Networking and System AdministrationUnit 811 min read
Directory Services, Active Directory, Windows Server Roles & LDAP
Unit 8 of Networking and System Administration explores centralized identity management (Active Directory), Windows Server roles (DNS, DHCP, file services), LDAP queries, Group Policy, and real-world deployments in Nepali enterprises like banks and universities.
Key points
- Directory services (AD/LDAP) centralize user authentication, authorization, and resource access across domains
- Windows Server roles (DNS, DHCP, FS) integrate with AD to create enterprise-grade networks
- LDAP filters use syntax like `(objectClass=user)(|(sn=Smith)(givenName=John))` to query directory entries
- Group Policy enforces security settings (password policies, software restrictions) via OU hierarchies
- Real-world: Ncell uses AD for employee access control; NEPSE’s trading system relies on LDAP for investor authentication
- ```
Core Concepts: What is a Directory Service?
A directory service is a database that stores, organizes, and provides access to information about network objects (users, groups, computers, printers, etc.). Unlike a database, it is optimized for fast read operations and hierarchical queries. The two most common implementations are:
- Lightweight Directory Access Protocol (LDAP) – Standard protocol for directory services (port 389/636)
- Active Directory (AD) – Microsoft’s implementation of LDAP with additional features like Group Policy
How It Works: The LDAP Data Model
LDAP organizes data in a tree-like structure called the Directory Information Tree (DIT). Each entry has:
- A Distinguished Name (DN) (e.g.,
CN=John Doe,OU=Sales,DC=company,DC=com) - Attributes (e.g.,
sn=Doe,mail=john@company.com,objectClass=user)
classDiagram
class Entry {
+DN: Distinguished Name
+Attributes: Key-value pairs
+ObjectClass: Type (user, group, computer)
}
class OrganizationalUnit {
+OU: Container for entries
}
class Domain {
+DC: Domain Component (e.g., DC=company,DC=com)
}
Entry "1" --> "*" Attributes : contains
OrganizationalUnit "1" --> "*" Entry : contains
Domain "1" --> "*" OrganizationalUnit : containsActive Directory: Microsoft’s Implementation
Key Components of AD
| Component | Description | Example in Nepal |
|---|---|---|
| Domain | Logical group of objects sharing a security database | ad.ncell.com for employee accounts |
| Domain Controller (DC) | Server running AD DS to authenticate and authorize users | Windows Server 2019/2022 with AD role |
| Organizational Unit (OU) | Container for grouping objects (e.g., OU=Students, OU=Faculty) |
OU=IT-Staff,DC=tu,DC=edu |
| Global Catalog (GC) | Distributed data store for fast searches across domains | Used in TU’s central authentication system |
| Group Policy (GPO) | Enforces settings (password policies, software deployment) | Blocks USB drives on NEPSE workstations |
How AD Authentication Works (Kerberos Protocol)
- User logs in → Workstation requests a Ticket Granting Ticket (TGT) from a DC.
- DC validates credentials and issues a TGT (encrypted with the Key Distribution Center (KDC)).
- User requests service access (e.g., file server) → Presents TGT to KDC.
- KDC issues a Service Ticket for the requested resource.
- User accesses resource using the service ticket.
sequenceDiagram
participant User
participant Workstation
participant DC as Domain Controller
participant KDC as Key Distribution Center
participant FileServer
User->>Workstation: Enters credentials (john/Ncell123)
Workstation->>DC: Request TGT (AS-REQ)
DC-->>Workstation: Returns TGT (AS-REP)
Workstation->>KDC: Request Service Ticket (TGS-REQ)
KDC-->>Workstation: Returns Service Ticket (TGS-REP)
Workstation->>FileServer: Access files (AP-REQ + Service Ticket)
FileServer-->>Workstation: Grants access (AP-REP)LDAP Queries: Filtering Directory Entries
LDAP uses a string-based query language to search the directory. Common filters:
- Equality match:
(attribute=value)→(cn=John Doe) - Substring search:
(attribute=*value*)→(sn=Do*) - OR condition:
(|(condition1)(condition2))→(|(department=IT)(title=Manager)) - AND condition:
(&(condition1)(condition2))→(&(objectClass=user)(mail=*@ncell.com))
Worked Example: Finding All IT Staff in Ncell
Query:
(&(objectClass=user)(department=IT)(|(title=Engineer)(title=Manager)))
Result: Returns all users where:
objectClass=userdepartment=ITtitleis either "Engineer" or "Manager"
Visual Filter Breakdown:
mindmap
root((LDAP Filter: IT Staff))
objectClass=user
department=IT
title=Engineer
title=ManagerWindows Server Roles for Directory Services
Windows Server integrates directory services with other roles:
| Role | Integration with AD | Example Use Case |
|---|---|---|
| DNS Server | Stores SRV records for AD (e.g., _ldap._tcp) |
ad.ncell.com resolves to DCs |
| DHCP Server | Assigns IPs dynamically in AD-managed subnets | TU campus devices get IPs from DHCP+AD |
| File Server | NTFS permissions + AD groups for access control | NEPSE trading data stored on AD-shared drives |
| Print Server | Drivers and permissions managed via AD | University lab printers accessible only to faculty |
Group Policy: Enforcing Security
Group Policy Objects (GPOs) apply settings via:
- Linking to OUs (e.g.,
OU=Studentsgets stricter policies thanOU=Faculty). - Processing order: Local → Site → Domain → OU (last applied wins).
- Common settings:
- Password complexity (
MinimumPasswordLength=12) - Software restrictions (block
notepad.exe) - Wireless network policies
- Password complexity (
## In the Real World
Ncell’s Employee Directory
- What it uses: Active Directory with LDAP for authentication.
