Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The...

21
Designing a Windows Server 2008 Applications Infrastructure Course Number: 70-647 Course Length: 8 Days Course Overview This instructor-led course will provide students with an understanding of how to design a Windows Server 2008 Network Infrastructure that meets business and technical requirements for network services. Students will learn how to design Active Directory forests, domain infrastructure, sites and replication, administrative structures, group policies, and Public Key Infrastructures. They will be able to design for security, high availability, disaster recovery, and migrations. Students will also learn how to design application infrastructure solutions based on Windows Server 2008 to meet varying business and technical requirements. Prerequisites The Microsoft Certified IT Professional (MCITP) credential validates that an individual has the comprehensive set of skills necessary to perform a particular job role, such as database administrator or enterprise messaging administrator. MCITP certifications build on the technical proficiency measured in the Microsoft Certified Technology Specialist (MCTS) certifications. Therefore, you will earn one or more MCTS certifications on your way to earning an MCITP credential. Audience The primary audience for this course is IT professionals (including Windows 2000/2003 enterprise administrators) interested in becoming a Windows Server 2008 Enterprise Administrator with a focus on network solutions, designing Active Directory Domain Services (AD DS) environments, and application infrastructure such as Web and Terminal Services. Certification Exam The Microsoft exam associated with this course is: 70-647: Pro: Windows Server 2008, Enterprise Administrator

Transcript of Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The...

Page 1: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Designing a Windows Server 2008 Applications Infrastructure

• Course Number: 70-647 • Course Length: 8 Days

Course Overview This instructor-led course will provide students with an understanding of how to design a Windows Server 2008 Network Infrastructure that meets business and technical requirements for network services. Students will learn how to design Active Directory forests, domain infrastructure, sites and replication, administrative structures, group policies, and Public Key Infrastructures. They will be able to design for security, high availability, disaster recovery, and migrations. Students will also learn how to design application infrastructure solutions based on Windows Server 2008 to meet varying business and technical requirements. Prerequisites The Microsoft Certified IT Professional (MCITP) credential validates that an individual has the comprehensive set of skills necessary to perform a particular job role, such as database administrator or enterprise messaging administrator. MCITP certifications build on the technical proficiency measured in the Microsoft Certified Technology Specialist (MCTS) certifications. Therefore, you will earn one or more MCTS certifications on your way to earning an MCITP credential. Audience The primary audience for this course is IT professionals (including Windows 2000/2003 enterprise administrators) interested in becoming a Windows Server 2008 Enterprise Administrator with a focus on network solutions, designing Active Directory Domain Services (AD DS) environments, and application infrastructure such as Web and Terminal Services. Certification Exam The Microsoft exam associated with this course is:

• 70-647: Pro: Windows Server 2008, Enterprise Administrator

Page 2: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Course Outline - Part 1 Course Introduction 11 min Course Introduction

Module 01 - Designing Network Infrastructure 1h 4m Designing Network Infrastructure Overview of the Network Life Cycle The MSF Network Design Team Description of the MSF Network Design Team Components of a Network Infrastructure Design Guidelines for Designing a Network Infrastructure Strategies for Connectivity Within a Location Bandwidth Requirements Demo - AD Sizer Network Data Collection Tools Network Infrastructure Considerations for Virtualization Virtual Machines Connectivity Requirements Throughput Requirements Network Reliability Requirements MAC Addressing for Virtual Machines Components of a Change Management Design Monitoring Network Usage Guidelines for Designing a Change Management Structure Module 01 - Review Module 02 - Network Security Plan 1h 48m Network Security Plan Reasons for Investing in Network Security Key Principles of Network Security Security Design and Implementation Components of Network Security Network Security Design Process Security Policies and Procedures Security Policies Demo - Designing a Network Security Plan Guidelines for Creating Policies and Procedures Roles for a Security Design Team Additional Roles for a Security Design Team Security Guidelines Reasons for Network Attacks Stages of Network Attacks Types of Network Attacks Common Network Vulnerabilities STRIDE Threat Model Overview Guidelines for Modeling Network Threats Countering Network Threats Risk Assessment Network Assets at Risk

