MCITP 70-640: Active Directory Computer Accounts

preview_player
Показать описание
This video looks at computer accounts in Active Directory. Each time you add a computer to the domain, a computer account is created for that computer in the Active Directory database. This video looks at how these computer accounts work and how to reset the computer accounts if the password in the computer accounts becomes out of sync with the password stored on the local computer.

Demonstration 04:57

Computer Account
A computer account in Active Directory is very simpler to a user accounts in Active Directory. Fundamentally, a computer and user account are made from the same attributes. Like a user account, the computer account has a password. Unlike a user account this password is randomly generated. This password is supply to the domain when the computer starts up which allows a secure connection to be created between the computer and the Domain Controller. This password is automatically changed after 30 days. If the computer has not connected to the domain for more than 30 days, the computer will still be able to access the domain. The password for the computer account will be changed next time the computer connects up to the domain.

Resting the computer account
Sometimes the password used on the local computer and that stored in the domain for the computer accounts become out of sync. When this occurs you will receive a message "The trust relationship between this workstation and the primary domain failed." When this occurs the computer will need to be readded to the domain.

Pre-Stage Computer Accounts
A computer accounts is automatically created for a computer when it is added to the domain. You can also manually create the computer account in advance before the computer is added to the domain. When this is done this referred to as pre-stage. There are a number of reasons why you may want to pre-stage the computer account:

1) Deployment solutions like Windows Deployments Solutions (WDS) can be configured to use only pre-stage accounts. This stop computers from being deployed unless a computer account has been created for them. This essentially puts some controls on images that are deploy using system like WDS.

2) A pre-stage computer account ensures that the computer is put into the correct organizational unit. If you do not use a pre-staged computer account, the computer account will be created in the default location of computers. The computers OU can't have additional group polices apply to it so limits how the computer can be administered. By pre-staging the computer ensures that administrators can control the computer using group policy as soon as the computer is added to the domain.

3) A pre-stage account allows a general user to be granted the right to add that computer to the domain. This means allows more granular administration to achieved rather than having to use an account like the administrators account.

Demonstration
To perform administration on computer accounts inside Active Directory , open Active Directory Users and Computers from administrative tools under the start menu.

If you select a computer account, you can access the properties of the computer account by right clicking and selecting properties. The properties contains information about the computer like what type of computer it is. For example, a "workstation or server" or a Domain Controller with or without it being configured as global catalog server.

To create a pre-stage computer account, open Active Directory User and Computers. Inside Active Directory User accounts, navigate to the OU that you want to create the computer account in. In the new computer dialog you can also set a user account that will be allowed to add the computer to the domain.

To add a computer to the domain, open Windows Explorer and right click on computer and select properties. From the system properties, select the option change settings and then press the button change. This will allow you to remove or add the computer to a domain.

To reset the password on a computer account, right click the computer account and select reset account. The computer will need to be removed from the domain and re-added again. When you remove the computer from the domain and palace it in a work group, you do not need to reboot the computer before adding it to the domain again. Once it is added to the domain, you will need to reboot the computer to complete the process.

References
Рекомендации по теме
Комментарии
Автор

Thanks for the comment and the sub, much appreciated.

itfreetraining
Автор

Very informative indeed. This whole playlist works perfectly with Windows DataCentre 2019 as if it was still 2012, so far. Great course. Much appreciated

BijouBakson
Автор

I wish you with do more videos, i am sure time is an issue but your course are so good people will pay either on Udemy or elsewhere, you are gifted teacher. Please don't ever take down these videos form you tube.Thanks

NeerajLalu
Автор

great video, learned more in 15 minutes watching this video than my many hours of winging it on my own, lol, thanks, new sub here

ossito
Автор

This video is awesome, it is what i was looking for. Thank you keep uploading such informative videos.

ramkumargupta
Автор

Clear Concise and easy to follow amazing work guys!!

ISMR
Автор

Fantastic work sir... post more videos...

it will helping me more...

ESWARANM-Techguy
Автор

All the videos of itfreetraining are great! I would like to know the attributes that get affected when changes are made in computer object tabs..

annapoornashanmugam
Автор

Outstanding video... Cant get any better than this. Thanks

le
Автор

👍Think u ss much very good computers courses r good jab I attended Thanks 👍🌺

dilshadbegum
Автор

I read in another article, the client machine added to AD responsible for resetting the password. But, in your video you mentioned AD takes care of that. I am confused. Please clarify.

skrnytbe
Автор

Thx for video. Can you tell me how can I add for example Helpdesk group as default group that can jpin prestaded computer accounts to domain?

Ragrik
Автор

If you could provide us for L2 support interview question and answers on windows 2008 in all lessons, that would be gr8ful..

gourishmesta
Автор

Hello, these videos are amazing . could you please provide me the ppt for these videos ? I am preparing or MCSA certification.

riteshpatel
Автор

How would you configure AD to not automatically joined any computer to the domain without manually first creating a computer account entry in AD or Pre-staging?
Hope anyone can understand my question and answer it.. Thanks.

garylparas
Автор

very very Excellent video, I really appropriate u!!!

MrFazi
Автор

Hi, Could u tel me how to find who changed the password of the User Account and from which computer they did (IP / Name) ?

மோகன்குமார்-நண
Автор

What's the difference between an User Account and a Computer Account?

chaozkreator
Автор

I’ve tried this but I continue to get and error that tells me there’s no computer account for the workstation trust relationship in the security database. How do I fix this?

rrrussell
Автор

Hi,
Could you help here, suppose i have created an OU called windows 7 computers, and i want to move all windows 7 computers that are joining to domain automatically in this OU.
Is this possible by GPO?

Cyberxpertz