- How it works: Employees log in via Kerberos tickets to access internal apps (billing systems, HR portals). GPOs enforce device encryption and VPN requirements.
- Worked example: A Ncell engineer in Kathmandu accesses the billing system in Pokhara. The request flows:
Engineer (KTM) → AD DC (KTM) → Kerberos TGT → Billing Server (PKA) → Access granted
NEPSE’s Investor Authentication
- What it uses: LDAP for investor credentials (username/password + OTP).
- How it works: When an investor logs into the trading platform, the system queries LDAP for:
(&(objectClass=person)(investorID=12345)(status=active)) - Security: GPOs disable guest accounts and require 2FA for admin access.
Tribhuvan University’s Centralized IT
- What it uses: Windows Server with AD for student/faculty accounts.
- How it works:
- Students in
OU=BEITMget access to ITM lab software. - Faculty in
OU=Professorscan reset student passwords via AD.
- Students in
- Challenge: Managing 50,000+ accounts across campuses requires fine-grained OU structures.
Comparing Directory Services
| Feature | Active Directory (AD) | OpenLDAP | ApacheDS |
|---|---|---|---|
| Vendor | Microsoft | Open-source | Open-source (Apache) |
| Protocol | LDAP + Kerberos + NTLM | LDAP | LDAP |
| Group Policy | Yes (GPOs) | No | No |
| Cross-platform | Windows-focused | Linux/Windows/Mac | Linux/Windows/Mac |
| Cost | Free (Windows Server) | Free | Free |
| Use Case | Enterprises (banks, universities) | Linux/Unix environments | Lightweight LDAP needs |
When to choose AD?
- Windows-heavy environments (e.g., Nepali banks using Windows Server).
- Need for Group Policy (e.g., enforcing security compliance in NEPSE).
When to choose OpenLDAP?
- Mixed OS environments (Linux servers + Windows clients).
- Cost-sensitive deployments (e.g., small NGOs).
## Exam Tip
What Examiners Look For
- LDAP Queries: Be able to write filters for:
- Finding users in a specific OU.
- Combining conditions with
&/|.
- AD Hierarchy: Draw and label:
- Domain → OU → Users/Groups.
- How GPOs apply from top to bottom.
- Kerberos Flow: Sequence diagram of TGT → Service Ticket.
- Real-world Mapping: Relate AD to:
- Nepali banks (employee access).
- Universities (student/faculty accounts).
- Troubleshooting: Common issues like:
- "User can’t log in" → Check if DC is online, replication status.
- "GPO not applying" → Verify link order, inheritance blocking.
Common Pitfalls
- Mixing LDAP and SQL: LDAP is for reads; SQL is for transactions.
- Ignoring GPO precedence: Settings in child OUs override parent OUs.
- Hardcoding passwords: Always use AD for authentication, not local accounts.
Sample Exam Question & Answer
Question: "Explain how Ncell could use Active Directory to manage 5,000 employee accounts across 10 branches. Include the roles of DNS, DHCP, and Group Policy in your answer."
Answer:
AD Structure:
classDiagram class Domain { +DC=ncell.com } class OU { +OU=Branches +OU=Departments } class BranchOU { +OU=Kathmandu +OU=Pokhara ... } Domain "1" --> "*" OU : contains OU "1" --> "*" BranchOU : contains- Domain:
ncell.comwith 2 DCs (KTM + PKR for redundancy). - OUs:
OU=Branches/Kathmandu(1,000 users).OU=Departments/IT(500 users across branches).
- Domain:
DNS Integration:
- SRV records point to DCs:
_ldap._tcp.dc._msdcs.ncell.com → DC1.ncell.com (192.168.1.10) _ldap._tcp.dc._msdcs.ncell.com → DC2.ncell.com (192.168.2.10) - Why? Ensures workstations find the nearest DC for authentication.
- SRV records point to DCs:
DHCP + AD:
- DHCP scope for
192.168.1.0/24(KTM branch) includes:- Option 006 (DNS Servers):
192.168.1.5(AD-integrated DNS). - Option 015 (DNS Domain):
ncell.com.
- Option 006 (DNS Servers):
- Result: New devices auto-register in AD via DNS updates.
- DHCP scope for
Group Policy:
- Branch-Specific GPO:
OU=Branches/Kathmandu→ Enforces VPN requirement for remote access.
- Department-Specific GPO:
OU=Departments/IT→ Allows RDP to dev servers; blocks USB storage.
- Password Policy (Domain-wide):
MinimumPasswordAge=1,MaximumPasswordAge=90.
- Branch-Specific GPO:
Authentication Flow (Kerberos):
sequenceDiagram participant Engineer participant Workstation participant DC_KTM participant KDC participant FileServer_PKR Engineer->>Workstation: Logs in (ID: jdoe, PW: *****) Workstation->>DC_KTM: AS-REQ (TGT request) DC_KTM-->>Workstation: AS-REP (TGT) Workstation->>KDC: TGS-REQ (Service Ticket for FileServer_PKR) KDC-->>Workstation: TGS-REP (Service Ticket) Workstation->>FileServer_PKR: AP-REQ + Service Ticket FileServer_PKR-->>Workstation: AP-REP (Access granted)
Backup & Recovery:
- AD Database: Backed up nightly via
ntdsutil. - Disaster Recovery: If DC_KTM fails, DC_PKR takes over via replication.
- AD Database: Backed up nightly via
Why This Works for Ncell:
- Centralized management: No need to log into each branch’s server.
- Security: GPOs enforce compliance (e.g., "No local admin accounts").
- Scalability: Adding a new branch? Create a new OU and link a GPO.
Based on the TU BITM syllabus for Networking and System Administration (IT271), unit 8.
Discussion
Loading…