Window2003 / Active Directory 그룹 정책 실습 파일
- Posted at 2007/04/30 13:53
- Filed under Study
Student Computers
Use the instructions in the following section to set up the classroom manually.
1. Install Windows Server 2003, Enterprise Edition
Task Summary
Set up the computer with two partitions 6 GB and
4 GB in size formatted with the NTFS file system.
[계속 보기]
Install Windows Server 2003, Enterprise Edition on the C partition.
1. Set up the hardware according to the manufacturer’s instructions. (Refer to the hardware requirements.)
Note
If necessary, configure your computer so that it starts from the hard disk and then from the CD-ROM drive.
2. Start the computer from the Windows Server 2003, Enterprise Edition compact disc.
3. On the Setup Notification page, press ENTER to continue.
4. On the Welcome to Setup page, press ENTER to continue.
5. On the Windows Licensing Agreement page, press F8 to agree.
6. On the Windows Server 2003, Enterprise Edition Setup page, partition the disks as follows:
a. C:\ 6 GB
b. D:\ 4 GB
c. Leave the remaining space on the disk as unpartitioned space
7. Select C:, and then press ENTER to install the operating system.
8. Select Format the partition using the NTFS file system (Quick), and then press ENTER to continue.
9. On the Regional and Language Options page, click Next.
10. On the Personalize Your Software page, type the following, and then click Next.
a. Name: MOC Classroom
b. Organization: Microsoft Corporation
11. On the Your Product Key page, type your product key, and then click Next.
12. On the Licensing Modes page, select Per server, in the Number of concurrent connections box, type 50 and then click Next.
13. On the Computer Name and Administrator Password page, type the following, and then click Next.
a. Computer name: Refer to the following table for student computer names and IP addresses. Replace x with the classroom number.
Computer Name IP Address
Vancouver 192.168.x.1
Denver 192.168.x.2
Perth 192.168.x.3
Brisbane 192.168.x.4
Lisbon 192.168.x.5
Bonn 192.168.x.6
Lima 192.168.x.7
Santiago 192.168.x.8
Bangalore 192.168.x.9
Singapore 192.168.x.10
Casablanca 192.168.x.11
Tunis 192.168.x.12
Acapulco 192.168.x.13
Miami 192.168.x.14
Auckland 192.168.x.15
Suva 192.168.x.16
Stockholm 192.168.x.17
Moscow 192.168.x.18
Caracas 192.168.x.19
Montevideo 192.168.x.20
Manila 192.168.x.21
Tokyo 192.168.x.22
Khartoum 192.168.x.23
Nairobi 192.168.x.24
b. Administrator password: P@ssw0rd
c. Confirm password: P@ssw0rd
14. On the Date and Time Settings page, select your time zone, and then click Next.
15. On the Networking Settings page, select Custom settings, and then click Next.
16. In the Networking Components dialog box, click Internet Protocol(TCP/IP), and then click Properties.
17. In the Internet Protocol(TCP/IP) Properties dialog box, click Use the following IP address, then type the following information in the appropriate boxes, and then click Advanced.
IP Address: 192.168.x.y (refer to the previous table for the value of x
and y)
Subnet Mask: 255.255.255.0
Preferred DNS Server: 192.168.x.200 (refer to the previous table for the value of x)
18. In the Internet Protocol(TCP/IP) Properties dialog box, click OK.
19. In the Networking Components dialog box, click Next.
20. On the Workgroup or Computer Domain page, click Next.
The installation is complete and the computer reboots.
2. Format the D drive
Task Summary
Format the 4 GB partition created during the operating system installation with NTFS and label the partition D Drive.
