IT271 Networking and System Administration

Networking and System AdministrationUnit 89 min read

Directory Services, Windows Server & Active Directory

Unit 8 of Networking and System Administration explores Active Directory (AD) architecture, Windows Server roles, domain vs. workgroup models, Group Policy Objects (GPOs), and LDAP/NTLM authentication, with real-world examples from banks, NEPSE, and cloud services.

Directory Services: Centralized Identity Management

Directory services store, organize, and provide access to information about network objects (users, groups, printers, etc.) in a structured, hierarchical manner. The most widely used directory service is Microsoft Active Directory (AD), which integrates with Windows Server.

How Directory Services Work

  1. Centralized Database: Stores user accounts, permissions, and resources in a single repository.
  2. Hierarchical Structure: Uses a tree or forest model to organize objects logically.
  3. Authentication & Authorization: Validates users via protocols like LDAP (Lightweight Directory Access Protocol) or NTLM (NT LAN Manager).
  4. Replication: Ensures consistency across multiple domain controllers.
User AccountsPermissionsResourcesCentralized DatabaseTreeDomainForestOrganizational Units (OUs)Hierarchical StructureLDAPNTLMAuthentication & AuthorizationDomain Controllers (DCs)ReplicationDirectoryService
Hierarchical structure of Directory Services showing key components

Worked Example: NEPSE Trading System

NEPSE’s internal network uses Active Directory to manage:

  • Trader accounts (users) with role-based access (e.g., brokers vs. admins).
  • Shared resources (e.g., trading terminals, databases) via Group Policy Objects (GPOs).
  • LDAP queries to authenticate traders before granting access to trading platforms.

Windows Server Roles and Active Directory

Windows Server provides roles (services) that can be installed to extend functionality. Key roles for directory services include:

Active Directory Domain Services (AD DS)DNS ServerFile and Storage ServicesRolesGroup Policy ManagementRemote Desktop ServicesFeaturesWindows Server 2022
Windows Server role hierarchy with AD DS highlighted
Role Purpose Example Use Case
Active Directory DS Manages domain, users, and policies. Bank employee access control.
DNS Server Resolves domain names to IP addresses (critical for AD). Ncell’s internal DNS for employee devices.
DHCP Server Automatically assigns IP addresses. Daraz’s warehouse network for IoT devices.
File & Storage Centralized file sharing (e.g., \\server\share). NTC’s document repository for engineers.

Active Directory Components

  1. Domain: A logical group of objects (e.g., company.local) sharing a common directory database.
  2. Domain Controller (DC): A server running AD DS that authenticates users and enforces policies.
  3. Organizational Unit (OU): A container for organizing objects (e.g., Marketing, Finance).
  4. Global Catalog (GC): A distributed data store for quick searches across domains.
mindmap
  root((Active Directory))
    Domain
      "Logical group (e.g., nepse.local)"
      "Shares schema, policies, and security"
    Domain Controller
      "Authenticates users via LDAP/NTLM"
      "Replicates with other DCs"
    Organizational Unit
      "Groups objects (e.g., 'Traders')"
      "Applies GPOs"
    Global Catalog
      "Index of all objects in a forest"
      "Used for fast searches"

In the Real World

  1. Nepal Rastra Bank (NRB) Internal Network

    • Uses Active Directory to manage 1,000+ employee accounts with role-based access (e.g., auditors vs. cash handlers).
    • GPOs enforce password policies (e.g., 12-character minimum) and restrict USB drives to prevent data leaks.
    • LDAP queries authenticate bankers when accessing the core banking system.
  2. Khalti’s Payment Gateway

    • Relies on Windows Server + AD for:
      • Merchant authentication (LDAP/NTLM) before processing transactions.
      • Centralized logging of all payment requests (stored in AD-integrated SQL databases).
      • Disaster recovery via AD replication across data centers.
  3. NEPSE’s Trading Terminals

    • Workgroup model (not AD) is used for public terminals in stock exchange halls because:
      • No need for centralized user management (anyone can log in).
      • Local accounts suffice for basic access control.
    • AD is used internally for employee workstations (e.g., IT staff managing the system).

