Module 2 - Managing User and Computer Accounts
Module 2 - Managing User and Computer Accounts
Managing User
and Computer
Accounts
Overview
Name Example
User logon name Tadams
Pre—Windows
contoso\Tadams
2000 logon name
User principal
[email protected]
logon name
LDAP CN=terry
distinguished adams,ou=sales,dc=contos
name o,dc=msft
LDAP relative
distinguished CN=terry adams
name
Guidelines for Creating a User
Account Naming Convention
Account Description
Useroptions
must
Users must change their
change
passwords the next time they
password at
log on to the network
next logon
User cannot Users do not have the
change permissions to change their
password own password
Identifies a computer in a
domain
Provides a means for
authenticating and auditing
computer access to the
network and to domain
resources
Is required for every computer
running:
Windows Server 2003
Windows XP Professional
Windows 2000
Windows NT
Why Create a Computer Account?
Security
Authentication
Auditing
Management
Software deployment
Desktop management
Hardware and software inventory
through Systems Management Server
Where Computer Accounts Are
Created in a Domain
Account Properties
When to Modify User and
Computer Account Properties
Modify
Makeuser account
it easier to useproperties
search to:
capabilities
to find users
Match a company’s organizational
hierarchy
Determine the group membership of
a user account
Modify computer account properties to:
Assist in asset tracking (Location
property)
Document who manages a computer
(Managed By property)
Properties Associated with User
Accounts
User Account
Template
What Properties Are in a Template?
Account lockout
thresholds:
Define the number
of failed logon
attempts
Prevent hackers
from guessing
user passwords
Logon failures can
occur:
At the logon
screen
At a screen saver
protected by a
password
When to Reset User Passwords