1. Log on as Administrator with a password of P@ssw0rd.
2. In the Manage Your Server window, click Don’t display this page at logon, and then close the window.
3. Click Start, and then click Run.
4. In the Run dialog box, type cmd and then click OK.
5. At the command prompt, type format d: /fs:ntfs /q and then press ENTER.
6. Type Y and then press ENTER.
7. When prompted for a Volume Label, type D Drive and then press ENTER.
8. Close the command prompt window.
3. Configure the Display
Task Summary
Set the screen resolution to 800 by 600, disable the screen saver password, and configure the wallpaper.
Set the screen resolution to 800 by 600 and configure the wallpaper
1. Copy the \\London\Setup\Images folder to C:\Images.
2. Right-click the desktop, and then click Properties.
3. In the Display Properties dialog box, click the Settings tab.
4. Under Screen Resolution, click and move the slider to 800 by 600 pixels.
5. On the Screen Saver tab, clear the On resume, password protect check box.
6. On the Desktop tab, click Browse.
7. In the Browse dialog box, browse to the C:\Images folder, and then click the appropriate image file for your computer.
Image file names are based on the first three letters of the computer name. For example, the Bangalore computer uses the Ban image file.
8. Click OK to close the Display Properties dialog box.
9. In the Monitor Settings dialog box, click Yes.
4. Install the Macromedia Flash 6.0 Plug-in
Task Summary
Install the Flash 6.0 plug-in by running Flash6A.exe.
1. Run \\London\Setup\Flash6A.exe.
2. In the File Download dialog box, click Open.
3. In the Macromedia Flash Player 6 dialog box, click Yes.
4. After installation is complete, click OK.
5. Install the Student Lab Files
Task Summary
Run \\London\Setup\
Allfiles.exe to install the student lab files.
1. Run \\London\Setup\Allfiles.exe, and then click OK.
2. In the File Download dialog box, click Open.
3. In the WinZip Self-Extractor - Allfiles.exe dialog box, click Unzip.
4. Click OK, and then click Close.
5. Share C:\Program Files\Microsoft Training\2209\labfiles using the default name of labfiles and default permissions of Everyone Read.
6. Install Active Directory
Task Summary
Create a forest root domain on each of the student computers. Refer to the tables for wizard answers.
Each student computer will be a domain controller in a new forest root domain. Refer to the following table while installing Active Directory to determine the New Domain Name and the NetBIOS Domain Name for each student computer:
Computer New Domain Name NetBIOS Domain Name
Vancouver nwtraders1.msft NWTRADERS1
Denver nwtraders2.msft NWTRADERS2
Perth nwtraders3.msft NWTRADERS3
Brisbane nwtraders4.msft NWTRADERS4
Lisbon nwtraders5.msft NWTRADERS5
Bonn nwtraders6.msft NWTRADERS6
Lima nwtraders7.msft NWTRADERS7
Santiago nwtraders8.msft NWTRADERS8
Bangalore nwtraders9.msft NWTRADERS9
Singapore nwtraders10.msft NWTRADERS10
Casablanca nwtraders11.msft NWTRADERS11
Tunis nwtraders12.msft NWTRADERS12
Acapulco nwtraders13.msft NWTRADERS13
Miami nwtraders14.msft NWTRADERS14
Auckland nwtraders15.msft NWTRADERS15
Suva nwtraders16.msft NWTRADERS16
Stockholm nwtraders17.msft NWTRADERS17
Moscow nwtraders18.msft NWTRADERS18
(continued)
Computer New Domain Name NetBIOS Domain Name
Caracas nwtraders19.msft NWTRADERS19
Montevideo nwtraders20.msft NWTRADERS20
Manila nwtraders21.msft NWTRADERS21
Tokyo nwtraders22.msft NWTRADERS22
Khartoum nwtraders23.msft NWTRADERS23
Nairobi nwtraders24.msft NWTRADERS24
Use the following instructions to install the Active Directory directory service on the student computers.
1. Click Start, and then click Run.
2. In the Run dialog box, type dcpromo and then click OK.
3. On the Welcome to the Active Directory Installation Wizard page, click Next.
4. On the Operating System Compatibility page, click Next.
5. Complete the Active Directory Installation Wizard by using the information in the following table.
On this wizard page Do this
Domain Controller Type Verify that Domain controller for a new domain is selected.
