Lesson 1: Implementing Administrative Templates

6-2

Lesson 2: Configuring Folder Redirection and Scripts

6-7

Lesson 3: Configuring Group Policy Preferences

6-12

Lesson 4: Managing Software with Group Policy

6-16

Lab: Managing User Desktops with Group Policy

6-19

Module 7: Configuring and Troubleshooting Remote Access

 

Lesson 1: Configuring Network Access

7-2

Lesson 2: Configuring VPN Access

7-19

Lesson 3: Overview of Network Policies

7-19

Lesson 4: Troubleshooting Routing and Remote Access

7-25

Lab A: Configuring Remote Access

7-30

Lesson 5: Configuring DirectAccess

7-34

Lab B: Configuring DirectAccess

7-47

Module 8: Installing, Configuring, and Troubleshooting the

 

Network Policy Server Role

 

Lesson 1: Installing and Configuring a Network Policy Server

8-2

Lesson 2: Configuring RADIUS Clients and Servers

8-6

Lesson 3: NPS Authentication Methods

8-12

Lesson 4: Monitoring and Troubleshooting a Network Policy Server

8-20

Lab: Installing and Configuring a Network Policy Server

8-25

Module 9: Implementing Network Access Protection

 

Lesson 1: Overview of Network Access Protection

9-2

Lesson 2: Overview of NAP Enforcement Processes

9-7

Lesson 3: Configuring NAP

9-14

Lesson 4: Monitoring and Troubleshooting NAP

9-19

Lab: Implementing NAP

9-23

Module 10: Optimizing File Services

 

Lesson 1: Overview of FSRM

10-2

Lesson 2: Using FSRM to Manage Quotas, File Screens, and

 

Storage Reports

10-7

Lesson 3: Implementing Classification and File Management Tasks

10-16

Lab A: Configuring Quotas and File Screening Using FSRM

10-22

Lesson 4: Overview of DFS

10-26

Lesson 5: Configuring DFS Namespaces

10-33

Lesson 6: Configuring and Troubleshooting DFS-R

10-37

Lab B: Implementing DFS

10-41

MCTxiii USEONLY

STUDENT . PROHIBITED USE

xiv Administering Windows Server® 2012

Module 11: Configuring Encryption and Advanced Auditing

Lesson 1: Encrypting Files by Using Encrypting File System

11-2

Lesson 2: Configuring Advanced Auditing

11-6

Lab: Configuring Encryption and Advanced Auditing

11-13

Module 12: Implementing Update Management

Lesson 1: Overview of WSUS

12-2

Lesson 2: Deploying Updates with WSUS

12-5

Lab: Implementing Update Management

12-9

Module 13: Monitoring Windows Server 2012

Lesson 1: Monitoring Tools

13-2

Lesson 2: Using Performance Monitor

13-8

Lesson 3: Monitoring Event Logs

13-16

Lab: Monitoring Windows Server 2012

13-19

Lab Answer Keys

Module 1 Lab: Using Windows Deployment Services to

 

Deploy Windows Server 2012

L1-1

Module 2 Lab: Configuring and Troubleshooting DNS

L2-7

Module 3 Lab: Maintaining AD DS

L3-13

Module 4 Lab: Managing User and Service Accounts

L4-21

Module 5 Lab: Implementing a Group Policy Infrastructure

L5-25

Module 6

Lab: Managing User Desktops with Group Policy

L6-33

Module 7 Lab A: Configuring Remote Access

L7-39

Module 7

Lab B: Configuring DirectAccess

L7-45

Module 8

Lab: Installing and Configuring a Network Policy Server

L8-59

Module 9

Lab: Implementing NAP

L9-63

Module 10 Lab A: Configuring Quotas and File Screening Using FSRM

L10-71

Module 10

Lab B: Implementing DFS

L10-75

Module 11

Lab: Configuring Encryption and Advanced Auditing

L11-79

Module 12

Lab: Implementing Update Management

L12-83

Module 13

Lab: Monitoring Windows Server 2012

L13-87

PROHIBITED USE STUDENT .ONLY USE MCT

About This Course

xvii

 

 

 

About This Course

MCT

This section provides you with a brief description of the course—20411B: Administering Windows

 

 

Server® 2012— audience, suggested prerequisites, and course objectives.

