{"id":66875,"date":"2026-01-27T19:33:46","date_gmt":"2026-01-27T11:33:46","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/66875.html"},"modified":"2026-01-27T19:33:46","modified_gmt":"2026-01-27T11:33:46","slug":"windows-server-%e5%9f%9f%e5%b1%82%e7%ba%a7%e7%ae%a1%e7%90%86%ef%bc%9a%e5%9f%9f%e3%80%81%e5%9f%9f%e6%a0%91%e3%80%81%e5%9f%9f%e6%a3%ae%e6%9e%97%e6%a6%82%e5%bf%b5%e5%8f%8a%e5%9f%9f%e6%9c%8d%e5%8a%a1","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/66875.html","title":{"rendered":"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e"},"content":{"rendered":"<p>\u6ce8&#xff1a;\u672c\u6587\u4e3a \u201cWindows Server | \u57df\u201d \u76f8\u5173\u5408\u8f91\u3002 \u82f1\u6587\u5f15\u6587&#xff0c;\u673a\u7ffb\u672a\u6821\u3002 \u4e2d\u6587\u5f15\u6587&#xff0c;\u7565\u4f5c\u91cd\u6392\u3002&#xff08;\u90e8\u5206\u8d44\u6599\u6709\u70b9\u9648\u65e7&#xff09; \u672a\u6574\u7406\u53bb\u91cd&#xff0c;\u56fe\u7247\u6e05\u6670\u5ea6\u53d7\u5f15\u6587\u539f\u56fe\u6240\u9650\u3002 \u5982\u6709\u5185\u5bb9\u5f02\u5e38&#xff0c;\u8bf7\u770b\u539f\u6587\u3002<\/p>\n<hr \/>\n<h2>THE DOMAIN, THE TREE AND THE FOREST<\/h2>\n<h2>\u57df\u3001\u57df\u6811\u4e0e\u57df\u6797<\/h2>\n<p>Domains, Trees and Forests, what now? I thought we were talking about donkeys and blueprints. \u57df\u3001\u57df\u6811\u3001\u57df\u6797&#xff0c;\u7a81\u7136\u8bb2\u8fd9\u4e9b\u662f\u4e3a\u4ec0\u4e48&#xff1f;\u6211\u8bb0\u5f97\u6211\u4eec\u4e4b\u524d\u804a\u7684\u53ef\u4e0d\u662f\u8fd9\u4e9b\u65e0\u5173\u7684\u5185\u5bb9\u3002<\/p>\n<p>Bear with me here, it might not fit into our last theme, but since this is the actual real terminology used by Microsoft, I\u2019d like to stick by them. \u8bf7\u8010\u5fc3\u542c\u6211\u8bb2\u89e3&#xff0c;\u8fd9\u4e00\u5185\u5bb9\u6216\u8bb8\u548c\u6211\u4eec\u4e0a\u4e00\u4e2a\u4e3b\u9898\u65e0\u5173&#xff0c;\u4f46\u8fd9\u4e9b\u662f\u5fae\u8f6f\u5b9e\u9645\u4f7f\u7528\u7684\u5b98\u65b9\u672f\u8bed&#xff0c;\u6211\u5e0c\u671b\u6cbf\u7528\u8fd9\u4e9b\u8868\u8ff0\u3002<\/p>\n<p>The Domain is basically the overall group that contains ALL the objects stored in the Active Directory database. A Domain can be hosted on 1 or multiple Domain Controllers (that thing we created previously). When using multiple Domain Controllers within 1 domain the changes to the Active Directory Database (NTDS) are replicated between all Domain Controllers. \u57df\u672c\u8d28\u4e0a\u662f\u4e00\u4e2a\u6574\u4f53\u7684\u7ec4&#xff0c;\u5305\u542b\u5b58\u50a8\u5728 Active Directory \u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u5bf9\u8c61\u3002\u4e00\u4e2a\u57df\u53ef\u4ee5\u90e8\u7f72\u5728 1 \u53f0\u6216\u591a\u53f0\u57df\u63a7\u5236\u5668\u4e0a&#xff08;\u5c31\u662f\u6211\u4eec\u4e4b\u524d\u521b\u5efa\u7684\u670d\u52a1\u7aef&#xff09;\u3002\u5f53\u5728 1 \u4e2a\u57df\u4e2d\u90e8\u7f72\u591a\u53f0\u57df\u63a7\u5236\u5668\u65f6&#xff0c;\u5bf9 Active Directory \u6570\u636e\u5e93&#xff08;NTDS&#xff09;\u6240\u505a\u7684\u6240\u6709\u66f4\u6539\u90fd\u4f1a\u5728\u6240\u6709\u57df\u63a7\u5236\u5668\u4e4b\u95f4\u8fdb\u884c\u590d\u5236\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113340-6978a29446b48.png\" alt=\"img\" width=\"100\" \/><\/p>\n<p>This is a singular domain \u8fd9\u662f\u4e00\u4e2a\u5355\u57df<\/p>\n<p>Regardless of how big your AD becomes or on how many locations in the world its located, when possible (the scalability\/limits are pretty huge.), and I can\u2019t stress this enough, you want to use a singular Domain since it simplifies AD management a ton. However this sadly isn\u2019t always possible due to support for other versions Active Directory servers (Functional Levels) or corporate shenanigans\/politics. \u65e0\u8bba\u4f60\u7684 AD \u89c4\u6a21\u53d8\u5f97\u591a\u5927&#xff0c;\u4e5f\u65e0\u8bba\u5176\u90e8\u7f72\u5728\u5168\u7403\u591a\u5c11\u4e2a\u5730\u70b9&#xff0c;\u5728\u6761\u4ef6\u5141\u8bb8\u7684\u60c5\u51b5\u4e0b&#xff08;AD \u7684\u53ef\u6269\u5c55\u6027\u548c\u4e0a\u9650\u6570\u503c\u90fd\u975e\u5e38\u9ad8&#xff09;&#xff0c;\u6211\u5fc5\u987b\u53cd\u590d\u5f3a\u8c03&#xff0c;\u5efa\u8bae\u4f7f\u7528\u5355\u57df\u67b6\u6784&#xff0c;\u56e0\u4e3a\u8fd9\u80fd\u6781\u5927\u7b80\u5316 AD \u7684\u7ba1\u7406\u5de5\u4f5c\u3002\u4f46\u9057\u61be\u7684\u662f&#xff0c;\u7531\u4e8e\u9700\u8981\u517c\u5bb9\u5176\u4ed6\u7248\u672c\u7684 Active Directory \u670d\u52a1\u5668&#xff08;\u529f\u80fd\u7ea7\u522b&#xff09;&#xff0c;\u6216\u662f\u53d7\u4f01\u4e1a\u5185\u90e8\u7684\u5404\u7c7b\u8003\u91cf\u4e0e\u7ec4\u7ec7\u67b6\u6784\u5f71\u54cd&#xff0c;\u5355\u57df\u67b6\u6784\u5e76\u975e\u603b\u80fd\u5b9e\u73b0\u3002<\/p>\n<p>There\u2019s also this concept called a Enhanced Security Administrative Environment (ESAE), also known as a Red Forest which Microsoft released after NotPetya hit the world. If implemented correctly this greatly reduces known attack vectors in AD, but its way too complicated to cover during this stage of the guide. \u8fd8\u6709\u4e00\u4e2a\u6982\u5ff5\u540d\u4e3a\u589e\u5f3a\u5b89\u5168\u7ba1\u7406\u73af\u5883&#xff08;ESAE&#xff09;&#xff0c;\u4e5f\u88ab\u79f0\u4f5c\u7ea2\u6797&#xff0c;\u662f\u5fae\u8f6f\u5728 NotPetya \u52d2\u7d22\u75c5\u6bd2\u5e2d\u5377\u5168\u7403\u540e\u63a8\u51fa\u7684\u67b6\u6784\u3002\u82e5\u914d\u7f6e\u5f97\u5f53&#xff0c;\u8be5\u67b6\u6784\u80fd\u5927\u5e45\u51cf\u5c11 AD \u4e2d\u5df2\u77e5\u7684\u653b\u51fb\u5411\u91cf&#xff0c;\u4f46\u5176\u5b9e\u73b0\u903b\u8f91\u8fc7\u4e8e\u590d\u6742&#xff0c;\u672c\u6307\u5357\u73b0\u9636\u6bb5\u6682\u4e0d\u5c55\u5f00\u8bb2\u89e3\u3002<\/p>\n<h4>Child Domain<\/h4>\n<h4>\u5b50\u57df<\/h4>\n<p>Let\u2019s say that \u2018Threepwood\u2019s Fine Leather Jackets and Pirate Paraphernalia\u2019 wants all the Office monkeys to work in their own Child Domain. Why would they want that? I have no idea. Let\u2019s just settle it under \u2018Corporate Shenanigans\u2019. This would look something like this. \u5047\u8bbe\u4e00\u5bb6\u540d\u4e3a\u201c\u601d\u91cc\u666e\u4f0d\u5fb7\u4f18\u8d28\u76ae\u5939\u514b\u4e0e\u6d77\u76d7\u7528\u54c1\u5e97\u201d\u7684\u4f01\u4e1a&#xff0c;\u5e0c\u671b\u6240\u6709\u529e\u516c\u4eba\u5458\u90fd\u5728\u72ec\u7acb\u7684\u5b50\u57df\u4e2d\u5f00\u5c55\u5de5\u4f5c\u3002\u81f3\u4e8e\u4f01\u4e1a\u4e3a\u4f55\u4f1a\u6709\u8fd9\u6837\u7684\u9700\u6c42&#xff0c;\u6211\u4eec\u65e0\u4ece\u5f97\u77e5&#xff0c;\u59d1\u4e14\u5c06\u5176\u5f52\u4e3a\u201c\u4f01\u4e1a\u5185\u90e8\u7684\u7279\u6b8a\u8003\u91cf\u201d\u3002\u8be5\u67b6\u6784\u7684\u5448\u73b0\u5f62\u5f0f\u5982\u4e0b\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113340-6978a29474b1a.png\" alt=\"img\" width=\"300\" \/><\/p>\n<p>This is a Root Domain with a Child Domain \u8fd9\u662f\u4e00\u4e2a\u5305\u542b\u5b50\u57df\u7684\u6839\u57df<\/p>\n<h4>Tree<\/h4>\n<h4>\u57df\u6811<\/h4>\n<p>When you have a child domain within the same Root Domain it is referred to \u2018being in the same Tree\u2019. They are however still separate domains. Each Domain needs at least 1 separate Domain Controller. This means that each Domain in a Tree has its own Active Directory Database (NTDS) with its own objects such users, groups etc. \u5f53\u540c\u4e00\u6839\u57df\u4e0b\u5b58\u5728\u5b50\u57df\u65f6&#xff0c;\u8fd9\u4e9b\u57df\u88ab\u79f0\u4f5c\u201c\u5904\u4e8e\u540c\u4e00\u57df\u6811\u4e2d\u201d\u3002\u4f46\u5b83\u4eec\u4f9d\u65e7\u662f\u76f8\u4e92\u72ec\u7acb\u7684\u57df&#xff0c;\u6bcf\u4e2a\u57df\u90fd\u81f3\u5c11\u9700\u8981 1 \u53f0\u72ec\u7acb\u7684\u57df\u63a7\u5236\u5668\u3002\u8fd9\u610f\u5473\u7740&#xff0c;\u57df\u6811\u4e2d\u7684\u6bcf\u4e2a\u57df\u90fd\u62e5\u6709\u72ec\u7acb\u7684 Active Directory \u6570\u636e\u5e93&#xff08;NTDS&#xff09;&#xff0c;\u5e76\u5b58\u50a8\u7740\u4e13\u5c5e\u7684\u7528\u6237\u3001\u7ec4\u7b49\u5bf9\u8c61\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113340-6978a2948c1a3.png\" alt=\"img\" width=\"500\" \/><\/p>\n<p>This is what the Tree looks like. \u8fd9\u662f\u57df\u6811\u7684\u5448\u73b0\u5f62\u5f0f\u3002<\/p>\n<p>A tree can consist of multiple child domains, they can even be inherited from each other, but there can only be 1 Root Domain, this is also referred to as the Tree Root. The advantage of creating these child domains from the Tree Root is that there is a trust created between each of the domains. This means that users from monkeys child domain can access resources in the pirates child domain, if they would have the appropriate rights to that resource of course. \u4e00\u4e2a\u57df\u6811\u53ef\u4ee5\u5305\u542b\u591a\u4e2a\u5b50\u57df&#xff0c;\u8fd9\u4e9b\u5b50\u57df\u751a\u81f3\u53ef\u4ee5\u5c42\u5c42\u5d4c\u5957&#xff0c;\u4f46\u4e00\u4e2a\u57df\u6811\u4e2d\u53ea\u80fd\u6709 1 \u4e2a\u6839\u57df&#xff0c;\u8be5\u6839\u57df\u4e5f\u88ab\u79f0\u4f5c\u57df\u6811\u6839\u3002\u4ece\u57df\u6811\u6839\u521b\u5efa\u5b50\u57df\u7684\u4f18\u52bf\u5728\u4e8e&#xff0c;\u5404\u57df\u4e4b\u95f4\u4f1a\u81ea\u52a8\u5efa\u7acb\u4fe1\u4efb\u5173\u7cfb\u3002\u8fd9\u610f\u5473\u7740&#xff0c;monkeys\u5b50\u57df\u4e2d\u7684\u7528\u6237&#xff0c;\u82e5\u62e5\u6709\u76f8\u5e94\u7684\u8d44\u6e90\u8bbf\u95ee\u6743\u9650&#xff0c;\u5373\u53ef\u8bbf\u95eepirates\u5b50\u57df\u4e2d\u7684\u8d44\u6e90\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113340-6978a294a46a3.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>Domains can have multiple child domains, including child domains themselves \u57df\u53ef\u4ee5\u62e5\u6709\u591a\u4e2a\u5b50\u57df&#xff0c;\u5b50\u57df\u4e5f\u53ef\u518d\u5305\u542b\u4e0b\u7ea7\u5b50\u57df<\/p>\n<h4>Forest<\/h4>\n<h4>\u57df\u6797<\/h4>\n<p>Now let\u2019s say that over time the TFLJPP company grows and acquires another company, \u2018Wally B. Feed Cartography and Co\u2019. The acquired company already has an AD configured with their own Tree. You could migrate over all the users\/systems from this over to your Tree, but this can be a daunting and time-consuming task. So, what we can do is add their Tree to our Forest. Doing this adds a trust between these two tree\u2019s. This means that, like with child domains, access to resources can now be shared cross company. \u5047\u8bbe\u968f\u7740\u65f6\u95f4\u63a8\u79fb&#xff0c;TFLJPP \u516c\u53f8\u4e0d\u65ad\u53d1\u5c55&#xff0c;\u5e76\u6536\u8d2d\u4e86\u53e6\u4e00\u5bb6\u540d\u4e3a\u201c\u6c83\u5229 B \u9972\u6599\u5236\u56fe\u516c\u53f8\u201d\u7684\u4f01\u4e1a\u3002\u88ab\u6536\u8d2d\u7684\u4f01\u4e1a\u5df2\u914d\u7f6e\u597d AD&#xff0c;\u5e76\u62e5\u6709\u72ec\u7acb\u7684\u57df\u6811\u3002\u4f60\u53ef\u4ee5\u5c06\u8be5\u4f01\u4e1a\u6240\u6709\u7684\u7528\u6237\u548c\u7cfb\u7edf\u8fc1\u79fb\u81f3\u81ea\u8eab\u7684\u57df\u6811\u4e2d&#xff0c;\u4f46\u8fd9\u4e00\u64cd\u4f5c\u7e41\u7410\u4e14\u8017\u65f6\u3002\u56e0\u6b64&#xff0c;\u53e6\u4e00\u79cd\u65b9\u6848\u662f\u5c06\u5bf9\u65b9\u7684\u57df\u6811\u52a0\u5165\u81ea\u8eab\u7684\u57df\u6797\u4e2d&#xff0c;\u64cd\u4f5c\u540e\u4e24\u4e2a\u57df\u6811\u4e4b\u95f4\u4f1a\u5efa\u7acb\u4fe1\u4efb\u5173\u7cfb\u3002\u8fd9\u610f\u5473\u7740&#xff0c;\u548c\u5b50\u57df\u95f4\u7684\u8d44\u6e90\u8bbf\u95ee\u903b\u8f91\u4e00\u81f4&#xff0c;\u4e24\u5bb6\u4f01\u4e1a\u4e4b\u95f4\u4e5f\u53ef\u4ee5\u5b9e\u73b0\u8d44\u6e90\u5171\u4eab\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113340-6978a294d8cf9.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>This is what a Forest looks like with multiple Tree\u2019s \u8fd9\u662f\u5305\u542b\u591a\u4e2a\u57df\u6811\u7684\u57df\u6797\u5448\u73b0\u5f62\u5f0f\u3002<\/p>\n<p>There are actually other types of trusts, such as shortcut, forest, external and realm trusts. Each with different characteristics (Transitive vs. Non-Transitive), direction types (One-way or Two-way) and authentication mechanism (Kerberos <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         V <\/p>\n<p>         5 <\/p>\n<p>        V5 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6833em\"><\/span><span style=\"margin-right: 0.2222em\" class=\"mord mathnormal\">V<\/span><span class=\"mord\">5<\/span><\/span><\/span><\/span><\/span> or NTLM). I will not go into details here since if I were to cover it fully it would require a lot more of preexisting knowledge of AD internals such as NTLM and Kerberos, which are even heavy topics to cover on their own. Just remember that I generally recommend against multiple domains\/tree\u2019s\/forest and trusts due the added complexity and security risks, unless you truly understand what you are doing\/are building a Red Forest. \u5b9e\u9645\u4e0a&#xff0c;\u4fe1\u4efb\u5173\u7cfb\u8fd8\u6709\u5176\u4ed6\u7c7b\u578b&#xff0c;\u4f8b\u5982\u5feb\u6377\u4fe1\u4efb\u3001\u6797\u4fe1\u4efb\u3001\u5916\u90e8\u4fe1\u4efb\u548c\u9886\u57df\u4fe1\u4efb\u3002\u4e0d\u540c\u7c7b\u578b\u7684\u4fe1\u4efb\u5173\u7cfb\u5177\u5907\u4e0d\u540c\u7684\u7279\u6027&#xff08;\u53ef\u4f20\u9012\u4e0e\u4e0d\u53ef\u4f20\u9012&#xff09;\u3001\u65b9\u5411\u7c7b\u578b&#xff08;\u5355\u5411\u6216\u53cc\u5411&#xff09;\u548c\u8eab\u4efd\u9a8c\u8bc1\u673a\u5236&#xff08;Kerberos <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         V <\/p>\n<p>         5 <\/p>\n<p>        V5 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6833em\"><\/span><span style=\"margin-right: 0.2222em\" class=\"mord mathnormal\">V<\/span><span class=\"mord\">5<\/span><\/span><\/span><\/span><\/span> \u6216 NTLM&#xff09;\u3002\u8fd9\u91cc\u6682\u4e0d\u5c55\u5f00\u8bb2\u89e3&#xff0c;\u56e0\u4e3a\u8981\u5168\u9762\u4ecb\u7ecd\u8fd9\u4e9b\u5185\u5bb9&#xff0c;\u9700\u8981\u8bfb\u8005\u5177\u5907\u5927\u91cf AD \u5e95\u5c42\u7684\u524d\u7f6e\u77e5\u8bc6&#xff0c;\u800c NTLM \u548c Kerberos \u672c\u8eab\u5c31\u662f\u4e24\u4e2a\u5e9e\u5927\u7684\u77e5\u8bc6\u70b9\u3002\u53ea\u9700\u8bb0\u4f4f&#xff0c;\u6211\u901a\u5e38\u4e0d\u5efa\u8bae\u90e8\u7f72\u591a\u57df\u3001\u591a\u57df\u6811\u3001\u591a\u57df\u6797\u53ca\u590d\u6742\u7684\u4fe1\u4efb\u5173\u7cfb&#xff0c;\u56e0\u4e3a\u8fd9\u4f1a\u589e\u52a0\u67b6\u6784\u7684\u590d\u6742\u6027\u548c\u5b89\u5168\u98ce\u9669&#xff0c;\u9664\u975e\u4f60\u5bf9\u76f8\u5173\u64cd\u4f5c\u6709\u6e05\u6670\u7684\u8ba4\u77e5&#xff0c;\u6216\u662f\u6b63\u5728\u642d\u5efa\u7ea2\u6797\u67b6\u6784\u3002<\/p>\n<h4>What we currently build<\/h4>\n<h4>\u6211\u4eec\u5f53\u524d\u7684\u642d\u5efa\u5185\u5bb9<\/h4>\n<p>A forest can encompass multiple domains and trees into 1 structure but doesn\u2019t have to. We already created a Forest and a tree when we setup Active Directory. These are created automatically. \u57df\u6797\u53ef\u5c06\u591a\u4e2a\u57df\u548c\u57df\u6811\u6574\u5408\u4e3a 1 \u4e2a\u67b6\u6784&#xff0c;\u4f46\u5e76\u975e\u5fc5\u987b\u5982\u6b64\u3002\u6211\u4eec\u5728\u642d\u5efa Active Directory \u7684\u8fc7\u7a0b\u4e2d&#xff0c;\u5df2\u7ecf\u81ea\u52a8\u521b\u5efa\u4e86\u4e00\u4e2a\u57df\u6797\u548c\u4e00\u4e2a\u57df\u6811\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113341-6978a2951e349.png\" alt=\"img\" width=\"300\" \/><\/p>\n<p>This what a setup with a singular domain actually looks like. \u8fd9\u662f\u5355\u57df\u67b6\u6784\u7684\u5b9e\u9645\u642d\u5efa\u5448\u73b0\u5f62\u5f0f\u3002<\/p>\n<hr \/>\n<h2>Active Directory Forest \u2013 Trees and Domain and Sites<\/h2>\n<h2>Active Directory \u57df\u6797\u2014\u2014\u57df\u6811\u3001\u57df\u4e0e\u7ad9\u70b9<\/h2>\n<p>Posted on 11\/04\/2020 By Christian<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113341-6978a29543afa.png\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0 \" width=\"700\" \/><\/p>\n<p>In this article, we will discuss \u201cActive Directory Forest \u2013 Trees and Domain and Sites\u201d. Active Directory (AD) is a directory service developed by Microsoft for the Windows domain environment. AD forest is the top container in an Active Directory setup that contains domains, users, computers, and group policies. \u672c\u6587\u5c06\u8bb2\u89e3\u201cActive Directory \u57df\u6797\u2014\u2014\u57df\u6811\u3001\u57df\u4e0e\u7ad9\u70b9\u201d\u76f8\u5173\u5185\u5bb9\u3002Active Directory&#xff08;AD&#xff09;\u662f\u5fae\u8f6f\u4e3a Windows \u57df\u73af\u5883\u5f00\u53d1\u7684\u4e00\u6b3e\u76ee\u5f55\u670d\u52a1&#xff0c;\u57df\u6797\u662f Active Directory \u67b6\u6784\u4e2d\u7684\u9876\u7ea7\u5bb9\u5668&#xff0c;\u5176\u4e2d\u5305\u542b\u57df\u3001\u7528\u6237\u3001\u8ba1\u7b97\u673a\u548c\u7ec4\u7b56\u7565\u3002<\/p>\n<p>The Active Directory structure is built on the domain level. The framework that holds the objects can be viewed at different levels namely forest, domain trees, and domains. An Active Directory framework can have more than one domain, and the above tiers are referred to as a forest. Active Directory \u7684\u67b6\u6784\u4ee5\u57df\u4e3a\u57fa\u7840\u5c42\u7ea7\u6784\u5efa&#xff0c;\u5b58\u50a8\u5bf9\u8c61\u7684\u6846\u67b6\u53ef\u5206\u4e3a\u4e0d\u540c\u5c42\u7ea7&#xff0c;\u5373\u57df\u6797\u3001\u57df\u6811\u548c\u57df\u3002\u4e00\u4e2a Active Directory \u67b6\u6784\u4e2d\u53ef\u5305\u542b\u591a\u4e2a\u57df&#xff0c;\u8fd9\u4e9b\u5c42\u7ea7\u5171\u540c\u6784\u6210\u7684\u6574\u4f53\u88ab\u79f0\u4f5c\u57df\u6797\u3002<\/p>\n<p>Note: Under each domain, you can have as many trees as possible. Having an Active Directory environment of this nature can create autonomy and segregation of duty thereby increasing security and if not configured correctly. It can also lead to exploitation in the Active Directory environment. \u6ce8&#xff1a;\u6bcf\u4e2a\u57df\u4e0b\u53ef\u521b\u5efa\u591a\u4e2a\u57df\u6811\u3002\u6b64\u7c7b Active Directory \u73af\u5883\u80fd\u5b9e\u73b0\u6743\u9650\u81ea\u6cbb\u548c\u804c\u8d23\u5206\u79bb&#xff0c;\u8fdb\u800c\u63d0\u5347\u5b89\u5168\u6027&#xff1b;\u4f46\u5982\u679c\u914d\u7f6e\u4e0d\u5f53&#xff0c;\u4e5f\u4f1a\u6210\u4e3a Active Directory \u73af\u5883\u4e2d\u88ab\u653b\u51fb\u5229\u7528\u7684\u6f0f\u6d1e\u3002<\/p>\n<h3>Active Directory Structure<\/h3>\n<h3>Active Directory \u7684\u67b6\u6784<\/h3>\n<p>Within a deployment, objects are grouped into domains as shown in the below diagram. The objects for a single domain are stored in a single database (which can be replicated). Domains are identified by their DNS name structure, (namespace). \u5728\u5b9e\u9645\u90e8\u7f72\u4e2d&#xff0c;\u5bf9\u8c61\u4f1a\u6309\u57df\u8fdb\u884c\u5206\u7ec4&#xff0c;\u5982\u4e0b\u56fe\u6240\u793a\u3002\u5355\u4e2a\u57df\u7684\u6240\u6709\u5bf9\u8c61\u5b58\u50a8\u5728\u4e00\u4e2a\u72ec\u7acb\u7684\u6570\u636e\u5e93\u4e2d&#xff08;\u8be5\u6570\u636e\u5e93\u652f\u6301\u590d\u5236&#xff09;&#xff0c;\u57df\u901a\u8fc7\u81ea\u8eab\u7684 DNS \u540d\u79f0\u7ed3\u6784&#xff08;\u547d\u540d\u7a7a\u95f4&#xff09;\u8fdb\u884c\u6807\u8bc6\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113341-6978a2956ec6d.