Create New Domain Verify that Domain in a new forest is selected.
New Domain Name Refer to the previous table.
NetBIOS Domain Name Refer to the previous table.
Database and Log Folders Leave as default.
Shared System Volume Leave as default.
DNS Registration Diagnostics Leave as default.
Permissions Leave as default.
Directory Services Restore Mode Administrator Password Restore Mode Password: P@ssw0rd
Confirm password: P@ssw0rd
Summary Click Next.
6. On the Completing the Active Directory Installation Wizard page, click Finish.
A message appears, prompting you to restart the computer so that the changes that you made can take effect.
7. Click Restart Now.
7. Configure Group Policy Settings
Task Summary
Configure Group Policy settings to allow Authenticated Users to log on locally and to configure Internet Explorer.
1. From the Administrative Tools menu, open Active Directory Users and Computers.
2. In the console tree, double-click nwtradersx.msft (where x is the number assigned to the student domain), right-click Domain Controllers, and then click Properties.
3. In the Domain Controllers Properties dialog box, on the Group Policy tab, click Edit.
4. In the Group Policy Object Editor, in the console tree, under Computer Configuration, double-click Windows Settings, double-click Security Settings, double-click Local Policies, and then click User Rights Assignments.
5. In the details pane, double-click Allow log on locally.
6. In the Allow log on locally Properties dialog box, click Add User or Group.
7. In the Add User or Group dialog box, type Authenticated Users, click OK, and then click OK to close the Allow log on locally Properties dialog box.
8. In the console tree, under Computer Configuration, double-click Administrative Templates, double-click Windows Components, and then click Internet Explorer.
9. In the details pane, double-click Security Zones: Use only machine settings.
10. In the Security Zones: Use only machine settings Properties dialog box, click Enabled, and then click OK.
11. Close Group Policy Object Editor, and then click OK to close the Domain Controllers Properties dialog box.
12. In the console tree, right-click nwtradersx.msft, and then click Properties.
13. In the nwtradersx.msft Properties dialog box, on the Group Policy tab, click Edit.
14. In the Group Policy Object Editor, in the console tree, under Computer Configuration, double-click Windows Settings, double-click Security Settings, double-click Account Policies, and then click Account Lockout Policy.
15. In the details pane, double-click Account lockout duration.
16. In the Account lockout duration Properties dialog box, select the Define this policy setting check box, in the Account is locked out for box, change the value from 30 to 0 and then click OK.
17. In the Suggested Value Changes dialog box, click OK to accept the suggested values.
18. Close the Group Policy Editor, click OK to close the nwtradersx.msft Properties dialog box, and then close Active Directory Users and Computers.
19. Open a command prompt window.
20. At the command prompt, type gpupdate and then press ENTER.
21. Close the command prompt window.
8. Configure Internet Explorer
Task Summary
Add the local computer to the list of Local intranet sites.
1. Click Start, point to All Programs, and then click Internet Explorer.
2. In the Internet Explorer message box, select the In the future, do not show this message check box, and then click OK.
3. On the Tools menu, click Internet Options.
4. On the Security tab, click Local Intranet, and then click Sites.
5. In the Local intranet dialog box, ensure that the Require server verification (https:) for all sites in this zone check box is cleared, and then type file://Computer (where Computer is the assigned computer name) in the Add this Web site to the zone box.
6. Click Add, and then click Close.
7. Click OK, and then close Internet Explorer.
9. Populate Active Directory
Task Summary
Create and configure the required objects in Active Directory.
1. From the Administrative Tools menu, open Active Directory Users and Computers.
2. In the console tree, double-click nwtradersx.msft (where x is the assigned student domain number), right-click nwtradersx.msft, point to New, and then click Organizational Unit.
