Home › Search
Search the lessons
6 learning paths and their video lessons - type a topic, command or term.
Active Directory basics: how AD DS is built
What AD DS is made of: components, schema, forest, domain, OUs and the admin tools.
AD DS components: logical and physical building blocks
The logical components: partitions, schema, domains, trees, forests, sites and OUs
The AD DS schema: classes, attributes and the schema master
What the schema defines: object classes, attributes and data syntax
The AD DS forest: root domain, security and replication boundary
What the forest root domain holds that other domains do not
The AD DS domain: objects, replication, administration and sign-in
The three common object types: users, computers and groups
Organisational units (OUs) and the default AD DS containers
The two reasons to create an OU: Group Policy and delegation
AD DS administration tools: ADAC, MMC snap-ins and PowerShell
What Active Directory Administrative Center can do beyond creating objects
How domain controllers work
What a DC stores, the global catalog, how sign-in and DC location work, and the FSMO roles.
What is a domain controller?
What NTDS.dit and SYSVOL hold on every domain controller
What is a global catalog?
Why the global catalog holds only part of each object
The AD DS sign-in process
How a computer finds a domain controller to authenticate a user
Domain controller SRV records
Why clients use SRV records in DNS to find a domain controller
What are operations masters (FSMO roles)?
The five FSMO roles and which exist per forest or per domain
Transferring and seizing FSMO roles
The difference between transferring and seizing a FSMO role
Deploying domain controllers
Promote DCs with Server Manager or PowerShell, install from media, upgrade, clone and virtualise.
Installing a domain controller from Server Manager
The two stages: adding the AD DS role, then promoting the server
Installing a domain controller on Server Core
Ways to install the DC role when Server Core has no local GUI
Installing a domain controller from media (IFM)
When installing from media beats promoting over the WAN
Upgrading domain controllers to a newer Windows Server
In-place upgrade versus adding new DCs and retiring old ones
Cloning virtual domain controllers
Requirements: generation identifier, Windows Server 2012 or later guests, PDC emulator
Best practices for virtualising domain controllers
Avoiding single points of failure with virtual DCs
Active Directory users and groups
User accounts, attributes and profiles; group types, scopes, nesting, default groups and identities.
User accounts in Active Directory
What a domain user account contains and what it controls
Configuring user account attributes
Where the attribute sections appear in Active Directory Administrative Center
User profiles, home folders and folder redirection
Where Windows keeps a local user profile and what it contains
Group types: security and distribution groups
The difference between security and distribution groups
Group scopes: local, domain local, global and universal
What group scope controls: membership and where permissions apply
Group nesting with IGDLA and IGUDLA
The IGDLA nesting pattern and what each letter stands for
Default administrative groups in Active Directory
Which default admin groups live in the forest root and which in every domain
Special identities in Windows and AD DS
How special identities differ from ordinary security groups
Managing group membership with Restricted Groups
Where the Restricted Groups setting lives in a GPO
Linux command line: first steps
Move around the file system, find out who and what is on the box, keep time and make archives.
Lesson 1: ls, cd and mkdir
Why ls hides dot files and how ls -a shows them
Lesson 2: Essential Linux commands every admin needs
All the useful forms of cd, including cd - and cd ..
Lesson 3: Linux time - RTC versus the system clock
The difference between the hardware RTC and the kernel's system clock
Lesson 4: date and hwclock - setting the hardware clock
Showing UTC and custom formats with date -u and date +FORMAT
Lesson 5: which, wc, lspci, gzip and tar
Locating a command's program file with which
Linux root and sudo security
Lock down root, give exactly the sudo rights people need, and keep sudoers safe and auditable.
Lesson 1: Linux root access security
Read the root password state with getent shadow
Lesson 2: Securing the root account and configuring sudo
Lock the root password and recognise the lock in /etc/shadow
Lesson 3: Sudoers mastery: reading the sudoers file
Validate all sudoers files with visudo -c
Lesson 4: Sudo privileges: limiting a user to specific commands
Create a drop-in rule file with visudo -f
Lesson 5: Role-based access control with groups
Create role groups and users with groupadd and useradd
Lesson 6: Sudoers and RBAC: fixing permissions and testing roles
Set sudoers.d files to root:root ownership and mode 0440
Lesson 7: Advanced sudoers configuration: logging, aliases and denials
Record sudo sessions with log_input and log_output
Lesson 8: Sudoers environment security
Why env_reset matters for every sudo rule
Lesson 9: Testing sudo security with environment variables
Plant test variables and see what sudo passes on
Lesson 10: Sudo session management and timestamp timeouts
Check and refresh cached sudo credentials with sudo -v
Lesson 11: Debugging and troubleshooting sudo policies
List another user's effective rights with sudo -U user -l
Lesson 12: Cleaning up sudoers and removing test users
Remove test accounts with userdel -r
Lesson 13: Keeping sudoers configuration in a Git repository
Four core sudoers best practices