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>Active Directory Forest: A forest is a collection of trees that share a common global catalog, directory schema, logical structure, and directory configuration. The forest represents the security boundary within which users, computers, groups, and other objects are accessible. Active Directory \u57df\u6797&#xff1a;\u57df\u6797\u662f\u591a\u4e2a\u57df\u6811\u7684\u96c6\u5408&#xff0c;\u8fd9\u4e9b\u57df\u6811\u5171\u4eab\u7edf\u4e00\u7684\u5168\u5c40\u7f16\u5f55\u3001\u76ee\u5f55\u67b6\u6784\u3001\u903b\u8f91\u7ed3\u6784\u548c\u76ee\u5f55\u914d\u7f6e\u3002\u57df\u6797\u662f\u4e00\u4e2a\u5b89\u5168\u8fb9\u754c&#xff0c;\u8be5\u8fb9\u754c\u5185\u7684\u7528\u6237\u3001\u8ba1\u7b97\u673a\u3001\u7ec4\u548c\u5176\u4ed6\u5bf9\u8c61\u53ef\u5b9e\u73b0\u76f8\u4e92\u8bbf\u95ee\u3002<\/p>\n<p>A forest is a collection of one or more domains that may have one or more trees. What makes a forest unique is that it shares the same schema. The schema defines what and how Active Directory objects are stored. \u57df\u6797\u662f\u4e00\u4e2a\u6216\u591a\u4e2a\u57df\u7684\u96c6\u5408&#xff0c;\u5176\u4e2d\u53ef\u5305\u542b\u4e00\u4e2a\u6216\u591a\u4e2a\u57df\u6811\u3002\u57df\u6797\u7684\u72ec\u7279\u6027\u5728\u4e8e&#xff0c;\u6797\u5185\u6240\u6709\u57df\u5171\u4eab\u540c\u4e00\u76ee\u5f55\u67b6\u6784&#xff0c;\u8be5\u67b6\u6784\u5b9a\u4e49\u4e86 Active Directory \u5bf9\u8c61\u7684\u5b58\u50a8\u7c7b\u578b\u548c\u5b58\u50a8\u65b9\u5f0f\u3002<\/p>\n<p>A forest is a group of trees that do not share a contiguous namespace. \u57df\u6797\u662f\u7531\u591a\u4e2a\u4e0d\u5171\u4eab\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u7684\u57df\u6811\u7ec4\u6210\u7684\u96c6\u5408\u3002<\/p>\n<p>Active Directory Domain: A domain is defined as a logical group of network objects (computers, users, devices) that share the same Active Directory database. Active Directory \u57df&#xff1a;\u57df\u662f\u7f51\u7edc\u5bf9\u8c61&#xff08;\u8ba1\u7b97\u673a\u3001\u7528\u6237\u3001\u8bbe\u5907&#xff09;\u7684\u903b\u8f91\u5206\u7ec4&#xff0c;\u540c\u4e00\u57df\u4e2d\u7684\u6240\u6709\u5bf9\u8c61\u5171\u4eab\u540c\u4e00\u4e2a Active Directory \u6570\u636e\u5e93\u3002<\/p>\n<p>When you add a domain to an existing tree, the new domain is a child domain of an existing parent domain. \u5f53\u5411\u73b0\u6709\u57df\u6811\u4e2d\u6dfb\u52a0\u65b0\u57df\u65f6&#xff0c;\u8be5\u65b0\u57df\u5c06\u6210\u4e3a\u73b0\u6709\u7236\u57df\u7684\u5b50\u57df\u3002<\/p>\n<p>Active Directory Tree: A tree is a collection of one or more domains and domain trees in a contiguous namespace and is linked in a transitive trust hierarchy. When you have multiple domains in the same namespace (e.g., techdirect.local, zone.techdirect.local), they are considered to be in the same tree. The tree also supports multiple levels of domains. Active Directory \u57df\u6811&#xff1a;\u57df\u6811\u662f\u4e00\u4e2a\u6216\u591a\u4e2a\u57df\/\u5b50\u57df\u6811\u7684\u96c6\u5408&#xff0c;\u8fd9\u4e9b\u57df\u5171\u4eab\u8fde\u7eed\u7684\u547d\u540d\u7a7a\u95f4&#xff0c;\u5e76\u901a\u8fc7\u53ef\u4f20\u9012\u4fe1\u4efb\u5c42\u6b21\u7ed3\u6784\u76f8\u4e92\u5173\u8054\u3002\u5f53\u591a\u4e2a\u57df\u5904\u4e8e\u540c\u4e00\u547d\u540d\u7a7a\u95f4\u4e2d\u65f6&#xff08;\u4f8b\u5982techdirect.local\u3001zone.techdirect.local&#xff09;&#xff0c;\u8fd9\u4e9b\u57df\u88ab\u89c6\u4f5c\u5904\u4e8e\u540c\u4e00\u57df\u6811\u4e2d\u3002\u57df\u6811\u540c\u65f6\u652f\u6301\u591a\u5c42\u7ea7\u7684\u57df\u5d4c\u5957\u3002<\/p>\n<p>A tree is a hierarchical arrangement of Windows domains that share a contiguous namespace. \u57df\u6811\u662f\u5171\u4eab\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u7684 Windows \u57df\u7684\u5c42\u7ea7\u5316\u7ec4\u7ec7\u5f62\u5f0f\u3002<\/p>\n<h3>Some other information on AD Forest \u2013 Trees and Domain and Sites<\/h3>\n<h3>AD \u57df\u6797\u3001\u57df\u6811\u3001\u57df\u4e0e\u7ad9\u70b9\u7684\u5176\u4ed6\u76f8\u5173\u4fe1\u606f<\/h3>\n<p>Parent and child domains are automatically linked by the trust. Users in different domains can use these trusts to access resources in another domain assuming that they have access. \u7236\u57df\u548c\u5b50\u57df\u4e4b\u95f4\u4f1a\u81ea\u52a8\u5efa\u7acb\u4fe1\u4efb\u5173\u7cfb&#xff0c;\u4e0d\u540c\u57df\u4e2d\u7684\u7528\u6237&#xff0c;\u82e5\u62e5\u6709\u76f8\u5e94\u6743\u9650&#xff0c;\u53ef\u901a\u8fc7\u8be5\u4fe1\u4efb\u5173\u7cfb\u8bbf\u95ee\u5176\u4ed6\u57df\u4e2d\u7684\u8d44\u6e90\u3002<\/p>\n<p>Trees in the forest are linked together via a trust automatically. This ensures that any users in any domain in the forest can access any resource in the forest to which they have access. \u57df\u6797\u4e2d\u7684\u5404\u4e2a\u57df\u6811\u4e4b\u95f4\u4e5f\u4f1a\u81ea\u52a8\u5efa\u7acb\u4fe1\u4efb\u5173\u7cfb&#xff0c;\u8fd9\u786e\u4fdd\u4e86\u57df\u6797\u4e2d\u4efb\u610f\u57df\u7684\u7528\u6237&#xff0c;\u90fd\u80fd\u8bbf\u95ee\u6797\u5185\u6240\u6709\u62e5\u6709\u6743\u9650\u7684\u8d44\u6e90\u3002<\/p>\n<ul>\n<li>\n<p>Global Catalog In order for users to find resources in any domain in the forest (remember that each domain has a separate database). Domain Controllers can be made into Global Catalog Servers. A Global Catalog Server contains partial information about every object in the forest. Using this information, the user can conduct searches. \u5168\u5c40\u7f16\u5f55&#xff1a;\u4e3a\u4e86\u8ba9\u7528\u6237\u80fd\u67e5\u627e\u57df\u6797\u4e2d\u4efb\u610f\u57df\u7684\u8d44\u6e90&#xff08;\u9700\u6ce8\u610f\u6bcf\u4e2a\u57df\u90fd\u6709\u72ec\u7acb\u7684\u6570\u636e\u5e93&#xff09;&#xff0c;\u53ef\u5c06\u57df\u63a7\u5236\u5668\u914d\u7f6e\u4e3a\u5168\u5c40\u7f16\u5f55\u670d\u52a1\u5668\u3002\u5168\u5c40\u7f16\u5f55\u670d\u52a1\u5668\u5b58\u50a8\u7740\u57df\u6797\u4e2d\u6240\u6709\u5bf9\u8c61\u7684\u90e8\u5206\u5c5e\u6027\u4fe1\u606f&#xff0c;\u7528\u6237\u53ef\u901a\u8fc7\u8fd9\u4e9b\u4fe1\u606f\u5b9e\u73b0\u8de8\u57df\u8d44\u6e90\u68c0\u7d22\u3002<\/p>\n<\/li>\n<li>\n<p>Trust relationship: A logical relationship established between domains that allow pass-through authentication. Providing for users in a trusted domain to access resources in a trusting domain without having a user account in the trusting domain. \u4fe1\u4efb\u5173\u7cfb&#xff1a;\u57df\u4e4b\u95f4\u5efa\u7acb\u7684\u4e00\u79cd\u903b\u8f91\u5173\u7cfb&#xff0c;\u652f\u6301\u76f4\u901a\u5f0f\u8eab\u4efd\u9a8c\u8bc1\u3002\u53d7\u4fe1\u4efb\u57df\u4e2d\u7684\u7528\u6237&#xff0c;\u65e0\u9700\u5728\u4fe1\u4efb\u57df\u4e2d\u521b\u5efa\u8d26\u6237&#xff0c;\u5373\u53ef\u8bbf\u95ee\u4fe1\u4efb\u57df\u4e2d\u7684\u8d44\u6e90\u3002<\/p>\n<\/li>\n<li>\n<p>Organizational units (OU) are containers that hold other Active Directory objects like users, computers, printers, shared folders, and even other organizational Units. The advantage of OU is that it can be used to set security policies and delegate administrative control. \u7ec4\u7ec7\u5355\u5143&#xff08;OU&#xff09;&#xff1a;\u7528\u4e8e\u5b58\u50a8 Active Directory \u5bf9\u8c61\u7684\u5bb9\u5668&#xff0c;\u53ef\u5b58\u653e\u7528\u6237\u3001\u8ba1\u7b97\u673a\u3001\u6253\u5370\u673a\u3001\u5171\u4eab\u6587\u4ef6\u5939&#xff0c;\u751a\u81f3\u5176\u4ed6\u7ec4\u7ec7\u5355\u5143\u3002\u7ec4\u7ec7\u5355\u5143\u7684\u4f18\u52bf\u5728\u4e8e&#xff0c;\u53ef\u901a\u8fc7\u5176\u914d\u7f6e\u5b89\u5168\u7b56\u7565\u5e76\u59d4\u6d3e\u7ba1\u7406\u6743\u9650\u3002<\/p>\n<\/li>\n<\/ul>\n<h4>Reasons to Create Additional Domain<\/h4>\n<h4>\u521b\u5efa\u989d\u5916\u57df\u7684\u539f\u56e0<\/h4>\n<p>There will be many occasions in which you will need to create additional domains. Multiple domains are useful when you are dealing with \u5b9e\u9645\u90e8\u7f72\u4e2d&#xff0c;\u5b58\u5728\u591a\u79cd\u9700\u8981\u521b\u5efa\u989d\u5916\u57df\u7684\u573a\u666f&#xff0c;\u4ee5\u4e0b\u60c5\u51b5\u4e2d&#xff0c;\u591a\u57df\u67b6\u6784\u4f1a\u66f4\u5177\u5b9e\u7528\u6027&#xff1a;<\/p>\n<ul>\n<li>\n<p>Different password requirements between organizations \u4e0d\u540c\u7ec4\u7ec7\u5b58\u5728\u4e0d\u540c\u7684\u5bc6\u7801\u7b56\u7565\u8981\u6c42<\/p>\n<\/li>\n<li>\n<p>Large numbers of objects \u57df\u5185\u5bf9\u8c61\u6570\u91cf\u89c4\u6a21\u8fc7\u5927<\/p>\n<\/li>\n<li>\n<p>Different internet domain names \u62e5\u6709\u4e0d\u540c\u7684\u516c\u7f51\u57df\u540d<\/p>\n<\/li>\n<li>\n<p>Better control of replication, and \u66f4\u4fbf\u4e8e\u63a7\u5236\u590d\u5236\u6d41\u91cf<\/p>\n<\/li>\n<li>\n<p>Decentralized network administration \u5b9e\u73b0\u5206\u6563\u5f0f\u7684\u7f51\u7edc\u7ba1\u7406<\/p>\n<\/li>\n<\/ul>\n<p>In order for you to decide whether to create multiple domains and how to use them to the best effect. You need to have a clear understanding of the relationship between trees and forests, known as a trust relationship. \u82e5\u8981\u5224\u65ad\u662f\u5426\u9700\u8981\u521b\u5efa\u591a\u57df\u67b6\u6784&#xff0c;\u4ee5\u53ca\u5982\u4f55\u6700\u5927\u5316\u53d1\u6325\u591a\u57df\u67b6\u6784\u7684\u4f5c\u7528&#xff0c;\u4f60\u9700\u8981\u6e05\u6670\u7406\u89e3\u57df\u6811\u548c\u57df\u6797\u4e4b\u95f4\u7684\u4fe1\u4efb\u5173\u7cfb\u3002<\/p>\n<p>While forests, trees, and domains are all logical grouping of objects, the physical grouping of objects is made possible using a site. \u57df\u6797\u3001\u57df\u6811\u548c\u57df\u5747\u662f\u5bf9\u5bf9\u8c61\u7684\u903b\u8f91\u5206\u7ec4&#xff0c;\u800c\u7ad9\u70b9\u5219\u662f\u5bf9\u5bf9\u8c61\u7684\u7269\u7406\u5206\u7ec4\u3002<\/p>\n<p>A site group objects based on IP addresses. Hence it cannot span across different physical locations. For example, if there are various branches of your organization located at different places, each location can be identified using a site. \u7ad9\u70b9\u57fa\u4e8e IP \u5730\u5740\u5bf9\u5bf9\u8c61\u8fdb\u884c\u5206\u7ec4&#xff0c;\u56e0\u6b64\u4e00\u4e2a\u7ad9\u70b9\u65e0\u6cd5\u8de8\u591a\u4e2a\u7269\u7406\u4f4d\u7f6e\u3002\u4f8b\u5982&#xff0c;\u82e5\u4f01\u4e1a\u5728\u4e0d\u540c\u5730\u533a\u8bbe\u6709\u5206\u652f\u673a\u6784&#xff0c;\u6bcf\u4e2a\u5206\u652f\u673a\u6784\u53ef\u5355\u72ec\u914d\u7f6e\u4e3a\u4e00\u4e2a\u7ad9\u70b9\u3002<\/p>\n<p>A site is mainly used for replication and traffic control purposes. It is important to understand that sites and domains are not interrelated. A site can contain multiple domains and a single domain could span across multiple sites. \u7ad9\u70b9\u7684\u4e3b\u8981\u4f5c\u7528\u662f\u63a7\u5236\u590d\u5236\u884c\u4e3a\u548c\u7f51\u7edc\u6d41\u91cf\u3002\u9700\u8981\u660e\u786e\u7684\u662f&#xff0c;\u7ad9\u70b9\u548c\u57df\u4e4b\u95f4\u4e0d\u5b58\u5728\u5173\u8054\u5173\u7cfb&#xff0c;\u4e00\u4e2a\u7ad9\u70b9\u4e2d\u53ef\u5305\u542b\u591a\u4e2a\u57df&#xff0c;\u4e00\u4e2a\u57df\u4e5f\u53ef\u8de8\u591a\u4e2a\u7ad9\u70b9\u90e8\u7f72\u3002<\/p>\n<p>I hope you found this blog post on \u201cActive Directory Forest \u2013 Trees and Domain and Sites\u201d helpful. If you have any questions, please let me know in the comment section. \u5e0c\u671b\u8fd9\u7bc7\u5173\u4e8e\u201cActive Directory \u57df\u6797\u2014\u2014\u57df\u6811\u3001\u57df\u4e0e\u7ad9\u70b9\u201d\u7684\u535a\u6587\u80fd\u4e3a\u4f60\u63d0\u4f9b\u5e2e\u52a9\u3002\u82e5\u6709\u4efb\u4f55\u95ee\u9898&#xff0c;\u53ef\u5728\u8bc4\u8bba\u533a\u7559\u8a00\u3002<\/p>\n<hr \/>\n<h2>Install and configure Active Directory Domain Services on Windows Server<\/h2>\n<h2>Windows Server \u4e2d Active Directory \u57df\u670d\u52a1\u7684\u5b89\u88c5\u4e0e\u914d\u7f6e<\/h2>\n<p>Posted on 30\/11\/2021 By Imoh Etuk<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113342-6978a296c9335.png\" alt=\"ADDS-in-Windows-Server-2022\" width=\"700\" \/><\/p>\n<p>In this write-up, I will take you through the step-by-step guide on how to install and configure Active Directory Domain Services on Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span>. Before we delve into the hands-on session of this write-up, let\u2019s take a look at some of the amazing new features that Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> brings. A quick peep into when Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> was released as it that a preview program started in March <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2021 <\/p>\n<p>        2021 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2021<\/span><\/span><\/span><\/span><\/span>. \u672c\u6587\u5c06\u4e3a\u4f60\u9010\u6b65\u8bb2\u89e3 Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u4e2d Active Directory \u57df\u670d\u52a1&#xff08;AD DS&#xff09;\u7684\u5b89\u88c5\u548c\u914d\u7f6e\u65b9\u6cd5\u3002\u5728\u8fdb\u5165\u5b9e\u64cd\u73af\u8282\u524d&#xff0c;\u6211\u4eec\u5148\u4e86\u89e3\u4e00\u4e0b Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u5e26\u6765\u7684\u5168\u65b0\u7279\u6027&#xff0c;\u540c\u65f6\u7b80\u5355\u4ecb\u7ecd\u5176\u53d1\u5e03\u65f6\u95f4&#xff1a;\u8be5\u7cfb\u7edf\u7684\u9884\u89c8\u7248\u4e8e<span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2021 <\/p>\n<p>        2021 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2021<\/span><\/span><\/span><\/span><\/span>\u5e74 3 \u6708\u63a8\u51fa\u3002<\/p>\n<p>Note: The general availability of Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>          2022 <\/p>\n<p>         2022 <\/p>\n<p>     <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> was announced on 1 September <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>          2021 <\/p>\n<p>         2021 <\/p>\n<p>     <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2021<\/span><\/span><\/span><\/span><\/span>, with a launch event as part of the Windows Server Summit on 16 September. \u6ce8&#xff1a;Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>          2022 <\/p>\n<p>         2022 <\/p>\n<p>     <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u7684\u6b63\u5f0f\u7248\u4e8e<span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>          2021 <\/p>\n<p>         2021 <\/p>\n<p>     <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2021<\/span><\/span><\/span><\/span><\/span>\u5e74 9 \u6708 1 \u65e5\u5b98\u5ba3\u53d1\u5e03&#xff0c;\u5e76\u5728<span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>          2021 <\/p>\n<p>         2021 <\/p>\n<p>     <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2021<\/span><\/span><\/span><\/span><\/span>\u5e74 9 \u6708 16 \u65e5\u7684 Windows Server \u5cf0\u4f1a\u4e2d\u4e3e\u529e\u4e86\u53d1\u5e03\u6d3b\u52a8\u3002<\/p>\n<h3>Windows Server 2022 Security capabilities<\/h3>\n<h3>Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u7684\u5b89\u5168\u529f\u80fd<\/h3>\n<p>Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> is built on the strong foundation of Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2019 <\/p>\n<p>        2019 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2019<\/span><\/span><\/span><\/span><\/span> and brings new security capabilities to combine with other security capabilities in Windows Server across multiple areas to provide defense-in-depth protection against advanced threats. Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u57fa\u4e8e Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2019 <\/p>\n<p>        2019 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2019<\/span><\/span><\/span><\/span><\/span> \u7684\u6210\u719f\u67b6\u6784\u8fdb\u884c\u5f00\u53d1&#xff0c;\u65b0\u589e\u4e86\u591a\u9879\u5b89\u5168\u529f\u80fd&#xff0c;\u5e76\u4e0e Windows Server \u539f\u6709\u7684\u591a\u9886\u57df\u5b89\u5168\u529f\u80fd\u76f8\u7ed3\u5408&#xff0c;\u5b9e\u73b0\u5bf9\u9ad8\u7ea7\u5a01\u80c1\u7684\u7eb5\u6df1\u9632\u5fa1\u3002<\/p>\n<p>Advanced multi-layer security in Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> provides the comprehensive protection that servers need today. Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u7684\u9ad8\u7ea7\u591a\u5c42\u5b89\u5168\u67b6\u6784&#xff0c;\u80fd\u4e3a\u670d\u52a1\u5668\u63d0\u4f9b\u5f53\u4e0b\u6240\u9700\u7684\u5168\u65b9\u4f4d\u5b89\u5168\u9632\u62a4\u3002<\/p>\n<p>In addition, it brings many innovations on three key themes: security, Azure hybrid integration and management, and application platform. \u6b64\u5916&#xff0c;\u8be5\u7cfb\u7edf\u5728\u4e09\u5927\u6838\u5fc3\u65b9\u5411\u4e0a\u5b9e\u73b0\u4e86\u591a\u9879\u521b\u65b0&#xff1a;\u5b89\u5168\u3001Azure \u6df7\u5408\u96c6\u6210\u4e0e\u7ba1\u7406\u3001\u5e94\u7528\u5e73\u53f0\u3002<\/p>\n<p>Also, Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> Datacenter: Azure Edition helps you use the benefits of the cloud to keep your VMs up to date while minimizing downtime. \u540c\u65f6&#xff0c;Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u6570\u636e\u4e2d\u5fc3\u7248&#xff1a;Azure \u7248\u53ef\u5145\u5206\u53d1\u6325\u4e91\u670d\u52a1\u7684\u4f18\u52bf&#xff0c;\u5728\u6700\u5927\u9650\u5ea6\u51cf\u5c11\u505c\u673a\u65f6\u95f4\u7684\u524d\u63d0\u4e0b&#xff0c;\u5b9e\u73b0\u865a\u62df\u673a&#xff08;VM&#xff09;\u7684\u6301\u7eed\u66f4\u65b0\u3002<\/p>\n<h4>What is Active Directory Domain Services (ADDS)?<\/h4>\n<h4>\u4ec0\u4e48\u662f Active Directory \u57df\u670d\u52a1&#xff08;AD DS&#xff09;&#xff1f;<\/h4>\n<p>Active Directory Domain Services is a technology that allows us to build and centrally manage a scalable Microsoft Enterprise network. Looking at the overview of the lab session we\u2019re going to carry out in this post, we are going to do the following: Active Directory \u57df\u670d\u52a1\u662f\u4e00\u9879\u80fd\u5e2e\u52a9\u6211\u4eec\u642d\u5efa\u5e76\u96c6\u4e2d\u7ba1\u7406\u53ef\u6269\u5c55\u5fae\u8f6f\u4f01\u4e1a\u7f51\u7edc\u7684\u6280\u672f\u3002\u672c\u6587\u7684\u5b9e\u64cd\u5b9e\u9a8c\u5c06\u5305\u542b\u4ee5\u4e0b\u5185\u5bb9&#xff1a;<\/p>\n<li>\n<p>Installing a new instance of Active Directory \u5b89\u88c5\u5168\u65b0\u7684 Active Directory \u5b9e\u4f8b<\/p>\n<\/li>\n<li>\n<p>Adding and configuring a new forest which is the overall container for Active Directory Domain Services and all its subjects \u6dfb\u52a0\u5e76\u914d\u7f6e\u65b0\u7684\u57df\u6797&#xff0c;\u57df\u6797\u662f Active Directory \u57df\u670d\u52a1\u53ca\u5176\u6240\u6709\u76f8\u5173\u5bf9\u8c61\u7684\u9876\u7ea7\u5bb9\u5668<\/p>\n<\/li>\n<li>\n<p>We will create the first Domain in the Forest which is known as the Forest Root Domain. We will give a fully qualified domain name (FQDN). Here, I am going to use blog.techdirectarchive.com as domain.