Page 3: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Calculating Risk Impact Microsoft Operations Framework (MOF) Risk Management Process Guidelines for Creating a Risk Management Plan Layers of the Defense-in-Depth Model Using Defense-in-Depth to Identify Risks Module 02 – Review Module 03 - IP Addressing Scheme 49m IP Addressing Scheme Considerations for Determining Hosts per Subnet 2n -2 Example - hosts Considerations for Determining Number of Subnets 2n -2 Example - Subnets Public Addressing vs. Private Addressing Guidelines for Designing IPv4 Addressing Classless IP addressing Options for Automatic IPv4 Address Assignment DHCP Communication Process Design Options for DHCP Server Methods for Improving DHCP Server Availability Securing DHCP Servers Guidelines for Designing DHCP Infrastructure Options for Determining a Lease Length Superscopes in DHCP Infrastructure Using Reservations in DHCP Infrastructure DHCP Class-Level Options DHCP User-Level Options Benefits of IPv6 IPv6 Address Types Global Unicast Unique / Local IPv6 Unicast Address Structure - Review IPv6 Address Auto Configuration Options IPv6 Address Auto Configuration Process Guidelines for Designing an IPv6 Addressing Scheme What Is Dual Layer IPv4 and IPv6? What Is ISATAP? What Is 6to4? What Is Teredo? Process for Transitioning to IPv6 Guidelines for Designing an IPv6 Transition Module 03 - Review Module 04 - Designing Network Routing 1h 31m Designing Network Routing Connectivity Requirements Local Connections Security Requirements OSI Model - Reminder Types of Network Devices

Page 4: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Reasons for Using Routers Types of Network Domains Benefits of Layer 3 Switches Virtual LANs Internet Connectivity Requirements Network Address Translation for Internet Connectivity Internet Security and Acceleration for Internet Connectivity ISA Server Strategies for Designing Firewalls Bastion Host Multi-Homed Firewall Back to Back Firewall Strategies for Designing Extranet Determining Connection Methods Selecting a Routing Protocol OPSF – Open Shortest Path First Using Packet Filters to Create Security Zones Selecting a Site-to-Site VPN Tunnel – VPN with PPTP Tunnel Selecting a Site-to-Site VPN Tunnel – VPN with L2TP / IPSec Selecting a Site-to-Site VPN Tunnel – VPN with IP-Sec in Tunnel mode Guidelines for Planning Router Connectivity Demo - Routing Factors Affecting Network Performance Factors that Affect Network Performance Tools for Evaluating Network Performance Network Upgrade Considerations Recommended Ethernet Utilization Guidelines Practices for Optimizing Network Throughput Calculating Actual Data Throughput QOS - Two methods DSCP Value / Bandwidth Throttling is Based on… What Is Quality of Service? What Is a QOS Policy? Demo - QOS Module 04 - Review Module 05 - Internal Networks Security 52m Internal Networks Security Reasons for Implementing Windows Firewall Methods for Configuring Windows Firewall Benefits of IPSec Connection Security Rules Types of Connection Security Rules IPSec Authentication Deployment Methods for Connection Security Rules Demo - Security Determining the Authentication Method Co-existence with IPSec Policies Integration with Windows Firewall Rules Guidelines for Designing IPSec Implementation

Page 5: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Demo - Connection Security Module 05 - Review Module 06 - Name Resolution Design 48m Name Resolution Design Reasons for Name Resolution Considerations for Configuring Name Resolution Physical Location Considerations for a Name Resolution Design Host Requirements for a Name Resolution Design NetBIOS Resources How Clients Resolve Host Names Determining DNS Server Requirements Considerations for Placing DNS Servers DNS Server Roles Securing DNS Servers DNS Namespace Options Hosting Options for DNS Demo - DNS Guidelines for Designing DNS Namespaces Selecting Zone Types Selecting Zone Data Location Zone Security Considerations Reasons for Designing Secondary Zones Zone Replication Zone Transfers Zone Delegation Module 06 - Review Module 07 - Advanced Name Resolution 36m Advanced Name Resolution Disabling Recursion Deleting and Modifying Root Hints Optimizing DNS Server Response Optimizing DNS Server Functionality AD Integrated Zones DNS Troubleshooting Tools Guidelines for Designing DNS Availability Using Load Balancing for DNS Servers DNS Security Risks DNS Security Policies Options for NetBIOS Name Resolution Scenarios Requiring Multiple WINS Servers DNS GlobalNames Zone Demo - Adv DNS WINS Fault Tolerance Selecting a WINS Replication Type Selecting a Partner Replication Method Selecting a WINS Replication Topology Guidelines for Interoperability with DNS Module 07 - Review

