Managing Terminal Services Using WMI
...................................
834
Remotely Managing a Terminal Session
....................................
835
Applying Service Packs and Updates
........................................
835
Performing Disaster Recovery on a Terminal Server
....................
835
Part VIII Desktop Administration
26 Windows Server Administration Tools for Desktops 839
Managing Desktops and Servers
......................................................
840
Operating System Deployment to Bare-Metal Systems
.................
840
Managing Updates and Applications
........................................
840
Supporting End Users and Remote Administration
.....................
841
Operating System Deployment Options
...........................................
841
Manual Installation Using Installation Media
............................
841
Unattended Installation
.........................................................
841
Manufacturer-Assisted Installation
...........................................
841
Cloning or Imaging Systems
...................................................
842
Windows Server 2008 Windows Deployment Services
.........................
843
WDS Image Types
.................................................................
844
Boot Images
.........................................................................
844
Installation Images
................................................................
844
Discover Images
...................................................................
844
Capture Images
....................................................................
844
Installing Windows Deployment Services (WDS)
................................
845
Configuring the WDS Server
...................................................
845
DHCP Configuration
.............................................................
848
Adding a Boot Image to the WDS Server
...................................
848
Adding Install Images to the WDS Server
..................................
850
Deploying the First Install Image
.............................................
850
Creating Discover Images
...............................................................
853
Creating Bootable Media with Discover Boot Images and the
Windows Automated Installation Kit
.....................................
854
Pre-creating Active Directory Computer Accounts for WDS
..........
856
Creating Custom Installations Using Capture Images
..........................
859
Customizing Install Images Using Unattended Answer Files
.........
861
Creating Multicast Images
......................................................
862
General Desktop Administration Tasks
.............................................
863
27 Group Policy Management for Network Clients 865
The Need for Group Policies
...........................................................
866
Windows Group Policies
................................................................
866
Windows Server 2008 Unleashed
xxx
Local Computer Policy
..........................................................
867
Local Security Policy
.............................................................
867
Local Administrators and Non-Administrators User Policies
.........
867
Domain Group Policies
..........................................................
868
Security Configuration Wizard
................................................
868
Policy Processing Overview
....................................................
868
Group Policy Feature Set
................................................................
870
Computer Configuration Policy Node
......................................
870
User Configuration Policy Node
..............................................
873
Planning Workgroup and Stand-Alone Local Group Policy
Configuration
............................................................................
874
Creating Local Administrators and Non-Administrators
Policies
.............................................................................
875
Planning Domain Group Policy Objects
...........................................
877
Policies and Preferences
.........................................................
878
Domain GPOs
......................................................................
880
Domain Controller GPOs
.......................................................
882
Active Directory Site GPOs
.....................................................
883
Small Business
......................................................................
883
Delegated Administration
......................................................
884
Managing Computers with Domain Policies
......................................
886
Creating a New Domain Group Policy Object
............................
887
Creating and Configuring GPO Links
.......................................
887
Managing User Account Control Settings
..................................
887
Creating a Software Restriction Policy
......................................
890
Deploying Printers
................................................................
892
Configuring Remote Desktop and Remote
Administration Support
.......................................................
897
Configuring Basic Firewall Settings with Group Policy
................
898
Configuring Windows Update Settings
.....................................
901
Creating a Wireless Policy
......................................................
902
Managing Users with Policies
.........................................................
905
Configuring Folder Redirection
...............................................
906
Removable Storage Access
......................................................
909
Managing Microsoft Management Console Access
......................
910
Managing Active Directory with Policies
..........................................
911
Fine-Grained Password Policies
...............................................
912
Configuring Restricted Groups for Domain Security Groups
.........
915
Extending Group Policy Functionality
......................................
919
Deploying Software Packages Using Domain
Group Policy Objects
...........................................................
921
Contents
xxxi
Synchronous Foreground Refresh
............................................
925
GPO Modeling and GPO Results in the GPMC
...........................
926
Managing Group Policy from Administrative or
Remote Workstations
..........................................................
929
Part IX Fault Tolerance Technologies
28 File System Management and Fault Tolerance 935
Windows Server 2008 File System Overview/Technologies
...................
935
Windows Volume and Partition Formats
...................................
936
NTFS-Formatted Partition Features
...........................................
