Monday, January 9, 2012

Microsoft's Active Directory Security Features


New and updated features since Windows Server 2003 (without SP1)
Windows Server 2003 operating systems with Service Pack 1 (SP1) offer the following improvements (compared to Windows Server 2003 without SP1) that help provide increased levels of support for Active Directory:

Improved replication and DNS diagnostic testing capabilities
Active Directory® has been updated to provide automatic directory service backup reminders, improved protection against replication errors, improvements to Install from Media (to facilitate adding new domain controllers that are DNS servers), improved DNS diagnostic testing capabilities, and access to a new platform for running domain controllers in virtual machines under Microsoft® Virtual Server 2005. For more information about these and other new Active Directory features and enhancements, see New features for Active Directory.

New and updated features since Windows NT 4.0
The Windows Server 2003 family offers the following improvements (in comparison to Windows NT 4.0) that help provide increased levels of support for Active Directory:
Simplified user and network-resource management
Using Active Directory, you can build hierarchical information structures that make it easier for you to control administrative credentials and other security settings and that make it easier for your users to locate network resources, such as files and printers.

Flexible, secure authentication and authorization
Flexible and secure authentication and authorization services provide protection for data while minimizing barriers to doing business over the Internet. Active Directory supports multiple authentication protocols, such as the Kerberos V5 protocol, Secure Sockets Layer (SSL) v3, and Transport Layer Security (TLS) using X.509 v3 certificates, and security groups that span domains efficiently.

Directory consolidation
You can organize and simplify the management of users, computers, applications, and devices, and make it easier for users to find the information they need. You can take advantage of synchronization support through Lightweight Directory Access Protocol (LDAP)-based interfaces, and you can work with directory consolidation requirements specific to your applications.

Directory-enabled applications and infrastructure
Active Directory features make it easier for you to configure and manage applications and other directory-enabled network components.

Scalability without complexity
Active Directory scales to millions of objects per domain and uses indexing technology and advanced replication techniques to speed performance.
Use of Internet standards
Active Directory provides access through LDAP and uses a Domain Name System (DNS)-based namespace.

A powerful development environment
Active Directory provides a powerful development environment through Active Directory Service Interfaces (ADSI), which provides an object-oriented interface to Active Directory. ADSI makes it easy for programmers and administrators to create directory programs by using high-level tools such as Microsoft Visual Basic, Java, C, or Visual C++, without having to worry about the underlying differences between the different namespaces. For more information, see Programming interfaces.

Replication and trust monitoring
Active Directory provides Windows Management Instrumentation (WMI) classes to monitor whether domain controllers are successfully replicating Active Directory information and whether trusts are functioning properly.
Message Queuing distribution lists
Message Queuing (also known as MSMQ) enables you to send messages to distribution lists that are hosted in Active Directory.

New and updated features since Windows 2000
The Windows Server 2003 family offers several improvements (in comparison to Windows 2000) that help provide increased levels of support for and better management of Active Directory. For a list of the Active Directory features that are new in this release,

2 comments:

  1. Hi Guan Ru,
    After reading through you post I found that you start off the post by jumping straight to the security features of Microsoft Active Directory. What I think you should have done is to acutally write the opening od the post of what is Microsoft Active Director, what is it about or what does it do and etc... Your ways of writing the post isn't really wrong but your readers wont be able to fully understand what you are writing about, instead if your start off with talking abit about Microsoft Active Directory let your readers have abit of knowledge to Microsoft Active Directory then when your talk about the security features your reader will be able to understand more or understand what you are trying to bring across to them.

    ReplyDelete
  2. Hi,
    your post research on Active Directory was good and information was very detail.

    I think you have to put some picture that relates to Active directory. So, it can help the reader to understand the post clearly that can explains the method it used for transmission and how it works.

    After I read your post, I know the features of the Microsoft's Active Directory.And you did a lot of research for this post.

    ReplyDelete