Page 6: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Module 08 - Network Access Solutions 1h 58m Network Access Solutions Business Requirements User Requirements Security Requirements Guidelines for Gathering Data for a Network Access Design Demo - NAS Authentication Methods Authentication Protocol Encryption Methods Network Policies Network Policy Processing Demo - Configure NP Remote Access Monitoring Remote Access Methods VPN Tunnelling Protocols Hardware Considerations Strategies for Placing VPN Servers User Environnent Configuration What Is RADIUS? RADIUS Roles How RADIUS Works for Remote Access Connection Request Policies Demo - Configuring Connection Wireless Networking Standards Wireless Security Threats Strategies for Wireless Security How RADIUS Works for 802.1X Connections Hardware Considerations for Wireless Networks Module 08 - Review Module 09 - Network Access Protection 1h 16m Network Access Protection Designing Network Access Protection What Is NAP? Scenarios for Implementing NAP Considerations for Designing NAP Network Components and Concepts for NAP HRA NAP Components NAP Architecture Overview Network Layer Protection with NAP Host Layer Protection with NAP NAP Process for Enforcement of Host Layer Protection NAP and Certificate Services NAP Enforcement Methods – EAP for IEEE 802.1X Connections NAP Enforcement Methods – IPSec Communications NAP Enforcement Methods Demo - NAP

Page 7: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Network Boundaries IPsec Enforcement VPN Enforcement DHCP Enforcement System Health Agents and Validators Status Monitored by Windows Security Health Validator NAP Integration with Other Products Considerations for Antivirus Software Considerations for Windows Updates Considerations for Firewall Protection Considerations for Spyware Protection Unsupported Platforms Considerations for Designing DHCP Enforcement Considerations for Designing VPN Enforcement Considerations for Designing 802.1X Enforcement Considerations for Designing IPsec Enforcement Module 09 - Review Module 10 - OS Deployment and Maintenance 55m OS Deployment and Maintenance Reasons for Planning the Operating System Deployment Design Options for Deploying Operating Systems Deployment Methods Determining Storage Requirements Security Considerations for Operating System Deployment Tools for Operating System Deployment Enhanced Features in WDS Demo - OS Deployment Network Infrastructure Requirements to Support WDS Comparing Transport Server and Deployment Server Considerations for Upgrading from RIS to WDS Considerations for Designing WDS Features of WDS Images Image Capture Utilities Considerations for Maintaining Boot and Install Images Scenarios for Using Multicasting Types of Multicast Transmissions Considerations for Designing Multicast Transmissions Overview of Update Management Tools How WSUS Works WSUS Deployment Scenarios Guidelines for Planning a WSUS Infrastructure Module 10 - Review Module 11 - File Service and DFS Design 1h 3m File Service and DFS Design Business Requirements for File Services Components of a File Services Design SMB Enhancements in Windows Server 2008 What Is Distributed File System?

Page 8: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Components of DFS Comparing Failover Clustering and DFS for High Availability New DFS Features in Windows Server 2008 Interoperability with Previous Versions of DFS Guidelines for Designing DFS Namespace Availability Referral Options Target Priority Options Considerations for Configuring Referrals Guidelines for Optimizing DFS Namespaces Best Practices for Deploying DFS Namespaces Demo - DFS Guidelines for Designing DFS Replication Sizing Folders Uses for FSRM FSRM Quotas FSRM File Screening Module 11 - Review Module 12 - Windows Server 2008 High Availability 47m Windows Server 2008 High Availability High Availability Requirements Service Level Agreements Components of a High Availability Design Infrastructure Requirements for High Availability High Availability Options in Windows Server 2008 Overview of Network Load Balancing Considerations for Storing Application Data for NLB Host Priority Affinity Selecting a Network Communication Method for NLB Demo - NLB Overview of Failover Clustering Failover Clustering Scenarios Shared Storage for Failover Clustering Guidelines for Designing Hardware for Failover Clustering Guidelines for Failover Clustering Capacity Planning Quorum Configuration for Failover Clustering Quorum Configurations Overview of Geographically Dispersed Clusters Data Replication for Geographically Dispersed Clusters Quorum Configuration for Geographically Dispersed Clusters Module 12 - Review Module 13 - Windows Server 2008 Print Services 58m Windows Server 2008 Print Services Considerations for a Print Services Design Local Printing Direct IP Printing Server-Based Printing Considerations for Selecting Printers

