{"id":176,"date":"2023-06-04T15:07:00","date_gmt":"2023-06-04T21:07:00","guid":{"rendered":"https:\/\/rasulnazriev.tech\/?p=176"},"modified":"2025-07-30T15:51:24","modified_gmt":"2025-07-30T21:51:24","slug":"active-directory-scenario","status":"publish","type":"post","link":"https:\/\/rasulnazriev.tech\/?p=176","title":{"rendered":"Active Directory Scenario"},"content":{"rendered":"\n<h6 class=\"wp-block-heading\">Hello dear readers. In this post, I would like to implement the following scenario in Microsoft Active Directory.<\/h6>\n\n\n\n<h6 class=\"wp-block-heading\">Scenario: I am building a small domain for the Small Book Company, a small bookstore that wishes to have an Active Directory management system to tie together the six computers used as point-of-sale and inventory look-up, research, and entry as well as the dozen or so employees. My job is to set up the domain server, and then create the necessary groups to facilitate this system. The company information is listed below. Deliverables are detailed at the end.<\/h6>\n\n\n\n<p>Small Book Company<\/p>\n\n\n\n<p>Employees: 12<\/p>\n\n\n\n<p>Jobs&#8211;These are basically generic user roles:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sales Staff\u2014Will use the system to complete sales (requires read access), and look up resources (read access).<\/li>\n\n\n\n<li>Managers\u2014Enter inventory (write access), Lookup Resources (read), Sales (read), reports (read), and update inventory (modify access)<\/li>\n\n\n\n<li>Administrator\u2014Full control of systems for management and administration<\/li>\n<\/ul>\n\n\n\n<p>Systems:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>POS: 6 Point-of-Sale systems (POS) used to make sales and lookup inventory<\/li>\n\n\n\n<li>Management PC: Management PC is used to enter and modify inventory<\/li>\n\n\n\n<li>Active Directory Server: Used for management<\/li>\n\n\n\n<li>Book Database (inventory) System\u2014Retains inventory of books and sales, Runs on a separate server.<\/li>\n\n\n\n<li>File Share: Used to share documents with staff.<\/li>\n<\/ul>\n\n\n\n<p>Domain Name: SmallBookCompany.com<\/p>\n\n\n\n<p>Policies:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Must have a password policy on computer resources<\/li>\n\n\n\n<li>Must have Windows Firewall enabled on all computer resources<\/li>\n\n\n\n<li>The Administrator for the system must be able to edit policies<\/li>\n<\/ul>\n\n\n\n<p>Additional:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Must implement a backup plan<\/li>\n<\/ul>\n\n\n\n<p>Let us start!<\/p>\n\n\n\n<p>For the lab, I implemented AGDLP(Account, Global Group, Domain Local Group, Permission). I created the domain SmallBooksCompany.com. In the domain, I created 3 organizational units: Sales, Managers, and BookFacility. The sales organizational unit contains global security group Sales and domain local group Sales Resources. Managers organizational unit contains global security group Managers and domain local group Managers Resources. BookFacility contains domain local group Servers.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"979\" height=\"580\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final1.png\" alt=\"\" class=\"wp-image-97\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final1.png 979w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final1-300x178.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final1-768x455.png 768w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/figure>\n\n\n\n<p>Firstly, as illustrated above, I created Active Directory PC used for management, and a Book Database server used to retain an inventory of books and sales. I created domain local security group Servers that contain Active Directory PC, Book Database server, and built-in Administrator.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1018\" height=\"747\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final2.png\" alt=\"\" class=\"wp-image-98\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final2.png 1018w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final2-300x220.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final2-768x564.png 768w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/figure>\n\n\n\n<p>Above is an overview of Sales OU. I created 6 POSs and 1 global security group with the users shown above. The users go to the global group, and resources and permissions go to the domain local group.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1018\" height=\"747\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final3.png\" alt=\"\" class=\"wp-image-99\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final3.png 1018w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final3-300x220.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final3-768x564.png 768w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/figure>\n\n\n\n<p>Next, I created Managers PC, Managers global group, and Managers Resources domain local group. I have six managers, which is certainly unnecessary, but this would not be the case in a real-world implementation.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"978\" height=\"589\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final4.png\" alt=\"\" class=\"wp-image-100\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final4.png 978w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final4-300x181.