IT271 Networking and System Administration

Networking and System AdministrationUnit 811 min read

Directory Services, Active Directory, Windows Server Roles & LDAP

Unit 8 of Networking and System Administration explores centralized identity management (Active Directory), Windows Server roles (DNS, DHCP, file services), LDAP queries, Group Policy, and real-world deployments in Nepali enterprises like banks and universities.

Key points

  • Directory services (AD/LDAP) centralize user authentication, authorization, and resource access across domains
  • Windows Server roles (DNS, DHCP, FS) integrate with AD to create enterprise-grade networks
  • LDAP filters use syntax like `(objectClass=user)(|(sn=Smith)(givenName=John))` to query directory entries
  • Group Policy enforces security settings (password policies, software restrictions) via OU hierarchies
  • Real-world: Ncell uses AD for employee access control; NEPSE’s trading system relies on LDAP for investor authentication
  • ```

Core Concepts: What is a Directory Service?

A directory service is a database that stores, organizes, and provides access to information about network objects (users, groups, computers, printers, etc.). Unlike a database, it is optimized for fast read operations and hierarchical queries. The two most common implementations are:

  1. Lightweight Directory Access Protocol (LDAP) – Standard protocol for directory services (port 389/636)
  2. Active Directory (AD) – Microsoft’s implementation of LDAP with additional features like Group Policy

How It Works: The LDAP Data Model

LDAP organizes data in a tree-like structure called the Directory Information Tree (DIT). Each entry has:

  • A Distinguished Name (DN) (e.g., CN=John Doe,OU=Sales,DC=company,DC=com)
  • Attributes (e.g., sn=Doe, mail=john@company.com, objectClass=user)
classDiagram
    class Entry {
        +DN: Distinguished Name
        +Attributes: Key-value pairs
        +ObjectClass: Type (user, group, computer)
    }
    class OrganizationalUnit {
        +OU: Container for entries
    }
    class Domain {
        +DC: Domain Component (e.g., DC=company,DC=com)
    }
    Entry "1" --> "*" Attributes : contains
    OrganizationalUnit "1" --> "*" Entry : contains
    Domain "1" --> "*" OrganizationalUnit : contains

Active Directory: Microsoft’s Implementation

Key Components of AD

Component Description Example in Nepal
Domain Logical group of objects sharing a security database ad.ncell.com for employee accounts
Domain Controller (DC) Server running AD DS to authenticate and authorize users Windows Server 2019/2022 with AD role
Organizational Unit (OU) Container for grouping objects (e.g., OU=Students, OU=Faculty) OU=IT-Staff,DC=tu,DC=edu
Global Catalog (GC) Distributed data store for fast searches across domains Used in TU’s central authentication system
Group Policy (GPO) Enforces settings (password policies, software deployment) Blocks USB drives on NEPSE workstations

How AD Authentication Works (Kerberos Protocol)

  1. User logs in → Workstation requests a Ticket Granting Ticket (TGT) from a DC.
  2. DC validates credentials and issues a TGT (encrypted with the Key Distribution Center (KDC)).
  3. User requests service access (e.g., file server) → Presents TGT to KDC.
  4. KDC issues a Service Ticket for the requested resource.
  5. User accesses resource using the service ticket.
sequenceDiagram
    participant User
    participant Workstation
    participant DC as Domain Controller
    participant KDC as Key Distribution Center
    participant FileServer

    User->>Workstation: Enters credentials (john/Ncell123)
    Workstation->>DC: Request TGT (AS-REQ)
    DC-->>Workstation: Returns TGT (AS-REP)
    Workstation->>KDC: Request Service Ticket (TGS-REQ)
    KDC-->>Workstation: Returns Service Ticket (TGS-REP)
    Workstation->>FileServer: Access files (AP-REQ + Service Ticket)
    FileServer-->>Workstation: Grants access (AP-REP)

LDAP Queries: Filtering Directory Entries

LDAP uses a string-based query language to search the directory. Common filters:

  • Equality match: (attribute=value) → (cn=John Doe)
  • Substring search: (attribute=*value*) → (sn=Do*)
  • OR condition: (|(condition1)(condition2)) → (|(department=IT)(title=Manager))
  • AND condition: (&(condition1)(condition2)) → (&(objectClass=user)(mail=*@ncell.com))

Worked Example: Finding All IT Staff in Ncell

Query:

(&(objectClass=user)(department=IT)(|(title=Engineer)(title=Manager)))

Result: Returns all users where:

  • objectClass=user
  • department=IT
  • title is either "Engineer" or "Manager"

Visual Filter Breakdown:

mindmap
  root((LDAP Filter: IT Staff))
    objectClass=user
    department=IT
    title=Engineer
    title=Manager

Windows Server Roles for Directory Services

Windows Server integrates directory services with other roles:

Role Integration with AD Example Use Case
DNS Server Stores SRV records for AD (e.g., _ldap._tcp) ad.ncell.com resolves to DCs
DHCP Server Assigns IPs dynamically in AD-managed subnets TU campus devices get IPs from DHCP+AD
File Server NTFS permissions + AD groups for access control NEPSE trading data stored on AD-shared drives
Print Server Drivers and permissions managed via AD University lab printers accessible only to faculty

Group Policy: Enforcing Security

Group Policy Objects (GPOs) apply settings via:

  1. Linking to OUs (e.g., OU=Students gets stricter policies than OU=Faculty).
  2. Processing order: Local → Site → Domain → OU (last applied wins).
  3. Common settings:
    • Password complexity (MinimumPasswordLength=12)
    • Software restrictions (block notepad.exe)
    • Wireless network policies