Page 9: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Demo - Printing Printer Pools XPS-Based Printing Interoperability of XPS and GDI-Based Printing Print Management Console Printer Driver Store Internet Printing Protocol Failover Clustering for Print Services Recommendations for Simplifying User Access to Printers Recommendations for Simplifying Print Services Administration Monitoring Print Services Considerations for Branch Office Printing Module 13 - Review Course Closure Course Outline - Part 2 Course Introduction 8 min Course Introduction

Module 01 - Designing an AD Forest Infrastructure 1h 7m Designing an AD Forest Infrastructure Overview of AD DS Forest Design Requirements Design Requirements – AD DS Forest Business Requirements for an AD DS Forest Design AD Forest Design Administrative and Security Requirements Technical Requirements for an AD DS Forest Design Types of AD DS Forests Benefits of a Single Forest Model Disadvantages of Single Forest Model Reasons for Implementing Multiple Forests Benefits of Implementing Forest Root Domains Types of Forest Functional Levels Forest Functional Levels Windows Server 2003 Forest Functional Level Guidelines for Designing an AD DS Forest Types of Trusts What Is UPN Suffix Routing? Guidelines for Designing Forest Trusts Demo: Implementing an AD Forest Trust Design Modifications to AD DS Schema Guidelines for AD DS Schema Modifications Demo: Schema Changes How Does Windows Time Service Work? Considerations for Configuring Windows Time Service Member Servers and Workstations Domain Controllers

Page 10: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Considerations Module 1 Review

Module 02 - Designing an AD Domain Infrastructure 1h 11m Designing an AD Domain Infrastructure AD DS Domain Design Models AD DS Domain Models Factors to Consider When Accessing Domain Models Reasons for Deploying Multiple AD DS Domains AD DS Domain Functional Levels Supported Domain Controller Operating Systems Considerations for Configuring and Placing the Domain Controllers Considerations for Deploying Domain Controllers in Branch Offices Read Only Domain Controller (RODC) Guidelines for Designing AD DS Domains Choosing an AD DS Namespace Strategy Guidelines for Integrating the Public and Private DNS Namespaces Guidelines for Integrating Multiple Internal DNS Namespaces Guidelines for Implementing DNS Servers Demo: Configuring Forwarders and Delegation Records Windows 2008 Domain Controllers Domain Controller on a Server Core Deploying Domain Controllers in Windows Server 2008 Deploying Domain Controllers in Windows Server 2008 - RODC Why Deploy RODC? Considerations When Deploying Domain Controllers Demo: Configuring an RODC Replication Policy Types of AD DS Domain Trusts Security Considerations for Trusts Demo: Implementing AD Domain Level Trust Design Module 02 Review

Module 03 - AD Sites and Replication 56m AD Sites and Replication Things to Document Before the AD Site Design Network Information for an AD DS Site Design Location Data for an AD DS Site Design AD DS Site Models Guidelines for Creating Additional AD DS Sites Demo: Implementing AD DS Site Design Locations How Does Automatic Site Coverage Work? Types of Replication Topologies Considerations for Choosing a Replication Protocol Levels of Connectivity Choosing Replication Protocols Demo: Implementing AD DS Replication Replication of Global Catalog, RODC, and SYSVOL Knowledge Consistency Checker Inter Site Topology Generator

Page 11: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Using Site Links to Manage Replication Considerations for Designing Site Links and Bridgehead Servers Considerations for Designing Site-Link Bridging Considerations for Site Link Bridging Options for Configuring AD DS Replication Guidelines for Configuring AD DS Replication Guidelines for Placing Domain Controllers Guidelines for Placing RODCs Guidelines for Placing Global Catalog Servers Guidelines for Placing Operations Master Servers Module 03 Review