<\/p>\n<p>\u521b\u5efa\u57df\u6797\u4e2d\u7684\u7b2c\u4e00\u4e2a\u57df&#xff0c;\u5373 \u6797\u6839\u57df&#xff0c;\u5e76\u4e3a\u5176\u914d\u7f6e\u5b8c\u5168\u9650\u5b9a\u57df\u540d&#xff08;FQDN&#xff09;&#xff0c;\u672c\u6587\u4e2d\u5c06\u4f7f\u7528 blog.techdirectarchive.com \u4f5c\u4e3a\u6797\u6839\u57df\u7684\u57df\u540d<\/p>\n<\/li>\n<li>\n<p>We will install DNS because we must have the Microsoft Active Directory Integrate with the DNS Server. \u5b89\u88c5 DNS \u670d\u52a1&#xff0c;\u56e0\u4e3a Microsoft Active Directory \u5fc5\u987b\u4e0e DNS \u670d\u52a1\u5668\u96c6\u6210\u4f7f\u7528<\/p>\n<\/li>\n<p>After we have successfully installed and configured the Active Directory Domain Name Services, the Server will become a Domain Controller which is popularly codenamed DC. \u6210\u529f\u5b89\u88c5\u5e76\u914d\u7f6e Active Directory \u57df\u670d\u52a1\u540e&#xff0c;\u8be5\u670d\u52a1\u5668\u5c06\u6210\u4e3a\u57df\u63a7\u5236\u5668&#xff08;\u5e38\u7b80\u79f0\u4e3a DC&#xff09;\u3002<\/p>\n<h5>Download Windows 2022<\/h5>\n<h5>\u4e0b\u8f7d Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span><\/h5>\n<p>All you need to get started with me in the demo session is a copy of Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> installed on your PC. To download the ISO file under the evaluation copy click here. Don\u2019t forget you can also try a copy of it directly on Azure (see screenshot below). \u8981\u8ddf\u968f\u672c\u6587\u5b8c\u6210\u5b9e\u64cd\u6f14\u793a&#xff0c;\u4f60\u9700\u8981\u5728\u7535\u8111\u4e0a\u5b89\u88c5 Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span>&#xff0c;\u53ef\u70b9\u51fb\u6b64\u5904\u4e0b\u8f7d\u8bc4\u4f30\u7248\u7684 ISO \u955c\u50cf\u6587\u4ef6\u3002\u6b64\u5916&#xff0c;\u4f60\u4e5f\u53ef\u4ee5\u76f4\u63a5\u5728 Azure \u4e91\u5e73\u53f0\u4e2d\u4f53\u9a8c\u8be5\u7cfb\u7edf&#xff08;\u89c1\u4e0b\u65b9\u622a\u56fe&#xff09;\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113343-6978a2971d287.png\" alt=\"Evaluation-copy-of-Windows-Server-2022\" width=\"700\" \/> Windows Server 2022 Evaluation Copy<\/p>\n<p>You can also install a copy of the Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> via Oracle VirtualBox or VMWare. \u4f60\u4e5f\u53ef\u4ee5\u901a\u8fc7 Oracle VirtualBox \u6216 VMWare \u865a\u62df\u673a\u5b89\u88c5 Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span>\u3002<\/p>\n<p>In case you run into the failed to open session error while trying to launch your VM Image on VirtualBox, \u82e5\u4f60\u5728 VirtualBox \u4e2d\u542f\u52a8\u865a\u62df\u673a\u955c\u50cf\u65f6\u9047\u5230\u201c\u6253\u5f00\u4f1a\u8bdd\u5931\u8d25\u201d\u7684\u9519\u8bef&#xff0c;\u53ef\u53c2\u8003\u76f8\u5173\u89e3\u51b3\u65b9\u6848\u3002<\/p>\n<h4>How to install and configure Active Directory Domain Services on Windows Server 2022<\/h4>\n<h4>Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u4e2d Active Directory \u57df\u670d\u52a1\u7684\u5b89\u88c5\u4e0e\u914d\u7f6e\u6b65\u9aa4<\/h4>\n<p>As confirmed by the screenshot below, we have our Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> set up completely on our PC. \u5982\u4e0b\u56fe\u6240\u793a&#xff0c;\u6211\u4eec\u5df2\u5728\u7535\u8111\u4e0a\u5b8c\u6210 Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2022 <\/p>\n<p>        2022 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2022<\/span><\/span><\/span><\/span><\/span> \u7684\u57fa\u7840\u5b89\u88c5\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113343-6978a2973dc76.jpg\" alt=\"Server-2022-Screen\" width=\"700\" \/><\/p>\n<p>Windows Server 2022<\/p>\n<p>Now let\u2019s take the following steps to have the Active Directory Domain Services (ADDS) installed. \u63a5\u4e0b\u6765&#xff0c;\u6211\u4eec\u6309\u4ee5\u4e0b\u6b65\u9aa4\u5b89\u88c5 Active Directory \u57df\u670d\u52a1&#xff08;AD DS&#xff09;\u3002<\/p>\n<p>Step 1. Open Server Manager \u2013 To open the server manager, hit the Windows key on your keyboard and type \u201cServer Manager\u201d to search for the application. Once it is open as illustrated by the figure below, we would proceed to the next step of installing Active Directory Domain Services. \u6b65\u9aa4 1 \u6253\u5f00\u670d\u52a1\u5668\u7ba1\u7406\u5668\u2014\u2014\u6309\u4e0b\u952e\u76d8\u4e0a\u7684Windows\u952e&#xff0c;\u8f93\u5165\u201cServer Manager\u201d\u641c\u7d22\u8be5\u7a0b\u5e8f\u3002\u6253\u5f00\u670d\u52a1\u5668\u7ba1\u7406\u5668\u540e&#xff08;\u5982\u4e0b\u56fe\u6240\u793a&#xff09;&#xff0c;\u5373\u53ef\u8fdb\u5165 Active Directory \u57df\u670d\u52a1\u7684\u4e0b\u4e00\u6b65\u5b89\u88c5\u6d41\u7a0b\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113343-6978a29765bda.png\" alt=\"Windows-Server-2022-Installed\" width=\"700\" \/> Server Manager \u670d\u52a1\u5668\u7ba1\u7406\u5668<\/p>\n<h5>Step 2: Add Roles and Features<\/h5>\n<h5>\u6b65\u9aa4 2&#xff1a;\u6dfb\u52a0\u89d2\u8272\u548c\u529f\u80fd<\/h5>\n<p>Right-click on \u201cManage\u201d on the \u201cServer Manager\u201d window and choose \u201cAdd Roles and Features\u201c. This will open the \u201cAdd Roles and Features Wizard\u201d which ushers us to the part where we install Active Directory Domain Services. Click on next. \u5728\u201c\u670d\u52a1\u5668\u7ba1\u7406\u5668\u201d\u7a97\u53e3\u4e2d&#xff0c;\u53f3\u952e\u70b9\u51fb\u201c\u7ba1\u7406\u201d\u9009\u9879&#xff0c;\u9009\u62e9\u201c\u6dfb\u52a0\u89d2\u8272\u548c\u529f\u80fd\u201d&#xff0c;\u6b64\u65f6\u4f1a\u5f39\u51fa\u201c\u6dfb\u52a0\u89d2\u8272\u548c\u529f\u80fd\u5411\u5bfc\u201d\u7a97\u53e3&#xff0c;\u8be5\u5411\u5bfc\u5c06\u5f15\u5bfc\u6211\u4eec\u5b8c\u6210 Active Directory \u57df\u670d\u52a1\u7684\u5b89\u88c5&#xff0c;\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113343-6978a297b65d0.jpg\" alt=\"Add-Roles-and-Features\" width=\"700\" \/><\/p>\n<p>Add Roles and Features \u6dfb\u52a0\u89d2\u8272\u548c\u529f\u80fd<\/p>\n<p>On the Before you begin page, click on next. \u5728\u201c\u5f00\u59cb\u4e4b\u524d\u201d\u9875\u9762&#xff0c;\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113343-6978a297e9706.jpg\" alt=\"Click-Next-to-Add-Roles-and-Features1\" width=\"700\" \/> Click Next to Add Roles and Features \u70b9\u51fb\u4e0b\u4e00\u6b65\u7ee7\u7eed\u6dfb\u52a0\u89d2\u8272\u548c\u529f\u80fd<\/p>\n<h5>Step 3: Installation Type<\/h5>\n<h5>\u6b65\u9aa4 3&#xff1a;\u9009\u62e9\u5b89\u88c5\u7c7b\u578b<\/h5>\n<p>On the \u201cInstallation Type\u201d, leave \u201cRole-based or feature-based installation\u201d radio button selected and click on next (see screenshot below). \u5728\u201c\u5b89\u88c5\u7c7b\u578b\u201d\u9875\u9762&#xff0c;\u4fdd\u6301\u201c\u57fa\u4e8e\u89d2\u8272\u6216\u57fa\u4e8e\u529f\u80fd\u7684\u5b89\u88c5\u201d\u5355\u9009\u6309\u94ae\u7684\u9009\u4e2d\u72b6\u6001&#xff0c;\u70b9\u51fb\u4e0b\u4e00\u6b65&#xff08;\u89c1\u4e0b\u56fe&#xff09;\u3002<\/p>\n<p>[<img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113344-6978a29828389.png\" alt=\"Installation-type-Role-Based\" width=\"700\" \/><\/p>\n<p>Select Role-Based Installation type \u9009\u62e9\u57fa\u4e8e\u89d2\u8272\u7684\u5b89\u88c5\u7c7b\u578b<\/p>\n<h5>Step 4: Server Selection<\/h5>\n<h5>\u6b65\u9aa4 4&#xff1a;\u9009\u62e9\u76ee\u6807\u670d\u52a1\u5668<\/h5>\n<p>On this interface titled \u201cSelect destination server\u201c, select the server you are to install AD DS and click next. I am going to choose my local server. \u5728\u201c\u9009\u62e9\u76ee\u6807\u670d\u52a1\u5668\u201d\u9875\u9762&#xff0c;\u9009\u62e9\u8981\u5b89\u88c5 AD DS \u7684\u670d\u52a1\u5668&#xff0c;\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002\u672c\u6587\u4e2d\u5c06\u9009\u62e9\u672c\u5730\u670d\u52a1\u5668\u4f5c\u4e3a\u76ee\u6807\u670d\u52a1\u5668\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113344-6978a298579cd.jpg\" alt=\"Server-Selection2\" width=\"700\" \/><\/p>\n<p>Server Selection<\/p>\n<h5>Step 5: Server Roles<\/h5>\n<h5>\u6b65\u9aa4 5&#xff1a;\u9009\u62e9\u670d\u52a1\u5668\u89d2\u8272<\/h5>\n<p>The previous step will lead you to the next page as shown below. Here, you will see many options with square checklist box beside them. As you can see, we are choosing \u201cActive Directory Domain Services\u201c. \u5b8c\u6210\u4e0a\u4e00\u6b65\u540e&#xff0c;\u8fdb\u5165\u5982\u4e0b\u6240\u793a\u7684\u9875\u9762&#xff0c;\u8be5\u9875\u9762\u5305\u542b\u591a\u4e2a\u5e26\u590d\u9009\u6846\u7684\u9009\u9879&#xff0c;\u6211\u4eec\u9700\u8981\u52fe\u9009\u201cActive Directory \u57df\u670d\u52a1\u201d\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113344-6978a2988ceab.png\" alt=\"Server-Roles\" width=\"700\" \/><\/p>\n<p>Server Roles \u9009\u62e9\u670d\u52a1\u5668\u89d2\u8272<\/p>\n<h5>Step 6: Add Features<\/h5>\n<h5>\u6b65\u9aa4 6&#xff1a;\u6dfb\u52a0\u529f\u80fd<\/h5>\n<p>Immediately you choose that option, a new part pops up. On the page, just click on \u201cAdd Features\u201d tab and hit \u201cNext\u201c. \u52fe\u9009\u201cActive Directory \u57df\u670d\u52a1\u201d\u540e&#xff0c;\u4f1a\u5f39\u51fa\u529f\u80fd\u6dfb\u52a0\u63d0\u793a\u6846&#xff0c;\u70b9\u51fb\u6846\u4e2d\u7684\u201c\u6dfb\u52a0\u529f\u80fd\u201d\u6309\u94ae&#xff0c;\u518d\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113344-6978a298c5eae.jpg\" alt=\"Add-AD-DS-Roles\" width=\"700\" \/><\/p>\n<p>Add AD DS Features \u6dfb\u52a0 AD DS \u76f8\u5173\u529f\u80fd<\/p>\n<h5>Step 7: Select Features<\/h5>\n<h5>\u6b65\u9aa4 7&#xff1a;\u9009\u62e9\u529f\u80fd<\/h5>\n<p>On the next page after Step 6 titled \u201cSelect features\u201c, just hit \u201cNext\u201d to lead you to installations of AD DS. \u5b8c\u6210\u6b65\u9aa4 6 \u540e&#xff0c;\u8fdb\u5165\u201c\u9009\u62e9\u529f\u80fd\u201d\u9875\u9762&#xff0c;\u76f4\u63a5\u70b9\u51fb\u4e0b\u4e00\u6b65&#xff0c;\u8fdb\u5165 AD DS \u7684\u5b89\u88c5\u786e\u8ba4\u73af\u8282\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113344-6978a298e9883.jpg\" alt=\"Select-AD-DS-Features1\" width=\"700\" \/><\/p>\n<p>Select the Features \u9009\u62e9\u529f\u80fd<\/p>\n<h5>Step 8: AD DS<\/h5>\n<h5>\u6b65\u9aa4 8&#xff1a;AD DS \u5b89\u88c5\u8bf4\u660e<\/h5>\n<p>As shown below, you will be presented with the next page titled \u201cActive Directory Domain Services\u201c. Here, click on \u201cNext\u201c \u8fdb\u5165\u5982\u4e0b\u6240\u793a\u7684\u201cActive Directory \u57df\u670d\u52a1\u201d\u8bf4\u660e\u9875\u9762&#xff0c;\u76f4\u63a5\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113345-6978a29926e2d.jpg\" alt=\"AD-DS-Installation-Window1\" width=\"700\" \/><\/p>\n<p>AD DS Installation Window AD DS \u5b89\u88c5\u8bf4\u660e\u9875\u9762<\/p>\n<h5>Step 9: Confirm your selections<\/h5>\n<h5>\u6b65\u9aa4 9&#xff1a;\u786e\u8ba4\u5b89\u88c5\u9009\u62e9<\/h5>\n<p>The next page is about Confirming that you want to install AD DS before actually installing it. Here, if you are sure about the installation, click on install. \u8fdb\u5165\u201c\u786e\u8ba4\u5b89\u88c5\u9009\u62e9\u201d\u9875\u9762&#xff0c;\u8be5\u9875\u9762\u7528\u4e8e\u5728\u6b63\u5f0f\u5b89\u88c5\u524d\u786e\u8ba4\u6240\u6709\u914d\u7f6e&#xff0c;\u786e\u8ba4\u65e0\u8bef\u540e\u70b9\u51fb\u5b89\u88c5\u3002<\/p>\n<p>You can optionally choose the option that restarts the server whenever required which we are not choosing it in our own case. Click on close once it is done. \u4f60\u53ef\u6839\u636e\u9700\u8981\u52fe\u9009\u201c\u9700\u8981\u65f6\u81ea\u52a8\u91cd\u542f\u76ee\u6807\u670d\u52a1\u5668\u201d\u9009\u9879&#xff0c;\u672c\u6587\u4e2d\u4e0d\u52fe\u9009\u8be5\u9009\u9879\u3002\u5b89\u88c5\u5b8c\u6210\u540e&#xff0c;\u70b9\u51fb\u5173\u95ed\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27nwtkl2xtiys.png\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>Confirm the AD DS Installation \u786e\u8ba4 AD DS \u5b89\u88c5\u9009\u62e9<\/p>\n<p>Close the Installation Complete Screen Wizard or go ahead with the next configuration of promoting the server to a domain controller which will be our next step as shown on the screenshot below \u5173\u95ed\u5b89\u88c5\u5b8c\u6210\u7684\u5411\u5bfc\u7a97\u53e3\u540e&#xff0c;\u5373\u53ef\u8fdb\u5165\u4e0b\u4e00\u6b65\u914d\u7f6e\u2014\u2014\u5c06\u8be5\u670d\u52a1\u5668\u63d0\u5347\u4e3a\u57df\u63a7\u5236\u5668&#xff0c;\u5177\u4f53\u64cd\u4f5c\u89c1\u4e0b\u56fe\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27s01kla5krat.jpg\" alt=\"AD-DS-Installation-Complete1\" width=\"700\" \/><\/p>\n<h4>Configuring Active Directory Domain Services (ADDS)<\/h4>\n<h4>\u914d\u7f6e Active Directory \u57df\u670d\u52a1&#xff08;AD DS&#xff09;<\/h4>\n<p>Now that the installation has completed successfully. We going to go ahead to configure the AD DS following the steps below: Active Directory \u57df\u670d\u52a1\u5df2\u5b89\u88c5\u5b8c\u6210&#xff0c;\u63a5\u4e0b\u6765\u6309\u4ee5\u4e0b\u6b65\u9aa4\u5b8c\u6210\u8be5\u670d\u52a1\u7684\u914d\u7f6e&#xff1a;<\/p>\n<h5>Step 1: Promote to Domain Controller and Add the Forest<\/h5>\n<h5>\u6b65\u9aa4 1&#xff1a;\u5c06\u670d\u52a1\u5668\u63d0\u5347\u4e3a\u57df\u63a7\u5236\u5668\u5e76\u521b\u5efa\u57df\u6797<\/h5>\n<p>After you have finished installing Active Directory Domain Services, the next step is to promote it to a Domain Controller (DC). On the same \u201cInstallation Complete Window\u201d as shown on the screenshot above, Click on \u201cPromote this server to a domain controller\u201d. \u5b89\u88c5\u5b8c Active Directory \u57df\u670d\u52a1\u540e&#xff0c;\u4e0b\u4e00\u6b65\u662f\u5c06\u5176\u63d0\u5347\u4e3a\u57df\u63a7\u5236\u5668&#xff08;DC&#xff09;\u3002\u5728\u4e0a\u8ff0\u7684\u5b89\u88c5\u5b8c\u6210\u7a97\u53e3\u4e2d&#xff0c;\u70b9\u51fb\u201c\u5c06\u6b64\u670d\u52a1\u5668\u63d0\u5347\u4e3a\u57df\u63a7\u5236\u5668\u201d\u3002<\/p>\n<p>Since this is a brand new Active Directory Domain Name Services, so we\u2019re going to choose &#034;Add a New Forest&#034; (see the screenshot below). \u7531\u4e8e\u672c\u6b21\u642d\u5efa\u7684\u662f\u5168\u65b0\u7684 Active Directory \u57df\u670d\u52a1&#xff0c;\u56e0\u6b64\u9009\u62e9**\u201c\u6dfb\u52a0\u65b0\u57df\u6797\u201d**&#xff08;\u89c1\u4e0b\u56fe&#xff09;\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27s5bftzfdlpn.png\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" width=\"700\" \/><\/p>\n<p>Promote the Server to a DC \u5c06\u670d\u52a1\u5668\u63d0\u5347\u4e3a\u57df\u63a7\u5236\u5668<\/p>\n<p>Since a forest is the overall container for AD DS and its services, we are going create the first domain within the forest which is known as the &#034;Forest Root Domain&#034; and specify a name which must be a fully qualified domain name (FQDN) as blog.techdirectarchive.com. \u57df\u6797\u662f AD DS \u53ca\u5176\u6240\u6709\u670d\u52a1\u7684\u9876\u7ea7\u5bb9\u5668&#xff0c;\u56e0\u6b64\u6211\u4eec\u9700\u8981\u5728\u57df\u6797\u4e2d\u521b\u5efa\u7b2c\u4e00\u4e2a\u57df&#xff08;\u5373 \u201c\u6797\u6839\u57df\u201d&#xff09;&#xff0c;\u5e76\u4e3a\u5176\u914d\u7f6e\u5b8c\u5168\u9650\u5b9a\u57df\u540d&#xff08;FQDN&#xff09;&#xff0c;\u672c\u6587\u4e2d\u914d\u7f6e\u4e3a blog.techdirectarchive.com\u3002<\/p>\n<p>You are free to specify your fully qualified domain name based on your organization\u2019s needs. Remember to specify the Active Directory Domain Services restored mode password as well. \u4f60\u53ef\u6839\u636e\u4f01\u4e1a\u9700\u6c42\u81ea\u5b9a\u4e49\u6797\u6839\u57df\u7684\u5b8c\u5168\u9650\u5b9a\u57df\u540d&#xff0c;\u540c\u65f6\u9700\u8981\u8bbe\u7f6e Active Directory \u57df\u670d\u52a1\u7684\u8fd8\u539f\u6a21\u5f0f\u5bc6\u7801\u3002<\/p>\n<p>Note: One suggested methods is to use a subdomain of a public registered domain. In my case techdirectarchive.com is my public registered domain name while blog.techdirectarchive.com is the subdomain. In some situations, you may see something like techdirectarchive.local. Now, one thing to note here is the .local is an unofficial top-level domain name which is not supported by internet standard and unofficial domain name should really only be used in a test lab environment. Avoid using it in the production environment because it causes issue with certificates. But for the purpose of the demo session in this post, if you don\u2019t have your public registered domain name you can go ahead and use the .local. \u6ce8&#xff1a;\u63a8\u8350\u4f7f\u7528\u516c\u5171\u6ce8\u518c\u57df\u540d\u7684\u5b50\u57df\u540d\u4f5c\u4e3a\u6797\u6839\u57df\u7684\u57df\u540d\u3002\u672c\u6587\u4e2d&#xff0c;techdirectarchive.com \u662f\u516c\u5171\u6ce8\u518c\u57df\u540d&#xff0c;blog.techdirectarchive.com \u662f\u5176\u5b50\u57df\u540d\u3002\u5b9e\u9645\u90e8\u7f72\u4e2d&#xff0c;\u4f60\u53ef\u80fd\u4f1a\u770b\u5230 techdirectarchive.local \u8fd9\u7c7b\u57df\u540d&#xff0c;\u9700\u8981\u6ce8\u610f\u7684\u662f&#xff0c;.local \u662f\u672a\u88ab\u4e92\u8054\u7f51\u6807\u51c6\u8ba4\u53ef\u7684\u975e\u5b98\u65b9\u9876\u7ea7\u57df\u540d&#xff0c;\u4ec5\u5efa\u8bae\u5728\u6d4b\u8bd5\u5b9e\u9a8c\u5ba4\u73af\u5883\u4e2d\u4f7f\u7528&#xff0c;\u5207\u52ff\u5728\u751f\u4ea7\u73af\u5883\u4e2d\u90e8\u7f72&#xff0c;\u5426\u5219\u4f1a\u5f15\u53d1\u8bc1\u4e66\u76f8\u5173\u7684\u95ee\u9898\u3002\u5982\u679c\u6ca1\u6709\u516c\u5171\u6ce8\u518c\u57df\u540d&#xff0c;\u53ef\u5728\u672c\u6587\u7684\u6f14\u793a\u5b9e\u9a8c\u4e2d\u4f7f\u7528.local \u540e\u7f00\u7684\u57df\u540d\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27mw4bpqbmirt.jpg\" alt=\"Add-the-Domain-Controller\" width=\"700\" \/><\/p>\n<p>Add the Domain Controller \u914d\u7f6e\u57df\u63a7\u5236\u5668<\/p>\n<p>At this stage, this is where you are to specify the forest and domain functional levels. This determines the AD DS and forest capabilities as well as determine which operating system can be run in the controller. \u672c\u6b65\u9aa4\u4e2d\u9700\u8981\u914d\u7f6e\u57df\u6797\u529f\u80fd\u7ea7\u522b\u548c\u57df\u529f\u80fd\u7ea7\u522b&#xff0c;\u8be5\u914d\u7f6e\u5c06\u51b3\u5b9a AD DS \u548c\u57df\u6797\u7684\u529f\u80fd\u7279\u6027&#xff0c;\u540c\u65f6\u4e5f\u4f1a\u9650\u5236\u57df\u63a7\u5236\u5668\u53ef\u8fd0\u884c\u7684\u64cd\u4f5c\u7cfb\u7edf\u7248\u672c\u3002<\/p>\n<p>Note one time that as shown on the screenshot above, the current functional level is Windows Server 2016. This means that all Domain Controller within the forest must have Windows Server 2016 and above because Windows Server 2016 is the latest we can choose because there have not been any significant changes since the Windows Server 2016 version. \u6ce8&#xff1a;\u5982\u4e0b\u56fe\u6240\u793a&#xff0c;\u672c\u6b21\u914d\u7f6e\u9009\u62e9\u7684\u529f\u80fd\u7ea7\u522b\u4e3a Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2016 <\/p>\n<p>        2016 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2016<\/span><\/span><\/span><\/span><\/span>&#xff0c;\u8fd9\u610f\u5473\u7740\u57df\u6797\u4e2d\u6240\u6709\u7684\u57df\u63a7\u5236\u5668\u90fd\u5fc5\u987b\u8fd0\u884c Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2016 <\/p>\n<p>        2016 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2016<\/span><\/span><\/span><\/span><\/span> \u53ca\u66f4\u9ad8\u7248\u672c\u7684\u7cfb\u7edf\u3002\u9009\u62e9\u8be5\u7248\u672c\u662f\u56e0\u4e3a Windows Server <span class=\"katex--inline\"><span class=\"katex\"><span class=\"katex-mathml\"> <\/p>\n<p>         2016 <\/p>\n<p>        2016 <\/p>\n<p>    <\/span><span class=\"katex-html\"><span class=\"base\"><span class=\"strut\" style=\"height: 0.6444em\"><\/span><span class=\"mord\">2016<\/span><\/span><\/span><\/span><\/span> \u4e4b\u540e\u7684\u7cfb\u7edf\u5728\u57df\u529f\u80fd\u7ea7\u522b\u4e0a\u672a\u8fdb\u884c\u91cd\u5927\u66f4\u65b0\u3002<\/p>\n<h5>Step 2: DNS Options<\/h5>\n<h5>\u6b65\u9aa4 2&#xff1a;DNS \u9009\u9879\u914d\u7f6e<\/h5>\n<p>On the next page ( DNS Options ), you will probably see an error on top with the words \u201cA delegation for this DNS server cannot be created because the authoritative parent zone nameserver cannot be found\u201d (see the screenshot below). Ignore it and click \u201cNext\u201c \u8fdb\u5165\u201cDNS \u9009\u9879\u201d\u9875\u9762\u540e&#xff0c;\u9875\u9762\u9876\u90e8\u53ef\u80fd\u4f1a\u51fa\u73b0\u62a5\u9519\u63d0\u793a&#xff1a;\u201c\u7531\u4e8e\u627e\u4e0d\u5230\u6743\u5a01\u7236\u533a\u57df\u540d\u79f0\u670d\u52a1\u5668&#xff0c;\u65e0\u6cd5\u4e3a\u6b64 DNS \u670d\u52a1\u5668\u521b\u5efa\u59d4\u6d3e\u201d&#xff08;\u89c1\u4e0b\u56fe&#xff09;&#xff0c;\u5ffd\u7565\u8be5\u62a5\u9519&#xff0c;\u76f4\u63a5\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-272oj4iuerrma.png\" alt=\"DNS-Options\" width=\"700\" \/><\/p>\n<p>DNS Options DNS \u9009\u9879\u914d\u7f6e<\/p>\n<h4>Step 3: NetBIOS domain name<\/h4>\n<h4>\u6b65\u9aa4 3&#xff1a;NetBIOS \u57df\u540d\u914d\u7f6e<\/h4>\n<p>On the next page, leave the NetBIOS domain name as default or you can change it as long as it is not longer than 15 characters. Click \u201cNext\u201d after that. \u8fdb\u5165 NetBIOS \u57df\u540d\u914d\u7f6e\u9875\u9762&#xff0c;\u53ef\u4fdd\u7559\u9ed8\u8ba4\u7684 NetBIOS \u57df\u540d&#xff0c;\u4e5f\u53ef\u81ea\u5b9a\u4e49&#xff08;\u5b57\u7b26\u6570\u4e0d\u8d85\u8fc7 15&#xff09;&#xff0c;\u914d\u7f6e\u5b8c\u6210\u540e\u70b9\u51fb\u4e0b\u4e00\u6b65\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27wy2vchxas4z.png\" alt=\"NetBios-Domain\" width=\"700\" \/><\/p>\n<p>NetBIOS Domain Name NetBIOS \u57df\u540d\u914d\u7f6e<\/p>\n<h5>Step 4: Paths<\/h5>\n<h5>\u6b65\u9aa4 4&#xff1a;\u6570\u636e\u5e93\u8def\u5f84\u914d\u7f6e<\/h5>\n<p>Leave paths as default and click \u201cNext\u201d as shown below. \u4fdd\u7559\u9ed8\u8ba4\u7684\u6570\u636e\u5e93\u3001\u65e5\u5fd7\u6587\u4ef6\u548c SYSVOL \u6587\u4ef6\u5939\u8def\u5f84&#xff0c;\u76f4\u63a5\u70b9\u51fb\u4e0b\u4e00\u6b65&#xff08;\u89c1\u4e0b\u56fe&#xff09;\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27kjeogpgnjhj.png\" alt=\"Paths-Winserver2022\" width=\"700\" \/><\/p>\n<p>Database Paths AD DS \u6570\u636e\u5e93\u8def\u5f84\u914d\u7f6e<\/p>\n<h5>Step 5: Review Selections<\/h5>\n<h5>\u6b65\u9aa4 5&#xff1a;\u68c0\u67e5\u914d\u7f6e\u9009\u62e9<\/h5>\n<p>In this step, the server allows you to review what you have done so far. If you are good with the selections you have done, click \u201cNext\u201d to proceed to the next stage. \u672c\u6b65\u9aa4\u4e3a\u914d\u7f6e\u68c0\u67e5\u73af\u8282&#xff0c;\u53ef\u67e5\u770b\u6b64\u524d\u7684\u6240\u6709\u914d\u7f6e\u9879&#xff0c;\u786e\u8ba4\u65e0\u8bef\u540e\u70b9\u51fb\u4e0b\u4e00\u6b65&#xff0c;\u8fdb\u5165\u5148\u51b3\u6761\u4ef6\u68c0\u67e5\u73af\u8282\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27fpp0x5b5lnd.png\" alt=\"Preview-Screen\" width=\"700\" \/><\/p>\n<p>Review Window \u914d\u7f6e\u68c0\u67e5\u9875\u9762<\/p>\n<h5>Step 6: Prerequisites Check<\/h5>\n<h5>\u6b65\u9aa4 6&#xff1a;\u5148\u51b3\u6761\u4ef6\u68c0\u67e5<\/h5>\n<p>In the prerequisites step, the system will be validated before Active Directory Domain Services is installed. If you get any errors here, please look at it and fix anything in the previous steps. If all is okay, click \u201cInstall\u201c. In our own case as shown in the screenshot below, all prerequisite check have been passed. \u5148\u51b3\u6761\u4ef6\u68c0\u67e5\u73af\u8282\u4e2d&#xff0c;\u7cfb\u7edf\u4f1a\u9a8c\u8bc1\u6240\u6709\u914d\u7f6e\u662f\u5426\u6ee1\u8db3 AD DS \u7684\u5b89\u88c5\u8981\u6c42\u3002\u82e5\u68c0\u67e5\u51fa\u73b0\u62a5\u9519&#xff0c;\u9700\u8fd4\u56de\u6b64\u524d\u6b65\u9aa4\u4fee\u6b63\u914d\u7f6e&#xff1b;\u82e5\u68c0\u67e5\u5168\u90e8\u901a\u8fc7&#xff0c;\u70b9\u51fb\u5b89\u88c5\u3002\u672c\u6587\u4e2d\u7684\u5b9e\u9a8c\u73af\u5883\u5df2\u901a\u8fc7\u6240\u6709\u5148\u51b3\u6761\u4ef6\u68c0\u67e5&#xff08;\u89c1\u4e0b\u56fe&#xff09;\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27ht51onjtrfh.png\" alt=\"Prerequisite-Check\" width=\"700\" \/><\/p>\n<p>Prerequisite Check Window \u5148\u51b3\u6761\u4ef6\u68c0\u67e5\u9875\u9762<\/p>\n<p>The configuration of the ADDS is in progress AD DS \u6b63\u5728\u914d\u7f6e\u4e2d<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27fnvzxc1lbpn.png\" alt=\"DC-Installation-Window\" width=\"700\" \/><\/p>\n<p>DC Installation Window \u57df\u63a7\u5236\u5668\u914d\u7f6e\u9875\u9762<\/p>\n<p>After that, the Server will reboot and you can then log into the Domain with the credentials you set in Step 1 as shown below: \u914d\u7f6e\u5b8c\u6210\u540e&#xff0c;\u670d\u52a1\u5668\u4f1a\u81ea\u52a8\u91cd\u542f&#xff0c;\u91cd\u542f\u540e\u53ef\u4f7f\u7528\u6b65\u9aa4 1 \u4e2d\u8bbe\u7f6e\u7684\u51ed\u636e\u767b\u5f55\u57df&#xff08;\u89c1\u4e0b\u56fe&#xff09;&#xff1a;<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27p2bxuenpdbm.png\" alt=\"Domain-Logon-Screen\" width=\"700\" \/><\/p>\n<p>Domain Controller Logon Screen \u57df\u63a7\u5236\u5668\u767b\u5f55\u754c\u9762<\/p>\n<p>Finally, if we check through the Server Manager and click on the \u201cTools\u201d then select the \u201cActive Directory Users and Computers\u201d you will see that our domain name is there. \u6700\u540e&#xff0c;\u6253\u5f00\u670d\u52a1\u5668\u7ba1\u7406\u5668&#xff0c;\u70b9\u51fb\u201c\u5de5\u5177\u201d&#xff0c;\u9009\u62e9\u201cActive Directory \u7528\u6237\u548c\u8ba1\u7b97\u673a\u201d&#xff0c;\u5373\u53ef\u770b\u5230\u6211\u4eec\u521b\u5efa\u7684\u57df\u3002<\/p>\n<p>In our case we have created on Organizational Unit (OU) which serves as department and created an account for myself as the user (see the screenshot below). \u672c\u6587\u4e2d&#xff0c;\u6211\u4eec\u5df2\u521b\u5efa\u4e86\u4e00\u4e2a\u4f5c\u4e3a\u90e8\u95e8\u4f7f\u7528\u7684\u7ec4\u7ec7\u5355\u5143&#xff08;OU&#xff09;&#xff0c;\u5e76\u4e3a\u672c\u4eba\u521b\u5efa\u4e86\u4e00\u4e2a\u7528\u6237\u8d26\u6237&#xff08;\u89c1\u4e0b\u56fe&#xff09;\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27ch3uzdz4mzf.png\" alt=\"Tools-to-locate-the-AD\" width=\"700\" \/><\/p>\n<p>Locate Active Direct Users and Computers \u6253\u5f00 Active Directory \u7528\u6237\u548c\u8ba1\u7b97\u673a<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27c4qna2lmedo.png\" alt=\"DC-Name\" width=\"700\" \/><\/p>\n<p>OU and User \u521b\u5efa\u7684\u7ec4\u7ec7\u5355\u5143\u548c\u7528\u6237\u8d26\u6237<\/p>\n<h5>Conclusion on how to Install and Configure Active Directory Domain Services on Windows<\/h5>\n<h5>Windows \u4e2d Active Directory \u57df\u670d\u52a1\u5b89\u88c5\u4e0e\u914d\u7f6e\u7684\u603b\u7ed3<\/h5>\n<p>In conclusion, one of the best features that make Windows Server to be widely adopted in the Enterprise environments is Active Directory. \u7efc\u4e0a&#xff0c;Active Directory \u662f Windows Server \u80fd\u5728\u4f01\u4e1a\u73af\u5883\u4e2d\u88ab\u5e7f\u6cdb\u5e94\u7528\u7684\u6838\u5fc3\u7279\u6027\u4e4b\u4e00\u3002<\/p>\n<p>This single Sign-on feature that seamlessly and easily integrates with most of Microsoft products makes user management among other tasks quite easy and fun. Congratulations, in this article you have learnt how to set it up from start to finish on Windows Server 2022. \u8fd9\u9879\u53ef\u4e0e\u7edd\u5927\u591a\u6570\u5fae\u8f6f\u4ea7\u54c1\u65e0\u7f1d\u4fbf\u6377\u96c6\u6210\u7684\u5355\u70b9\u767b\u5f55\u529f\u80fd&#xff0c;\u8ba9\u7528\u6237\u7ba1\u7406\u53ca\u5176\u4ed6\u5404\u7c7b\u76f8\u5173\u64cd\u4f5c\u4efb\u52a1\u53d8\u5f97\u5341\u5206\u7b80\u4fbf\u3001\u6613\u4e8e\u4e0a\u624b\u3002\u606d\u559c\u4f60&#xff0c;\u901a\u8fc7\u672c\u7bc7\u6587\u7ae0&#xff0c;\u4f60\u5df2\u638c\u63e1\u5728 Windows Server 2022 \u4e2d\u4ece\u5934\u81f3\u5c3e\u5b8c\u6574\u642d\u5efa\u8be5\u670d\u52a1\u7684\u65b9\u6cd5\u3002<\/p>\n<p>I hope you found this blog post helpful on how to install and configure Active Directory Domain Services on Windows Server 2022. If you have any questions, please let me know in the comment section. \u5e0c\u671b\u8fd9\u7bc7\u535a\u6587\u80fd\u4e3a\u4f60\u642d\u5efa Windows Server 2022 \u4e2d\u7684 Active Directory \u57df\u670d\u52a1\u63d0\u4f9b\u5b9e\u64cd\u5e2e\u52a9\u3002\u82e5\u4f60\u8fd8\u6709\u4efb\u4f55\u95ee\u9898&#xff0c;\u53ef\u5728\u8bc4\u8bba\u533a\u7559\u8a00\u544a\u77e5\u3002<\/p>\n<hr \/>\n<h2>How to add a second Domain Controller<\/h2>\n<h2>\u5982\u4f55\u6dfb\u52a0\u7b2c\u4e8c\u53f0\u57df\u63a7\u5236\u5668<\/h2>\n<p>Posted on 08\/01\/2020 By Christian<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27iaifoj4s2pg.jpg\" alt=\"img\" width=\"200\" \/><\/p>\n<p>A domain controller (DC) is a server computer that responds to authentication requests. It participates in the replication and contains a complete copy of all directory information for their domain. If your environment requires high availability of IT systems when one DC fails, another takes over to ensure successful login, etc. \u57df\u63a7\u5236\u5668&#xff08;DC&#xff09;\u662f\u4e00\u53f0\u7528\u4e8e\u54cd\u5e94\u8eab\u4efd\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668&#xff0c;\u5b83\u53c2\u4e0e\u76ee\u5f55\u6570\u636e\u7684\u590d\u5236\u8fc7\u7a0b&#xff0c;\u4e14\u5b58\u50a8\u7740\u6240\u5728\u57df\u7684\u5168\u90e8\u76ee\u5f55\u4fe1\u606f\u7684\u5b8c\u6574\u526f\u672c\u3002\u82e5\u4f60\u7684 IT \u73af\u5883\u5bf9\u9ad8\u53ef\u7528\u6027\u6709\u8981\u6c42&#xff0c;\u90a3\u4e48\u5f53\u4e00\u53f0\u57df\u63a7\u5236\u5668\u53d1\u751f\u6545\u969c\u65f6&#xff0c;\u53e6\u4e00\u53f0\u57df\u63a7\u5236\u5668\u53ef\u7acb\u5373\u63a5\u7ba1\u5de5\u4f5c&#xff0c;\u4fdd\u969c\u7528\u6237\u767b\u5f55\u7b49\u64cd\u4f5c\u7684\u6b63\u5e38\u6267\u884c\u3002<\/p>\n<p>If you wish to install an additional domain controller to balance the load and increase fault tolerance. This how-to guide describes the steps needed to add a domain controller to your existing Active Directory (AD) environment. \u82e5\u4f60\u5e0c\u671b\u90e8\u7f72\u989d\u5916\u7684\u57df\u63a7\u5236\u5668\u4ee5\u5b9e\u73b0\u8d1f\u8f7d\u5747\u8861\u3001\u63d0\u5347\u67b6\u6784\u7684\u5bb9\u9519\u80fd\u529b&#xff0c;\u672c\u6587\u5c06\u8be6\u7ec6\u8bb2\u89e3\u5728\u73b0\u6709 Active Directory&#xff08;AD&#xff09;\u73af\u5883\u4e2d\u6dfb\u52a0\u57df\u63a7\u5236\u5668\u7684\u5177\u4f53\u6b65\u9aa4\u3002<\/p>\n<h3>Add a second Domain Controller<\/h3>\n<h3>\u6dfb\u52a0\u7b2c\u4e8c\u53f0\u57df\u63a7\u5236\u5668<\/h3>\n<p>Kindly follow the steps discussed below to add an additional DC to your domain. You will have to install the AD DS role and promote it as a Domain Controller. \u8bf7\u6309\u7167\u4e0b\u8ff0\u6b65\u9aa4\u4e3a\u4f60\u7684\u57df\u6dfb\u52a0\u989d\u5916\u7684\u57df\u63a7\u5236\u5668&#xff0c;\u6574\u4e2a\u8fc7\u7a0b\u9700\u8981\u5148\u5b89\u88c5 AD DS \u89d2\u8272&#xff0c;\u518d\u5c06\u8be5\u670d\u52a1\u5668\u63d0\u5347\u4e3a\u57df\u63a7\u5236\u5668\u3002<\/p>\n<p>Add a domain controller into an existing domain<\/p>\n<p>\u5728\u73b0\u6709\u57df\u4e2d\u6dfb\u52a0\u4e00\u53f0\u57df\u63a7\u5236\u5668<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27bu3w2pbfavc.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>Note: You can decide to join this server to the domain before promoting it as a domain controller. \u6ce8&#xff1a;\u4f60\u53ef\u9009\u62e9\u5148\u5c06\u8be5\u670d\u52a1\u5668\u52a0\u5165\u57df&#xff0c;\u518d\u5c06\u5176\u63d0\u5347\u4e3a\u57df\u63a7\u5236\u5668\u3002<\/p>\n<p>But in my case, I did not join the second Domain Controller to the domain previously. Because, when adding a new domain controller into an existing domain, this action will be performed by default. \u4f46\u5728\u672c\u6b21\u5b9e\u64cd\u4e2d&#xff0c;\u6211\u5e76\u672a\u63d0\u524d\u5c06\u8fd9\u53f0\u7b2c\u4e8c\u53f0\u57df\u63a7\u5236\u5668\u52a0\u5165\u57df&#xff0c;\u539f\u56e0\u662f\u5728\u73b0\u6709\u57df\u4e2d\u6dfb\u52a0\u65b0\u57df\u63a7\u5236\u5668\u65f6&#xff0c;\u8be5\u64cd\u4f5c\u4f1a\u88ab\u7cfb\u7edf\u81ea\u52a8\u6267\u884c\u3002<\/p>\n<p>If you previously joined the Server to the Domain before promoting it, it will move the computer object out of the computer OU to the Domain Controller OU (Container) Next click on Change to enter the credential needed to join the domain. \u82e5\u4f60\u63d0\u524d\u5c06\u670d\u52a1\u5668\u52a0\u5165\u57df\u540e\u518d\u6267\u884c\u63d0\u5347\u64cd\u4f5c&#xff0c;\u7cfb\u7edf\u4f1a\u5c06\u8be5\u670d\u52a1\u5668\u5bf9\u5e94\u7684\u8ba1\u7b97\u673a\u5bf9\u8c61\u4ece\u8ba1\u7b97\u673a\u7ec4\u7ec7\u5355\u5143&#xff08;OU&#xff09;\u79fb\u81f3\u57df\u63a7\u5236\u5668\u7ec4\u7ec7\u5355\u5143&#xff08;\u5bb9\u5668&#xff09;\u3002\u63a5\u4e0b\u6765\u70b9\u51fb\u201c\u66f4\u6539\u201d\u6309\u94ae&#xff0c;\u8f93\u5165\u52a0\u5165\u57df\u6240\u9700\u7684\u51ed\u636e\u4fe1\u606f\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27djwxoeidnle.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>You may encounter an error in this stage if you are using the default administrator account. \u82e5\u4f60\u4f7f\u7528\u9ed8\u8ba4\u7684\u7ba1\u7406\u5458\u8d26\u6237\u6267\u884c\u6b64\u64cd\u4f5c&#xff0c;\u672c\u6b65\u9aa4\u53ef\u80fd\u4f1a\u51fa\u73b0\u62a5\u9519\u3002<\/p>\n<p>Create a new account and add the user as a member of the domain Administrator. This works! Remember to uncheck the Domain Name System Here (DNS) server. We do not need it as there is an existing DNS server. \u6b64\u65f6\u53ef\u65b0\u5efa\u4e00\u4e2a\u7528\u6237\u8d26\u6237&#xff0c;\u5e76\u5c06\u8be5\u8d26\u6237\u6dfb\u52a0\u81f3\u57df\u7ba1\u7406\u5458\u7ec4&#xff0c;\u91c7\u7528\u6b64\u65b9\u5f0f\u5373\u53ef\u6b63\u5e38\u6267\u884c\u64cd\u4f5c\u3002\u6ce8\u610f\u53d6\u6d88\u52fe\u9009\u201c\u6b64\u5904\u7684\u57df\u540d\u7cfb\u7edf&#xff08;DNS&#xff09;\u670d\u52a1\u5668\u201d\u9009\u9879&#xff0c;\u7531\u4e8e\u5f53\u524d\u73af\u5883\u4e2d\u5df2\u6709\u53ef\u7528\u7684 DNS \u670d\u52a1\u5668&#xff0c;\u56e0\u6b64\u65e0\u9700\u518d\u4e3a\u6b64\u670d\u52a1\u5668\u914d\u7f6e DNS \u670d\u52a1\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27ukizyc0ivjz.png\" alt=\"img\" width=\"700\" \/><\/p>\n<h5>Specify Replication Server<\/h5>\n<h5>\u6307\u5b9a\u590d\u5236\u6e90\u670d\u52a1\u5668<\/h5>\n<p>Under Additional Options, select \u201cReplicate from\u201d using the drop-down button to specify the DC to replicate from. \u5728\u201c\u5176\u4ed6\u9009\u9879\u201d\u680f\u4e2d&#xff0c;\u70b9\u51fb\u4e0b\u62c9\u6309\u94ae\u9009\u62e9\u201c\u4ece\u4ee5\u4e0b\u670d\u52a1\u5668\u590d\u5236\u201d&#xff0c;\u6307\u5b9a\u8be5\u57df\u63a7\u5236\u5668\u7684\u76ee\u5f55\u6570\u636e\u590d\u5236\u6e90\u670d\u52a1\u5668\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27av5rwuvgtxo.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>Under paths, you can decide to store them in a different location as best practice. I will leave them as default. \u4ece\u6700\u4f73\u5b9e\u8df5\u89d2\u5ea6\u51fa\u53d1&#xff0c;\u4f60\u53ef\u5728\u201c\u8def\u5f84\u201d\u680f\u4e2d\u4fee\u6539 AD DS \u6570\u636e\u5e93\u3001\u65e5\u5fd7\u6587\u4ef6\u548c SYSVOL \u6587\u4ef6\u5939\u7684\u5b58\u50a8\u4f4d\u7f6e&#xff0c;\u672c\u6b21\u5b9e\u64cd\u4e2d\u5c06\u4fdd\u7559\u7cfb\u7edf\u9ed8\u8ba4\u914d\u7f6e\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27nbouz4ogbvy.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>Under the review Option, click on next as this gives you an opportunity to review what you have done. \u8fdb\u5165\u201c\u68c0\u67e5\u9009\u9879\u201d\u9875\u9762&#xff0c;\u70b9\u51fb\u201c\u4e0b\u4e00\u6b65\u201d&#xff0c;\u8be5\u9875\u9762\u53ef\u8ba9\u4f60\u590d\u6838\u6b64\u524d\u7684\u6240\u6709\u914d\u7f6e\u9879\u3002<\/p>\n<p>Here it will perform the prerequisite checks and if it passes, it will prompt you to install Active Directory Domain Services. \u7cfb\u7edf\u5c06\u5728\u6b64\u5904\u6267\u884c\u5148\u51b3\u6761\u4ef6\u68c0\u67e5&#xff0c;\u82e5\u68c0\u67e5\u5168\u90e8\u901a\u8fc7&#xff0c;\u4f1a\u5f39\u51fa\u63d0\u793a\u8ba9\u4f60\u5b89\u88c5 Active Directory \u57df\u670d\u52a1\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27g01xnbvgusi.png\" alt=\"img\" width=\"700\" \/><\/p>\n<p>After installation, the computer will reboot. Now both DCs are global catalogs and can respond to user queries. \u5b89\u88c5\u5b8c\u6210\u540e&#xff0c;\u8be5\u670d\u52a1\u5668\u5c06\u81ea\u52a8\u91cd\u542f\u3002\u6b64\u65f6&#xff0c;\u4e24\u53f0\u57df\u63a7\u5236\u5668\u5747\u5df2\u914d\u7f6e\u4e3a\u5168\u5c40\u7f16\u5f55\u670d\u52a1\u5668&#xff0c;\u53ef\u54cd\u5e94\u7528\u6237\u7684\u76ee\u5f55\u67e5\u8be2\u8bf7\u6c42\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27csoikypimj1.png\" alt=\"img\" width=\"300\" \/><\/p>\n<p>That is all. Verify the replication from Active Directory Sites and Services. I will be blogging on how to perform manual replication and testing if replication works. Keep an eye on this site for this. \u64cd\u4f5c\u5230\u6b64\u5168\u90e8\u5b8c\u6210\u3002\u4f60\u53ef\u901a\u8fc7\u201cActive Directory \u7ad9\u70b9\u548c\u670d\u52a1\u201d\u5de5\u5177\u9a8c\u8bc1\u76ee\u5f55\u6570\u636e\u7684\u590d\u5236\u60c5\u51b5\u3002<\/p>\n<p>I hope you found this blog post helpful on how to add a second Domain Controller. \u5e0c\u671b\u8fd9\u7bc7\u535a\u6587\u80fd\u4e3a\u4f60\u6dfb\u52a0\u7b2c\u4e8c\u53f0\u57df\u63a7\u5236\u5668\u7684\u64cd\u4f5c\u63d0\u4f9b\u5e2e\u52a9\u3002<\/p>\n<hr \/>\n<h2>Relationship between Domain Trees and Forests<\/h2>\n<h2>\u57df\u6811\u4e0e\u57df\u6797\u7684\u5173\u7cfb<\/h2>\n<p>As you expand upon and organize Active Directory, you will create trees and forests. In Windows NT, the namespace was flat. Although NT domains could be configured to trust one another, each was a completely separate entity. \u5728\u62d3\u5c55\u548c\u89c4\u5212 Active Directory \u7684\u8fc7\u7a0b\u4e2d&#xff0c;\u4f60\u4f1a\u642d\u5efa\u57df\u6811\u548c\u57df\u6797\u3002\u5728 Windows NT \u7cfb\u7edf\u4e2d&#xff0c;\u547d\u540d\u7a7a\u95f4\u4e3a\u6241\u5e73\u7ed3\u6784\u3002\u5c3d\u7ba1 NT \u57df\u53ef\u914d\u7f6e\u4e3a\u5f7c\u6b64\u4fe1\u4efb&#xff0c;\u4f46\u6bcf\u4e2a\u57df\u90fd\u662f\u5b8c\u5168\u72ec\u7acb\u7684\u5b9e\u4f53\u3002<\/p>\n<p>With Windows 2000 and later Windows versions, you can create a group of subdomains branching off from a root domain; these subdomains form a tree [1]. Subdomains are also called child domains [2], as they use the namespace of the root domains in which they reside. For instance, if the root domain is named domain.com, a child domain created under it would be named something like child1.domain.com. \u5728 Windows 2000 \u53ca\u540e\u7eed\u7684 Windows \u7248\u672c\u4e2d&#xff0c;\u4f60\u53ef\u4ee5\u4ece\u6839\u57df\u5206\u652f\u521b\u5efa\u4e00\u7ec4\u5b50\u57df&#xff0c;\u8fd9\u4e9b\u5b50\u57df\u5171\u540c\u6784\u6210\u4e00\u4e2a\u57df\u6811\u3002\u5b50\u57df\u4e5f\u88ab\u79f0\u4f5c\u5b50\u57df&#xff0c;\u56e0\u4e3a\u5b83\u4eec\u4f1a\u6cbf\u7528\u6240\u5728\u6839\u57df\u7684\u547d\u540d\u7a7a\u95f4\u3002\u4f8b\u5982&#xff0c;\u82e5\u6839\u57df\u7684\u57df\u540d\u4e3a domain.com&#xff0c;\u5728\u5176\u4e0b\u521b\u5efa\u7684\u5b50\u57df\u53ef\u547d\u540d\u4e3a child1.domain.com \u8fd9\u7c7b\u5f62\u5f0f\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-270wunzrbwbuy.gif\" alt=\"a root domain.