 

 

knowledge necessary to broaden that implementation to manage and maintain the core infrastructure required for a Windows Server 2008 environment. Candidates must also have knowledge equivalent to that already covered in Windows Server 2012 Enterprise Core 1 course, as this course will build upon that knowledge.

Course Description

 

The main objective for this course is to configure and maintain core infrastructure services in a Windows

 

USE

Server 2012 enterprise environment. The primary audience for this course is Information Technology

(IT) Professionals who have successfully implemented a Microsoft® Windows Server 2008 server, either in

an existing enterprise infrastructure or as a standalone installation, and wish to acquire the skills and

.ONLY

Audience

This course is intended for students to broaden the initial deployment of services in Core 1, and

STUDENT

 

provide the skills necessary to manage and maintain domain-based Windows Server 2012 infrastructure. Candidates would typically be System Administrators and must have at least one year experience working in a Windows Server 2012 or Windows® 8 environment. The secondary audience for this course will be candidates aspiring to acquire the Microsoft Certified Solutions Associate (MCSA) credential either in its own right, or to proceed in acquiring the Microsoft Certified Solutions Expert (MCSE) credentials, of which this course is a prerequisite.

Student Prerequisites

This course requires that you have the ability to meet following prerequisites:

• Install and Configure Windows Server 2012 into existing enterprise environments, or as standalone

 

installations.

 

Configure local storage.

USE

Configure roles and features.

 

• Configure file and print services.

 

• Configure Windows Server 2012 servers for local and remote administration.

 

• Configure IPv4 and IPv6 addresses.

PROHIBITED

Configure Domain Name System (DNS) and Dynamic Host Configuration Protocol (DHCP) services.

 

Install domain controllers.

 

• Create and configure users, groups, computers and organizational units (OUs).

 

• Create and manage Group Policies.

 

• Configure local security policies.

 

xviii

About This Course

Course Objectives

After completing this course, students will be able to:

Deploy, manage, and maintain servers.

Configure file and print services.

Configure network services and access.

Configure a network policy server Infrastructure.

Configure and manage Active Directory® Domain Services (AD DS).

Configure and manage Group Policy.

Course Outline

The course outline is as follows:

Module 1, “Deploying and Maintaining Server Images”

Module 2, “Configuring and Troubleshooting Domain Name System”

Module 3, “Maintaining Active Directory Domain Services”

Module 4, “Managing User and Service Accounts”

Module 5, “Implementing a Group Policy Infrastructure”

Module 6, “Managing User Desktops with Group Policy”

Module 7, “Configuring and Troubleshooting Remote Access”

Module 8, “Installing, Configuring, and Troubleshooting the Network Policy Server Role”

Module 9, “Implementing Network Access Protection”

Module 10, “Optimizing File Services”

Module 11, “Configuring Encryption and Advanced Auditing”

Module 12, “Implementing Update Management”

Module 13, “Monitoring Windows Server 2012”

Exam/Course Mapping

This course, 20411B: Administering Windows Server® 2012, has a direct mapping of its content to the objective domain for the Microsoft Exam 70-411: Administering Windows Server 2012.

The following table is provided as a study aid that will assist you in preparation for taking this exam, and to show you how the exam objectives and the course content fit together. The course is not designed exclusively to support the exam, but rather provides broader knowledge and skills to allow a real-world implementation of the particular technology. The course will also contain content that is not directly covered in the examination and will utilize the unique experience and skills of your qualified Microsoft Certified Trainer.

Note: The exam objectives are available online at the following URL:

http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-411#tab2.

