Skip to main content

Server Administration 2012 Lab-12 & 13 Security & Share Level Permissions

Pre-requisites:
Before working on this lab, you must have
1. A computer running windows 2012 server Domain Controller.
2. A computer running windows 2012 server or windows 7.
Domain: MICROSOFT.COM

SYS1
Domain Controller Member Server
IP Address 10.0.0.1
Subnet Mask 255.0.0.0
Preferred DNS 10.0.0.1

SYS2
Client
IP Address 10.0.0.2
Subnet Mask 255.0.0.0
Preferred DNS 10.0.0.1

Lab – 1: Security Level Permissions

1. Open Computer Go to any NTFS partition and create a folder (DATA), along with some files in it.
2. Right click the folder (DATA) and select propertiesand click Security tabclick Advanced tabclick Editclick Disable inheritance.
3. ClickRemoveApplyOKOK
4. Click Edit
5. Add Administratoror Administratorsand allowFull controlpermission.
6. Then Add the Users (User1) and Allow Read permission.
7. ClickApplyOKOK

Verification:
1. Login as User(User1) on the same computer, and Open Computer icon, and verify the respective permissions by accessing the folder.
2. The User can just read the Files and Folders.

Lab – 2: Share Level Permissions

1. Logon to a Computer as Administrator, Open Computer Open any drive and create a folder (SALES) along with some files in it.
2. Right click the folder (SALES) and Select Share
3. Select the drop down arrow mark and select Findenter the User name(User 1)click OKselect the User(User 1)and assign Permissions (Ex: Read/Write)click Shareclick Done.

Verification: 
Access the Shared folder
1. Logon to Member Server or Client as User (User 1)  Open Network.
2. Open System Name in which the shared folder is present.
3. Access the shared folder (SALES) & verify the permissions by creating some files.

Accessing Shared folders using UNC Path:
1. Logon to Member server or Client as a User.
2. Click Start click Run and type the Syntax \\Servername\Sharename. Example: \\SYS1\SALES

Comments

Popular posts from this blog

Server Administration 2012 Lab-8 Creating Domain User Accounts

1. Log in as Administrator to the Domain Controller . 2. Press Windows Key to go to Start, select Active Directory User and Computers. 3. In the console tree, expand your domain MICROSOFT.COM , and then right click Users Container, select New User. 4. Specify the First name and User Logon name and then click Next . 5. Enter the Password and Confirm Password for the User account, click Next . 6. Review the configuration settings for the User Account and then click Finish. Verification: 1. Login as User ( User1@Microsoft.com ) in Member Server or Client.

Server Administration 2012 Lab-10 Enabling Account Lockout policy

1. Log on to D.C as Administrator, click Press Windows Key to go to Start, select Group Policy Management. 2. Expand ForestExpand DomainsExpand Microsoft.comright click Default Domain policy and select Edit. 3. Expand Computer ConfigurationExpand PoliciesExpand WindowsSettings Expand Security SettingsExpand Account PoliciesOpen Account Lockout Policy. 4. Double click, Account lockout threshold. 5. Enter the Value for Number of invalid logon attempts(Ex: 2) 6. Set the Account lockout duration and clickOK. 7. Close the Group Policy Management Window. Verification: 1. Enter the password for user (User1) wrongly for 2 times while logging in and the user account will be locked. Unlocking the locked User accountManually 1. Log on to D.C as Administrator, click Start  Programs Administrative Tools Active Directory Users and Computers. 2. Right click the User (User1) and select Properties. 3. Check the box Unlock account click Apply and OK. Verification: 1. Log in a...

Server Administration 2012 Lab-45 Configuring Additional Domain Controller using IFM

1. Log in as Administrator to the Domain Controller (SYS1). 2. Create a Shared folder (Ex: ifm) in C drive. 3. Go to Start, type cmd in Search Apps, and select Command Prompt 4. Type Ntdsutil 5. Type Activate instance ntds. 6. Type ifm. 7. Type create sysvol full C:\ifm 8. Verify for the snapshot generated successfully. Verification 1. Log in as Administrator to the Workgroup Computer(SYS2), Assign IP Address and Preferred DNS Server Address. 2. Access the shared folder (Ex: ifm) on Domain Controller and copy it to local hard disk drive (Ex: C drive). 3. Go to Server Manager Dashboard, Click Add roles and features. 4. In Before you begin page, click Next. 5. In Select installation type, select Role-based or feature-based installation, click Next. 6. In Select destination server, from Server Pool select SYS2, click Next. 7. In Roles, check the box Active Directory Domain Services. 8. Click Add Features, to install the required features for Active Directory Domain Servi...