Module 04 - Planning an AD Domain Administrative Structure 1h 20m Planning an AD Domain Administrative Structure Types of IT Administrative Models Guidelines for Gathering Information on the Current Administrative Structures Business Requirements for Existing Structure Legal Requirements Guidelines for Gathering Information on Organizational Resources Guidelines for Gathering Information on Administrative Processes Strategies for Designing Organizational Units Strategies for Delegating Administrative Control Strategies for Designing Group Policy Structures Considerations for Designing Organizational Unit Hierarchies Guidelines for Designing an Organizational Unit Structure Demo: Creating an AD OU Design AD DS Groups in Windows Server 2008 Group Scope Guidelines for Developing a Group Naming Strategy Considerations for Group Nesting Group Nesting Strategies for Using Groups to Access Resources Strategies for Placing Group Objects Guidelines for Designing an AD DS Group Strategy Guidelines for Designing a User Account Strategy Guidelines for Designing a Computer Account Strategy Naming Strategies for Computer Accounts Guidelines for Securing User and Computer Account Management Demo: Automating User Account Management Tools for Automating User and Computer Account Management Module 04 Review

Module 05 - AD Group Policy 1h 21m AD Group Policy Gathering Organizational Information Gathering Information on Security Requirements Gathering Information on Desktop Management Requirements Gathering Information on Desktop Management Gathering Information on Administrative Processes Configuring Group Policy Settings

Page 12: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Demo: Designing AD Group Policy Applying Group Policy Settings Demo: Implementing AD Group Policy Group Policy Storage Locations ADMX Format for Administrative Template Guidelines for Designing Administrative Templates Slow Link Detection Best Practices for Group Policy Model Design Guidelines for Designing Group Policy Inheritance Guidelines for Designing Group Policy Filtering Guidelines for Designing Group Policy Application GPO Backup and Recovery Strategy GPO Migration Strategy Delegating GPO Administration GPO Administration Module 05 Review

Module 06 - Designing AD Security 1h 52m Designing AD Security Gathering Information for Designing Account Security Policies Key Components for Designing Account Security Policies Guidelines for Designing Account and Password Policy Guidelines for Designing Secure Account Management Fine-Grained Password Policies What Are Fine-Grained Password Policies? Storing Fine-Grained Password Policies Demo: Designing AD DS Security Password Setting Object Attributes How PSOs Are Processed and Applied Guidelines for Designing Fine-Grained Password Policies Key Components that Affect Domain Controller Security Why Modify the Default Domain Controller Security Policy? Server Core Server Roles Server Core as a Solution for Domain Controller Deployment What is the Security Configuration Wizard? Scenarios for Using the Security Configuration Wizard What Are Read-Only Domain Controllers? Prerequisites for Deploying RODCs Administrator Role Separation on RODCs Demo: Domain Controller/RODC Security Policies Administrator Responsibilities Service Administrator and Service Management Data Administrators and Data Management What Are Administrative Autonomy and Isolation? Delegation of Administrative Permission Attributes of a Good Delegation Model Guidelines for Creating a Delegation Model Guidelines for Using and Securing Administrator Accounts Demo: Restricted Groups Auditing Administrative Access

Page 13: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Module 06 Review

Module 07 - Designing AD High Availability 27m Designing AD High Availability What is High Availability? Components of an Active Directory High Availability Design Active Directory High Availability Business Requirements for AD DS High Availability Infrastructure Requirements for AD DS High Availability High Availability Options for Network Infrastructure Process of Planning for High Availability Guidelines for Designing Highly Available Domain Controllers Global Catalog Placement and High Availability Demo: Designing AD DS Availability High Availability of DNS Guidelines for Designing Highly Available Network Infrastructure Module 07 Review