PROHIBITED USE STUDENT .ONLY USE MCT

About This Course xix

 

 

 

 

 

 

 

 

Exam 70-411: Administering Windows Server 2012

 

 

MCT

 

 

 

 

 

 

Exam Objective Domain

Course Content

 

 

Deploy, Manage, and Maintain Servers (17%)

Module

Lesson

Lab

 

 

 

This objective may include but is not limited to: Install

Mod 1

Lesson

Mod 1

 

Deploy and

the Windows Deployment Services (WDS) role;

 

1/2/3

Ex

 

 

manage server

configure and manage boot, install, and discover

 

 

1/2/3/4

 

images.

images; update images with patches, hotfixes, and

 

 

 

USE

 

drivers; install features for offline images

 

 

 

 

 

 

This objective may include but is not limited to: Install

Mod 12

Lesson

Mod 12

 

Implement

and configure the Windows Server Update Services

 

1/2

Ex 1/2/3

patch

(WSUS) role; configure group policies for updates;

 

 

 

 

 

management.

configure client-side targeting; configure WSUS

 

 

 

 

 

 

synchronization; configure WSUS groups

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 13

Lesson

Mod 13

 

Monitor

Configure Data Collector Sets (DCS); configure alerts;

 

1/2/3

Ex 1/2/3.ONLY

monitor real-time performance; monitor virtual

 

 

 

 

 

servers.

 

 

 

 

 

machines (VMs); monitor events; configure event

 

 

 

 

 

 

 

 

 

 

 

 

subscriptions; configure network monitoring

 

 

 

 

 

Configure File and Print Services (15%)

 

 

 

 

 

 

This objective may include but is not limited to: Install

Mod 10

Lesson

Mod 10

 

Configure

and configure DFS namespaces; configure DFS

 

4/5/6

Lab B

 

 

Distributed File

Replication Targets; configure Replication Scheduling;

 

 

Ex 1/2/3

System (DFS).

configure Remote Differential Compression settings;

 

 

 

 

 

 

configure staging; configure fault tolerance

 

 

 

 

 

Configure File

This objective may include but is not limited to: Install

Mod 10

Lesson

Mod 10

 

Server Resource

 

1/2/3

Lab A

 

 

the FSRM role; configure quotas; configure file screens;

 

 

 

Manager

 

 

Ex 1/2

configure reports

 

 

(FSRM).

 

 

 

STUDENT

 

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 11

Lesson

Mod 11

 

Configure file

Configure Bitlocker encryption; configure the Network

 

1

Ex 1

USE

and disk

Unlock feature; configure Bitlocker policies; configure

 

 

 

encryption.

the EFS recovery agent; manage EFS and Bitlocker

 

 

 

 

certificates including backup and restore

 

 

 

Configure

This objective may include but is not limited to:

Mod 11

Lesson

Mod 11

 

Implement auditing using Group Policy and

 

2

Ex 2

PROHIBITED

advanced audit

 

 

 

 

AuditPol.exe; create expression-based audit policies;

 

 

 

 

 

policies.

 

 

 

 

 

create removable device audit policies

 

 

 

 

 

 

 

 

 

 

 

xx

About This Course

Exam 70-411: Administering Windows Server 2012

Exam Objective Domain

Course Content

MCT

Configure Network Services and Access (17%)

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 2

Lesson

Mod 2

USE

 

Configure primary and secondary zones; configure stub

 

1/3/4

Ex 2/4

Configure DNS

zones; configure conditional forwards; configure zone

 

 

 

zones.

and conditional forward storage in Active Directory;

 

 

 

 

configure zone delegation; configure zone transfer

 

 

 

.ONLY

 

settings; configure notify settings

 

 

 

 

 

 

 

 

 

 

This objective may include but is not limited to: Create

Mod 2

Lesson

Mod 2

 

 

Configure DNS

and configure DNS Resource Records (RR) including A,

 

2/5

Ex 1/3

 

 

AAAA, PTR, SOA, NS, SRV, CNAME, and MX records;

 

 

 

 

 

records.

configure zone scavenging; configure record options

 

 

 

 

 

 

including Time To Live (TTL) and weight; configure

 

 

 

 

 

 

round robin; configure secure dynamic updates

 

 

 

 

 

 

This objective may include but is not limited to: Install

Mod 7

Lesson

Mod 7

 

 

Configure VPN

and configure the Remote Access role; implement

 

1/2/3/

Lab A Ex

Network Address Translation (NAT); configure VPN

 

4

1/2

 

 

and routing.