3. In the New Object – Organizational Unit dialog box, in the Name box, type CSO and then click OK.
4. In the console tree, right-click CSO, point to New, and then click User.
5. In the New Object – User dialog box, use the following parameters to create a new user:
First name: Holly
Last name: Holt
Full name: Holly Holt
User logon name: HoltH
User logon name (pre-Windows 2000): HoltH
Password: P@ssw0rd
Confirm Password: P@ssw0rd
User must change password at next logon: Cleared
User cannot change password: Cleared
Password never expires: Cleared
Account is disabled: Cleared
6. Click Finish.
7. Repeat steps 3-6 to create 10 additional users in the CSO organizational unit. Change the First name, Last name, Full name, User logon name, and User logon name (pre-Windows 2000) as appropriate, according to the following table:
First name
Last name
Full name
User logon name User logon name (pre-Windows 2000)
Michael Allen Michael Allen AllenM AllenM
Don Hall Don Hall HallD HallD
Max Benson Max Benson BensonM BensonM
Nicole Caron Nicole Caron CaronN CaronN
Eva Corets Eva Corets CoretsE CoretsE
Andrew Ma Andrew Ma MaA MaA
Sairaj Uddin Sairaj Uddin UddinS UddinS
Mandy Vance Mandy Vance VanceM VanceM
Brian Walton Brain Walton WaltonB WaltonB
Tai Yee Tai Yee YeeT YeeT
Mary Baker Mary Baker BakerM BakerM
8. In the details pane, select all of the user accounts, right-click, and then click Properties.
9. In the Properties On Multiple Objects dialog box, on the Address tab, select the Street check box.
10. Type 40 North 1st Street and then click OK.
11. In the details pane, double-click Holly Holt.
12. In the Holly Holt Properties dialog box, configure additional account properties according to the following table:
Tab Property Value
General Description Phone Rep Manager
Office Lakeridge Towers
Telephone number X2596
Address City Redmond
State WA
Zip/Postal Code 98052
Country/region United States
Account User must change password at next logon Selected
Account is disabled Selected
Organization Title Phone Rep Manager
Department CSO
Company Northwind Traders
13. Click OK to close the Holly Holt Properties dialog box.
14. In the details pane, select Andrew Ma, Don Hall, and Mandy Vance, right-click, and then click Properties.
15. In the Properties On Multiple Objects dialog box, on the Account tab, under Account options, select the check box to the left of Password never expires, select the Password never expires check box, and then click OK.