936
File System Quotas
................................................................
936
Data Compression
................................................................
937
Data Encryption
...................................................................
937
File Screening
.......................................................................
937
Volume Shadow Copy Service (VSS)
.........................................
937
Remote Storage Service (RSS)
..................................................
938
Distributed File System (DFS)
..................................................
938
Distributed File System Replication (DFSR)
................................
939
File System Management Tools
...............................................
939
File System Monitoring and Reporting
.....................................
939
File System Access Services and Technologies
....................................
940
Windows Folder Sharing
........................................................
940
Distributed File System (DFS) Namespaces and Replication
..........
940
WWW Directory Publishing
...................................................
940
File Transfer Protocol Service
..................................................
940
Secure File Transfer Protocol (SFTP)
..........................................
941
Windows SharePoint Services (WSS)
.........................................
941
Services for NFS
....................................................................
941
Services for Macintosh
...........................................................
941
Windows Server 2008 Disks
............................................................
942
Master Boot Record Disks
.......................................................
942
GUID Partition Table (GPT) Disks
............................................
942
Basic Disk
............................................................................
942
Dynamic Disk
......................................................................
943
Partition or Volume
..............................................................
943
Mount Point
........................................................................
943
Simple Volumes
....................................................................
943
Spanned Volumes
.................................................................
944
Striped Volumes
...................................................................
944
Fault-Tolerant Volumes
..........................................................
944
Mirrored Volumes
.................................................................
944
RAID-5 Volumes
...................................................................
944
Windows Server 2008 Unleashed
xxxii
Utilizing External Disk Subsystems
..................................................
945
Hardware-Based Disk Arrays
...................................................
945
Boot from Storage Area Networks
............................................
945
Managing External Storage
.....................................................
945
External Storage Support Requirements
....................................
946
Managing Windows Server 2008 Disks
.............................................
946
The Disk Management MMC Snap-In
.......................................
946
Diskpart.exe Command-Line Utility
.........................................
946
Adding a New Disk to Windows
..............................................
946
Converting Basic Disks to Dynamic Disks
.................................
948
Creating Fault-Tolerant Volumes Using Disk Management
...........
948
Creating a Fault-Tolerant Volume Using Diskpart.exe
..................
950
System File Reliability
...................................................................
952
System File Stability
..............................................................
952
Adding the File Services Role
..........................................................
953
Managing Data Access Using Windows Server 2008 Shares
..................
955
Access-Based Enumeration
......................................................
956
Client-Side Caching and Offline Files
.......................................
956
Managing Folder Shares
.........................................................
957
Volume-Based NTFS Quota Management
..........................................
960
File Server Resource Manager (FSRM)
...............................................
961
Uses of File Server Resource Manager
.......................................
962
Installing the File Server Resource Manager Tools
.......................
963
FSRM Global Options
............................................................
964
Configuring Quotas with File Server Resource Manager
...............
964
Adjusting Quotas
..................................................................
965
Creating a Quota Template
.....................................................
966
Creating File Screens
.............................................................
967
Creating a File Screen Template
...............................................
968
File Screen Exceptions
...........................................................
969
Generating Storage Reports with FSRM
.....................................
970
Troubleshooting File System Services
........................................
971
The Distributed File System
............................................................
972
DFS Namespaces
...................................................................
972
DFS Replication
....................................................................
973
DFS Terminology
..................................................................
974
DFS Replication Terminology
..................................................
975
Planning a DFS Deployment
...........................................................
975
Configuring File Share and NTFS Permissions for
DFS Root and Folder Targets
.................................................
976
Choosing a DFS Type
............................................................
976
Planning for DFS Replication
..................................................
976
Determining the Replication Topology
.....................................
977
Contents
xxxiii
Installing DFS
..............................................................................
978
Creating the DFS Namespace and Root
.....................................
978
Adding an Additional Namespace Server to a Domain-Based
Namespace
........................................................................
980
Creating a DFS Folder and Replication Group
............................
981
Best Practices for DFS Replication
............................................
984
Managing and Troubleshooting DFS
................................................
984
Taking a Target Offline for Maintenance
...................................
985
Disabling Replication for Extended Downtime
...........................
986
Limiting Connections to Site DFS Targets
.................................