 

 

 

settings; configure remote dial-in settings for users;

 

 

 

 

 

 

 

 

 

 

 

 

configure routing

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 7

Lesson

Mod 7

 

 

Configure

Implement server requirements; implement client

 

5

Lab B Ex

DirectAccess.

configuration; configure DNS for Direct Access;

 

 

1/2/3

 

 

 

configure certificates for Direct Access

 

 

 

 

 

Configure a Network Policy Server Infrastructure (14%)

 

 

 

 

 

Configure

This objective may include but is not limited to:

Mod 8

Lesson

Mod 8

STUDENT

Configure multiple RADIUS server infrastructures;

 

3/4

Ex 2

Network Policy

 

Server (NPS).

configure RADIUS clients; manage RADIUS templates;

 

 

 

 

 

configure RADIUS accounting; configure certificates

 

 

 

 

 

 

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 6

Lesson

 

 

 

Configure NPS

Configure connection request policies; configure

 

2

 

 

 

network policies for VPN clients (multilink and

Mod 8

Lesson

Mod 8

USE

policies.

bandwidth allocation, IP filters, encryption, IP

 

1/2

Ex 1

 

addressing); manage NPS templates; import and export

 

 

 

PROHIBITED

 

NPS policies

 

 

 

 

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 9

Lesson

Mod 9

 

 

Configure

Configure System Health Validators (SHVs); configure

 

1/2/3/

Ex 1/2/3

Network Access

health policies; configure NAP enforcement using DHCP

 

4

 

 

 

Protection

and VPN; configure isolation and remediation of non-

 

 

 

 

 

(NAP).

compliant computers using DHCP and VPN; configure

 

 

 

 

 

 

NAP client settings

 

 

 

 

 

About This Course

Exam 70-411: Administering Windows Server 2012

Exam Objective Domain

Course Content

MCTxxi

Configure and Manage Active Directory (19%)

 

 

 

 

 

 

This objective may include but is not limited to: Create

Mod 4

Lesson

Mod 4

 

Configure

and configure Service Accounts; create and configure

 

1/2/3

Ex 1/2

service

Group Managed Service Accounts; create and configure

 

 

 

USE

authentication.

Managed Service Accounts; configure Kerberos

 

 

 

 

delegation; manage Service Principal Names (SPNs)

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 3

Lesson

Mod 3

 

Configure

Configure Universal Group Membership Caching

 

1/2/3

Ex 1/2

Domain

(UGMC); transfer and seize operations masters; install

 

 

 

 

 

Controllers.

and configure a read-only domain controller (RODC);

 

 

 

 

 

 

configure Domain Controller cloning

 

 

 

 

 

 

This objective may include but is not limited to: Back up

Mod 3

Lesson

Mod 3

 

Maintain Active

Active Directory and SYSVOL; manage Active Directory

 

1/3/4/

Ex 2/3.ONLY

offline; optimize an Active Directory database; clean up

 

5

 

STUDENT

Directory.

metadata; configure Active Directory snapshots;

 

 

 

 

 

 

 

 

 

perform objectand container-level recovery; perform

 

 

 

 

 

 

Active Directory restore

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 4

Lesson

Mod 4

 

Configure

Configure domain user password policy; configure and

 

1/2/3

Ex 1

 

 

account

apply Password Settings Objects (PSOs); delegate

 

 

 

 

 

policies.

password settings management; configure local user

 

 

 

 

 

 

password policy; configure account lockout settings

 

