Академический Документы
Профессиональный Документы
Культура Документы
ADMINISTRATORS
• Disable Advertising
• Disable Tips, Tricks and Fun Facts
• Disable rotation of lock screen picture (daily)
#1
• User
• User Configuration > Administrative Templates >
Windows Components > Cloud Content
• Computer
• User Configuration > Administrative Templates >
Windows Components > Cloud Content
LINKS
#2
ADMINISTRATORS GROUP MEMBERSHIP
• Example:
• Domain\WorkstationAdmins
• Domain\DomainAdmins
#3
ENABLING THE ACTIVE DIRECTORY
RECYCLE BIN
• The Active Directory Recycle Bin stores deleted
Active Directory data for a specified amount of time
• Default Tombstone age is 180 days
• Server Manager > Tools > Active Directory
Administrative Center
• Click Domain
• Click Enable Recycle Bin in Right Frame
• PowerShell
• Enable-ADOptionalFeature "Recycle Bin Feature" -server $((Get-ADForest -Current
LocalComputer).DomainNamingMaster) -scope ForestOrConfigurationSet -target $
(Get-ADForest -Current LocalComputer)
#4
FINE-GRAINED PASSWORD POLICIES
#5
SYSTEM AUDIT POLICIES
#6
IDENTIFYING INACTIVE USERS AND
COMPUTERS (COMMAND LINE)
• Dsquery Command:
• Run from cmd prompt
• Query Inactive Computers and output to a text file
• Dsquery computer -inactive 90 > c:
\temp\inactive-computers.txt
• Query Inactive Users and output to a text file
• Dsquery user -inactive 90 > c:
\temp\inactive-users.txt
#7
IDENTIFYING INACTIVE USERS AND
COMPUTERS (POWERSHELL)
• Computer
• $DaysInactive = 90
• $time = (Get-Date).Adddays(-($DaysInactive))
• Get-ADComputer -Filter {LastLogonTimeStamp -lt $time} -Properties
LastLogonTimeStamp | Select-Object Name | Sort-Object Name | Out-
Default
• User
• $DaysInactive = 90
• $time = (Get-Date).Adddays(-($DaysInactive))
• Get-ADComputer -Filter {LastLogonTimeStamp -lt $time} -Properties
LastLogonTimeStamp | Select-Object Name | Sort-Object Name | Out-
Default
ONE-LINERS….
• Computer
• $DaysInactive = 90; $time = (Get-Date).Adddays(-($DaysInactive));
Get-ADUser -Filter {LastLogonTimeStamp -lt $time} -Properties
LastLogonTimeStamp | Select-Object Name | Sort-Object Name | Out-
Default
• User
• $DaysInactive = 90; $time = (Get-Date).Adddays(-($DaysInactive));
Get-ADUser -Filter {LastLogonTimeStamp -lt $time} -Properties
LastLogonTimeStamp | Select-Object Name | Sort-Object Name | Out-
Default
#8
PROJECT HONOLULU
• Project Honolulu is a new web-based management tool that combines the
roles of many Windows server tools including:
• Displaying resources and resource utilization
• Certificate Management
• Event Viewer
• File Explorer
• Firewall Management
• Configuring Local Users and Groups
• Network Settings
• Viewing/Ending Processes and Creating Process Dumps
• Registry Editing
• Managing Windows Services
• Enabling/Disabling Roles & Features
• Managing Hyper-V VMs & Virtual Switches
• Managing Storage
• Managing Windows Update
• Internet Explorer does NOT work in Honolulu
• Update your WMF to version 5.1 if you’re using Windows 2012 or 2012 R2
• https://www.microsoft.com/en-us/download/details.aspx?id=54616
• https://aka.ms/HonoluluDownload
#9
AND #10….. POWERSHELL
• ‘Nuf Said!!!
• No, really!
#10
POWERSHELL
• Some Basics
$credential = (Get-Credential)
• Long@more.net
• clong18@moberlyspartans.org
ftp://ftp.more.net/pub/S_P/Presentations/
THANK YOU!