Module 08 - AD Disaster Recovery Strategy 57m AD Disaster Recovery Strategy Overview of Database Maintenance NTDSUtil.exe Benefits of Restartable AD DS in Windows Server 2008 Considerations for Using Restartable AD DS Overview of AD DS Backup and Recovery Windows Server Backup AD DS Backup and Recovery in Windows Server 2008 Active Directory Domain Services Backup System Components System State Data Critical Volumes – Review Options for Restoring AD DS Considerations for Restoring AD DS Guidelines for Designing Backup and Recovery in AD DS Why Monitor AD DS? Tools for Monitoring AD DS Reliability and Performance Monitor Demo: Disaster Recovery and Monitoring Guidelines for Monitoring Active Directory Domain Controllers NTDS Counters – Monitoring AD Module 08 Review

Module 09 - Public Key Infrastructure Design 1h 29m Public Key Infrastructure Design What is a PKI? Key Components of a PKI PKI Solution Requirements Applications That Use PKI Certification Authorities and PKI Comparison of Enterprise and Standalone Internal and Public Certification Authorities

Page 14: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Using Both Internal and External Public CAs Active Directory Certificate Services in Windows Server 2008 Features in AD CS Gathering Information for Designing Certification Authority Hierarchy Certification Authority Hierarchy Roles Common Roles in a CA Hierarchy Demo: Designing PKI for Windows Server Options for Designing Certification Authority Hierarchy Types of CA Hierarchies Guidelines for Designing a Certification Authority Hierarchy What Are Certificate Templates? Certificate Templates in Windows Server 2008 Managing Certificate Templates Superseding Templates Feature Designing Certificate Templates Designing Certificate Templates with Customized Add-ons Demo: Updating Templates Guidelines for Designing Certificate Templates Certificate Distribution and Enrollment Choosing Enrollment Method Certificate Autoenrollment Demo: Implementing Autoenrollment What is Certificate Revocation? Guidelines for Designing Certificate Revocation Module 09 Review

Module 10 - Designing an AD RMS Infrastructure 45m Designing an AD RMS Infrastructure What is AD RMS? Key Components of AD RMS Scalability Requirements for AD RMS Design Considerations for External Client AD RMS Access What are AD RMS Rights Policy Templates? Options for Configuring AD RMS Clusters Guidelines for Designing AD RMS Clusters Options for Granting External Users Access to AD RMS Guidelines for Designing AD RMS Access AD RMS Backup Components Options for Restoring AD RMS Troubleshooting AD RMS Restores – Different Processes Restoring a Cluster Member Restoring a Non-Cluster Server Demo: Exploring RMS RMS Root Server Guidelines for Implementing an AD RMS Backup and Recovery Strategy Module 10 Review

Module 11 - Planning an AD Federation Services Implementation 54m Planning an AD Federation Services Implementation What is Active Directory Federation Services?

Page 15: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Key Components of AD FS Deployment Scenarios for AD FS AD FS Server Roles AD FS Server Placement AD FS User Account Stores Components of a B2B Federation Trust B2B Federation Trust Demo: Adding the Federation Service Role Demo: Exporting Certificates Demo: Importing Certificates Key Components of B2B Federation Trust Guidelines for Configuring Certificates and Applications Guidelines for Designing the Account and Resource Partner Components Guidelines for Deploying and Securing AD FS Servers Deploy Federation Server Proxy In Perimeter Network When… Additional Guidelines for Deploying and Securing ADFS Servers Options for Configuring AD FS Claims AD FS Group Claims Guidelines for Usage of AD FS Claims Understanding AD FS Applications Guidelines for Usage of Token-based and Claims-aware Applications Module 11 Review

Module 12 - Planning an AD LDS Implementation 1h Planning an AD LDS Implementation What is AD LDS? AD LDS Usage LDAP-Compliant Application Directories Definitions - LDAP Application Directories LDAP Compliant Applications - Defined Extranet Authentication Scenarios Using AD LDS for Developing Schema Modifications Key Sizing Factors for AD LDS Servers AD LDS Replication Scenarios Integration of AD LDS with AD DS Guidelines for Designing AD LDS Instances and Application Partitions Schema Changes and AD LDS Replication of AD LDS Data Planning AD LDS Replication Traffic across WAN Links AD LDS Sites and Site Links Guidelines for Designing AD LDS Schema and Replication User Proxies in AD LDS Authentication and Authorization in AD LDS Implementing Synchronization between AD DS and AD LDS Demo: Working with AD LDS Module 12 Review

