This repository contains an in-depth walkthrough for the "EXTRA" exercise involving Active Directory configuration, User Profiles, and Homefolder Management.
You are tasked with setting up a complex organizational structure on SRV-DC-01 within the AD.training.com domain, including specific storage requirements and profile types for different departments.
Log in to SRV-DC-01 as the Domain Administrator and open Active Directory Users & Computers.
- Create a root OU named "EXTRA".
- Under "EXTRA", create the following sub-OUs:
Servers: To house all domain server objects.Workstations: To house client machine objects.Departments: To house the departmental OUs.
- Under "Departments", create:
PRODUCTIONHRTECHNICALMANAGEMENT
- User Creation: In each departmental OU, create 2 standard user accounts (e.g.,
ProdUser1,ProdUser2).
Log in to SRV-FILE-01 to prepare the storage infrastructure.
- Open Server Manager > File and Storage Services > Shares.
- Create two new SMB Shares:
Test-Homefolders$: (Hidden share recommended)Test-Userprofiles$: (Hidden share recommended)
- Permissions: Ensure "Authenticated Users" or the specific departmental groups have Modify NTFS permissions.
Configure the user profile paths in the "Profile" tab of each user's AD properties.
Mandatory profiles provide a read-only environment. If the user makes changes, they are discarded at logout.
- Path: Set Profile Path to
\\SRV-FILE-01\Test-Userprofiles$\mandatory. - Setup: Rename the
NTUSER.DATtoNTUSER.MANin the profile folder to make it mandatory. - Homefolder:
- Connect
H:to\\SRV-FILE-01\Test-Homefolders$\%username%. - Hard Limit: Use File Server Resource Manager (FSRM) on SRV-FILE-01 to set a Hard Quota of 400MB on the homefolder directory.
- Connect
Roaming profiles sync changes back to the server.
- Path: Set Profile Path to
\\SRV-FILE-01\Test-Userprofiles$\%username%. - Homefolder:
- Connect
H:to\\SRV-FILE-01\Test-Homefolders$\%username%. - Hard Limit: Set a Hard Quota of 1GB via FSRM.
- Connect
- Path: Same as Technical.
- Homefolder:
- Connect
H:to\\SRV-FILE-01\Test-Homefolders$\%username%. - Soft Limit: Set a Soft Quota of 1GB via FSRM. Soft quotas allow users to exceed the limit but trigger an email/log notification to the admin.
- Connect
- OUs created under "EXTRA"?
- 2 Users per department?
- Shares created on SRV-FILE-01?
-
.MANextension verified for Mandatory users? - Quotas (Hard vs Soft) applied in FSRM?
Created by Lennert Van Hoyweghen - IT Trainer