Figure A: The Active Directory Users and Computers interface allows managing individual domains
You can see that production.com is one of our network domains and there is no other domain listed in Figure A. That's because Active Directory Users and Computers only lists one domain at a time to keep the interface look neat. The domain is listed in the interface that corresponds to the domain controller that you are logged in to. For example, while writing this article, I logged into one of those domain controllers, production.com, so the Active Directory Users and Computers will connect to the production.com domain.
The problem is that these domains are often geographically dispersed. For example, large companies must have different domains for each company's office. If you're now in Miami, Florida and another part of the company presenting an office in Las Vegas, Nevada, it won't have to travel a great distance across the United States every time you need to manage a Las Vegas domain. .
Although the Active Directory Users and Computers default displays the domain associated with the domain controller that you are logged in to, it is still possible to use this interface to display any domain you have the right to manipulate. . All you need to do now is right-click the domain that is being displayed, then select the Connect to Domain command from the right-click menu. When you do so, there will be a screen displayed, which allows you to enter the domain name you want to connect to or click the Browse button and browse the domain.
When a domain is located far away, you can be very difficult to log in directly to the domain controller. For example, I worked in a number of offices in which domain controllers were placed in separate buildings or there were no favorable conditions for me to log in to the domain controller to perform security work. daily maintenance.
However, the good news is that there is no need to log in to the domain controller to access the Active Directory Users and Computers interface, just log in to the domain controller to access the Active Directory Users and Computers interface from Administrative Tools menu. You can access this interface as a member server by manually loading it into the Microsoft Management Console.
To do so, enter the MMC command into the server's RUN command window. When done, the server will open an empty Microsoft Management Console. Next, select the Add / Remove Snap-In command from the console's File menu. Windows will now open the Add / Remove Snap-In properties window. Click the Add button on the Standalone tab in the properties window, you will see a list of available snap-ins. Select the Active Directory Users and Computers option from the list of snap-ins and click Add , followed by Close and OK . The console will now be loaded.
In some cases, loading the interface in this way may cause an error. If you see an error and the interface does not allow domain management after right-clicking on Active Directory Users and Computers, select the Connect to Domain Controller command from the right-click menu. You can now connect the console to a domain controller without logging in to that domain controller. That way you will be able to manage the same domain as in the domain controller console.
The technique works if you have a server, but what if your workstation is using Windows Vista, and all servers are on the other side of the building.
One of the simplest solutions to solve this problem is to set up an RDP session for one of the servers. RDP is remote desktop protocol (Remote Desktop Protocol). This protocol will allow remote control of servers in your organization. In a Windows Server 2003 environment, you can enable a remote session by right-clicking My Computer and selecting the Properties command from the right-click menu. You will then see the system properties window. Go to the Remote tab and select the Enable Remote Desktop on this Computer checkbox (see Figure B).
Figure B: Configure a server to support remote desktop connections (Remote Desktop)
To connect to the server from a Windows Vista machine, select the Remote Desktop Connection command from the All Programs / Accessories menu. When done, you will see the screen appear as shown in Figure C. Now enter your server name and click the Connect button to set up a remote session.
Figure C: It is easier to connect to a remote server using Windows Vista
Conclude
In this article, I have explained about Active Directory Users and Computers. In it, we explained how to use this interface to manage remote domains. In Part 12, I will continue the discussion by showing you the other possibilities of this tool. Invite you to read.