## In the Real World

  1. Ncell’s Employee Directory

    • What it uses: Active Directory with LDAP for authentication.
    • How it works: Employees log in via Kerberos tickets to access internal apps (billing systems, HR portals). GPOs enforce device encryption and VPN requirements.
    • Worked example: A Ncell engineer in Kathmandu accesses the billing system in Pokhara. The request flows:
      Engineer (KTM) → AD DC (KTM) → Kerberos TGT → Billing Server (PKA) → Access granted
      
  2. NEPSE’s Investor Authentication

    • What it uses: LDAP for investor credentials (username/password + OTP).
    • How it works: When an investor logs into the trading platform, the system queries LDAP for:
      (&(objectClass=person)(investorID=12345)(status=active))
      
    • Security: GPOs disable guest accounts and require 2FA for admin access.
  3. Tribhuvan University’s Centralized IT

    • What it uses: Windows Server with AD for student/faculty accounts.
    • How it works:
      • Students in OU=BEITM get access to ITM lab software.
      • Faculty in OU=Professors can reset student passwords via AD.
    • Challenge: Managing 50,000+ accounts across campuses requires fine-grained OU structures.

Comparing Directory Services

Feature Active Directory (AD) OpenLDAP ApacheDS
Vendor Microsoft Open-source Open-source (Apache)
Protocol LDAP + Kerberos + NTLM LDAP LDAP
Group Policy Yes (GPOs) No No
Cross-platform Windows-focused Linux/Windows/Mac Linux/Windows/Mac
Cost Free (Windows Server) Free Free
Use Case Enterprises (banks, universities) Linux/Unix environments Lightweight LDAP needs

When to choose AD?

  • Windows-heavy environments (e.g., Nepali banks using Windows Server).
  • Need for Group Policy (e.g., enforcing security compliance in NEPSE).

When to choose OpenLDAP?

  • Mixed OS environments (Linux servers + Windows clients).
  • Cost-sensitive deployments (e.g., small NGOs).

## Exam Tip

What Examiners Look For

  1. LDAP Queries: Be able to write filters for:
    • Finding users in a specific OU.
    • Combining conditions with &/|.
  2. AD Hierarchy: Draw and label:
    • Domain → OU → Users/Groups.
    • How GPOs apply from top to bottom.
  3. Kerberos Flow: Sequence diagram of TGT → Service Ticket.
  4. Real-world Mapping: Relate AD to:
    • Nepali banks (employee access).
    • Universities (student/faculty accounts).
  5. Troubleshooting: Common issues like:
    • "User can’t log in" → Check if DC is online, replication status.
    • "GPO not applying" → Verify link order, inheritance blocking.

Common Pitfalls

  • Mixing LDAP and SQL: LDAP is for reads; SQL is for transactions.
  • Ignoring GPO precedence: Settings in child OUs override parent OUs.
  • Hardcoding passwords: Always use AD for authentication, not local accounts.

Sample Exam Question & Answer

Question: "Explain how Ncell could use Active Directory to manage 5,000 employee accounts across 10 branches. Include the roles of DNS, DHCP, and Group Policy in your answer."

Answer:

  1. AD Structure:

    classDiagram
      class Domain {
        +DC=ncell.com
      }
      class OU {
        +OU=Branches
        +OU=Departments
      }
      class BranchOU {
        +OU=Kathmandu
        +OU=Pokhara
        ...
      }
      Domain "1" --> "*" OU : contains
      OU "1" --> "*" BranchOU : contains
    • Domain: ncell.com with 2 DCs (KTM + PKR for redundancy).
    • OUs:
      • OU=Branches/Kathmandu (1,000 users).
      • OU=Departments/IT (500 users across branches).
  2. DNS Integration:

    • SRV records point to DCs:
      _ldap._tcp.dc._msdcs.ncell.com → DC1.ncell.com (192.168.1.10)
      _ldap._tcp.dc._msdcs.ncell.com → DC2.ncell.com (192.168.2.10)
      
    • Why? Ensures workstations find the nearest DC for authentication.
  3. DHCP + AD:

    • DHCP scope for 192.168.1.0/24 (KTM branch) includes:
      • Option 006 (DNS Servers): 192.168.1.5 (AD-integrated DNS).
      • Option 015 (DNS Domain): ncell.com.
    • Result: New devices auto-register in AD via DNS updates.
  4. Group Policy:

    • Branch-Specific GPO:
      • OU=Branches/Kathmandu → Enforces VPN requirement for remote access.
    • Department-Specific GPO:
      • OU=Departments/IT → Allows RDP to dev servers; blocks USB storage.
    • Password Policy (Domain-wide):
      • MinimumPasswordAge=1, MaximumPasswordAge=90.
  5. Authentication Flow (Kerberos):

    sequenceDiagram
      participant Engineer
      participant Workstation
      participant DC_KTM
      participant KDC
      participant FileServer_PKR
    
      Engineer->>Workstation: Logs in (ID: jdoe, PW: *****)
      Workstation->>DC_KTM: AS-REQ (TGT request)
      DC_KTM-->>Workstation: AS-REP (TGT)
      Workstation->>KDC: TGS-REQ (Service Ticket for FileServer_PKR)
      KDC-->>Workstation: TGS-REP (Service Ticket)
      Workstation->>FileServer_PKR: AP-REQ + Service Ticket
      FileServer_PKR-->>Workstation: AP-REP (Access granted)
  6. Backup & Recovery:

    • AD Database: Backed up nightly via ntdsutil.
    • Disaster Recovery: If DC_KTM fails, DC_PKR takes over via replication.

Why This Works for Ncell:

  • Centralized management: No need to log into each branch’s server.
  • Security: GPOs enforce compliance (e.g., "No local admin accounts").
  • Scalability: Adding a new branch? Create a new OU and link a GPO.

Based on the TU BITM syllabus for Networking and System Administration (IT271), unit 8.

Discussion

Loading…