16. In the console tree, right-click Users¸ point to New, and then click Group.
17. In the New Object – Group dialog box, in the Group Name box, type Marketing and then click OK.
18. In the console tree, right-click nwtradersx.msft, point to New¸ and then click Organizational Unit.
19. In the New Object – Organizational Unit dialog box, in the Name box, type Development and then click OK.
20. In the console tree, right-click Development, point to New, and then click User.
21. In the New Object – User dialog box use the following parameters to create a new user:
First name: Bjorn
Last name: Rettig
Full name: Bjorn Rettig
User logon name: RettigB
User logon name (pre-Windows 2000): RettigB
Password: P@ssw0rd
Confirm password: P@ssw0rd
User must change password at next logon: Cleared
User cannot change password: Cleared
Password never expires: Cleared
Account is disabled: Cleared
22. Click Finish.
23. In the details pane, double-click Bjorn Rettig.
24. In the Bjorn Rettig Properties dialog box, on the Member Of tab, click Add.
25. In the Select Groups dialog box, type Marketing; Domain Admins and then click OK.
26. Click OK to close the Bjorn Rettig Properties dialog box.
27. In the console tree, right-click CSO, point to New¸ and then click User.
28. In the New Object – User dialog box use the following parameters to create a new user:
First name: John
Last name: Rodman
Full name: John Rodman
User logon name: RodmanJ
User logon name (pre-Windows 2000): RodmanJ
Password: BadP@ssw0rd
Confirm password: BadP@ssw0rd
User must change password at next logon: Cleared
User cannot change password: Cleared
Password never expires: Cleared
Account is disabled: Cleared
29. In the console tree, right-click nwtradersx.msft, point to New, and then click Organizational Unit.
30. In the New Object – Organizational Unit dialog box, in the Name box, type HR and then click OK.
31. In the console tree, right-click HR, point to New, and then click User.
32. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Peter
• Last name: Houston
• Full name: Peter Houston
• User logon name: HoustonP
• User logon name (pre-Windows 2000): HoustonP
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
33. In the console tree, click Computers, right-click Computers, point to New, and then click Computer.
34. In the New Object – Computer dialog box, in the Computer name box, type bakerm1 click Next, click Next, and then click Finish.
35. In the details pane, right-click bakerm1, click Disable Account, in the Active Directory dialog box, click Yes, and then in the Active Directory message box, click OK.
36. On the View menu, click Advanced Features.
37. In the console tree, right-click CSO, and then click Properties.
38. In the CSO Properties dialog box, on the Security tab, click Add.
39. In the Select Users, Computers, or Groups dialog box, type Marketing and then click OK.
40. In the Permissions for Marketing list, select the Deny check box to the right of Create All Child Objects, and then click OK.
41. In the Security dialog box, click Yes.
42. On the View menu, click Advanced Features.
43. In the console tree, right-click nwtradersx.msft, point to New, and then click Organizational Unit.
44. In the New Object – Organizational Unit dialog box, in the Name box, type Sales and then click OK.
45. In the console tree, right-click Sales, point to New, and then click Organizational Unit.
46. In the New Object – Organizational Unit dialog box, in the Name box, type Mobile Sales Force and then click OK.
47. In the console tree, right-click Sales, point to New, and then click Organizational Unit.
48. In the New Object – Organizational Unit dialog box, in the Name box, type Sales Admin Assistants and then click OK.
49. In the console tree, right-click Sales, point to New, and then click Group.
50. In the New Object – Group dialog box, in the Group Name box, type Sales IT and then click OK.
51. In the console tree, right-click Sales, point to New, and then click User.
52. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Lori
• Last name: Kane
• Full name: Lori Kane
• User logon name: KaneL
• User logon name (pre-Windows 2000): KaneL
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
53. In the console tree, right-click Sales, point to New, and then click User.
54. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Sharon
• Last name: Salavaria
• Full name: Sharon Salavaria
• User logon name: SalavariaS
• User logon name (pre-Windows 2000): SalavariaS
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
55. In the console tree, right-click Mobile Sales Force, point to New, and then click User.
56. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Andy
• Last name: Ruth
• Full name: Andy Ruth
• User logon name: RuthA
• User logon name (pre-Windows 2000): RuthA
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
57. In the console tree, right-click Mobile Sales Force, point to New, and then click User.
58. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Sunil
• Last name: Koduri
• Full name: Sunil Koduri
• User logon name: KoduriS
• User logon name (pre-Windows 2000): KoduriS
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
59. In the console tree, right-click Sales Admin Assistants, point to New, and then click User.
60. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Josh
• Last name: Barnhill
• Full name: Josh Barnhill
• User logon name: BarnhillJ
• User logon name (pre-Windows 2000): BarnhillJ
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
61. In the console tree, right-click Sales Admin Assistants, point to New, and then click User.
62. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Ben
• Last name: Smith
• Full name: Ben Smith
• User logon name: SmithB
• User logon name (pre-Windows 2000): SmithB
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
63. In the console tree, click Sales, in the details pane, right-click Sales IT, and then click Properties.
64. On the Members tab, click Add.
65. In the Select Users, Contacts, or Computers dialog box, type Sharon Salavaria; Sunil Koduri; Ben Smith and then click OK.
