Networking and System AdministrationUnit 89 min read
Directory Services, Windows Server & Active Directory
Unit 8 of Networking and System Administration explores Active Directory (AD) architecture, Windows Server roles, domain vs. workgroup models, Group Policy Objects (GPOs), and LDAP/NTLM authentication, with real-world examples from banks, NEPSE, and cloud services.
Directory Services: Centralized Identity Management
Directory services store, organize, and provide access to information about network objects (users, groups, printers, etc.) in a structured, hierarchical manner. The most widely used directory service is Microsoft Active Directory (AD), which integrates with Windows Server.
How Directory Services Work
- Centralized Database: Stores user accounts, permissions, and resources in a single repository.
- Hierarchical Structure: Uses a tree or forest model to organize objects logically.
- Authentication & Authorization: Validates users via protocols like LDAP (Lightweight Directory Access Protocol) or NTLM (NT LAN Manager).
- Replication: Ensures consistency across multiple domain controllers.
Worked Example: NEPSE Trading System
NEPSE’s internal network uses Active Directory to manage:
- Trader accounts (users) with role-based access (e.g., brokers vs. admins).
- Shared resources (e.g., trading terminals, databases) via Group Policy Objects (GPOs).
- LDAP queries to authenticate traders before granting access to trading platforms.
Windows Server Roles and Active Directory
Windows Server provides roles (services) that can be installed to extend functionality. Key roles for directory services include:
| Role | Purpose | Example Use Case |
|---|---|---|
| Active Directory DS | Manages domain, users, and policies. | Bank employee access control. |
| DNS Server | Resolves domain names to IP addresses (critical for AD). | Ncell’s internal DNS for employee devices. |
| DHCP Server | Automatically assigns IP addresses. | Daraz’s warehouse network for IoT devices. |
| File & Storage | Centralized file sharing (e.g., \\server\share). |
NTC’s document repository for engineers. |
Active Directory Components
- Domain: A logical group of objects (e.g.,
company.local) sharing a common directory database. - Domain Controller (DC): A server running AD DS that authenticates users and enforces policies.
- Organizational Unit (OU): A container for organizing objects (e.g.,
Marketing,Finance). - Global Catalog (GC): A distributed data store for quick searches across domains.
mindmap
root((Active Directory))
Domain
"Logical group (e.g., nepse.local)"
"Shares schema, policies, and security"
Domain Controller
"Authenticates users via LDAP/NTLM"
"Replicates with other DCs"
Organizational Unit
"Groups objects (e.g., 'Traders')"
"Applies GPOs"
Global Catalog
"Index of all objects in a forest"
"Used for fast searches"In the Real World
Nepal Rastra Bank (NRB) Internal Network
- Uses Active Directory to manage 1,000+ employee accounts with role-based access (e.g., auditors vs. cash handlers).
- GPOs enforce password policies (e.g., 12-character minimum) and restrict USB drives to prevent data leaks.
- LDAP queries authenticate bankers when accessing the core banking system.
Khalti’s Payment Gateway
- Relies on Windows Server + AD for:
- Merchant authentication (LDAP/NTLM) before processing transactions.
- Centralized logging of all payment requests (stored in AD-integrated SQL databases).
- Disaster recovery via AD replication across data centers.
- Relies on Windows Server + AD for:
NEPSE’s Trading Terminals
- Workgroup model (not AD) is used for public terminals in stock exchange halls because:
- No need for centralized user management (anyone can log in).
- Local accounts suffice for basic access control.
- AD is used internally for employee workstations (e.g., IT staff managing the system).
- Workgroup model (not AD) is used for public terminals in stock exchange halls because:
Domain vs. Workgroup Models
| Feature | Domain Model | Workgroup Model |
|---|---|---|
| Centralized Management | Yes (via AD) | No (local accounts on each PC) |
| User Authentication | LDAP/NTLM (server-based) | Local SAM database (per machine) |
| Scalability | High (supports 10,000+ users) | Low (max ~20 users) |
| Security | Strong (GPOs, auditing) | Weak (no group policies) |
| Example Use Case | Corporate networks (banks, NEPSE) | Home networks, public kiosks (e.g., Daraz pickup counters) |
Worked Example: Kathmandu Traffic Police System
- Workgroup model is used for traffic violation cameras because:
- Each camera runs on a standalone PC with a local account.
- No need for centralized user management (only admins access the system).
- Domain model is used for internal police network:
- Officers log in via AD to access case files.
- GPOs enforce security policies (e.g., screen lock after 5 mins of inactivity).
Group Policy Objects (GPOs): Enforcing Rules
GPOs allow admins to apply settings to users/computers in an OU. Examples:
- Password policies: Enforce 14-character passwords with special characters.
- Software restrictions: Block WhatsApp on company devices (for security).
- Drive mappings: Auto-map
Z:\to a shared folder for all employees. - Firewall rules: Allow only HTTP/HTTPS traffic to
nepse.com.
Authentication Protocols: LDAP vs. NTLM
| Protocol | How It Works | Security Level | Example Use Case |
|---|---|---|---|
| LDAP | Query-based (e.g., ldap://dc.company.local:389). Uses TLS for encryption. |
High | Ncell employee login to internal portal. |
| NTLM | Challenge-response (older, less secure). Used in legacy systems. | Medium | Daraz warehouse access cards. |
LDAP Query Example (NEPSE Employee Login)
LDAP Query:
ldap://nepse-dc.nepse.local:389
Search Base: ou=Employees,dc=nepse,dc=local
Filter: (sAMAccountName=jdoe)
Attributes: displayName, memberOf
Result:
displayName: John Doe
memberOf: CN=Traders,OU=Finance,DC=nepse,DC=local
Active Directory Forest and Trusts
- Forest: A collection of trees (domains) sharing a common schema and configuration.
- Trust: Allows users in Domain A to access resources in Domain B without re-authenticating.
- Two-way trust: Bidirectional (e.g.,
nepse.local↔nrb.gov.np). - One-way trust: Unidirectional (e.g.,
khalti.comtrustsncell.comfor payment processing).
- Two-way trust: Bidirectional (e.g.,
Exam Tip
- Diagrams are key: Draw AD forest/tree structures, GPO inheritance, and LDAP query flows.
- Compare domain vs. workgroup: Always ask why a company would choose one over the other (e.g., scalability, security).
- Real-world mapping:
- Banks → AD with strict GPOs.
- Public kiosks → Workgroup model.
- NEPSE → Hybrid (AD for employees, workgroup for public terminals).
- Protocol questions: Know when to use LDAP (secure) vs. NTLM (legacy).
- GPOs: Memorize 3 common use cases (password policies, software restrictions, drive mappings).
Based on the TU BIM syllabus for Networking and System Administration (IT271), unit 8.
Discussion
Loading…