Module 13 - AD Migrations Strategy 59m AD Migrations Strategy AD DS Migration Strategies

Page 16: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Domain Upgrade Strategy Domain Restructure Strategy Domain Upgrade and Restructure Criteria for Choosing a Migration Strategy Guidelines for Choosing the Domain Upgrade Strategy Guidelines for Choosing the Domain Restructure Strategy Guidelines for Choosing the Domain Upgrade and Restructure Strategy Documenting the Current Environment Active Directory Structure Current Network Services Current Domain Controller Hardware and Software Cleaning Up the Current Active Directory Environment Hardware and Application Compatibility Preparing a Domain and Forest for Upgrade Upgrade Guidelines Domain Functional Levels in Windows Server 2008 Windows 2000 Native Functional Level Windows Server 2003 Functional Level Windows Server 2008 Functional Mode SID History Active Directory Migration Tool ADMT Scenarios Preparing a Domain to Run ADMT Demo: Installing ADMT Intraforest and Interforest Restructuring Demo: Using ADMT Trusts Guidelines for Restructuring Domains Module 13 Review Course Closure Course Outline - Part 3 Course Introduction 6 min Course Introduction

Module 01 - IIS Web Farms Strategy 34m IIS Web Farms Strategy Overview of Hardware and Platform Options Things to Consider Choosing The Right Hardware Choosing the OS and IIS Configuration Design Web Farm Availability and Scalability Overview of Web Farms Design Load Balancing Session State Requirements Shared Offline Configuration Files DFS Enabled Share Shared Configuration for 2 Nodes

Page 17: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Xcopy Deployment Design Deployment and Update Plan for FTP, SFTP and SMTP Design Content Storage Local Content Storage Design Folder Hierarchy Specify Volumes (RAID level, size) Module 01 - Review Module 02 - IIS Server Performance 36m IIS Server Performance Designing Application Pools Overview of Application Pools Design Application Pools Overview of Application Pool's Basic Properties Specify Recycle Thresholds Specify App Pool Identity Specify Performance Settings Designing Script Mapping Overview of Script Mapping Plan Script Mapping Properties Design Script Mapping Designing Bandwidth Allocation Overview of Bandwidth Allocation Bandwidth Allocation Settings Design Bandwidth Allocation Specify Max Bandwidth per Site Specify WSRM Settings per Application Design Website Logging Overview of Website Logging Best Practices for Auditing IIS 7.0 Logs Plan Logging for Web Site and Web Applications Review Logs Design Logging Module 02 - Review Module 03 - Planning IIS Server Security 42m Planning IIS Server Security Design and Verify Transport Security Overview of IIS Security Overview SSL Certificates Best Practices of Configuring a Secure Web Server Import an Assigned Certificate Best Practices for Configuring SSL Certificates Associate a Certificate to a Web Site Design SSL to Support HTTPS Plan Request Filtering Design Security Design Authentication and Authorization Overview of Authentication and Authorization

Page 18: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Define the Users and Groups Plan Access Define Application Restrictions in IIS 7.0 Specify Authentication Specify Authorization Manage Authentication Design Delegation Administration Overview of Delegated Administrative Rights Plan Delegated Administration Overview of Feature Delegation Module 03 - Review Module 04 - Planning IIS Server Maintenance and UDDI 28m Planning IIS Server Maintenance and UDDI Designing Internet Information Services Backup and Recovery IIS 7.0 Modular Architecture IIS Configuration History Centralized Configuration for Web Farms Maintenance and Recovery Designing Backup and Recovery for Web Farms Specify Monitoring Requirements Failed Request Tracing Rules IIS 7.0 Logging Modules Worker Processes and Real Time Monitoring System Center Management Pack for IIS 7.0 Deploying UDDI Services Evaluate Need for UDDI UDDI Requirements Design UDDI Infrastructure Manage UDDI Service Tuning and Troubleshooting IIS 7.0 Specify Recycling Thresholds 32 bit vs. 64 bit Architecture Troubleshooting Application Pools Module 04 - Review Module 05 - Terminal Services Infrastructure 41m Terminal Services Infrastructure Design Terminal Services Licensing Overview of TS Licensing Checklist for TS Licensing Terminal Services License Server Discovery Specify Terminal Services Connection Properties Remote Desktop Connection Display Single Sign-On for Terminal Services Terminal Services Easy Print Design Device Redirection Plug and Play Device Redirection Microsoft Point of Service for .NET Device Redirection Design Terminal Services Gateway