66. In the Sales IT Properties dialog box, click OK.
67. In the console tree, right-click nwtradersx.msft, point to New, and then click Organizational Unit.
68. In the New Object – Organizational Unit dialog box, in the Name box, type GPMCPractice and then click OK.
69. In the console tree, right-click GPMCPractice, point to New, and then click Organizational Unit.
70. In the New Object – Organizational Unit dialog box, in the Name box, type Marketing and then click OK.
71. In the console tree, right-click GPMCPractice, point to New, and then click Organizational Unit.
72. In the New Object – Organizational Unit dialog box, in the Name box, type Finance and then click OK.
73. In the console tree, right-click GPMCPractice, point to New, and then click Organizational Unit.
74. In the New Object – Organizational Unit dialog box, in the Name box, type Engineering and then click OK.
75. In the console tree, right-click Marketing, point to New, and then click Organizational Unit.
76. In the New Object – Organizational Unit dialog box, in the Name box, type Marketing Assistants and then click OK.
77. In the console tree, right-click Finance, point to New, and then click User.
78. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Server
• Last name: Admin
• Full name: Server Admin
• User logon name: ServerAdmin
• User logon name (pre-Windows 2000): ServerAdmin
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
79. In the console tree, right-click Finance, point to New, and then click User.
80. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Finance
• Last name: Admin
• Full name: Finance Admin
• User logon name: FinanceAdmin
• User logon name (pre-Windows 2000): FinanceAdmin
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
81. In the console tree, right-click nwtradersx.msft, point to New, and then click Organizational Unit.
82. In the New Object – Organizational Unit dialog box, in the Name box, type Databases and then click OK.
83. In the console tree, right-click Databases, point to New, and then click Group.
84. In the New Object – Group dialog box, in the Group Name box, type DB Users and then click OK.
85. In the console tree, right-click Databases, point to New, and then click Group.
86. In the New Object – Group dialog box, in the Group Name box, type DB Operators and then click OK.
87. In the console tree, right-click Databases, point to New, and then click User.
88. In the New Object – User dialog box use the following parameters to create a new user:
• First name: John
• Last name: Frum
• Full name: John Frum
• User logon name: FrumJ
• User logon name (pre-Windows 2000): FrumJ
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
89. In the console tree, right-click HR, point to New, and then click Group.
90. In the New Object – Group dialog box, in the Group Name box, type Human Resources and then click OK.
91. In the console tree, right-click HR, point to New, and then click User.
92. In the New Object – User dialog box use the following parameters to create a new user:
• First name: Julia
• Last name: Moseley
• Full name: Julia Moseley
• User logon name: MoseleyJ
• User logon name (pre-Windows 2000): MoseleyJ
• Password: P@ssw0rd
• Confirm password: P@ssw0rd
• User must change password at next logon: Cleared
• User cannot change password: Cleared
• Password never expires: Cleared
Account is disabled: Cleared
93. In the console tree, click HR¸ and then in the details pane, double-click Julia Moseley.
94. In the Julia Moseley Properties dialog box, on the Member Of tab, click Add.
95. In the Select Groups dialog box, type Human Resources and then click OK.
96. In the Julia Moseley Properties dialog box, click OK.
97. Close Active Directory Users and Computers.
98. Log on as Kanel with a password of P@ssw0rd.
99. Log off.
100. Log on as Koduris with a password of P@ssw0rd.
101. Log off.
102. Log on as Barnhillj with a password of P@ssw0rd.
103. Log off.
104. Log on as Administrator with a password of P@ssw0rd.
10. Lock out Bjorn Rettig’s Account
Task Summary
Run the C:\Program Files\Microsoft Training\Labfiles\Setup
\Lockout.cmd batch file to lock out Bjorn Rettig’s account.
1. Open a command prompt window.
2. At the command prompt, type “C:\Program Files\Microsoft Training\
2209\Labfiles\Setup\Lockout.cmd” and then press ENTER.