Domain vs. Workgroup Models

Feature Domain Model Workgroup Model
Centralized Management Yes (via AD) No (local accounts on each PC)
User Authentication LDAP/NTLM (server-based) Local SAM database (per machine)
Scalability High (supports 10,000+ users) Low (max ~20 users)
Security Strong (GPOs, auditing) Weak (no group policies)
Example Use Case Corporate networks (banks, NEPSE) Home networks, public kiosks (e.g., Daraz pickup counters)

Worked Example: Kathmandu Traffic Police System

  • Workgroup model is used for traffic violation cameras because:
    • Each camera runs on a standalone PC with a local account.
    • No need for centralized user management (only admins access the system).
  • Domain model is used for internal police network:
    • Officers log in via AD to access case files.
    • GPOs enforce security policies (e.g., screen lock after 5 mins of inactivity).

Group Policy Objects (GPOs): Enforcing Rules

GPOs allow admins to apply settings to users/computers in an OU. Examples:

  • Password policies: Enforce 14-character passwords with special characters.
  • Software restrictions: Block WhatsApp on company devices (for security).
  • Drive mappings: Auto-map Z:\ to a shared folder for all employees.
  • Firewall rules: Allow only HTTP/HTTPS traffic to nepse.com.
GPO CreationAdminPolicy ApplicationGPOUser ActionUserPCResultUser
Sequence of GPO enforcement: Admin → GPO → UserPC → User

Authentication Protocols: LDAP vs. NTLM

Protocol How It Works Security Level Example Use Case
LDAP Query-based (e.g., ldap://dc.company.local:389). Uses TLS for encryption. High Ncell employee login to internal portal.
NTLM Challenge-response (older, less secure). Used in legacy systems. Medium Daraz warehouse access cards.
016324863LDAP Query32 bitsResponse32 bitsNTLM Challenge-Response32 bitsServer Response32 bits
LDAP query vs. NTLM handshake packet examples

LDAP Query Example (NEPSE Employee Login)

LDAP Query:
ldap://nepse-dc.nepse.local:389
Search Base: ou=Employees,dc=nepse,dc=local
Filter: (sAMAccountName=jdoe)
Attributes: displayName, memberOf

Result:

displayName: John Doe
memberOf: CN=Traders,OU=Finance,DC=nepse,DC=local

Active Directory Forest and Trusts

  • Forest: A collection of trees (domains) sharing a common schema and configuration.
  • Trust: Allows users in Domain A to access resources in Domain B without re-authenticating.
    • Two-way trust: Bidirectional (e.g., nepse.local ↔ nrb.gov.np).
    • One-way trust: Unidirectional (e.g., khalti.com trusts ncell.com for payment processing).
Two-Way TrustOne-Way Trustnepse.localnrb.gov.npkhalti.comncell.com
Active Directory forest trusts: nepse.local ↔ nrb.gov.np (bidirectional) vs. khalti.com → ncell.com (unidirectional)

Exam Tip

  1. Diagrams are key: Draw AD forest/tree structures, GPO inheritance, and LDAP query flows.
  2. Compare domain vs. workgroup: Always ask why a company would choose one over the other (e.g., scalability, security).
  3. Real-world mapping:
    • Banks → AD with strict GPOs.
    • Public kiosks → Workgroup model.
    • NEPSE → Hybrid (AD for employees, workgroup for public terminals).
  4. Protocol questions: Know when to use LDAP (secure) vs. NTLM (legacy).
  5. GPOs: Memorize 3 common use cases (password policies, software restrictions, drive mappings).

Based on the TU BIM syllabus for Networking and System Administration (IT271), unit 8.

Discussion

Loading…