 

 

 

 

Configure and Manage Group Policy (18%)

 

 

 

 

 

 

This objective may include but is not limited to:

Mod 5

Lesson

Mod 5

 

Configure

Configure processing order and precedence; configure

 

1/3/4

Ex 1/2

blocking of inheritance; configure enforced policies;

 

 

USE

Group Policy

configure security filtering and WMI filtering; configure

 

 

processing.

loopback processing; configure and manage slow-link

 

 

 

processing; configure client-side extension (CSE)

 

 

 

behavior

 

 

 

This objective may include but is not limited to:

Mod 6

Lesson

Mod 6

 

 

Configure settings including software installation, folder

 

1/2/4

Ex 2

PROHIBITED

Configure

redirection, scripts, and administrative template

 

 

 

 

 

 

 

 

Group Policy

settings; import security templates; import custom

 

 

 

 

 

settings.

administrative template file; convert administrative

 

 

 

 

 

 

templates using ADMX Migrator; configure property

 

 

 

 

 

 

filters for administrative templates

 

 

 

 

 

Manage Group

This objective may include but is not limited to: Back up,

Mod 5

Lesson

Mod 5

 

import, copy, and restore GPOs; create and configure

 

2

Ex 4

 

 

Policy objects

 

 

 

Migration Table; reset default GPOs; delegate Group

 

 

 

 

 

(GPOs).

 

 

 

 

 

Policy management

 

 

 

 

 

 

 

 

 

 

 

Lab Answer Keys: Provide step-by-step lab solution guidance at your fingertips when it’s needed.
Module Reviews and Takeaways: Provide improved on-the-job reference material to boost knowledge and skills retention.
Labs: Provide a real-world, hands-on platform for you to apply the knowledge and skills learned in the module.

xxii About This Course

 

Exam 70-411: Administering Windows Server 2012

 

 

 

 

MCT

 

 

 

 

 

 

Exam Objective Domain

 

Course Content

 

 

This objective may include but is not limited to:

Mod 6

 

Lesson

Mod 6

 

USE

Configure

Configure Group Policy Preferences (GPP) settings

 

 

1/2/3

Ex 1

 

 

 

 

 

including printers, network drive mappings, power

 

 

 

 

 

 

Group Policy

 

 

 

 

 

 

options, custom registry settings, Control Panel settings,

 

 

 

 

 

 

preferences.

 

 

 

 

 

 

Internet Explorer settings, file and folder deployment,

 

 

 

 

 

 

 

 

 

 

 

 

 

 

and shortcut deployment; configure item-level targeting

 

 

 

 

 

.ONLY

 

 

 

 

 

 

 

Important: Attending this course in itself will not successfully prepare you to pass any associated certification exams.

The taking of this course does not guarantee that you will automatically pass any certification exam. In addition to attendance at this course, you should also have the following:

Real-world, hands-on experience administering, managing and maintaining a Windows Server 2012 infrastructure.

Additional study outside of the content in this handbook.

There may also be additional study and preparation resources, such as practice tests, available for you to prepare for this exam. Details of these are available at the following URL: http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-411#tab3

You should familiarize yourself with the audience profile and exam prerequisites to ensure you are sufficiently prepared before taking the certification exam. The complete audience profile for this exam is available at the following URL:

http://www.microsoft.com/learning/en/us/exam.aspx?ID=70-411#tab1

The exam/course mapping table outlined above is accurate at the time of printing, however it is subject

STUDENT

to change at any time and Microsoft bears no responsibility for any discrepancies between the version

USE

published here and the version available online and will provide no notification of such changes.

Course Materials

The following materials are included with your kit:

Course Handbook A succinct classroom learning guide that provides all the critical technical

 

 

information in a crisp, tightly-focused format, which is just right for an effective in-class learning

 

 

experience.

 

 

Lessons: Guide you through the learning objectives and provide the key points that are critical to

 

 

PROHIBITED

the success of the in-class learning experience.

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]