3. Verify that the last error message returned by the batch file is The referenced account is locked out and may not be logged on to.
4. Close the command prompt window.
11. Install GPMC
Task Summary
Install the Group Policy Management Console (GPMC) by running gpmc.msi.
1. Run \\London\Setup\gpmc.msi.
2. In the File Download dialog box, click Open.
3. On the Welcome to the Microsoft Group Policy Management Console Setup Wizard page, click Next.
4. On the License Agreement page, click I Agree, and then click Next.
5. On the Completing the Microsoft Group Policy Management Console Setup Wizard page, click Finish.
12. Configure Group Policy for GPMC
1. From the Administrative Tools menu, open Group Policy Management.
2. In the console tree, double-click the student’s forest, double-click Domains, double-click the student’s domain, and then click Group Policy Objects.
3. Right-click Group Policy Objects, and then click New.
4. In the New GPO dialog box, in the Name box, type Default Logon Policy and then click OK.
5. In the details pane, right-click Default Logon Policy, and then click Import Settings.
6. On the Welcome to the Import Settings Wizard page, click Next.
7. On the Backup GPO page, click Next.
8. On the Backup location page, click Browse.
9. In the Browse For Folder dialog box, browse to the C:\Program Files\
Microsoft Training\2209\Labfiles\Setup\Backup Policies folder, and then click OK.
10. On the Backup location page, click Next.
11. On the Source GPO page, select Default Logon Policy, and then click Next.
12. On the Scanning Backup page, click Next.
13. On the Migrating References page, verify that Copying them identically from the source is selected, and then click Next.
14. On the Completing the Import Settings Wizard page, click Finish.
15. In the Import dialog box, click OK.
16. Repeat steps 3-7, then steps 10-12 (in step 11, replace the name of the Source GPO as appropriate), and then steps 14 and 15 for the following Group Policy objects:
Windows Update Policy
Finance Restrictions
Allow Registry Editing
Security Settings
Wireless Configuration
Deny Windows Messenger
Deny Control Panel
Allow Control Panel
17. In the console tree, double-click GPMCPractice, right-click Marketing, and then click Link an Existing GPO.
18. In the Select GPO dialog box, select Deny Control Panel, and then click OK.
19. In the console tree, right-click Marketing, and then click Link an Existing GPO.
20. In the Select GPO dialog box, select Allow Control Panel, and then click OK.
21. In the console tree, right-click Finance, and then click Link an Existing GPO.
22. In the Select GPO dialog box, select Finance Restrictions, and then click OK.
23. In the console tree, right-click Finance, and then click Link an Existing GPO.
24. In the Select GPO dialog box, select Security Settings, and then click OK.
25. In the console tree, right-click Sales, and then click Link an Existing GPO.
26. In the Select GPO dialog box, select Deny Windows Messenger, and then click OK.
27. In the console tree, right-click Sales, and then click Link an Existing GPO.
28. In the Select GPO dialog box, select Security Settings, and then click OK.
29. In the console tree, double-click Sales, right-click Mobile Sales Force, and then click Link an Existing GPO.
30. In the Select GPO dialog box, select Wireless Configuration, and then click OK.
31. Close Group Policy Management.
13. Create Files and Folders
Task Summary
Create and configure the required files and folders.
1. Create a directory named Reports at the root of drive C:.
2. In Windows Explorer, right-click C:\Reports, and then click Properties.
3. In the Reports Properties dialog box, on the Security tab, click Add.
4. In the Select Users, Computers, or Groups dialog box, type DB Users;DB Operators and then click OK.
5. In the Reports Properties dialog box, verify that DB Operators (Nwtradersx\DB Operators) is selected, and then in the Permissions for DB Operators list, select the Allow check box to the right of Modify.
6. Select DB Users (Nwtradersx\DB Users), in the Permissions for DB Users list, select the Allow check box to the right of Modify, and then click OK.