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final4-768x463.png 768w\" sizes=\"auto, (max-width: 978px) 100vw, 978px\" \/><\/figure>\n\n\n\n<p>The screenshot above illustrates the password policy taken into effect. I edited Default Domain Policy, so changes made are linked across the domain SmallBooksCompany.com<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"974\" height=\"615\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final5.png\" alt=\"\" class=\"wp-image-102\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final5.png 974w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final5-300x189.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final5-768x485.png 768w\" sizes=\"auto, (max-width: 974px) 100vw, 974px\" \/><\/figure>\n\n\n\n<p>Firewall rules are configured by me. For public profiles, both Inbound and Outbound connections must be blocked because we do not want unattended online activities.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"979\" height=\"580\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final6.png\" alt=\"\" class=\"wp-image-103\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final6.png 979w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final6-300x178.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final6-768x455.png 768w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/figure>\n\n\n\n<p>In the default domain policy, under the delegation tab,  I added Administrator along with its privileges as illustrated above. Again, changes made in the default domain policy are going to affect the entire domain.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"979\" height=\"580\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final7.png\" alt=\"\" class=\"wp-image-105\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final7.png 979w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final7-300x178.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final7-768x455.png 768w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/figure>\n\n\n\n<p>Regarding hardening the domain controller, I disabled the Guest account so that no one can log in as a guest.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"979\" height=\"580\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final8.png\" alt=\"\" class=\"wp-image-107\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final8.png 979w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final8-300x178.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final8-768x455.png 768w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/figure>\n\n\n\n<p>Above, some audit changes were made to monitor logs, attempts to change policies and other events.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1018\" height=\"747\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final9.png\" alt=\"\" class=\"wp-image-108\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final9.png 1018w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final9-300x220.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final9-768x564.png 768w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/figure>\n\n\n\n<p>I created a folder BookFacilityDoc and shared it across the network using Quick SMB. The above screenshot illustrates share permissions given to necessary users\/groups. As can be seen, full control was given to every known group\/user to leave the final decision on NTFS permissions. In other words, in NTFS vs Share permissions, the lowest permissions take precedence.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1018\" height=\"747\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10.png\" alt=\"\" class=\"wp-image-109\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10.png 1018w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10-300x220.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10-768x564.png 768w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/figure>\n\n\n\n<p>Here are the NTFS permissions illustrated in the screenshot above.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1018\" height=\"747\" src=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10-1.png\" alt=\"\" class=\"wp-image-110\" srcset=\"https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10-1.png 1018w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10-1-300x220.png 300w, https:\/\/rasulnazriev.tech\/wp-content\/uploads\/2023\/06\/Final10-1-768x564.png 768w\" sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/figure>\n\n\n\n<p>I created 3 iSCSi disks and implemented RAID-5 for redundancy. The disks should be available across the network for file sharing and storage. The RAID works as a good backup plan in case one of the disks goes down. That was my Active Directory implementation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello dear readers. In this post, I would like to implement the following scenario in Microsoft Active Directory. Scenario: I am building a small domain for the Small Book Company, a small bookstore that wishes to have an Active Directory management system to tie together the six computers used as point-of-sale and inventory look-up, research, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":128,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-176","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=\/wp\/v2\/posts\/176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=176"}],"version-history":[{"count":1,"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=\/wp\/v2\/posts\/176\/revisions"}],"predecessor-version":[{"id":177,"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=\/wp\/v2\/posts\/176\/revisions\/177"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=\/wp\/v2\/media\/128"}],"wp:attachment":[{"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rasulnazriev.tech\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}