\" width=\"700\" \/><\/p>\n<p>This shows a child domain and its relationship to a root domain. \u8be5\u56fe\u5c55\u793a\u4e86\u5b50\u57df\u53ca\u5176\u4e0e\u6839\u57df\u7684\u5173\u8054\u5173\u7cfb\u3002<\/p>\n<p>In organizing Active Directory, you may also want to join groups of domains together into a structure, called a forest [3] Forests are collections of root domains (they do not share a contiguous namespace). The root domain, the first domain that you create, contains the configuration and schema for the forest. Additional domains are added to the root domain to form the tree structure or the forest structure, depending on the domain name requirements. Domains within a forest share two-way transitive trust relationships and share a common schema and global catalog. \u5728\u89c4\u5212 Active Directory \u65f6&#xff0c;\u4f60\u8fd8\u53ef\u5c06\u591a\u4e2a\u57df\u7ec4\u6574\u5408\u4e3a\u4e00\u4e2a\u540d\u4e3a\u57df\u6797\u7684\u67b6\u6784\u3002\u57df\u6797\u662f\u6839\u57df\u7684\u96c6\u5408&#xff0c;\u8fd9\u4e9b\u6839\u57df\u4e4b\u95f4\u4e0d\u5171\u4eab\u8fde\u7eed\u7684\u547d\u540d\u7a7a\u95f4\u3002\u4f60\u521b\u5efa\u7684\u7b2c\u4e00\u4e2a\u57df\u5373\u4e3a\u6839\u57df&#xff0c;\u5176\u4e2d\u5b58\u50a8\u7740\u57df\u6797\u7684\u914d\u7f6e\u548c\u67b6\u6784\u4fe1\u606f\u3002\u53ef\u6839\u636e\u57df\u540d\u7684\u9700\u6c42&#xff0c;\u5728\u6839\u57df\u4e2d\u6dfb\u52a0\u989d\u5916\u7684\u57df&#xff0c;\u4ee5\u6b64\u5f62\u6210\u57df\u6811\u6216\u57df\u6797\u67b6\u6784\u3002\u57df\u6797\u4e2d\u7684\u6240\u6709\u57df\u4e4b\u95f4\u5747\u5b58\u5728\u53cc\u5411\u53ef\u4f20\u9012\u4fe1\u4efb\u5173\u7cfb&#xff0c;\u4e14\u5171\u4eab\u7edf\u4e00\u7684\u67b6\u6784\u548c\u5168\u5c40\u7f16\u5f55\u3002<\/p>\n<p>Question: What are trees and what are forests? \u95ee\u9898&#xff1a; \u4ec0\u4e48\u662f\u57df\u6811&#xff1f;\u4ec0\u4e48\u662f\u57df\u6797&#xff1f;<\/p>\n<p>Answer: Trees are a cohesive group of domains, known as subdomains or child domains, that grow from a root domain. All the domains within a tree share a contiguous namespace. Forests are collections of root domains. They do not share a contiguous namespace. \u7b54\u6848&#xff1a; \u57df\u6811\u662f\u4ece\u6839\u57df\u5ef6\u4f38\u800c\u6765\u7684\u3001\u76f8\u4e92\u5173\u8054\u7684\u57df\u7ec4&#xff0c;\u8fd9\u4e9b\u57df\u4e5f\u88ab\u79f0\u4f5c\u5b50\u57df\u3002\u540c\u4e00\u4e2a\u57df\u6811\u4e2d\u7684\u6240\u6709\u57df\u5171\u4eab\u8fde\u7eed\u7684\u547d\u540d\u7a7a\u95f4\u3002\u57df\u6797\u662f\u6839\u57df\u7684\u96c6\u5408&#xff0c;\u8fd9\u4e9b\u6839\u57df\u4e4b\u95f4\u4e0d\u5171\u4eab\u8fde\u7eed\u7684\u547d\u540d\u7a7a\u95f4\u3002<\/p>\n<h3>Why create Multiple Domains?<\/h3>\n<h3>\u4e3a\u4f55\u521b\u5efa\u591a\u4e2a\u57df&#xff1f;<\/h3>\n<p>There will be many occasions in which you will need to create additional domains. Multiple domains are useful when you are dealing with: \u5b9e\u9645\u90e8\u7f72\u4e2d&#xff0c;\u5b58\u5728\u591a\u79cd\u9700\u8981\u521b\u5efa\u989d\u5916\u57df\u7684\u573a\u666f&#xff0c;\u5728\u4ee5\u4e0b\u60c5\u51b5\u4e2d&#xff0c;\u591a\u57df\u67b6\u6784\u5177\u5907\u5b9e\u9645\u5e94\u7528\u4ef7\u503c&#xff1a;<\/p>\n<li>\n<p>Different password requirements between organizations \u4e0d\u540c\u7ec4\u7ec7\u5355\u5143\u5b58\u5728\u4e0d\u540c\u7684\u5bc6\u7801\u7b56\u7565\u8981\u6c42<\/p>\n<\/li>\n<li>\n<p>Large numbers of objects \u57df\u5185\u5b58\u5728\u5927\u91cf\u7684\u5bf9\u8c61<\/p>\n<\/li>\n<li>\n<p>Different internet domain names \u4f01\u4e1a\u62e5\u6709\u4e0d\u540c\u7684\u516c\u7f51\u57df\u540d<\/p>\n<\/li>\n<li>\n<p>Better control of replication \u66f4\u4fbf\u4e8e\u7ba1\u63a7\u76ee\u5f55\u6570\u636e\u7684\u590d\u5236\u8fc7\u7a0b<\/p>\n<\/li>\n<li>\n<p>Decentralized network administration \u5b9e\u73b0\u5206\u6563\u5f0f\u7684\u7f51\u7edc\u7ba1\u7406<\/p>\n<\/li>\n<p>In order for you to decide whether to create multiple domains and how to use them to best effect, you need to have a clear understanding of the relationship between trees and forests-known as a trust relationship [4]. The series of images below will explain to you the workings of the trust relationship. \u82e5\u8981\u5224\u65ad\u662f\u5426\u9700\u8981\u521b\u5efa\u591a\u57df\u67b6\u6784&#xff0c;\u4ee5\u53ca\u5982\u4f55\u6700\u5927\u5316\u53d1\u6325\u591a\u57df\u67b6\u6784\u7684\u4f5c\u7528&#xff0c;\u4f60\u9700\u8981\u6e05\u6670\u7406\u89e3\u57df\u6811\u4e0e\u57df\u6797\u4e4b\u95f4\u7684\u5173\u8054\u5173\u7cfb&#xff0c;\u5373\u4fe1\u4efb\u5173\u7cfb\u3002\u4ee5\u4e0b\u4e00\u7cfb\u5217\u56fe\u793a\u5c06\u4e3a\u4f60\u89e3\u6790\u4fe1\u4efb\u5173\u7cfb\u7684\u5de5\u4f5c\u673a\u5236\u3002<\/p>\n<p>Hierarchical Arrangement of Windows Domains Windows \u57df\u7684\u5c42\u7ea7\u5316\u7ec4\u7ec7\u5f62\u5f0f<\/p>\n<li>\n<p>A tree is a hierarchical arrangement of Windows domains that share a continuous namespace. \u57df\u6811\u662f\u5171\u4eab\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u7684 Windows \u57df\u7684\u5c42\u7ea7\u5316\u7ec4\u7ec7\u5f62\u5f0f\u3002 <img decoding=\"async\" src=\"2026-01-27xhtnawcke4f.gif\" alt=\"1)\" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>When you add a domain to an existing tree, the new domain is a child domain of an existing parent domain. The name of the child domain is combined with the name of the parent domain to form its DNS name. \u5f53\u5411\u73b0\u6709\u57df\u6811\u4e2d\u6dfb\u52a0\u65b0\u57df\u65f6&#xff0c;\u8be5\u65b0\u57df\u5c06\u6210\u4e3a\u73b0\u6709\u7236\u57df\u7684\u5b50\u57df&#xff0c;\u5b50\u57df\u7684\u540d\u79f0\u4f1a\u4e0e\u7236\u57df\u7684\u540d\u79f0\u7ed3\u5408&#xff0c;\u6784\u6210\u5176\u57df\u540d\u7cfb\u7edf&#xff08;DNS&#xff09;\u540d\u79f0\u3002 <img decoding=\"async\" src=\"2026-01-27vgbnt1ddont.gif\" alt=\"2).\" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>A forest is a group of trees that do not share a contiguous namespace. The trees in a forest share a common configuration, schema, and global catalog. \u57df\u6797\u662f\u7531\u591a\u4e2a\u4e0d\u5171\u4eab\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u7684\u57df\u6811\u7ec4\u6210\u7684\u96c6\u5408&#xff0c;\u57df\u6797\u4e2d\u7684\u6240\u6709\u57df\u6811\u5171\u4eab\u7edf\u4e00\u7684\u914d\u7f6e\u3001\u67b6\u6784\u548c\u5168\u5c40\u7f16\u5f55\u3002 <img decoding=\"async\" src=\"2026-01-27jkgkikb52re.gif\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0 \" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>By default, the name of the root tree, or the first tree that is created in the forest, is used to refer to a given forest. Each tree in a forest has its own unique namespace. \u9ed8\u8ba4\u60c5\u51b5\u4e0b&#xff0c;\u6839\u6811&#xff08;\u5373\u57df\u6797\u4e2d\u521b\u5efa\u7684\u7b2c\u4e00\u4e2a\u57df\u6811&#xff09;\u7684\u540d\u79f0\u88ab\u7528\u4e8e\u6307\u4ee3\u7279\u5b9a\u7684\u57df\u6797&#xff0c;\u57df\u6797\u4e2d\u7684\u6bcf\u4e2a\u57df\u6811\u90fd\u62e5\u6709\u81ea\u8eab\u552f\u4e00\u7684\u547d\u540d\u7a7a\u95f4\u3002 <img decoding=\"async\" src=\"2026-01-27szeyarmepib.gif\" alt=\"4) \" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>In order for you to decide how to administer a forest, you need to determine the kind of trust relationship your trees or domains will have. By default, all root domains within a forest have a two-way transitive trust relationship with one another. \u82e5\u8981\u786e\u5b9a\u57df\u6797\u7684\u7ba1\u7406\u65b9\u5f0f&#xff0c;\u4f60\u9700\u8981\u5148\u5b9a\u4e49\u57df\u6811\u6216\u57df\u4e4b\u95f4\u7684\u4fe1\u4efb\u5173\u7cfb\u7c7b\u578b\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b&#xff0c;\u57df\u6797\u4e2d\u7684\u6240\u6709\u6839\u57df\u4e4b\u95f4\u5747\u5b58\u5728\u53cc\u5411\u53ef\u4f20\u9012\u4fe1\u4efb\u5173\u7cfb\u3002 <img decoding=\"async\" src=\"2026-01-27k0utrrqimyl.gif\" alt=\"5)\" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>Active Directory supports two forms of trust relationships: 1) one-way, non-transitive trusts and 2) two-way transitive trusts. One-way, non-transitive trusts must be explicitly created by the administrator. If you have Windows Server 2016 domains coexisting with Windows domains on your network, the trust relationship between the Server and Windows domains are always explicitly one-way non-transitive trusts. Active Directory \u652f\u6301\u4e24\u79cd\u4fe1\u4efb\u5173\u7cfb\u7c7b\u578b&#xff1a;1) \u5355\u5411\u4e0d\u53ef\u4f20\u9012\u4fe1\u4efb&#xff1b;2) \u53cc\u5411\u53ef\u4f20\u9012\u4fe1\u4efb\u3002\u5355\u5411\u4e0d\u53ef\u4f20\u9012\u4fe1\u4efb\u5fc5\u987b\u7531\u7ba1\u7406\u5458\u624b\u52a8\u521b\u5efa\u3002\u82e5\u4f60\u7684\u7f51\u7edc\u4e2d\u540c\u65f6\u5b58\u5728 Windows Server 2016 \u57df\u548c\u65e9\u671f Windows \u57df&#xff0c;\u4e24\u7c7b\u57df\u4e4b\u95f4\u7684\u4fe1\u4efb\u5173\u7cfb\u59cb\u7ec8\u4e3a\u624b\u52a8\u914d\u7f6e\u7684\u5355\u5411\u4e0d\u53ef\u4f20\u9012\u4fe1\u4efb\u3002 <img decoding=\"async\" src=\"2026-01-27orplbaxocew.gif\" alt=\"6)\" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>In a one-way non-transitive trust relationship, if domain green trusts domain yellow, domain yellow does not automatically trust domain green. \u5728\u5355\u5411\u4e0d\u53ef\u4f20\u9012\u4fe1\u4efb\u5173\u7cfb\u4e2d&#xff0c;\u82e5 green \u57df\u4fe1\u4efb yellow \u57df&#xff0c;yellow \u57df\u5e76\u4e0d\u4f1a\u81ea\u52a8\u4fe1\u4efb green \u57df\u3002 <img decoding=\"async\" src=\"2026-01-27rk30tyzwyzi.gif\" alt=\"7)\" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>Windows networks use one-way, non-transitive trust relationships. You manually create these relationships between existing domains. In a large network, this imposes a lot of administrative overhead. Active Directory supports one-way non-transitive trusts for connections to Windows networks and between Active Directory domains. \u65e9\u671f Windows \u7f51\u7edc\u91c7\u7528\u5355\u5411\u4e0d\u53ef\u4f20\u9012\u4fe1\u4efb\u5173\u7cfb&#xff0c;\u8fd9\u7c7b\u4fe1\u4efb\u5173\u7cfb\u9700\u8981\u7ba1\u7406\u5458\u5728\u73b0\u6709\u57df\u4e4b\u95f4\u624b\u52a8\u521b\u5efa&#xff0c;\u5728\u5927\u578b\u7f51\u7edc\u4e2d\u4f1a\u589e\u52a0\u5927\u91cf\u7684\u7ba1\u7406\u5de5\u4f5c\u8d1f\u62c5\u3002Active Directory \u4e3a\u4e0e\u65e9\u671f Windows \u7f51\u7edc\u7684\u8fde\u63a5&#xff0c;\u4ee5\u53ca Active Directory \u57df\u4e4b\u95f4\u7684\u8fde\u63a5&#xff0c;\u5747\u63d0\u4f9b\u4e86\u5355\u5411\u4e0d\u53ef\u4f20\u9012\u4fe1\u4efb\u7684\u652f\u6301\u3002 <img decoding=\"async\" src=\"2026-01-27m5vxmmsj5kv.gif\" alt=\"8) \" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>In a two-way transitive trust relationship, if domain green trusts domain blue, then domain blue automatically trusts domain green. \u5728\u53cc\u5411\u53ef\u4f20\u9012\u4fe1\u4efb\u5173\u7cfb\u4e2d&#xff0c;\u82e5 green \u57df\u4fe1\u4efb blue \u57df&#xff0c;blue \u57df\u4f1a\u81ea\u52a8\u4fe1\u4efb green \u57df\u3002 <img decoding=\"async\" src=\"2026-01-27cfl5b0t4nyy.gif\" alt=\"9)\" width=\"700\" \/><\/p>\n<\/li>\n<li>\n<p>If a two-way transitive trust exists between two domains, you can grant permissions to resources in one domain to user and group accounts in the other domain, and vice versa. Two-way, transitive trust relationships are the default between Windows domains. \u82e5\u4e24\u4e2a\u57df\u4e4b\u95f4\u5b58\u5728\u53cc\u5411\u53ef\u4f20\u9012\u4fe1\u4efb\u5173\u7cfb&#xff0c;\u53ef\u5c06\u4e00\u4e2a\u57df\u4e2d\u7684\u8d44\u6e90\u8bbf\u95ee\u6743\u9650\u6388\u4e88\u53e6\u4e00\u4e2a\u57df\u7684\u7528\u6237\u548c\u7ec4\u8d26\u6237&#xff0c;\u53cd\u4e4b\u4ea6\u7136\u3002\u53cc\u5411\u53ef\u4f20\u9012\u4fe1\u4efb\u662f Windows \u57df\u4e4b\u95f4\u7684\u9ed8\u8ba4\u4fe1\u4efb\u5173\u7cfb\u7c7b\u578b\u3002 <img decoding=\"async\" src=\"2026-01-27mzevje2xesd.gif\" alt=\"10)\" width=\"700\" \/><\/p>\n<\/li>\n<h3>Enhancing Hierarchy and Simplifying Management<\/h3>\n<h3>\u5f3a\u5316\u5c42\u7ea7\u67b6\u6784\u4e0e\u7b80\u5316\u7ba1\u7406\u5de5\u4f5c<\/h3>\n<p>In the context of Active Directory (AD) domains, a continuous namespace [5] plays a pivotal role in organizing and managing resources within Forests and Trees. A continuous namespace consists of a hierarchical and contiguous structure of domain names that share a common root domain. This structure enables efficient administration, seamless navigation, and streamlined access to resources, while also simplifying the process of implementing security policies and trust relationships. \u5728 Active Directory&#xff08;AD&#xff09;\u57df\u7684\u67b6\u6784\u4f53\u7cfb\u4e2d&#xff0c;\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u5728\u57df\u6797\u548c\u57df\u6811\u5185\u7684\u8d44\u6e90\u7ec4\u7ec7\u4e0e\u7ba1\u7406\u5de5\u4f5c\u4e2d\u53d1\u6325\u7740\u5173\u952e\u4f5c\u7528\u3002\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u662f\u6307\u5171\u4eab\u540c\u4e00\u6839\u57df\u3001\u5448\u5c42\u7ea7\u5316\u8fde\u7eed\u7ed3\u6784\u7684\u57df\u540d\u4f53\u7cfb\u3002\u8be5\u7ed3\u6784\u4e0d\u4ec5\u80fd\u5b9e\u73b0\u9ad8\u6548\u7684\u7ba1\u7406\u3001\u65e0\u7f1d\u7684\u8d44\u6e90\u68c0\u7d22\u548c\u4fbf\u6377\u7684\u8d44\u6e90\u8bbf\u95ee&#xff0c;\u8fd8\u80fd\u7b80\u5316\u5b89\u5168\u7b56\u7565\u4e0e\u4fe1\u4efb\u5173\u7cfb\u7684\u5b9e\u65bd\u6d41\u7a0b\u3002<\/p>\n<p>The benefits and significance of a continuous namespace in Active Directory domains using Forests and Trees can be highlighted in the following key aspects: \u5728\u57fa\u4e8e\u57df\u6797\u548c\u57df\u6811\u7684 Active Directory \u57df\u67b6\u6784\u4e2d&#xff0c;\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u7684\u4f18\u52bf\u4e0e\u610f\u4e49\u4e3b\u8981\u4f53\u73b0\u5728\u4ee5\u4e0b\u6838\u5fc3\u65b9\u9762&#xff1a;<\/p>\n<li>\n<p>Hierarchy and Organization: A continuous namespace provides a well-structured hierarchy, allowing for a clear organization of resources and domains. This hierarchy facilitates the arrangement of domains within Trees and Forests, making it easier for administrators to manage resources and users in a large-scale environment. \u5c42\u7ea7\u67b6\u6784\u4e0e\u7ec4\u7ec7\u6027&#xff1a;\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u63d0\u4f9b\u4e86\u7ed3\u6784\u6e05\u6670\u7684\u5c42\u7ea7\u4f53\u7cfb&#xff0c;\u53ef\u5b9e\u73b0\u8d44\u6e90\u4e0e\u57df\u7684\u6709\u5e8f\u7ec4\u7ec7\u3002\u8be5\u5c42\u7ea7\u4f53\u7cfb\u4fbf\u4e8e\u5728\u57df\u6811\u548c\u57df\u6797\u4e2d\u89c4\u5212\u57df\u7684\u5e03\u5c40&#xff0c;\u8ba9\u7ba1\u7406\u5458\u80fd\u66f4\u9ad8\u6548\u5730\u5728\u5927\u89c4\u6a21\u7f51\u7edc\u73af\u5883\u4e2d\u7ba1\u7406\u8d44\u6e90\u548c\u7528\u6237\u3002<\/p>\n<\/li>\n<li>\n<p>Simplified Trust Relationships: Trust relationships are crucial for granting access to resources across different domains within a Forest. A continuous namespace ensures that parent and child domains share a common root domain, which automatically establishes a transitive trust relationship between them. This simplification reduces the administrative overhead of manually creating and maintaining trust relationships. \u7b80\u5316\u7684\u4fe1\u4efb\u5173\u7cfb&#xff1a;\u4fe1\u4efb\u5173\u7cfb\u662f\u5b9e\u73b0\u57df\u6797\u5185\u8de8\u57df\u8d44\u6e90\u8bbf\u95ee\u6388\u6743\u7684\u5173\u952e\u3002\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u786e\u4fdd\u7236\u57df\u4e0e\u5b50\u57df\u5171\u4eab\u540c\u4e00\u6839\u57df&#xff0c;\u4e8c\u8005\u4e4b\u95f4\u4f1a\u81ea\u52a8\u5efa\u7acb\u53ef\u4f20\u9012\u4fe1\u4efb\u5173\u7cfb&#xff0c;\u8fd9\u4e00\u7279\u6027\u51cf\u5c11\u4e86\u624b\u52a8\u521b\u5efa\u548c\u7ef4\u62a4\u4fe1\u4efb\u5173\u7cfb\u7684\u7ba1\u7406\u5de5\u4f5c\u8d1f\u62c5\u3002<\/p>\n<\/li>\n<li>\n<p>Name Resolution and Resource Access: A continuous namespace improves name resolution and resource access within an Active Directory Forest. As domain names are contiguous, the Domain Name System (DNS) can resolve names more efficiently, ensuring that users and services can quickly locate and access resources across the Forest. \u4f18\u5316\u540d\u79f0\u89e3\u6790\u4e0e\u8d44\u6e90\u8bbf\u95ee&#xff1a;\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u80fd\u63d0\u5347 Active Directory \u57df\u6797\u5185\u7684\u540d\u79f0\u89e3\u6790\u6548\u7387\u548c\u8d44\u6e90\u8bbf\u95ee\u4f53\u9a8c\u3002\u7531\u4e8e\u57df\u540d\u5448\u8fde\u7eed\u7ed3\u6784&#xff0c;\u57df\u540d\u7cfb\u7edf&#xff08;DNS&#xff09;\u53ef\u66f4\u9ad8\u6548\u5730\u5b8c\u6210\u540d\u79f0\u89e3\u6790&#xff0c;\u786e\u4fdd\u7528\u6237\u548c\u670d\u52a1\u80fd\u5feb\u901f\u5728\u57df\u6797\u4e2d\u5b9a\u4f4d\u5e76\u8bbf\u95ee\u8d44\u6e90\u3002<\/p>\n<\/li>\n<li>\n<p>Streamlined Group Policy Implementation: Implementing Group Policy Objects (GPOs) is essential for managing and configuring settings within an Active Directory environment. A continuous namespace enables administrators to efficiently apply GPOs across the entire domain hierarchy, ensuring that policies are enforced consistently and reliably throughout the Forest. \u4fbf\u6377\u7684\u7ec4\u7b56\u7565\u5b9e\u65bd&#xff1a;\u7ec4\u7b56\u7565\u5bf9\u8c61&#xff08;GPO&#xff09;\u7684\u914d\u7f6e\u662f\u7ba1\u7406 