![]() |
|
#1
|
|||||
|
|||||
|
Domain - Local security Database
Also that you cannot logon to a domain locally? So when you login you will be logging in using domain credentials based on the active directory entries? Also what happens if the domains down and AD is not installed would you be able to login to the dc? Hope someone can explain in the simplest terms as I'm new to this domain environment thanks, Dave Level 1,2,3 NVQ IT USERS (ITQ) Passed 271 - Passed 272 - Passed (MCDST) (MCP) 270 - Currently Studying - A+ - N+ - |
|
#2
|
|||||||||
|
|||||||||
|
Quote:
Quote:
If AD is not installed, you have no domain. If you mean what happens if the DC is down, a message would be presented to the user explaining the domain controller cannot be contacted, or if the cached credentials are configured, it may log the user on although not provide access to resources which require authentication.
|
|
#3
|
||||||
|
||||||
|
Quote:
Thanks, Level 1,2,3 NVQ IT USERS (ITQ) Passed 271 - Passed 272 - Passed (MCDST) (MCP) 270 - Currently Studying - A+ - N+ - |
|
#4
|
||||||
|
||||||
|
Quote:
The security database - something to do with SAM off the top of my head? (derkit is learning mode also!) MBCS, BSc(Hons), Cert(Maths), A+, Net+, MCP, MCDST, ITIL-F v3 Aims: 70-270 (by mid-Feb) 70-290 (by start of June) 70-291 and MCSA (by end of Sep) CCENT or CCNA (by year-end) "Get balls deep!" - Craigie |
|
#5
|
|||||||||
|
|||||||||
|
Quote:
Quote:
|
|
#6
|
||||||
|
||||||
|
Quote:
SAM is the local security account manager, opposed to the active directory held on the domain controller.
|
|
#7
|
||||
|
||||
|
There are two distinct differences.
Workgroups are machine specific, if you don't have a machine created on the machine locally you can't 'generally' log on. In AD, if you have the DC go down the only way you could log onto a workstation is if you had previously logged onto it and the machine has it stored in the cache (and yes, by default the machine retains 10 cached profiles). As far as where the user\password information is kept, that's stored within Active Directory itself, each DC and GC will hold that information allowing you to log in (this is done via Kerberos Tickets), the thing to always remember is that Kerberos relies on a time being correct to within a defined skew (defaults to 5 minutes), if the clock on the machine is out of sync by more than 5 minutes you will have issues. Another thing worth mentioning is that depending on the type of change AD will only sync at regular intervals, however if you make a change to an account (for instance changing the password) then the AD will sync between all DC's to ensure that they all have the correct and upto date information. SAM is pretty old school, it was from the old NT4 days (and was actually something you could export to disk and apply programs such as L0pht Crack against). CNA | CNE | CCNA | MCP | MCP+I | MCSE NT4 | MCSA 2003 | Security+ | MCSA:S 2003 | MCSE 2003 | MCSE:S 2003 | ITIL Foundation v2 | MCTS:SCCM 2007 | MBCS | MCTS:Win 7 | MCITP:EDA7 | MCITP:SA | MCITP:EA | MCTS:Hyper-V Disclaimer: The views of SimonD are just that, his views. He doesn't suggest or recommend that others live their lives by following his example. |
|
#8
|
|||||
|
|||||
|
Thanks for the info boycie MBCS, BSc(Hons), Cert(Maths), A+, Net+, MCP, MCDST, ITIL-F v3 Aims: 70-270 (by mid-Feb) 70-290 (by start of June) 70-291 and MCSA (by end of Sep) CCENT or CCNA (by year-end) "Get balls deep!" - Craigie |
|
#9
|
||||||
|
||||||
|
Quote:
MBCS, BSc(Hons), Cert(Maths), A+, Net+, MCP, MCDST, ITIL-F v3 Aims: 70-270 (by mid-Feb) 70-290 (by start of June) 70-291 and MCSA (by end of Sep) CCENT or CCNA (by year-end) "Get balls deep!" - Craigie |
|
#10
|
||||||
|
||||||
|
Quote:
http://www.windowsnetworking.com/kba...eNTDS.DIT.html |
|
#11
|
|||||
|
|||||
|
Thanks everyone for all the help
![]() Im slowly getting through this 270 Just making sure I understand every little bit and going through it gradually So if the ethernet was pulled out of the dc it would be possible to only logon using credentials I have used previously? What If I have never logged on before would that make the domain unaccessible? Thanks for the link sparky Dave Level 1,2,3 NVQ IT USERS (ITQ) Passed 271 - Passed 272 - Passed (MCDST) (MCP) 270 - Currently Studying - A+ - N+ -
|
|
#12
|
||||||
|
||||||
|
Quote:
CNA | CNE | CCNA | MCP | MCP+I | MCSE NT4 | MCSA 2003 | Security+ | MCSA:S 2003 | MCSE 2003 | MCSE:S 2003 | ITIL Foundation v2 | MCTS:SCCM 2007 | MBCS | MCTS:Win 7 | MCITP:EDA7 | MCITP:SA | MCITP:EA | MCTS:Hyper-V Disclaimer: The views of SimonD are just that, his views. He doesn't suggest or recommend that others live their lives by following his example. |
![]() |
|
||||||
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Sharing and security model for local accounts | HTF | Networking | 0 | 21-Jan-2010 01:43 PM |
| Ccna vtp | cisco lab rat | Routing & Switching | 0 | 18-Dec-2009 09:56 PM |
| Want to dip your toe into Security ? | UKDarkstar | Security Exams | 8 | 23-Feb-2009 01:22 PM |
| Migrating Vista Local User Profiles to Domain? | fortch | Software | 6 | 08-Jun-2008 11:08 AM |