7. Create a directory named Logs at the root of drive C:.
8. In the C:\Logs folder, create a file named Logs.txt.
9. In Windows Explorer, right-click C:\Logs, and then click Properties.
10. In the Logs Properties dialog box, on the Security tab, click Add.
11. In the Select Users, Computers, or Groups dialog box, type MoseleyJ and then click OK.
12. In the Logs Properties dialog box, verify that Julia Moseley (MoseleyJ@nwtradersx.msft) is selected, and then in the Permissions for Julia Moseley list, select the Allow check box to the right of Full Control.
13. Click Advanced.
14. In the Advanced Security Settings for Logs dialog box, on the Owner tab, click Other Users or Groups.
15. In the Select Users, Computers, or Groups dialog box, type MoseleyJ and then click OK.
16. In the Advanced Security Settings for Logs dialog box¸ verify that Julia Moseley (MoseleyJ@nwtradersx.msft) is selected, and then select the Replace Owner on subcontainer and objects check box.
17. On the Permissions tab, clear the Allow inheritable permissions from the parent to propagate to this object and all child objects. Include these with entries explicitly defined here check box, and then in the Security dialog box, click Remove.
18. In the Advanced Security Settings for Logs dialog box, click Apply.
19. In the Advanced Security Settings for Logs dialog box, in the Permissions entries list, verify that Administrators (NWTRADERSx\Administrators) is selected, and then click Remove.
20. In the Advanced Security Settings for Logs dialog box, click OK.
21. In the Logs Properties dialog box, click OK.
22. Open a command prompt window.
23. At the command prompt, type md “C:\Daily Reports” and then press ENTER.
24. In the C:\Daily Reports folder, create a text file named Daily Report.txt.
25. Right-click C:\Daily Reports, and then click Properties.
26. In the Daily Reports Properties dialog box, on the Security tab, select Users (NWTRADERSx\Users).
27. In the Permissions for Users list, select the Allow check box to the right of Modify.
28. On the Sharing tab, click Share This Folder, and then click OK.
29. At the command prompt, type md C:\salesusers and then press ENTER.
30. At the command prompt, type net share salesusers=C:\salesusers /grant:users,full and then press ENTER.
31. At the command prompt, type cacls C:\salesusers /e /g users:f and then press ENTER.
32. At the command prompt, type md C:\users and then press ENTER.
33. At the command prompt, type net share users=C:\users /grant:users,full and then press ENTER.
34. At the command prompt, type cacls C:\users /e /g users:f and then press ENTER.
35. At the command prompt, type md C:\gpmc and then press ENTER.
36. At the command prompt, type net share gpmc=C:\gpmc /grant:users,full and then press ENTER.
37. At the command prompt, type cacls C:\gpmc /e /g users:f and then press ENTER.
38. At the command prompt, type md C:\public and then press ENTER.
39. At the command prompt, type net share public=C:\public and then press ENTER.
40. At the command prompt, type md C:\data and then press ENTER.
41. At the command prompt, type net share data=C:\data and then press ENTER.
42. At the command prompt, type md C:\cso and then press ENTER.
43. At the command prompt, type net share cso=C:\cso and then press ENTER.
44. At the command prompt, type md C:\projects and then press ENTER.
45. At the command prompt, type net share projects=C:\projects /grant:users,full and then press ENTER.
46. At the command prompt, type cacls C:\projects /e /g users:f and then press ENTER.
47. At the command prompt, type echo > C:\projects\project1.txt and then press ENTER.
48. At the command prompt, type echo > C:\projects\project2.txt and then press ENTER.
49. Close the command prompt window.
14. Enable Windows Audio
Task Summary
Enable the Windows Audio service.
1. &nb
출처 / Aqua World
Posted by XROK!
- Tag
- active directory


,
windows server 2003

,
예제


- Response
- No Trackback , No Comment
Trackback URL : http://www.xrok.net/trackback/559