Active Directory \u73af\u5883\u5404\u9879\u8bbe\u7f6e\u7684\u6838\u5fc3\u65b9\u5f0f\u3002\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u8ba9\u7ba1\u7406\u5458\u80fd\u5728\u6574\u4e2a\u57df\u5c42\u7ea7\u4e2d\u9ad8\u6548\u90e8\u7f72\u7ec4\u7b56\u7565\u5bf9\u8c61&#xff0c;\u786e\u4fdd\u7b56\u7565\u5728\u57df\u6797\u4e2d\u5f97\u5230\u4e00\u81f4\u4e14\u53ef\u9760\u7684\u6267\u884c\u3002<\/p>\n<\/li>\n<li>\n<p>Scalability and Flexibility: Continuous namespaces offer greater scalability and flexibility when expanding the domain infrastructure. By adding new child domains or Trees under the common root domain, organizations can accommodate growth and evolving requirements without disrupting the existing namespace or introducing complexity. \u9ad8\u53ef\u6269\u5c55\u6027\u4e0e\u7075\u6d3b\u6027&#xff1a;\u5728\u62d3\u5c55\u57df\u67b6\u6784\u65f6&#xff0c;\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u5177\u5907\u66f4\u5f3a\u7684\u53ef\u6269\u5c55\u6027\u548c\u7075\u6d3b\u6027\u3002\u4f01\u4e1a\u53ef\u5728\u516c\u5171\u6839\u57df\u4e0b\u6dfb\u52a0\u65b0\u7684\u5b50\u57df\u6216\u57df\u6811&#xff0c;\u4ee5\u6b64\u9002\u5e94\u4e1a\u52a1\u53d1\u5c55\u548c\u9700\u6c42\u53d8\u5316&#xff0c;\u4e14\u4e0d\u4f1a\u7834\u574f\u73b0\u6709\u7684\u547d\u540d\u7a7a\u95f4&#xff0c;\u4e5f\u4e0d\u4f1a\u589e\u52a0\u67b6\u6784\u7684\u590d\u6742\u6027\u3002<\/p>\n<\/li>\n<p>A continuous namespace plays a critical role in Active Directory domains using Forests and Trees by enhancing hierarchy, simplifying management, and streamlining resource access. By providing a well-structured, scalable, and flexible foundation, continuous namespaces contribute to the overall efficiency and effectiveness of Active Directory-based infrastructures. \u5728\u57fa\u4e8e\u57df\u6797\u548c\u57df\u6811\u7684 Active Directory \u57df\u67b6\u6784\u4e2d&#xff0c;\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u901a\u8fc7\u5f3a\u5316\u5c42\u7ea7\u67b6\u6784\u3001\u7b80\u5316\u7ba1\u7406\u5de5\u4f5c\u3001\u4f18\u5316\u8d44\u6e90\u8bbf\u95ee&#xff0c;\u53d1\u6325\u7740\u81f3\u5173\u91cd\u8981\u7684\u4f5c\u7528\u3002\u5176\u4e3a Active Directory \u67b6\u6784\u63d0\u4f9b\u4e86\u7ed3\u6784\u6e05\u6670\u3001\u53ef\u6269\u5c55\u4e14\u7075\u6d3b\u7684\u57fa\u7840&#xff0c;\u8fdb\u800c\u63d0\u5347\u4e86\u6574\u4e2a\u57fa\u4e8e Active Directory \u7684\u7f51\u7edc\u67b6\u6784\u7684\u6548\u7387\u4e0e\u5b9e\u7528\u6027\u3002<\/p>\n<h3>Domains and Forests<\/h3>\n<h3>\u57df\u4e0e\u57df\u6797<\/h3>\n<p>Question: What Are Domains and Forests? \u95ee\u9898&#xff1a; \u4ec0\u4e48\u662f\u57df\u548c\u57df\u6797&#xff1f;<\/p>\n<p>The Logical Structure of Active Directory Active Directory \u7684\u903b\u8f91\u7ed3\u6784 Active Directory stores network object information and implements the services that make this information available and usable to users. Active Directory presents this information through a standardized, logical structure that helps you establish and understand the organization of domains and domain resources in a useful way. This presentation of object information is referred to as the logical structure because it is independent of the physical aspects of the Active Directory infrastructure, such as the domain controllers required for each domain in the network. Active Directory \u5b58\u50a8\u7f51\u7edc\u5bf9\u8c61\u7684\u76f8\u5173\u4fe1\u606f&#xff0c;\u5e76\u63d0\u4f9b\u76f8\u5e94\u670d\u52a1\u4e3a\u7528\u6237\u5f00\u653e\u8be5\u4fe1\u606f\u7684\u8bbf\u95ee\u548c\u4f7f\u7528\u6743\u9650\u3002Active Directory \u901a\u8fc7\u6807\u51c6\u5316\u7684\u903b\u8f91\u7ed3\u6784\u5c55\u793a\u8fd9\u4e9b\u4fe1\u606f&#xff0c;\u52a9\u529b\u7ba1\u7406\u5458\u5408\u7406\u89c4\u5212\u5e76\u7406\u89e3\u57df\u548c\u57df\u8d44\u6e90\u7684\u7ec4\u7ec7\u65b9\u5f0f\u3002\u8be5\u5bf9\u8c61\u4fe1\u606f\u7684\u5c55\u793a\u65b9\u5f0f\u88ab\u79f0\u4f5c\u903b\u8f91\u7ed3\u6784&#xff0c;\u539f\u56e0\u662f\u5176\u72ec\u7acb\u4e8e Active Directory \u67b6\u6784\u7684\u7269\u7406\u5c42\u9762&#xff0c;\u4f8b\u5982\u7f51\u7edc\u4e2d\u6bcf\u4e2a\u57df\u6240\u9700\u7684\u57df\u63a7\u5236\u5668\u7b49\u7269\u7406\u7ec4\u4ef6\u3002<\/p>\n<p>Benefits of the Logical Structure \u903b\u8f91\u7ed3\u6784\u7684\u4f18\u52bf The logical structure provides a number of benefits for deploying, managing, and securing network services and resources. These benefits include: Active Directory \u7684\u903b\u8f91\u7ed3\u6784\u4e3a\u7f51\u7edc\u670d\u52a1\u4e0e\u8d44\u6e90\u7684\u90e8\u7f72\u3001\u7ba1\u7406\u548c\u5b89\u5168\u9632\u62a4\u5e26\u6765\u8bf8\u591a\u4f18\u52bf&#xff0c;\u5177\u4f53\u5305\u62ec&#xff1a;<\/p>\n<li>\n<p>Increased network security. The logical structure can provide security measures such as autonomy for individual groups or complete isolation of specific resources. \u63d0\u5347\u7f51\u7edc\u5b89\u5168\u6027\u3002\u903b\u8f91\u7ed3\u6784\u53ef\u5b9e\u73b0\u5404\u7c7b\u5b89\u5168\u9632\u62a4\u63aa\u65bd&#xff0c;\u4f8b\u5982\u4e3a\u5404\u7ec4\u7ec7\u5355\u5143\u914d\u7f6e\u6743\u9650\u81ea\u6cbb&#xff0c;\u6216\u5bf9\u7279\u5b9a\u8d44\u6e90\u8fdb\u884c\u5b8c\u5168\u9694\u79bb\u3002<\/p>\n<\/li>\n<li>\n<p>Simplified network management. The hierarchical nature of the logical structure simplifies configuration, control, and administration of the network, including managing user and group accounts and all network resources. \u7b80\u5316\u7f51\u7edc\u7ba1\u7406\u3002\u903b\u8f91\u7ed3\u6784\u7684\u5c42\u7ea7\u5316\u7279\u6027&#xff0c;\u8ba9\u7f51\u7edc\u7684\u914d\u7f6e\u3001\u63a7\u5236\u548c\u7ba1\u7406\u5de5\u4f5c\u66f4\u7b80\u4fbf&#xff0c;\u5176\u4e2d\u5305\u62ec\u7528\u6237\u548c\u7ec4\u8d26\u6237\u7684\u7ba1\u7406&#xff0c;\u4ee5\u53ca\u6240\u6709\u7f51\u7edc\u8d44\u6e90\u7684\u7ba1\u7406\u3002<\/p>\n<\/li>\n<li>\n<p>Simplified resource sharing. The logical structure of domains and forests and the relationships established between them can simplify the sharing of resources across an organization. \u7b80\u5316\u8d44\u6e90\u5171\u4eab\u3002\u57df\u548c\u57df\u6797\u7684\u903b\u8f91\u7ed3\u6784&#xff0c;\u4ee5\u53ca\u4e8c\u8005\u4e4b\u95f4\u5efa\u7acb\u7684\u5173\u8054\u5173\u7cfb&#xff0c;\u80fd\u8ba9\u4f01\u4e1a\u5185\u90e8\u7684\u8d44\u6e90\u5171\u4eab\u66f4\u4fbf\u6377\u3002<\/p>\n<\/li>\n<li>\n<p>Low total cost of ownership. The reduced administration costs for network management and the reduced load on network resources that can be achieved with the Active Directory logical structure can significantly lower the total cost of ownership. \u964d\u4f4e\u603b\u4f53\u62e5\u6709\u6210\u672c\u3002Active Directory \u7684\u903b\u8f91\u7ed3\u6784\u80fd\u51cf\u5c11\u7f51\u7edc\u7ba1\u7406\u7684\u4eba\u5de5\u6210\u672c&#xff0c;\u964d\u4f4e\u7f51\u7edc\u8d44\u6e90\u7684\u8d1f\u8f7d&#xff0c;\u8fdb\u800c\u5927\u5e45\u964d\u4f4e\u4f01\u4e1a\u7684\u603b\u4f53\u62e5\u6709\u6210\u672c\u3002<\/p>\n<\/li>\n<p>An efficient Active Directory logical structure also facilitates the system integration of features such as Group Policy, enabling desktop lockdown, software distribution, and administration of users, groups, workstations, and servers. In addition, the logical structure can facilitate the integration of services such as Exchange 2000, public key infrastructure (PKI), and domain-based distributed file system (DFS). \u9ad8\u6548\u7684 Active Directory \u903b\u8f91\u7ed3\u6784\u8fd8\u80fd\u63a8\u52a8\u7ec4\u7b56\u7565\u7b49\u529f\u80fd\u7684\u7cfb\u7edf\u96c6\u6210&#xff0c;\u5b9e\u73b0\u684c\u9762\u73af\u5883\u7684\u7ba1\u63a7\u3001\u8f6f\u4ef6\u5206\u53d1&#xff0c;\u4ee5\u53ca\u5bf9\u7528\u6237\u3001\u7ec4\u3001\u5de5\u4f5c\u7ad9\u548c\u670d\u52a1\u5668\u7684\u7edf\u4e00\u7ba1\u7406\u3002\u6b64\u5916&#xff0c;\u8be5\u903b\u8f91\u7ed3\u6784\u8fd8\u80fd\u52a9\u529b Exchange 2000\u3001\u516c\u94a5\u57fa\u7840\u8bbe\u65bd&#xff08;PKI&#xff09;\u548c\u57fa\u4e8e\u57df\u7684\u5206\u5e03\u5f0f\u6587\u4ef6\u7cfb\u7edf&#xff08;DFS&#xff09;\u7b49\u670d\u52a1\u7684\u96c6\u6210\u90e8\u7f72\u3002<\/p>\n<h4>Domain Trees Forest &#8211; Exercise<\/h4>\n<h4>\u57df\u6811\u4e0e\u57df\u6797\u2014\u2014\u5b9e\u64cd\u7ec3\u4e60<\/h4>\n<p>[1] Trees: A tree is a collection of domains that share a contiguous namespace. [1] \u57df\u6811&#xff1a;\u57df\u6811\u662f\u5171\u4eab\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u7684\u591a\u4e2a\u57df\u7684\u96c6\u5408\u3002<\/p>\n<p>[2] Child domains: A domain located in the namespace tree directly under another domain name (the parent domain), which contains the name of the parent in its own name. Example: sales.tacteam.net is a child domain of the tacteam.net parent domain. [2] \u5b50\u57df&#xff1a;\u5b50\u57df\u662f\u5728\u547d\u540d\u7a7a\u95f4\u6811\u4e2d\u76f4\u63a5\u96b6\u5c5e\u4e8e\u53e6\u4e00\u57df\u540d&#xff08;\u7236\u57df&#xff09;\u7684\u57df&#xff0c;\u5176\u57df\u540d\u4e2d\u5305\u542b\u7236\u57df\u7684\u540d\u79f0\u3002\u793a\u4f8b&#xff1a;sales.tacteam.net \u662f\u7236\u57df tacteam.net \u7684\u5b50\u57df\u3002<\/p>\n<p>[3] Forests: Two or more domain trees which do not share a contiguous namespace can be joined in a forest. [3] \u57df\u6797&#xff1a;\u4e24\u4e2a\u53ca\u4ee5\u4e0a\u4e0d\u5171\u4eab\u8fde\u7eed\u547d\u540d\u7a7a\u95f4\u7684\u57df\u6811&#xff0c;\u53ef\u6574\u5408\u4e3a\u4e00\u4e2a\u57df\u6797\u3002<\/p>\n<p>[4] Trust relationship: A logical relationship established between domains that allows pass-through authentication, providing for users in a trusted domain to access resources in a trusting domain, without having a user account in the trusting domain. [4] \u4fe1\u4efb\u5173\u7cfb&#xff1a;\u4fe1\u4efb\u5173\u7cfb\u662f\u57df\u4e4b\u95f4\u5efa\u7acb\u7684\u4e00\u79cd\u903b\u8f91\u5173\u7cfb&#xff0c;\u652f\u6301\u76f4\u901a\u5f0f\u8eab\u4efd\u9a8c\u8bc1&#xff0c;\u8ba9\u53d7\u4fe1\u4efb\u57df\u4e2d\u7684\u7528\u6237\u65e0\u9700\u5728\u4fe1\u4efb\u57df\u4e2d\u521b\u5efa\u8d26\u6237&#xff0c;\u5373\u53ef\u8bbf\u95ee\u4fe1\u4efb\u57df\u4e2d\u7684\u8d44\u6e90\u3002<\/p>\n<p>[5] continuous namespace: A continuous namespace in Active Directory is a hierarchical domain structure where child domains are subdomains of the parent domain. For example, if the parent domain is example.com, a continuous child domain would be child.example.com. [5] \u8fde\u7eed\u547d\u540d\u7a7a\u95f4&#xff1a;Active Directory \u4e2d\u7684\u8fde\u7eed\u547d\u540d\u7a7a\u95f4&#xff0c;\u662f\u6307\u5b50\u57df\u4f5c\u4e3a\u7236\u57df\u7684\u4e0b\u7ea7\u5b50\u57df\u7684\u5c42\u7ea7\u5316\u57df\u7ed3\u6784\u3002\u4f8b\u5982&#xff0c;\u82e5\u7236\u57df\u4e3aexample.com&#xff0c;\u5219\u5176\u8fde\u7eed\u5b50\u57df\u53ef\u4e3achild.example.com\u3002<\/p>\n<hr \/>\n<h2>Windows Server \u4e2d\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u7684\u533a\u522b\u4e0e\u8054\u7cfb<\/h2>\n<p>anyzt520 \u4e8e 2018-08-31 10:57:42 \u53d1\u5e03<\/p>\n<h3>\u57df&#xff08;Domain&#xff09;<\/h3>\n<p>\u5728\u9610\u8ff0\u57df\u7684\u6982\u5ff5\u524d&#xff0c;\u9996\u5148\u5bf9\u5de5\u4f5c\u7ec4\u7684\u7f51\u7edc\u7ba1\u7406\u7279\u6027\u8fdb\u884c\u68b3\u7406&#xff0c;\u5de5\u4f5c\u7ec4\u7684\u7ba1\u7406\u7279\u5f81\u53ef\u5f52\u7eb3\u4e3a\u4ee5\u4e0b\u4e94\u70b9&#xff1a;<\/p>\n<li>\u7f51\u7edc\u5185\u6bcf\u4e00\u53f0\u8ba1\u7b97\u673a\u72ec\u7acb\u7ef4\u62a4\u81ea\u8eab\u8d44\u6e90&#xff0c;\u65e0\u6cd5\u5b9e\u73b0\u5168\u7f51\u8d44\u6e90\u7684\u96c6\u4e2d\u5316\u7ba1\u7406&#xff1b;<\/li>\n<li>\u6bcf\u4e00\u53f0\u8ba1\u7b97\u673a\u7684\u7528\u6237\u8d26\u6237\u4fe1\u606f\u5747\u5b58\u50a8\u5728\u672c\u5730\u7cfb\u7edf\u4e2d&#xff1b;<\/li>\n<li>\u5355\u4e2a\u7528\u6237\u8d26\u6237\u4ec5\u80fd\u5728\u521b\u5efa\u8be5\u8d26\u6237\u7684\u672c\u5730\u8ba1\u7b97\u673a\u5b8c\u6210\u767b\u5f55\u64cd\u4f5c&#xff1b;<\/li>\n<li>\u5de5\u4f5c\u7ec4\u5185\u7684\u6240\u6709\u8ba1\u7b97\u673a\u5904\u4e8e\u5bf9\u7b49\u7684\u7f51\u7edc\u5730\u4f4d&#xff0c;\u5bf9\u5176\u4ed6\u8ba1\u7b97\u673a\u800c\u8a00&#xff0c;\u517c\u5177\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u673a\u7684\u53cc\u91cd\u5c5e\u6027&#xff1b;<\/li>\n<li>\u5de5\u4f5c\u7ec4\u7684\u9002\u7528\u7f51\u7edc\u89c4\u6a21\u4e00\u822c\u4e3a\u5c11\u4e8e 10 \u53f0\u8ba1\u7b97\u673a\u7684\u5c0f\u578b\u7f51\u7edc\u3002<\/li>\n<p>\u5728\u4f01\u4e1a\u4fe1\u606f\u5316\u5efa\u8bbe\u7684\u8fc7\u7a0b\u4e2d&#xff0c;\u5f53\u7f51\u7edc\u5185\u8ba1\u7b97\u673a\u6570\u91cf\u4ece 8 \u53f0\u6269\u5f20\u81f3 50 \u53f0\u65f6&#xff0c;\u5de5\u4f5c\u7ec4\u7684\u5206\u6563\u5f0f\u7ba1\u7406\u6a21\u5f0f\u4f1a\u663e\u73b0\u51fa\u660e\u663e\u7684\u5c40\u9650\u6027&#xff0c;\u4e0d\u4ec5\u4f1a\u589e\u52a0\u7f51\u7edc\u6545\u969c\u7684\u5904\u7406\u6210\u672c&#xff0c;\u8fd8\u6613\u51fa\u73b0\u75c5\u6bd2\u4f20\u64ad\u3001\u6d4f\u89c8\u5668\u9996\u9875\u7be1\u6539\u3001\u5185\u90e8\u7f51\u7edc\u6076\u610f\u653b\u51fb\u7b49\u95ee\u9898&#xff0c;\u65e0\u6cd5\u6ee1\u8db3\u4f01\u4e1a\u7684\u7f51\u7edc\u7ba1\u7406\u9700\u6c42\u3002\u7531\u6b64\u4fbf\u9700\u8981\u4e00\u79cd\u53ef\u5b9e\u73b0\u96c6\u4e2d\u5316\u7ba1\u7406\u7684\u7f51\u7edc\u7ec4\u7ec7\u6a21\u5f0f&#xff0c;\u57df\u7684\u6982\u5ff5\u4e5f\u7531\u6b64\u4ea7\u751f\u3002<\/p>\n<p>\u82e5\u5c06\u5de5\u4f5c\u7ec4\u7684\u7ba1\u7406\u6a21\u5f0f\u7c7b\u6bd4\u4e3a\u65e0\u7edf\u4e00\u7ba1\u7406\u7684\u5206\u6563\u5f0f\u7ec4\u7ec7\u5f62\u5f0f&#xff0c;\u90a3\u4e48\u57df\u5219\u662f\u5177\u5907\u96c6\u4e2d\u5316\u7ba1\u7406\u4f53\u7cfb\u7684\u7f51\u7edc\u7ec4\u7ec7\u5f62\u5f0f&#xff0c;\u8be5\u6982\u5ff5\u6700\u65e9\u5728\u5fae\u8f6f NT \u64cd\u4f5c\u7cfb\u7edf\u65f6\u4ee3\u88ab\u63d0\u51fa&#xff0c;\u5355\u57df\u73af\u5883\u53ef\u6ee1\u8db3\u89c4\u6a21\u8f83\u5c0f\u3001\u5730\u57df\u8de8\u5ea6\u8f83\u7a84\u7684\u4f01\u4e1a\u7f51\u7edc\u7ba1\u7406\u9700\u6c42\u3002\u800c\u5bf9\u4e8e\u8de8\u5730\u57df\u3001\u5927\u89c4\u6a21\u7684\u4f01\u4e1a\u7f51\u7edc\u7ba1\u7406\u9700\u6c42&#xff0c;\u9700\u4f9d\u6258\u57df\u6811\u4e0e\u57df\u68ee\u6797\u7684\u5c42\u7ea7\u5316\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u5b9e\u73b0\u591a\u4e2a\u57df\u7684\u8054\u5408\u7ba1\u7406&#xff0c;\u51cf\u5c11\u91cd\u590d\u7ba1\u7406\u64cd\u4f5c&#xff0c;\u540c\u65f6\u63d0\u5347\u4e0d\u540c\u57df\u4e4b\u95f4\u7684\u8d44\u6e90\u8c03\u7528\u6548\u7387\u3002<\/p>\n<p>\u57df\u4e0e\u57df\u4e4b\u95f4\u7684\u5173\u8054\u53ca\u57df\u5185\u8d44\u6e90\u7684\u8bbf\u95ee&#xff0c;\u9700\u4f9d\u6258\u57df\u540d\u7cfb\u7edf&#xff08;DNS&#xff09;\u5b9e\u73b0\u5b9a\u4f4d\u4e0e\u89e3\u6790&#xff0c;DNS \u53ef\u7c7b\u6bd4\u4e3a\u7f51\u7edc\u4e2d\u7684\u5b9a\u4f4d\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u4e3a\u57df\u7684\u8bbf\u95ee\u3001\u52a0\u5165\u53ca\u8d44\u6e90\u8c03\u7528\u63d0\u4f9b\u5730\u5740\u89e3\u6790\u4e0e\u8def\u5f84\u6307\u5f15\u3002\u5728\u57df\u73af\u5883\u7684\u642d\u5efa\u4e0e\u4f7f\u7528\u4e2d&#xff0c;\u57df\u63a7\u5236\u5668&#xff08;DC&#xff09;\u662f\u57df\u73af\u5883\u4e2d\u7684\u7ba1\u7406\u8282\u70b9&#xff0c;\u5b9e\u8d28\u4e3a\u5b89\u88c5\u4e86 Active Directory&#xff08;AD&#xff09;\u6d3b\u52a8\u76ee\u5f55\u7684\u7269\u7406\u670d\u52a1\u5668&#xff0c;\u57df\u5185\u6240\u6709\u7528\u6237\u7684\u8d26\u6237\u4fe1\u606f\u3001\u8ba1\u7b97\u673a\u4fe1\u606f\u5747\u7edf\u4e00\u5b58\u50a8\u5728\u57df\u63a7\u5236\u5668\u4e2d\u3002<\/p>\n<p>\u5728\u5b9e\u9645\u64cd\u4f5c\u4e2d&#xff0c;\u5e38\u4f1a\u51fa\u73b0\u5ba2\u6237\u7aef\u65e0\u6cd5\u52a0\u5165\u57df\u7684\u60c5\u51b5&#xff0c;\u5176\u4e2d\u6700\u5178\u578b\u7684\u95ee\u9898\u4e3a\u65e0\u6cd5\u8054\u7cfb\u5230\u57df\u63a7\u5236\u5668\u3002\u4ee5\u5b9e\u9a8c\u573a\u666f\u4e3a\u4f8b&#xff0c;\u64cd\u4f5c\u4eba\u5458\u5b8c\u6210 dcpromo \u547d\u4ee4\u6267\u884c\u5e76\u642d\u5efa\u57df\u63a7\u5236\u5668\u540e&#xff0c;\u5ba2\u6237\u7aef\u6267\u884c\u52a0\u5165\u57df\u64cd\u4f5c\u65f6\u63d0\u793a\u65e0\u6cd5\u8054\u7cfb\u5230\u57df\u63a7\u5236\u5668&#xff0c;\u7ecf ping \u547d\u4ee4\u68c0\u6d4b&#xff0c;\u5ba2\u6237\u7aef\u4e0e\u57df\u63a7\u5236\u5668\u7684\u7f51\u7edc\u8fde\u901a\u6027\u6b63\u5e38&#xff0c;\u8fdb\u4e00\u6b65\u901a\u8fc7 nslookup \u547d\u4ee4\u68c0\u6d4b\u57df\u540d\u89e3\u6790&#xff0c;\u53d1\u73b0\u5ba2\u6237\u7aef\u65e0\u6cd5\u89e3\u6790\u57df\u63a7\u5236\u5668\u57df\u540d&#xff0c;\u6392\u67e5\u540e\u786e\u5b9a\u4e3a\u5ba2\u6237\u7aef DNS \u670d\u52a1\u5668\u5730\u5740\u672a\u914d\u7f6e&#xff0c;\u586b\u5199\u6b63\u786e\u7684 DNS \u670d\u52a1\u5668\u5730\u5740\u540e&#xff0c;\u5ba2\u6237\u7aef\u53ef\u6210\u529f\u52a0\u5165\u57df\u3002\u7531\u6b64\u53ef\u89c1&#xff0c;DNS \u5728\u57df\u73af\u5883\u4e2d\u5360\u636e\u4e0d\u53ef\u66ff\u4ee3\u7684\u5730\u4f4d&#xff0c;\u5176\u5e76\u975e\u5355\u4e00\u7684\u7f51\u7edc\u670d\u52a1&#xff0c;\u800c\u662f\u7531\u82e5\u5e72\u53f0 DNS \u670d\u52a1\u5668\u4e0e DNS \u6210\u5458\u673a\u6784\u6210\u7684\u8ba1\u7b97\u673a\u7ec4\u7ec7\u4f53\u7cfb\u3002<\/p>\n<p>\u5728\u57df\u73af\u5883\u4e2d&#xff0c;DNS \u7684\u4f5c\u7528\u53ef\u5f52\u7eb3\u4e3a\u4ee5\u4e0b\u4e09\u70b9&#xff1a;<\/p>\n<li>\u4e3a\u57df\u63d0\u4f9b\u7b26\u5408 DNS \u6807\u51c6\u7684\u547d\u540d\u89c4\u5219&#xff0c;\u5b9e\u73b0\u57df\u7684\u6807\u51c6\u5316\u547d\u540d&#xff1b;<\/li>\n<li>\u4e3a\u57df\u63a7\u5236\u5668&#xff08;DC&#xff09;\u7684\u521b\u5efa\u63d0\u4f9b\u652f\u6491&#xff0c;\u521b\u5efa DC \u65f6\u9700\u4f9d\u6258\u5bf9\u5e94\u7684 DNS \u670d\u52a1\u5b8c\u6210\u914d\u7f6e&#xff1b;<\/li>\n<li>\u5b9e\u73b0\u57df\u63a7\u5236\u5668&#xff08;DC&#xff09;\u7684\u5b9a\u4f4d&#xff0c;\u5ba2\u6237\u7aef\u52a0\u5165\u57df\u7684\u8fc7\u7a0b\u4e2d&#xff0c;\u9700\u901a\u8fc7 DNS \u89e3\u6790\u83b7\u53d6 DC \u7684\u7f51\u7edc\u5730\u5740\u3002<\/li>\n<p>\u7ed3\u5408\u5b9e\u9645\u64cd\u4f5c\u7ecf\u9a8c&#xff0c;\u5ba2\u6237\u7aef\u52a0\u5165\u57df\u7684\u8fc7\u7a0b\u4e2d&#xff0c;\u9700\u91cd\u70b9\u5173\u6ce8\u4ee5\u4e0b\u4e09\u65b9\u9762\u7684\u95ee\u9898&#xff0c;\u540c\u65f6\u505a\u597d\u5bf9\u5e94\u7684\u68c0\u6d4b\u4e0e\u914d\u7f6e\u5de5\u4f5c&#xff1a;<\/p>\n<h4>1 \u7f51\u7edc\u8fde\u901a\u4e0e\u57df\u540d\u89e3\u6790\u95ee\u9898<\/h4>\n<p>a) \u901a\u8fc7 ping \u547d\u4ee4\u68c0\u6d4b\u5ba2\u6237\u7aef\u4e0e DC\u3001DNS \u670d\u52a1\u5668\u7684\u7f51\u7edc\u8fde\u901a\u6027&#xff0c;\u786e\u4fdd\u4e8c\u8005\u4e4b\u95f4\u7684\u7f51\u7edc\u901a\u4fe1\u6b63\u5e38&#xff1b; b) \u901a\u8fc7 DNS \u670d\u52a1\u5b8c\u6210 DC \u7684\u57df\u540d\u89e3\u6790&#xff0c;\u5ba2\u6237\u7aef\u53ef\u901a\u8fc7nslookup \u57df\u540d\u7684\u547d\u4ee4\u7ec4\u5408&#xff0c;\u68c0\u6d4b\u672c\u5730 DNS \u670d\u52a1\u5668\u5730\u5740\u7684\u914d\u7f6e\u662f\u5426\u6b63\u786e\u3002<\/p>\n<h4>2 \u6743\u9650\u9a8c\u8bc1\u95ee\u9898<\/h4>\n<p>\u5ba2\u6237\u7aef\u52a0\u5165\u57df\u65f6&#xff0c;\u9700\u8f93\u5165\u5177\u5907\u57df\u52a0\u5165\u6743\u9650\u7684\u7528\u6237\u8d26\u6237\u4e0e\u5bc6\u7801\u3002\u5b9e\u9645\u64cd\u4f5c\u4e2d\u5b58\u5728\u8ba4\u77e5\u8bef\u533a&#xff0c;\u5373\u8ba4\u4e3a\u4ec5 