986
Backing Up DFS
...........................................................................
987
Using the Volume Shadow Copy Service
...........................................
987
Using VSS and Windows Server Backup
....................................
988
Configuring Shadow Copies
...................................................
988
Recovering Data Using Shadow Copies
.....................................
989
29 System-Level Fault Tolerance (Clustering/Network Load Balancing) 993
Building Fault-Tolerant Windows Server 2008 Systems
........................
994
Powering the Computer and Network Infrastructure
...................
994
Designing Fault-Tolerant IP Networks
.......................................
995
Designing Fault-Tolerant Server Disks
.......................................
996
Increasing Service and Application Availability
..........................
997
Windows Server 2008 Clustering Technologies
..................................
997
Windows Server 2008 Cluster Terminology
...............................
999
Determining the Correct Clustering Technology
..............................
1001
Failover Clusters
.................................................................
1002
Network Load Balancing
......................................................
1002
Overview of Failover Clusters
........................................................
1003
Failover Cluster Quorum Models
...........................................
1003
Choosing Applications for Failover Clusters
.............................
1004
Shared Storage for Failover Clusters
........................................
1005
Failover Cluster Node Operating System Selection
....................
1009
Deploying Failover Clusters
..........................................................
1009
Installing the Failover Clustering Feature
................................
1011
Running the Validate a Configuration Wizard
..........................
1011
Creating a Failover Cluster
....................................................
1013
Configuring Cluster Networks
...............................................
1015
Adding Nodes to the Cluster
.................................................
1016
Adding Storage to the Cluster
...............................................
1017
Cluster Quorum Configuration
..............................................
1018
Deploying Services or Applications on Failover Clusters
.............
1019
Configuring Failover and Failback
..........................................
1021
Windows Server 2008 Unleashed
xxxiv
Testing Failover Clusters
.......................................................
1022
Failover Cluster Maintenance
................................................
1026
Removing Nodes from a Failover Cluster
.................................
1027
Cluster Migration and Upgrades
............................................
1027
Backing Up and Restoring Failover Clusters
.....................................
1028
Failover Cluster Node—Backup Best Practices
...........................
1028
Restoring an Entire Cluster to a Previous State
.........................
1029
Deploying Network Load Balancing Clusters
...................................
1030
NLB Applications and Services
..............................................
1030
Installing the Network Load Balancing Feature
.........................
1031
Creating Port Rules
..............................................................
1031
Port Rules Filtering Mode and Affinity
....................................
1032
Using Cluster Operation Mode
..............................................
1033
Configuring Network Cards for NLB
.......................................
1033
Creating an NLB Cluster
.......................................................
1033
Adding Additional Nodes to an Existing NLB Cluster
................
1037
Managing NLB Clusters
...............................................................
1039
Backing Up and Restoring NLB Nodes
....................................
1039
Performing Maintenance on an NLB Cluster Node
....................
1039
30 Backing Up the Windows Server 2008 Environment 1043
Understanding Your Backup and Recovery Needs and Options
...........
1044
Identifying the Different Services and Technologies
..................
1044
Identifying Single Points of Failure
.........................................
1044
Evaluating Different Disaster Scenarios
...................................
1044
Prioritizing the Environment
................................................
1046
Identifying Bare Minimum Services
........................................
1046
Determining the Service-Level Agreement and
Return-to-Operation Requirements
.......................................
1047
Creating the Disaster Recovery Solution
.........................................
1048
Disaster Recovery Solution Overview Document
.......................
1048
Getting Disaster Recovery Solutions Approved
.........................
1049
Documenting the Enterprise
.........................................................
1049
Developing a Backup Strategy
.......................................................
1050
Assigning Tasks and Designating Team Members
......................
1050
Creating Regular Backup Procedures
.......................................
1051
Windows Server Backup Overview
.................................................
1051
Backup Storage Support and Media Management
.....................
1051
Backup Media Files
..............................................................
1053
Backup Options
..................................................................
1053
Windows Server Backup MMC Snap-In
...................................
1054
Windows Backup Command-Line Utility
................................
1054
Contents
xxxv
Using Windows Server Backup
......................................................
1054
Installing Windows Server Backup
.........................................
1054
Scheduling a Backup Using Windows Server
Backup and Allocating Disks
...............................................