Page 19: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Overview of TS Gateway Prerequisites for TS Gateway Functionality Terminal Services Connection Authorization Policies (TS CAPs) Terminal Services Remote Access Policies (TS RAPs) Design Terminal Services Session Broker Overview of Terminal Services Session Broker DNS Round Robin and TS Session Broker Load Balancing Deploying TS Session Broker Load Balancing Design RemoteApp Programs Overview of TS RemoteApp Programs Key Scenarios for TS RemoteApp Programs Deploying RemoteApp Programs Through a File Share or Other Distribution Mechanism Managing RemoteApp Programs and Settings Design Web Design Overview of Terminal Services Web Access Functionality of TS Web Access Deploying RemoteApp Programs Through TS Web Access Module 05 - Review Module 06 - Terminal Services Maintenance Strategy 34m Terminal Services Maintenance Strategy Design Windows System Resource Manager (WSRM) Policies for Application Resource and Reporting Review Windows System Resource Manager Working with Resource-Allocation Policies Specify Group Policy Settings for Terminal Servers Group Policy Settings for Terminal Services Printing Group Policy Settings for TS Gateway Controlling Client Behavior for RemoteApp Programs Design High Availability Review Network Load Balancing (NLB) with Terminal Services Steps for Configuring NLB with Terminal Services Specify Monitoring Requirements Windows Terminal Server Management Pack TS Per User Licensing Usage Tracking TS Gateway Monitoring Capabilities Specify Maintenance and Recovery Terminal Services Server Drain Mode License Server Availability Events Autoreconnect Failure Event TS Gateway Availability Events TS Session Broker Availability Events Module 06 - Review Module 07 - Windows Media Services 44m Windows Media Services Design Windows Media Services for Live Streaming Overview of Windows Media Services for Windows Server 2008 Standard Edition vs. Enterprise Edition Evaluate 32 bit vs. 64 bit Backwards Compatibility with Windows Media Services for Windows Server 2003

Page 20: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Live Streaming Capabilities Planning for Multi Site Deployments Authentication and Authorization Windows Media Services for On-Demand Content Digital Rights Management Design Content Storage Design Content Deployment Protocol Selection Improving Performance for On-Demand Content Specify Performance Settings Evaluate Need for Web Farm Design Bandwidth Allocation Using WSRM Server Core Installation Monitoring Windows Media Services Specify Monitoring Requirements Management Pack for Windows Media Services Specify Maintenance and Recovery Module 07 - Review Module 08 - Server Consolidation and Virtualization 25m Server Consolidation and Virtualization Virtualization of a Test Server Environment Overview of Virtual Server Hosting in Windows Server 2008 Design Virtual Server Hosting Design a Standard Host Configuration Consolidate a Virtualized Test Environment Deploying Web Applications from Virtualized to Produced Environments Virtualization and Migration of Legacy Applications Evaluate Appropriateness of Virtualization Moving Legacy Applications to Virtual Servers Design Standard Virtual Configuration Design and Test a Virtualized Deployment Environment Virtualized Test Environment Best Practices Evaluate Customization to Standard Configuration Design Internal Networking Module 08 - Review Module 09 - Server Virtualization Provisioning 30m Server Virtualization Provisioning Design Virtual Server Provisioning Workflow Model Designing a Virtual Server Environment Management Design Static Computing versus Virtual Computing Evaluate Appropriateness for Virtualization Identifying Appropriate Solutions Envisioning Assessing the Current Environment Determining Solutions Evaluate Customization to Standard Configuration Virtualization Strategy

Page 21: Designing a Windows Server 2008 Applications Infrastructure · • Course Number: 70-647 ... The Microsoft Certified IT Professional (MCITP) credential validates that an individual

Design Deployment for Virtualization Design with System Center for Deployment Host Ratings Module 09 - Review Course Closure

Total Duration: 34h 6m