1058
Running a Manual Backup to a Remote Server Share
.................
1060
Storing a Backup on DVD
.....................................................
1062
Managing Backups Using the Command-Line Utility wbadmin.exe
.....
1063
Viewing Backup History
.......................................................
1064
Running a Manual Backup to Remote Storage Using
wbadmin.exe
....................................................................
1064
Backing Up Windows Server 2008 Role Services
...............................
1064
Backing Up the System State
.................................................
1065
Backing Up Active Directory
.................................................
1066
Certificate Services
..............................................................
1068
Domain Name Service
.........................................................
1069
Windows Internet Naming Service
.........................................
1070
Dynamic Host Configuration Protocol
....................................
1070
Distributed File System
........................................................
1071
Internet Information Services
................................................
1071
Windows SharePoint Services
................................................
1071
Volume Shadow Copy Service (VSS)
...............................................
1073
Enabling Shadow Copies for Shared Volumes
...........................
1074
Windows Server 2008 Startup Options
............................................
1075
Emergency Management Services Console Redirection
..............
1075
31 Recovering from a Disaster 1077
Ongoing Backup and Recovery Preparedness
...................................
1077
Project Management Office (PMO)
.........................................
1078
Change Control
..................................................................
1079
Disaster Recovery Delegation of Responsibilities
.......................
1080
Achieving 99.999% Uptime Using Windows Server 2008
...........
1081
When Disasters Strike
..................................................................
1081
Qualifying the Disaster or Failure
...........................................
1081
Validating Priorities
.............................................................
1082
Assume and Be Doomed
.......................................................
1082
Synchronizing with Business Owners
.....................................
1082
Communicating with Vendors and Staff
.................................
1082
Assigning Tasks and Scheduling Resources
...............................
1083
Keeping the Troops Happy
....................................................
1083
Recovering the Infrastructure
................................................
1083
Postmortem Meeting
...........................................................
1083
Windows Server 2008 Unleashed
xxxvi
Disaster Scenario Troubleshooting
.................................................
1084
Network Outage
..................................................................
1084
Physical Site Failure
.............................................................
1084
Server or System Failure
.......................................................
1085
Recovering from a Server or System Failure
.....................................
1087
Access Issues
......................................................................
1087
Data Corruption and File and Folder Recovery
.........................
1092
Managing and Accessing Windows Server Backup Media
...................
1095
Windows Server Backup Managed Disks
..................................
1095
DVD Media
........................................................................
1095
Windows Server Backup Volume Recovery
......................................
1096
Windows Server 2008 Data Volume Recovery
..........................
1096
Windows Server 2008 System Volume Recovery
.......................
1097
Windows Complete PC Restore
.............................................
1099
Complete PC Restore to Alternate Hardware
............................
1099
Recovering Role Services and Features
............................................
1099
Windows Server 2008 System State Recovery
...........................
1100
System State Recovery for Domain Controllers
.........................
1101
DHCP
...............................................................................
1104
Windows SharePoint Services
................................................
1104
Part X Optimizing, Tuning, Debugging, and Problem Solving
32 Optimizing Windows Server 2008 for Branch Office Communications 1111
Understanding Read-Only Domain Controllers (RODCs)
...................
1112
Organizations’ Branch Office Concerns and Dilemmas
..............
1113
Understanding When to Leverage RODCs
...............................
1114
Installing a Read-Only Domain Controller
......................................
1116
Examining Prerequisite Tasks When Deploying an RODC
..........
1117
Limitations Associated with Windows Server 2008 RODCs
.........
1117
Conducting a RODC Installation
...........................................
1118
Performing a Staged RODC Installation
..................................
1125
Understanding BitLocker Drive Encryption
.....................................
1129
Examining BitLocker’s Drive Encryption Components and
Windows Server 2008 Enhancements
...................................
1130
Comprehending BitLocker’s Drive Encryption
Hardware Requirements
.....................................................
1131
Understanding BitLocker Deployment Scenarios
.......................
1131
Configuring BitLocker Drive Encryption on a
Windows Server 2008 Branch Office Domain Controller
..................
1131
Configuring the System Partitions for BitLocker
.......................
1132
Installing BitLocker Drive Encryption
.....................................
1133
Contents
xxxvii