Administrator \u8d26\u6237\u5177\u5907\u57df\u52a0\u5165\u7684\u9a8c\u8bc1\u6743\u9650&#xff0c;\u5b9e\u5219\u666e\u901a\u7684 Domain User \u8d26\u6237\u4e5f\u53ef\u5b8c\u6210\u975e\u57df\u6210\u5458\u673a\u7684\u57df\u52a0\u5165\u9a8c\u8bc1\u64cd\u4f5c&#xff0c;\u57df\u5185\u7684\u666e\u901a\u7528\u6237\u8d26\u6237\u5747\u53ef\u534f\u52a9\u5b8c\u6210\u65b0\u8ba1\u7b97\u673a\u7684\u57df\u52a0\u5165\u64cd\u4f5c\u3002<\/p>\n<h4>3 \u57df\u767b\u5f55\u914d\u7f6e\u95ee\u9898<\/h4>\n<p>\u5ba2\u6237\u7aef\u6210\u529f\u52a0\u5165\u57df\u540e&#xff0c;\u82e5\u76f4\u63a5\u4f7f\u7528 Administrator \u8d26\u6237\u767b\u5f55&#xff0c;\u9ed8\u8ba4\u5c06\u767b\u5f55\u81f3\u672c\u5730\u8ba1\u7b97\u673a&#xff0c;\u800c\u975e\u57df\u73af\u5883\u3002\u9700\u5728\u767b\u5f55\u754c\u9762\u4e2d\u70b9\u51fb\u767b\u5f55\u9009\u9879&#xff0c;\u5728\u201c\u767b\u5f55\u5230\u201d\u7684\u4e0b\u62c9\u83dc\u5355\u4e2d\u9009\u62e9\u5df2\u52a0\u5165\u7684\u57df&#xff0c;\u65b9\u53ef\u5b8c\u6210\u57df\u73af\u5883\u7684\u767b\u5f55\u64cd\u4f5c\u3002<\/p>\n<h4>\u7279\u6b8a\u95ee\u9898\u5904\u7406<\/h4>\n<p>a) SID \u91cd\u590d\u95ee\u9898&#xff1a;\u82e5\u5f85\u52a0\u5165\u57df\u7684\u8ba1\u7b97\u673a\u7cfb\u7edf\u901a\u8fc7 GHOST \u5de5\u5177\u5b89\u88c5&#xff0c;\u4e14\u672a\u5b8c\u6210\u7cfb\u7edf\u91cd\u65b0\u5c01\u88c5&#xff0c;\u4f1a\u51fa\u73b0 SID \u91cd\u590d\u7684\u60c5\u51b5&#xff0c;\u6b64\u7c7b\u8ba1\u7b97\u673a\u65e0\u6cd5\u6b63\u5e38\u52a0\u5165\u57df&#xff0c;\u9700\u5bf9\u7cfb\u7edf\u8fdb\u884c\u91cd\u65b0\u5c01\u88c5\u5904\u7406&#xff0c;\u5173\u4e8e SID \u7684\u8be6\u7ec6\u8bf4\u660e\u53ca\u7cfb\u7edf\u5c01\u88c5\u65b9\u6cd5\u53ef\u53c2\u8003\u300a\u5fae\u8f6f\u7ea7 DNA \u624b\u672f-\u65b0 SID \u7684\u8bde\u751f\u4e4b\u7cfb\u7edf\u5c01\u88c5\u300b&#xff1b; b) DNS \u670d\u52a1\u5668\u6545\u969c\u95ee\u9898&#xff1a;\u82e5\u5ba2\u6237\u7aef\u5df2\u6b63\u786e\u914d\u7f6e\u5185\u7f51 DNS \u670d\u52a1\u5668\u5730\u5740&#xff0c;\u4e14\u53ef\u901a\u8fc7 ping \u547d\u4ee4\u8fde\u901a DNS \u670d\u52a1\u5668\u4e0e DC&#xff0c;\u4f46\u4ecd\u65e0\u6cd5\u8054\u7cfb\u5230 DC&#xff0c;\u5927\u6982\u7387\u4e3a DNS \u670d\u52a1\u5668\u51fa\u73b0\u6545\u969c\u3002\u57df\u63a7\u5236\u5668\u7684\u5b9a\u4f4d\u4fe1\u606f\u5b58\u50a8\u5728 DNS \u670d\u52a1\u7684 SRV \u8d44\u6e90\u8bb0\u5f55\u4e2d&#xff0c;\u8be5\u95ee\u9898\u591a\u7531 SRV \u8d44\u6e90\u8bb0\u5f55\u672a\u751f\u6548\u6216\u4e0d\u5b58\u5728\u5bfc\u81f4&#xff0c;\u89e3\u51b3\u65b9\u6cd5\u4e3a\u5728 DNS \u670d\u52a1\u5668\u4e2d&#xff0c;\u901a\u8fc7\u8fd0\u884cservices.msc\u6253\u5f00\u670d\u52a1\u7ba1\u7406\u5668&#xff0c;\u91cd\u542f Net Logon \u670d\u52a1\u5373\u53ef\u3002<\/p>\n<p>\u5bf9\u57df\u73af\u5883\u7684\u76f8\u5173\u77e5\u8bc6\u70b9\u8fdb\u884c\u68b3\u7406&#xff0c;\u53ef\u603b\u7ed3\u4e3a\u4ee5\u4e0b\u4e09\u70b9&#xff1a;<\/p>\n<li>DNS \u76f8\u5173&#xff1a;\u5305\u542b DNS \u7684\u6982\u5ff5\u3001\u5728\u57df\u73af\u5883\u4e2d\u7684\u4f5c\u7528\u3001\u6545\u969c\u6392\u67e5\u65b9\u6cd5\u53ca\u5bf9\u5e94\u7684\u68c0\u6d4b\u5de5\u5177&#xff1b;<\/li>\n<li>SID \u76f8\u5173&#xff1a;\u82e5\u4e24\u53f0\u8ba1\u7b97\u673a\u7684\u7cfb\u7edf SID \u76f8\u540c&#xff0c;\u65e0\u6cd5\u540c\u65f6\u52a0\u5165\u540c\u4e00\u57df&#xff0c;\u8be5\u95ee\u9898\u591a\u7531 GHOST \u514b\u9686\u7cfb\u7edf\u672a\u91cd\u65b0\u5c01\u88c5\u5bfc\u81f4&#xff1b;<\/li>\n<li>\u6743\u9650\u76f8\u5173&#xff1a;\u5b8c\u6210\u8ba1\u7b97\u673a\u57df\u52a0\u5165\u9a8c\u8bc1\u7684\u7528\u6237\u8d26\u6237&#xff0c;\u5e76\u975e\u4ec5\u9650\u5b9a\u4e3a Administrator \u8d26\u6237\u3002<\/li>\n<p>\u57df\u65e2\u662f Windows \u7f51\u7edc\u7cfb\u7edf\u7684\u903b\u8f91\u7ec4\u7ec7\u5355\u5143&#xff0c;\u4e5f\u662f Internet \u7684\u903b\u8f91\u7ec4\u7ec7\u5355\u5143&#xff0c;\u5728 Windows \u64cd\u4f5c\u7cfb\u7edf\u4e2d&#xff0c;\u57df\u662f\u7f51\u7edc\u7684\u5b89\u5168\u8fb9\u754c\u3002\u57df\u7ba1\u7406\u5458\u7684\u7ba1\u7406\u6743\u9650\u4ec5\u8986\u76d6\u57df\u7684\u5185\u90e8&#xff0c;\u9664\u975e\u5176\u4ed6\u57df\u4e3a\u5176\u8d4b\u4e88\u660e\u786e\u7684\u7ba1\u7406\u6743\u9650&#xff0c;\u5426\u5219\u57df\u7ba1\u7406\u5458\u65e0\u6cd5\u8bbf\u95ee\u6216\u7ba1\u7406\u5176\u4ed6\u57df\u3002\u6bcf\u4e2a\u57df\u5747\u5177\u5907\u72ec\u7acb\u7684\u5b89\u5168\u7b56\u7565&#xff0c;\u4e14\u4e0e\u5176\u4ed6\u57df\u4e4b\u95f4\u53ef\u5efa\u7acb\u81ea\u5b9a\u4e49\u7684\u5b89\u5168\u4fe1\u4efb\u5173\u7cfb\u3002<\/p>\n<p>\u57df\u4e0e\u5de5\u4f5c\u7ec4\u7684\u7ba1\u7406\u6a21\u5f0f\u53ef\u901a\u8fc7\u5bf9\u6bd4\u5b9e\u73b0\u66f4\u6e05\u6670\u7684\u7406\u89e3&#xff1a;\u5de5\u4f5c\u7ec4\u6a21\u5f0f\u4e0b&#xff0c;\u6240\u6709\u7cfb\u7edf\u914d\u7f6e\u4e0e\u7b56\u7565\u5747\u5728\u672c\u5730\u8ba1\u7b97\u673a\u5b8c\u6210&#xff0c;\u7528\u6237\u767b\u5f55\u4e3a\u672c\u5730\u767b\u5f55&#xff0c;\u8d26\u6237\u5bc6\u7801\u7684\u9a8c\u8bc1\u4f9d\u6258\u672c\u5730\u7cfb\u7edf\u6570\u636e\u5e93\u5b9e\u73b0&#xff1b;\u57df\u6a21\u5f0f\u4e0b&#xff0c;\u6240\u6709\u7cfb\u7edf\u914d\u7f6e\u4e0e\u7b56\u7565\u7531\u57df\u63a7\u5236\u5668\u7edf\u4e00\u5236\u5b9a&#xff0c;\u7528\u6237\u8d26\u6237\u4e0e\u5bc6\u7801\u7684\u9a8c\u8bc1\u4f9d\u6258\u57df\u63a7\u5236\u5668\u7684\u6570\u636e\u5e93\u5b9e\u73b0&#xff0c;\u540c\u4e00\u57df\u7684\u7528\u6237\u8d26\u6237\u53ef\u5728\u57df\u5185\u4efb\u610f\u4e00\u53f0\u8ba1\u7b97\u673a\u5b8c\u6210\u767b\u5f55\u64cd\u4f5c\u3002<\/p>\n<p>\u82e5\u5c06\u5de5\u4f5c\u7ec4\u7c7b\u6bd4\u4e3a\u65e0\u51c6\u5165\u9650\u5236\u7684\u5f00\u653e\u5f0f\u7f51\u7edc\u7ec4\u7ec7&#xff0c;\u57df\u5219\u4e3a\u5177\u5907\u4e25\u683c\u51c6\u5165\u4e0e\u7ba1\u7406\u673a\u5236\u7684\u7f51\u7edc\u7ec4\u7ec7&#xff1b;\u5de5\u4f5c\u7ec4\u5185\u7684\u8ba1\u7b97\u673a\u53ef\u81ea\u7531\u52a0\u5165\u4e0e\u9000\u51fa&#xff0c;\u800c\u57df\u5bf9\u8ba1\u7b97\u673a\u7684\u52a0\u5165\u4e0e\u9000\u51fa\u8bbe\u7f6e\u4e86\u4e25\u683c\u7684\u6743\u9650\u4e0e\u9a8c\u8bc1\u673a\u5236\u3002\u57df\u7684\u672c\u8d28\u662f\u7531\u670d\u52a1\u5668\u63a7\u5236\u7f51\u7edc\u8ba1\u7b97\u673a\u52a0\u5165\u6743\u9650\u7684\u8ba1\u7b97\u673a\u7ec4\u5408&#xff0c;\u57fa\u4e8e\u8be5\u7ec4\u5408\u5f62\u5f0f\u7684\u7ba1\u7406\u9700\u6c42&#xff0c;\u9700\u5efa\u7acb\u4e25\u683c\u7684\u7ba1\u7406\u673a\u5236&#xff0c;\u8fd9\u4e00\u673a\u5236\u5bf9\u63d0\u5347\u7f51\u7edc\u5b89\u5168\u6027\u5177\u6709\u91cd\u8981\u610f\u4e49\u3002\u5728\u5bf9\u7b49\u7f51\u6a21\u5f0f\u4e0b&#xff0c;\u4efb\u610f\u4e00\u53f0\u8ba1\u7b97\u673a\u63a5\u5165\u7f51\u7edc\u540e&#xff0c;\u5747\u53ef\u8bbf\u95ee\u5168\u7f51\u7684\u5171\u4eab\u8d44\u6e90&#xff0c;\u5373\u4fbf\u5171\u4eab\u6587\u4ef6\u8bbe\u7f6e\u8bbf\u95ee\u5bc6\u7801&#xff0c;\u4e5f\u5b58\u5728\u8f83\u9ad8\u7684\u7834\u89e3\u98ce\u9669&#xff0c;\u4e14\u5728 Windows 9x \u6784\u6210\u7684\u5bf9\u7b49\u7f51\u4e2d&#xff0c;\u6570\u636e\u4f20\u8f93\u8fc7\u7a0b\u4e0d\u5177\u5907\u5b89\u5168\u9632\u62a4\u80fd\u529b\u3002<\/p>\n<p>\u5728\u57df\u6a21\u5f0f\u4e0b&#xff0c;\u7f51\u7edc\u4e2d\u81f3\u5c11\u5b58\u5728\u4e00\u53f0\u670d\u52a1\u5668&#xff0c;\u4e13\u95e8\u5b8c\u6210\u8054\u5165\u7f51\u7edc\u7684\u8ba1\u7b97\u673a\u4e0e\u7528\u6237\u7684\u8eab\u4efd\u9a8c\u8bc1\u5de5\u4f5c&#xff0c;\u8be5\u670d\u52a1\u5668\u5373\u4e3a\u57df\u63a7\u5236\u5668&#xff08;Domain Controller&#xff0c;\u7b80\u5199\u4e3a DC&#xff09;\u3002\u57df\u63a7\u5236\u5668\u4e2d\u5b58\u50a8\u6709\u5305\u542b\u57df\u8d26\u6237\u3001\u5bc6\u7801\u3001\u57df\u5185\u8ba1\u7b97\u673a\u4fe1\u606f\u7684\u6570\u636e\u5e93&#xff0c;\u5f53\u8ba1\u7b97\u673a\u63a5\u5165\u7f51\u7edc\u65f6&#xff0c;\u57df\u63a7\u5236\u5668\u4f1a\u4f9d\u6b21\u9a8c\u8bc1\u8ba1\u7b97\u673a\u7684\u57df\u5f52\u5c5e\u3001\u7528\u6237\u767b\u5f55\u8d26\u6237\u7684\u6709\u6548\u6027\u3001\u767b\u5f55\u5bc6\u7801\u7684\u6b63\u786e\u6027&#xff0c;\u82e5\u4efb\u4e00\u9a8c\u8bc1\u9879\u4e0d\u901a\u8fc7&#xff0c;\u57df\u63a7\u5236\u5668\u5c06\u62d2\u7edd\u8be5\u7528\u6237\u4ece\u8be5\u8ba1\u7b97\u673a\u5b8c\u6210\u57df\u767b\u5f55\u64cd\u4f5c\u3002\u672a\u5b8c\u6210\u57df\u767b\u5f55\u7684\u7528\u6237&#xff0c;\u65e0\u6cd5\u8bbf\u95ee\u57df\u5185\u53d7\u6743\u9650\u4fdd\u62a4\u7684\u8d44\u6e90&#xff0c;\u4ec5\u80fd\u4ee5\u5bf9\u7b49\u7f51\u7528\u6237\u7684\u8eab\u4efd\u8bbf\u95ee Windows \u5f00\u653e\u7684\u5171\u4eab\u8d44\u6e90&#xff0c;\u4ee5\u6b64\u5b9e\u73b0\u57df\u5185\u8d44\u6e90\u7684\u5b89\u5168\u9632\u62a4\u3002<\/p>\n<p>\u5c06\u8ba1\u7b97\u673a\u52a0\u5165\u57df\u7684\u64cd\u4f5c&#xff0c;\u5e76\u975e\u4ec5\u5b9e\u73b0\u8ba1\u7b97\u673a\u4e0e\u57df\u63a7\u5236\u5668\u5728\u7f51\u7edc\u4e2d\u7684\u4e92\u901a\u5373\u53ef&#xff0c;\u8fd8\u9700\u7531\u7f51\u7edc\u7ba1\u7406\u5458\u5728\u57df\u63a7\u5236\u5668\u4e2d\u5b8c\u6210\u5bf9\u5e94\u7684\u914d\u7f6e&#xff0c;\u5c06\u8be5\u8ba1\u7b97\u673a\u6dfb\u52a0\u81f3\u57df\u7684\u8bbe\u5907\u5217\u8868\u4e2d&#xff0c;\u65b9\u53ef\u5b9e\u73b0\u57df\u5185\u6587\u4ef6\u5171\u4eab\u4e0e\u96c6\u4e2d\u5316\u7ba1\u7406\u3002<\/p>\n<p>\u57df\u662f\u57df\u73af\u5883\u4e2d\u6700\u57fa\u672c\u7684\u7ba1\u7406\u5355\u5143&#xff0c;\u540c\u65f6\u4e5f\u662f\u6700\u57fa\u5c42\u7684\u5bb9\u5668&#xff0c;\u53ef\u5b9e\u73b0\u5bf9\u5458\u5de5\u3001\u8ba1\u7b97\u673a\u7b49\u57fa\u7840\u6570\u636e\u7684\u5b58\u50a8\u3002\u5728\u4e00\u4e2a Active Directory \u4e2d&#xff0c;\u53ef\u6839\u636e\u4f01\u4e1a\u7684\u7ba1\u7406\u9700\u6c42\u521b\u5efa\u591a\u4e2a\u57df&#xff0c;\u4f8b\u5982\u7532\u516c\u53f8\u7684\u8d22\u52a1\u79d1\u3001\u4eba\u4e8b\u79d1\u3001\u9500\u552e\u79d1\u53ef\u5206\u522b\u521b\u5efa\u72ec\u7acb\u7684\u57df&#xff0c;\u56e0\u4e0a\u8ff0\u57df\u540c\u5c5e\u7532\u516c\u53f8\u7684\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u53ef\u5c06\u5176\u6574\u5408\u4e3a\u4e00\u68f5\u57df\u6811\u8fdb\u884c\u7edf\u4e00\u7ba1\u7406&#xff1b;\u82e5\u7532\u516c\u53f8\u3001\u4e59\u516c\u53f8\u3001\u4e19\u516c\u53f8\u540c\u5c5e A \u96c6\u56e2\u7684\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u4e3a\u5b9e\u73b0 A \u96c6\u56e2\u5bf9\u65d7\u4e0b\u5b50\u516c\u53f8\u7684\u5c42\u7ea7\u5316\u7ba1\u7406&#xff0c;\u53ef\u5c06\u5404\u5b50\u516c\u53f8\u7684\u57df\u6811\u8fdb\u4e00\u6b65\u6574\u5408\u4e3a\u57df\u68ee\u6797&#xff0c;\u6b64\u65f6 A \u96c6\u56e2\u53ef\u6309\u7167\u201c\u5b50\u516c\u53f8&#xff08;\u57df\u6811&#xff09;\u2192\u90e8\u95e8&#xff08;\u57df&#xff09;\u2192\u5458\u5de5\u201d\u7684\u5c42\u7ea7\u7ed3\u6784\u5b9e\u73b0\u7f51\u7edc\u8d44\u6e90\u7684\u7ba1\u7406\u3002Active Directory \u7684\u8be5\u79cd\u5c42\u6b21\u7ed3\u6784&#xff0c;\u4f7f\u4f01\u4e1a\u7f51\u7edc\u5177\u5907\u8f83\u5f3a\u7684\u6269\u5c55\u6027&#xff0c;\u540c\u65f6\u4fbf\u4e8e\u7f51\u7edc\u8d44\u6e90\u7684\u7ec4\u7ec7\u3001\u7ba1\u7406\u4e0e\u76ee\u5f55\u5b9a\u4f4d\u3002\u82e5\u4f01\u4e1a\u7684\u90e8\u95e8\u540d\u79f0\u53d1\u751f\u53d8\u66f4&#xff0c;\u4f8b\u5982\u7532\u516c\u53f8\u7684\u4eba\u4e8b\u79d1\u66f4\u540d\u4e3a\u4eba\u529b\u8d44\u6e90\u90e8&#xff0c;\u5bf9\u5e94\u7684\u57df\u540d\u9700\u4ece\u201c\u4eba\u4e8b\u79d1.\u7532\u516c\u53f8.A \u96c6\u56e2\u201d\u66f4\u6539\u4e3a\u201c\u4eba\u529b\u8d44\u6e90\u90e8.\u7532\u516c\u53f8.A \u96c6\u56e2\u201d&#xff0c;\u6b64\u65f6\u4fbf\u4ea7\u751f\u57df\u66f4\u540d\u7684\u9700\u6c42\u3002<\/p>\n<h3>OU&#xff08;Organizational Unit&#xff0c;\u7ec4\u7ec7\u5355\u5143&#xff09;<\/h3>\n<p>OU \u662f\u4e00\u79cd\u5bb9\u5668\u5bf9\u8c61&#xff0c;\u53ef\u5c06\u57df\u4e2d\u7684\u5404\u7c7b\u5bf9\u8c61\u5212\u5206\u4e3a\u4e0d\u540c\u7684\u903b\u8f91\u7ec4&#xff0c;\u56e0\u6b64 OU \u5c5e\u4e8e\u7eaf\u7cb9\u7684\u903b\u8f91\u6982\u5ff5&#xff0c;\u5176\u4e3b\u8981\u4f5c\u7528\u4e3a\u7b80\u5316\u57df\u7684\u7ba1\u7406\u5de5\u4f5c\u3002OU \u53ef\u5305\u542b\u591a\u79cd\u7c7b\u578b\u7684\u5bf9\u8c61&#xff0c;\u4f8b\u5982\u7528\u6237\u8d26\u6237\u3001\u7528\u6237\u7ec4\u3001\u8ba1\u7b97\u673a\u3001\u6253\u5370\u673a&#xff0c;\u540c\u65f6\u4e5f\u53ef\u5305\u542b\u5176\u4ed6 OU\u3002\u57fa\u4e8e\u8be5\u7279\u6027&#xff0c;\u53ef\u5229\u7528 OU \u5c06\u57df\u4e2d\u7684\u5bf9\u8c61\u6784\u5efa\u4e3a\u5b8c\u5168\u7684\u903b\u8f91\u5c42\u6b21\u7ed3\u6784&#xff0c;\u9488\u5bf9\u4f01\u4e1a\u7684\u7ba1\u7406\u9700\u6c42&#xff0c;\u53ef\u6309\u7167\u90e8\u95e8\u3001\u5730\u7406\u4f4d\u7f6e\u3001\u529f\u80fd\u4e0e\u6743\u9650\u7b49\u4e0d\u540c\u7ef4\u5ea6&#xff0c;\u6784\u5efa\u5bf9\u5e94\u7684 OU \u5c42\u6b21\u7ed3\u6784\u3002<\/p>\n<p>OU \u7684\u5c42\u6b21\u7ed3\u6784\u4ec5\u5c40\u9650\u4e8e\u57df\u7684\u5185\u90e8&#xff0c;\u4e0d\u540c\u57df\u4e2d\u7684 OU \u5c42\u6b21\u7ed3\u6784\u76f8\u4e92\u72ec\u7acb&#xff0c;\u5f7c\u6b64\u4e4b\u95f4\u65e0\u5173\u8054\u5173\u7cfb\u3002<\/p>\n<h3>\u57df\u6811<\/h3>\n<p>\u591a\u4e2a\u57df\u901a\u8fc7\u4fe1\u4efb\u5173\u7cfb\u5efa\u7acb\u8fde\u63a5\u540e&#xff0c;\u6240\u6709\u57df\u5c06\u5171\u4eab\u7edf\u4e00\u7684\u67b6\u6784&#xff08;Schema&#xff09;\u3001\u914d\u7f6e\u4fe1\u606f\u4e0e\u5168\u5c40\u76ee\u5f55&#xff08;Global Catalog&#xff09;&#xff0c;\u7531\u6b64\u5f62\u6210\u7684\u57df\u7ec4\u7ec7\u4f53\u7cfb\u5373\u4e3a\u57df\u6811\u3002\u57df\u6811\u7531\u591a\u4e2a\u57df\u6784\u6210&#xff0c;\u57df\u6811\u5185\u7684\u6240\u6709\u57df\u5171\u4eab\u76f8\u540c\u7684\u67b6\u6784\u4e0e\u914d\u7f6e\u4fe1\u606f&#xff0c;\u4e14\u5177\u5907\u8fde\u7eed\u7684\u540d\u5b57\u7a7a\u95f4&#xff0c;\u57df\u6811\u5185\u7684\u57df\u4e4b\u95f4\u901a\u8fc7\u4fe1\u4efb\u5173\u7cfb\u5b9e\u73b0\u4e92\u901a\u4e0e\u7ba1\u7406\u3002\u5728\u4e00\u4e2a Active Directory \u4e2d&#xff0c;\u53ef\u5305\u542b\u4e00\u68f5\u6216\u591a\u68f5\u57df\u6811\u3002<\/p>\n<h3>\u57df\u68ee\u6797<\/h3>\n<p>\u57df\u68ee\u6797\u662f\u7531\u4e00\u68f5\u6216\u591a\u68f5\u4e0d\u5177\u5907\u8fde\u7eed\u540d\u5b57\u7a7a\u95f4\u7684\u57df\u6811\u6784\u6210\u7684\u57df\u7ec4\u7ec7\u4f53\u7cfb\u3002\u57df\u68ee\u6797\u5185\u7684\u6240\u6709\u57df\u6811\u5171\u4eab\u7edf\u4e00\u7684\u67b6\u6784&#xff08;Schema&#xff09;\u3001\u914d\u7f6e\u4fe1\u606f\u4e0e\u5168\u5c40\u76ee\u5f55&#xff08;Global Catalog&#xff09;&#xff0c;\u57df\u6811\u4e4b\u95f4\u901a\u8fc7 Kerberos \u4fe1\u4efb\u5173\u7cfb\u5efa\u7acb\u8fde\u63a5&#xff0c;\u56e0\u6b64\u6bcf\u4e00\u68f5\u57df\u6811\u5747\u53ef\u8bc6\u522b\u68ee\u6797\u5185\u7684 Kerberos \u4fe1\u4efb\u5173\u7cfb&#xff0c;\u4e0d\u540c\u57df\u6811\u4e4b\u95f4\u53ef\u5b9e\u73b0\u5bf9\u8c61\u7684\u4ea4\u53c9\u5f15\u7528\u3002<\/p>\n<h3>Active Directory \u4e0e\u7ad9\u70b9\u7684\u5173\u7cfb<\/h3>\n<p>\u7ad9\u70b9\u662f Active Directory \u4e2d\u7684\u91cd\u8981\u6982\u5ff5&#xff0c;\u4e5f\u662f\u521d\u5b66\u8005\u6613\u4ea7\u751f\u7406\u89e3\u8bef\u533a\u7684\u5185\u5bb9&#xff0c;\u4e3b\u8981\u8bef\u533a\u96c6\u4e2d\u5728\u7ad9\u70b9\u4e0e\u57df\u7684\u533a\u522b\u3001\u4e8c\u8005\u7684\u7ba1\u7406\u8303\u56f4\u754c\u5b9a\u3001\u7ad9\u70b9\u5b58\u5728\u7684\u5b9e\u9645\u610f\u4e49\u7b49\u65b9\u9762&#xff0c;\u4e0b\u6587\u5c06\u5bf9\u7ad9\u70b9\u7684\u6982\u5ff5\u4e0e\u8bbe\u8ba1\u521d\u8877\u8fdb\u884c\u9610\u8ff0&#xff0c;\u660e\u786e\u7ad9\u70b9\u4e0e\u57df\u7684\u7ba1\u7406\u8fb9\u754c\u4e0e\u534f\u540c\u5173\u7cfb\u3002<\/p>\n<p>\u57df\u662f\u5171\u4eab\u7528\u6237\u8d26\u6237\u3001\u8ba1\u7b97\u673a\u8d26\u6237\u53ca\u5b89\u5168\u7b56\u7565\u7684\u4e00\u7ec4\u8ba1\u7b97\u673a&#xff0c;\u8be5\u5b9a\u4e49\u57fa\u4e8e\u7f51\u7edc\u903b\u8f91\u56e0\u7d20\u8fdb\u884c\u754c\u5b9a&#xff0c;\u53ea\u8981\u7528\u6237\u4e0e\u8ba1\u7b97\u673a\u5904\u4e8e\u540c\u4e00\u4e2a Active Directory \u5185&#xff0c;\u5373\u88ab\u7eb3\u5165\u57df\u7684\u5b89\u5168\u8fb9\u754c\u8303\u56f4\u3002\u4ece\u57df\u7684\u5b9a\u4e49\u53ef\u770b\u51fa&#xff0c;\u57df\u7684\u7ba1\u7406\u4f53\u7cfb\u672a\u8003\u8651\u7f51\u7edc\u4f20\u8f93\u901f\u7387\u7b49\u7269\u7406\u56e0\u7d20&#xff0c;\u65e0\u8bba\u8ba1\u7b97\u673a\u4e0e\u57df\u63a7\u5236\u5668\u4e4b\u95f4\u4e3a\u9ad8\u901f\u7269\u7406\u8fde\u63a5\u8fd8\u662f\u4f4e\u901f\u7269\u7406\u8fde\u63a5&#xff0c;\u57df\u7684\u7ba1\u7406\u7b56\u7565\u5747\u4fdd\u6301\u4e00\u81f4\u3002\u4f46\u5728\u5b9e\u9645\u7684\u4f01\u4e1a\u751f\u4ea7\u73af\u5883\u4e2d&#xff0c;\u82e5\u5ffd\u7565\u7f51\u7edc\u4f20\u8f93\u901f\u7387\u7684\u7269\u7406\u56e0\u7d20&#xff0c;\u57df\u7684\u7ba1\u7406\u5de5\u4f5c\u5c06\u51fa\u73b0\u8bf8\u591a\u6548\u7387\u95ee\u9898&#xff0c;\u4ee5\u4e0b\u901a\u8fc7\u5b9e\u9645\u6848\u4f8b\u8fdb\u884c\u8bf4\u660e&#xff1a;<\/p>\n<p>\u67d0\u57df\u7684\u57df\u63a7\u5236\u5668\u5206\u5e03\u4e8e\u5317\u4eac\u3001\u4e0a\u6d77\u4e24\u4e2a\u5730\u57df&#xff0c;\u5317\u4eac\u90e8\u7f72\u6709 A\u3001B\u3001C 3 \u53f0\u57df\u63a7\u5236\u5668&#xff0c;\u4e0a\u6d77\u90e8\u7f72\u6709 D\u3001E\u3001F 3 \u53f0\u57df\u63a7\u5236\u5668&#xff1b;\u5317\u4eac\u4e0e\u4e0a\u6d77\u7684\u672c\u5730\u5c40\u57df\u7f51\u5747\u4e3a\u5343\u5146\u4ee5\u592a\u7f51&#xff0c;\u4e24\u5730\u4e4b\u95f4\u901a\u8fc7 128 K \u7684\u4e13\u7ebf\u5b9e\u73b0\u7f51\u7edc\u8fde\u901a\u3002\u5f53\u57df\u63a7\u5236\u5668 A \u7684 Active Directory \u914d\u7f6e\u53d1\u751f\u66f4\u6539\u65f6&#xff0c;\u9700\u5c06\u8be5\u66f4\u6539\u540c\u6b65\u81f3\u5176\u4ed6 5 \u53f0\u57df\u63a7\u5236\u5668&#xff0c;\u4ece\u7f51\u7edc\u4f20\u8f93\u6548\u7387\u7684\u89d2\u5ea6&#xff0c;\u6700\u4f18\u7684\u540c\u6b65\u7b56\u7565\u4e3a&#xff1a;\u57df\u63a7\u5236\u5668 A \u5148\u5c06\u914d\u7f6e\u66f4\u6539\u540c\u6b65\u81f3\u540c\u5730\u57df\u7684 B\u3001C \u4e24\u53f0\u57df\u63a7\u5236\u5668&#xff0c;\u518d\u901a\u8fc7\u8de8\u5730\u57df\u4e13\u7ebf\u5c06\u914d\u7f6e\u66f4\u6539\u540c\u6b65\u81f3\u4e0a\u6d77\u7684\u57df\u63a7\u5236\u5668 D&#xff0c;\u6700\u540e\u7531\u57df\u63a7\u5236\u5668 D \u540c\u6b65\u81f3\u4e0a\u6d77\u7684 E\u3001F \u4e24\u53f0\u57df\u63a7\u5236\u5668\u3002\u8be5\u7b56\u7565\u4ec5\u9700\u901a\u8fc7\u8de8\u5730\u57df\u4f4e\u901f\u94fe\u8def\u5b8c\u6210\u4e00\u6b21\u6570\u636e\u4f20\u8f93&#xff0c;\u53ef\u6700\u5927\u9650\u5ea6\u63d0\u5347\u540c\u6b65\u6548\u7387\u3002<\/p>\n<p>\u82e5\u57df\u7684\u7ba1\u7406\u4f53\u7cfb\u4e0d\u8003\u8651\u7f51\u7edc\u4f20\u8f93\u901f\u7387&#xff0c;\u77e5\u8bc6\u4e00\u81f4\u6027\u68c0\u67e5\u5668&#xff08;KCC&#xff09;\u89c4\u5212\u7684\u590d\u5236\u62d3\u6251\u53ef\u80fd\u51fa\u73b0\u975e\u6700\u4f18\u7684\u60c5\u51b5&#xff0c;\u4f8b\u5982\u540c\u6b65\u987a\u5e8f\u4e3a A\u2192D\u2192B\u2192E\u2192C\u2192F&#xff0c;\u8be5\u79cd\u62d3\u6251\u9700\u901a\u8fc7\u8de8\u5730\u57df\u4f4e\u901f\u94fe\u8def\u5b8c\u6210 5 \u6b21\u6570\u636e\u4f20\u8f93&#xff0c;\u5927\u5e45\u964d\u4f4e Active Directory \u914d\u7f6e\u7684\u540c\u6b65\u6548\u7387\u3002\u9664\u6b64\u4e4b\u5916&#xff0c;\u7528\u6237\u65e5\u5e38\u7684\u57df\u767b\u5f55\u8eab\u4efd\u9a8c\u8bc1\u4e5f\u4f1a\u53d7\u6b64\u5f71\u54cd&#xff0c;\u82e5\u5317\u4eac\u7684\u7528\u6237\u901a\u8fc7\u4e0a\u6d77\u7684\u57df\u63a7\u5236\u5668\u5b8c\u6210\u8eab\u4efd\u9a8c\u8bc1&#xff0c;\u5c06\u663e\u8457\u964d\u4f4e\u767b\u5f55\u6548\u7387\u3002<\/p>\n<p>\u7531\u6b64\u53ef\u89c1&#xff0c;\u5728\u57df\u7684\u5b9e\u9645\u8fd0\u7ef4\u5de5\u4f5c\u4e2d&#xff0c;\u7f51\u7edc\u4f20\u8f93\u901f\u7387\u7684\u7269\u7406\u56e0\u7d20\u65e0\u6cd5\u88ab\u5ffd\u7565&#xff0c;\u5fae\u8f6f\u56e0\u6b64\u5f15\u5165\u7ad9\u70b9\u7684\u6982\u5ff5&#xff0c;\u5b9e\u73b0\u5bf9\u8ba1\u7b97\u673a\u7684\u7269\u7406\u7ef4\u5ea6\u7ba1\u7406\u3002\u7ad9\u70b9\u7684\u5b9a\u4e49\u4e3a&#xff1a;\u7531\u9ad8\u901f\u7f51\u7edc\u8fde\u63a5\u7684\u4e00\u7ec4\u8ba1\u7b97\u673a&#xff0c;\u8be5\u6982\u5ff5\u7a81\u51fa\u4e86\u7f51\u7edc\u4f20\u8f93\u901f\u7387\u7684\u7269\u7406\u56e0\u7d20&#xff0c;\u800c\u57df\u7684\u6982\u5ff5\u5219\u7a81\u51fa\u4e86 Active Directory \u5171\u4eab\u7684\u903b\u8f91\u56e0\u7d20&#xff0c;\u5c06\u7ad9\u70b9\u4e0e\u57df\u7ed3\u5408&#xff0c;\u53ef\u4ece\u7269\u7406\u4e0e\u903b\u8f91\u4e24\u4e2a\u7ef4\u5ea6\u5b9e\u73b0\u5bf9\u8ba1\u7b97\u673a\u7684\u5168\u65b9\u4f4d\u7ba1\u7406\u3002\u8be5\u79cd\u7ba1\u7406\u601d\u8def\u5728\u5fae\u8f6f\u7684\u5176\u4ed6\u4ea7\u54c1\u4e2d\u4e5f\u6709\u5e94\u7528&#xff0c;\u4f8b\u5982 Exchange \u4e2d\u7684\u7ba1\u7406\u7ec4\u4e0e\u8def\u7531\u7ec4&#xff0c;\u7ba1\u7406\u7ec4\u5bf9\u5e94\u903b\u8f91\u7ef4\u5ea6\u7684\u7ba1\u7406&#xff0c;\u8def\u7531\u7ec4\u5bf9\u5e94\u7269\u7406\u7ef4\u5ea6\u7684\u7ba1\u7406&#xff0c;\u4e0e\u57df\u548c\u7ad9\u70b9\u7684\u7ba1\u7406\u903b\u8f91\u4e00\u81f4\u3002<\/p>\n<p>\u57fa\u4e8e\u7ad9\u70b9\u7684\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u53ef\u6709\u6548\u89e3\u51b3\u4e0a\u8ff0\u57df\u7ba1\u7406\u4e2d\u7684\u6548\u7387\u95ee\u9898&#xff1a;\u6839\u636e\u5317\u4eac\u4e0e\u4e0a\u6d77\u4e4b\u95f4\u7684\u4f4e\u901f\u94fe\u8def&#xff0c;\u5c06\u5317\u4eac\u7684\u8ba1\u7b97\u673a\u5212\u5206\u4e3a\u4e00\u4e2a\u7ad9\u70b9&#xff0c;\u4e0a\u6d77\u7684\u8ba1\u7b97\u673a\u5212\u5206\u4e3a\u53e6\u4e00\u4e2a\u7ad9\u70b9\u3002\u7ad9\u70b9\u7684\u7ba1\u7406\u673a\u5236\u53ef\u5b9e\u73b0\u4e24\u9879\u4f18\u5316&#xff1a;\u4e00\u662f\u7528\u6237\u767b\u5f55\u65f6&#xff0c;\u5c06\u4f18\u5148\u9009\u62e9\u672c\u7ad9\u70b9\u5185\u7684\u57df\u63a7\u5236\u5668\u5b8c\u6210\u8eab\u4efd\u9a8c\u8bc1&#xff1b;\u4e8c\u662f\u77e5\u8bc6\u4e00\u81f4\u6027\u68c0\u67e5\u5668&#xff08;KCC&#xff09;\u5728\u89c4\u5212\u590d\u5236\u62d3\u6251\u65f6&#xff0c;\u5c06\u4f18\u5148\u5b8c\u6210\u672c\u7ad9\u70b9\u5185\u57df\u63a7\u5236\u5668\u7684 Active Directory \u590d\u5236&#xff0c;\u518d\u8fdb\u884c\u8de8\u7ad9\u70b9\u7684\u590d\u5236\u64cd\u4f5c\u3002\u540c\u65f6&#xff0c;\u8de8\u7ad9\u70b9\u7684 Active Directory \u590d\u5236\u4f1a\u5bf9\u6570\u636e\u8fdb\u884c\u538b\u7f29\u5904\u7406&#xff0c;\u53ef\u6709\u6548\u51cf\u5c11\u4f4e\u901f\u94fe\u8def\u7684\u7f51\u7edc\u6570\u636e\u4f20\u8f93\u91cf&#xff0c;\u63d0\u5347\u8de8\u7ad9\u70b9\u590d\u5236\u7684\u6548\u7387\u3002<\/p>\n<hr \/>\n<h2>\u57df\u3001\u57df\u6811\u3001\u57df\u6797\u3001\u6839\u57df<\/h2>\n<p>FLy_\u9e4f\u7a0b\u4e07\u91cc \u8f6c\u8f7d\u4e8e 2018-06-14 13:03:29 \u53d1\u5e03<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27jvx4juyvozm.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p>\u5982\u56fe\u6240\u793a&#xff0c;contoso \u516c\u53f8\u7684 IT \u73af\u5883\u4e2d\u5b58\u5728\u591a\u79cd\u7c7b\u578b\u7684 IT \u8d44\u6e90&#xff0c;\u4e14\u6240\u6709\u8d44\u6e90\u5747\u5904\u4e8e\u5206\u6563\u5f0f\u7ba1\u7406\u7684\u72b6\u6001&#xff0c;\u8be5\u79cd\u7ba1\u7406\u6a21\u5f0f\u4e0d\u4ec5\u589e\u52a0\u4e86\u4f01\u4e1a\u7684 IT \u7ba1\u7406\u6210\u672c&#xff0c;\u8fd8\u5bfc\u81f4\u4f01\u4e1a\u7684\u7ba1\u7406\u5236\u5ea6\u65e0\u6cd5\u5728\u751f\u4ea7\u73af\u5883\u4e2d\u843d\u5730\u6267\u884c\u3002<\/p>\n<p>\u9488\u5bf9 IT \u8d44\u6e90\u5206\u6563\u5f0f\u7ba1\u7406\u7684\u95ee\u9898&#xff0c;\u9700\u5efa\u7acb\u4e00\u79cd\u903b\u8f91\u5c42\u9762\u7684\u96c6\u4e2d\u5316\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u5982\u540c\u4e0d\u540c\u5730\u57df\u3001\u4e0d\u540c\u793e\u4f1a\u5173\u7cfb\u7684\u4e2a\u4f53&#xff0c;\u5747\u5f52\u5c5e\u4e8e\u540c\u4e00\u56fd\u5bb6\u7684\u903b\u8f91\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u901a\u8fc7\u56fd\u5bb6\u7684\u903b\u8f91\u8fb9\u754c\u5b9e\u73b0\u5bf9\u5883\u5185\u7269\u7406\u8d44\u6e90\u4e0e\u4eba\u5458\u7684\u7edf\u4e00\u7ba1\u7406&#xff0c;\u4f01\u4e1a\u7684 IT \u8d44\u6e90\u4e5f\u53ef\u901a\u8fc7\u8be5\u79cd\u903b\u8f91\u96c6\u4e2d\u5316\u7684\u65b9\u5f0f\u5b9e\u73b0\u7ba1\u7406\u4f18\u5316\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27ezhroofgx2v.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27kl2rgbh0bwa.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p>\u57df\u7684\u6982\u5ff5\u6b63\u662f\u57fa\u4e8e\u4f01\u4e1a IT \u8d44\u6e90\u7684\u903b\u8f91\u96c6\u4e2d\u5316\u7ba1\u7406\u9700\u6c42\u63d0\u51fa&#xff0c;\u901a\u8fc7\u57df\u53ef\u5c06\u4f01\u4e1a IT \u73af\u5883\u4e2d\u7684\u6240\u6709\u8d44\u6e90\u7eb3\u5165\u7edf\u4e00\u7684\u903b\u8f91\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u5b9e\u73b0\u8d44\u6e90\u7684\u96c6\u4e2d\u5316\u7ba1\u7406\u3002contoso \u516c\u53f8\u901a\u8fc7\u521b\u5efa contoso.com \u57df&#xff0c;\u89e3\u51b3\u4e86\u4f01\u4e1a\u5185\u90e8 IT \u8d44\u6e90\u7684\u5206\u6563\u7ba1\u7406\u95ee\u9898&#xff0c;\u6709\u6548\u964d\u4f4e\u4e86\u4f01\u4e1a\u7684 IT \u7ba1\u7406\u6210\u672c\u3002<\/p>\n<p>\u968f\u7740\u4f01\u4e1a\u4e1a\u52a1\u7684\u53d1\u5c55&#xff0c;contoso \u516c\u53f8\u5728\u5317\u4eac\u3001\u4e0a\u6d77\u8bbe\u7acb\u4e86\u5b50\u516c\u53f8&#xff0c;\u8de8\u5730\u57df\u7684\u4e1a\u52a1\u5e03\u5c40\u4f7f IT \u8d44\u6e90\u7684\u7ba1\u7406\u8303\u56f4\u8fdb\u4e00\u6b65\u6269\u5927&#xff0c;\u5206\u6563\u5f0f\u7684\u7ba1\u7406\u6a21\u5f0f\u518d\u6b21\u663e\u73b0\u51fa\u5c40\u9650\u6027&#xff0c;\u6b64\u65f6\u53ef\u901a\u8fc7\u57df\u7684\u5c42\u7ea7\u5316\u6269\u5c55\u5b9e\u73b0\u8de8\u5730\u57df IT \u8d44\u6e90\u7684\u96c6\u4e2d\u7ba1\u7406\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27l1d5umc3cqv.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p>\u4ee5 contoso.com \u4e3a\u7236\u57df&#xff0c;\u4e3a\u5317\u4eac\u3001\u4e0a\u6d77\u5b50\u516c\u53f8\u5206\u522b\u521b\u5efa bj.contoso.com \u4e0e sh.contoso.com \u5b50\u57df&#xff0c;\u5b50\u57df\u7684\u57df\u540d\u4e0e\u7236\u57df\u7684\u57df\u540d\u5177\u5907\u8fde\u7eed\u7684\u540d\u5b57\u7a7a\u95f4&#xff0c;\u7236\u57df\u4e0e\u5b50\u57df\u4e4b\u95f4\u5f62\u6210\u7236\u5b50\u7ea7\u7684\u57df\u7ba1\u7406\u5173\u7cfb\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27swcpv3ncrzp.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p>\u7531\u7236\u57df\u4e0e\u82e5\u5e72\u5b50\u57df\u901a\u8fc7\u4fe1\u4efb\u5173\u7cfb\u6784\u5efa\u7684\u3001\u5177\u5907\u8fde\u7eed\u540d\u5b57\u7a7a\u95f4\u7684\u57df\u7ec4\u7ec7\u4f53\u7cfb&#xff0c;\u5373\u4e3a\u57df\u6811\u3002\u901a\u8fc7\u57df\u6811\u7684\u7ba1\u7406\u6a21\u5f0f&#xff0c;contoso \u516c\u53f8\u5b9e\u73b0\u4e86\u5bf9\u8de8\u5730\u57df\u5206\u652f\u673a\u6784 IT \u8d44\u6e90\u7684\u96c6\u4e2d\u5316\u7ba1\u7406&#xff0c;\u8fdb\u4e00\u6b65\u964d\u4f4e\u4e86\u4f01\u4e1a\u7684\u7ba1\u7406\u6210\u672c\u3002<\/p>\n<p>\u4f01\u4e1a\u5728\u53d1\u5c55\u8fc7\u7a0b\u4e2d&#xff0c;\u5e38\u4f1a\u5f00\u5c55\u591a\u9879\u76ee\u7684\u8fd0\u8425\u6a21\u5f0f&#xff0c;\u4e14\u4e3a\u4e0d\u540c\u9879\u76ee\u914d\u7f6e\u72ec\u7acb\u7684\u7ba1\u7406\u56e2\u961f\u4e0e\u7ba1\u7406\u673a\u5236&#xff0c;\u8be5\u79cd\u6a21\u5f0f\u53ef\u63d0\u5347\u4f01\u4e1a\u7ecf\u8425\u7684\u53ef\u9760\u6027&#xff0c;\u964d\u4f4e\u5355\u4e00\u9879\u76ee\u8fd0\u8425\u7684\u98ce\u9669\u3002\u591a\u9879\u76ee\u8fd0\u8425\u6a21\u5f0f\u4e0b&#xff0c;\u4f01\u4e1a\u9700\u8981\u4e00\u79cd\u53ef\u517c\u987e\u96c6\u4e2d\u7ba1\u7406\u4e0e\u9879\u76ee\u72ec\u7acb\u6027\u7684 IT \u8d44\u6e90\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u57df\u73af\u5883\u7684\u6269\u5c55\u7279\u6027\u53ef\u6ee1\u8db3\u8be5\u79cd\u9700\u6c42\u3002<\/p>\n<p>contoso \u516c\u53f8\u5728\u8fd0\u8425\u4e3b\u9879\u76ee\u7684\u540c\u65f6&#xff0c;\u5f00\u5c55\u4e86 seattle \u9879\u76ee\u7684\u8fd0\u8425&#xff0c;\u4e3a\u8be5\u9879\u76ee\u521b\u5efa\u72ec\u7acb\u7684 seattle.com \u57df&#xff0c;\u8be5\u57df\u4e0e contoso.com \u57df\u540c\u5c5e contoso \u516c\u53f8\u7684\u57df\u68ee\u6797\u7ba1\u7406\u4f53\u7cfb&#xff0c;\u4e8c\u8005\u7684\u57df\u540d\u4e0d\u5177\u5907\u8fde\u7eed\u7684\u540d\u5b57\u7a7a\u95f4&#xff0c;\u4f46\u53ef\u901a\u8fc7\u57df\u68ee\u6797\u5b9e\u73b0\u96c6\u4e2d\u5316\u7ba1\u7406\u3002\u8be5\u79cd\u6a21\u5f0f\u65e2\u901a\u8fc7\u57df\u68ee\u6797\u5b9e\u73b0\u4e86\u4f01\u4e1a\u5bf9\u591a\u9879\u76ee IT \u8d44\u6e90\u7684\u7edf\u4e00\u7ba1\u7406&#xff0c;\u53c8\u901a\u8fc7\u72ec\u7acb\u7684\u57df\u4fdd\u8bc1\u4e86 seattle \u9879\u76ee\u7684\u7ba1\u7406\u72ec\u7acb\u6027\u3002\u540e\u7eed seattle \u9879\u76ee\u8bbe\u7acb\u4e86\u5206\u652f\u673a\u6784&#xff0c;\u4e3a\u5176\u521b\u5efa work.seattle.com \u5b50\u57df&#xff0c;\u5f62\u6210\u4e86 seattle \u9879\u76ee\u72ec\u7acb\u7684\u57df\u6811\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-274kg5ztzi3z2.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p>\u7531\u4e00\u68f5\u6216\u591a\u68f5\u4e0d\u5177\u5907\u8fde\u7eed\u540d\u5b57\u7a7a\u95f4\u7684\u57df\u6811\u6784\u6210\u7684\u57df\u7ec4\u7ec7\u4f53\u7cfb&#xff0c;\u5373\u4e3a\u57df\u6797&#xff08;\u57df\u68ee\u6797&#xff09;\u3002<\/p>\n<p>\u4f01\u4e1a\u591a\u9879\u76ee\u8fd0\u8425\u6a21\u5f0f\u4e0b&#xff0c;\u4e3b\u8425\u9879\u76ee\u5728 IT \u73af\u5883\u7ba1\u7406\u4e2d\u9700\u5177\u5907\u4f18\u5148\u6027&#xff0c;\u57df\u73af\u5883\u901a\u8fc7\u6839\u57df\u7684\u8bbe\u7f6e\u5b9e\u73b0\u8be5\u79cd\u7ba1\u7406\u9700\u6c42\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-274izlqonxwra.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p>\u5728\u57df\u68ee\u6797\u4e2d&#xff0c;\u7b2c\u4e00\u4e2a\u88ab\u521b\u5efa\u7684\u57df\u88ab\u79f0\u4e3a\u6839\u57df&#xff0c;\u6839\u57df\u5728\u57df\u68ee\u6797\u7684\u7ba1\u7406\u4f53\u7cfb\u4e2d\u5177\u5907\u72ec\u7279\u7684\u7ba1\u7406\u5c5e\u6027&#xff0c;\u4e14\u4e00\u4e2a\u57df\u68ee\u6797\u4e2d\u4ec5\u80fd\u5b58\u5728\u4e00\u4e2a\u6839\u57df&#xff0c;\u901a\u8fc7\u6839\u57df\u53ef\u5b9e\u73b0\u4f01\u4e1a\u4e3b\u8425\u9879\u76ee\u5728 IT \u73af\u5883\u7ba1\u7406\u4e2d\u7684\u4f18\u5148\u6027\u7ba1\u63a7&#xff0c;\u6ee1\u8db3\u4f01\u4e1a\u591a\u9879\u76ee\u8fd0\u8425\u7684\u98ce\u9669\u7ba1\u63a7\u4e0e\u7ba1\u7406\u9700\u6c42\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27pmxxchbdkln.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p>\u5728\u591a\u57df\u73af\u5883\u7684\u7ba1\u7406\u4e2d&#xff0c;\u53ef\u901a\u8fc7\u57df\u63a7\u5236\u5668\u7684\u7ec4\u914d\u7f6e\u7279\u5f81\u5feb\u901f\u8bc6\u522b\u6839\u57df&#xff1a;\u6839\u57df\u7684\u57df\u63a7\u5236\u5668\u4e2d\u4f1a\u5b58\u5728\u4e24\u4e2a\u7279\u6b8a\u7684\u7528\u6237\u7ec4&#xff0c;\u5206\u522b\u4e3aEnterprise Admins\u4e0eSchema Admins&#xff0c;\u800c\u57df\u68ee\u6797\u4e2d\u5176\u4ed6\u57df\u7684\u57df\u63a7\u5236\u5668\u4e2d&#xff0c;\u5747\u4e0d\u4f1a\u5b58\u5728\u8fd9\u4e24\u4e2a\u7528\u6237\u7ec4\u3002<\/p>\n<p>\u4ee5\u4e0a\u4e3a\u57df\u3001\u57df\u6811\u3001\u57df\u6797\u3001\u6839\u57df\u7684\u6982\u5ff5\u4e0e\u7ba1\u7406\u7279\u5f81\u9610\u8ff0&#xff0c;\u53ef\u5e2e\u52a9\u7ba1\u7406\u4eba\u5458\u7406\u89e3\u57df\u73af\u5883\u5728\u4f01\u4e1a IT \u8d44\u6e90\u7ba1\u7406\u4e2d\u7684\u5e94\u7528\u65b9\u5f0f\u3002\u5173\u4e8e\u591a\u57df\u4f01\u4e1a\u7ba1\u7406\u73af\u5883\u7684\u642d\u5efa\u65b9\u6cd5&#xff0c;\u5c06\u5728\u540e\u7eed\u5185\u5bb9\u4e2d\u8fdb\u884c\u8be6\u7ec6\u8bf4\u660e\u3002<\/p>\n<hr \/>\n<h2>\u5173\u4e8e\u6d3b\u52a8\u76ee\u5f55\u57df\u3001\u57df\u6811\u3001\u57df\u6797\u3001\u5b50\u57df<\/h2>\n<p>\u6df1\u6d77\u5929\u54e5 \u4e8e 2020-03-22 21:19:36 \u53d1\u5e03<\/p>\n<h3>1 \u6982\u5ff5\u89e3\u91ca\u4e0e\u6280\u672f\u9009\u578b<\/h3>\n<h4>1.1 \u57fa\u672c\u6982\u5ff5\u754c\u5b9a<\/h4>\n<li>\u6d3b\u52a8\u76ee\u5f55\u57df&#xff1a;\u4e00\u79cd\u57fa\u4e8e Windows \u7cfb\u7edf\u7684\u7f51\u7edc\u8ba1\u7b97\u673a\u7ba1\u7406\u6a21\u5f0f&#xff0c;\u901a\u8fc7\u96c6\u4e2d\u5316\u7684\u7ba1\u7406\u4f53\u7cfb\u5b9e\u73b0\u4f01\u4e1a\u7f51\u7edc\u8d44\u6e90\u4e0e\u7528\u6237\u7684\u7edf\u4e00\u7ba1\u7406&#xff1b;<\/li>\n<li>\u57df\u6811&#xff1a;\u7531\u7236\u57df\u4e0e\u82e5\u5e72\u5b50\u57df\u6784\u6210&#xff0c;\u4e14\u6240\u6709\u57df\u5177\u5907\u8fde\u7eed\u540d\u5b57\u7a7a\u95f4\u7684\u591a\u57df\u7f51\u7edc\u7ba1\u7406\u6a21\u5f0f&#xff0c;\u57df\u6811\u5185\u7684\u57df\u901a\u8fc7\u4fe1\u4efb\u5173\u7cfb\u5b9e\u73b0\u4e92\u901a&#xff1b;<\/li>\n<li>\u57df\u6797&#xff1a;\u7531\u4e00\u68f5\u6216\u591a\u68f5\u4e0d\u5177\u5907\u8fde\u7eed\u540d\u5b57\u7a7a\u95f4\u7684\u57df\u6811\u6784\u6210\u7684 Windows \u57df\u7f51\u7edc\u7ba1\u7406\u6a21\u5f0f&#xff0c;\u57df\u6797\u5185\u7684\u6240\u6709\u57df\u6811\u5171\u4eab\u7edf\u4e00\u7684\u67b6\u6784\u4e0e\u914d\u7f6e\u4fe1\u606f&#xff1b;<\/li>\n<li>\u5b50\u57df&#xff1a;\u76f8\u5bf9\u7236\u57df\u800c\u8a00\u7684\u57df\u6982\u5ff5&#xff0c;\u6307\u57df\u540d\u4e2d\u7684\u5206\u6bb5\u90e8\u5206&#xff0c;\u5404\u5206\u6bb5\u4e4b\u95f4\u4ee5\u5c0f\u6570\u70b9\u5206\u9694&#xff1b;\u4f4d\u4e8e\u57df\u540d\u672b\u5c3e\u7684\u5b50\u57df\u4e3a\u4e00\u7ea7\u57df&#xff08;\u6700\u9ad8\u7ea7\u5b50\u57df&#xff09;&#xff0c;\u4f4d\u4e8e\u4e00\u7ea7\u57df\u524d\u65b9\u7684\u5b50\u57df\u4e3a\u4e8c\u7ea7\u57df&#xff0c;\u4ee5\u6b64\u7c7b\u63a8\u3002<\/li>\n<h4>1.2 \u5206\u652f\u673a\u6784\u6280\u672f\u9009\u578b<\/h4>\n<p>\u5de5\u7a0b\u5e08\u5728 winsnet.com \u57df\u7f51\u7edc\u7684\u57fa\u7840\u4e0a&#xff0c;\u4e3a\u5916\u57df\u65b0\u7ec4\u5efa\u7684\u5b50\u516c\u53f8\u8bbe\u8ba1\u6d3b\u52a8\u76ee\u5f55\u57df\u7f51\u7edc\u7ba1\u7406\u65b9\u6848\u65f6&#xff0c;\u5e94\u9009\u62e9\u57df\u6811\u7684\u7f51\u7edc\u7ba1\u7406\u6a21\u5f0f&#xff0c;\u901a\u8fc7\u4e3a\u5b50\u516c\u53f8\u521b\u5efa\u5b50\u57df&#xff0c;\u5f62\u6210\u4ee5 winsnet.com \u4e3a\u7236\u57df\u7684\u57df\u6811&#xff0c;\u5b9e\u73b0\u603b\u516c\u53f8\u5bf9\u5b50\u516c\u53f8 IT \u8d44\u6e90\u7684\u96c6\u4e2d\u5316\u7ba1\u7406\u4e0e\u8de8\u5730\u57df\u8d44\u6e90\u4e92\u901a\u3002<\/p>\n<h3>2 \u5b9e\u9a8c\u6b65\u9aa4<\/h3>\n<p>\u672c\u5b9e\u9a8c\u5206\u522b\u5728 Windows Server 2008 R2\u3001Windows Server 2012 \u5e73\u53f0\u5b8c\u6210&#xff0c;\u5b9e\u9a8c\u76ee\u6807\u4e3a\u5c06\u4e00\u53f0\u5168\u65b0\u7684 Windows Server 2008 R2 \u670d\u52a1\u5668\u914d\u7f6e\u4e3a\u57df\u63a7\u5236\u5668&#xff0c;\u540c\u65f6\u5b8c\u6210\u5ba2\u6237\u7aef\u52a0\u5165\u57df\u3001\u57df\u7528\u6237\u7ba1\u7406\u3001\u57df\u7ec4\u7ba1\u7406\u7b49\u64cd\u4f5c\u3002<\/p>\n<h4>2.1 \u5b9e\u9a8c\u73af\u5883\u51c6\u5907<\/h4>\n<p>\u6253\u5f00\u5168\u65b0\u7684 Windows Server 2008 R2 \u865a\u62df\u673a&#xff0c;\u901a\u8fc7\u5feb\u7167\u8fd8\u539f\u81f3\u201c\u7cfb\u7edf\u5b89\u88c5\u201d\u72b6\u6001&#xff0c;\u4e3a\u540e\u7eed\u57df\u63a7\u5236\u5668\u914d\u7f6e\u505a\u51c6\u5907\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27j3c1djsoiws.png\" alt=\"img\" width=\"600\" \/><\/p>\n<h4>2.2 \u670d\u52a1\u5668 TCP\/IP \u53c2\u6570\u914d\u7f6e<\/h4>\n<p>\u4e3a\u670d\u52a1\u5668\u914d\u7f6e TCP\/IP \u9759\u6001\u53c2\u6570&#xff0c;\u5177\u4f53\u914d\u7f6e\u8981\u6c42\u5982\u4e0b&#xff1a;<\/p>\n<li>IP \u5730\u5740\u914d\u7f6e\u4e3a 192.168.1.X&#xff0c;\u5176\u4e2d X \u4e3a\u5b9e\u9a8c\u5ba4\u8ba1\u7b97\u673a\u7f16\u53f7&#xff1b;<\/li>\n<li>DNS \u670d\u52a1\u5668 IP \u5730\u5740\u914d\u7f6e\u4e3a 192.168.1.X&#xff0c;\u672c\u5b9e\u9a8c\u4e2d\u57df\u63a7\u5236\u5668\u4e0e DNS \u670d\u52a1\u5668\u90e8\u7f72\u5728\u540c\u4e00\u53f0\u8ba1\u7b97\u673a\u3002<\/li>\n<h4>2.3 \u57df\u63a7\u5236\u5668\u5347\u7ea7\u914d\u7f6e<\/h4>\n<p>\u901a\u8fc7\u8fd0\u884c dcpromo \u547d\u4ee4&#xff0c;\u5c06\u8be5\u670d\u52a1\u5668\u5347\u7ea7\u4e3a winsnet.com \u57df\u7684\u57df\u63a7\u5236\u5668&#xff0c;\u5176\u4e2d\u57df\u540d\u4e2d\u7684 X \u4e3a\u5b9e\u9a8c\u5ba4\u8ba1\u7b97\u673a\u7f16\u53f7&#xff0c;\u5177\u4f53\u64cd\u4f5c\u6b65\u9aa4\u5bf9\u5e94\u4ee5\u4e0b\u622a\u56fe&#xff1a;<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27kw3xllltzr0.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-274gwse2fcffc.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27lglquzdeubu.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27bs4t5l3ejif.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27wuch1vumdio.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27rjjnruehne2.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27uywmr5losns.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27ubjjlhz10pu.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-273oiovo2330i.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27h4ytpigk5cq.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27ibnjhnaedm4.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27hgkxq4uuh45.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27q42hh2h2ofc.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27mrpxb4tducy.png\" alt=\"img\" width=\"600\" \/><\/p>\n<h4>2.4 \u57df\u7528\u6237\u521b\u5efa<\/h4>\n<p>\u5728\u57df\u63a7\u5236\u5668\u4e2d\u521b\u5efa\u57df\u7528\u6237 user01&#xff0c;\u8be5\u8d26\u6237\u4f5c\u4e3a\u5ba2\u6237\u7aef\u52a0\u5165\u57df\u7684\u8ba4\u8bc1\u51ed\u8bc1&#xff0c;\u5177\u4f53\u64cd\u4f5c\u622a\u56fe\u5982\u4e0b&#xff1a;<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27khh244ooi5i.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-275phd32ezfre.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27z14qp5saht3.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27nmgut1r0asx.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27lqggn5h5whn.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-275uctd1k2o5w.png\" alt=\"img\" width=\"600\" \/><\/p>\n<h4>2.5 \u57df\u7528\u6237\u767b\u5f55\u65f6\u95f4\u914d\u7f6e<\/h4>\n<p>\u4e3a user01 \u7528\u6237\u914d\u7f6e\u767b\u5f55\u65f6\u95f4\u9650\u5236&#xff0c;\u4ec5\u5141\u8bb8\u8be5\u7528\u6237\u5728\u6bcf\u65e5\u65e9\u4e0a 8&#xff1a;00-12&#xff1a;00\u3001\u4e0b\u5348 15&#xff1a;00-18&#xff1a;00 \u5b8c\u6210\u57df\u767b\u5f55\u64cd\u4f5c&#xff0c;\u5177\u4f53\u914d\u7f6e\u622a\u56fe\u5982\u4e0b&#xff1a;<\/p>\n<p><img decoding=\"async\" src=\"2026-01-27d3qujnnv4te.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27a0k2mpas5yg.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27cynx3otxgys.png\" alt=\"img\" width=\"600\" \/><\/p>\n<h4>2.6 \u5ba2\u6237\u7aef\u52a0\u5165\u57df\u914d\u7f6e<\/h4>\n<p>\u51c6\u5907\u4e24\u53f0\u5b89\u88c5\u5ba2\u6237\u7aef\u64cd\u4f5c\u7cfb\u7edf\u7684\u865a\u62df\u673a&#xff0c;\u4e00\u53f0\u4e3a Windows XP \u7cfb\u7edf&#xff0c;\u4e00\u53f0\u4e3a Windows 7 \u7cfb\u7edf&#xff0c;\u4e3a\u4e24\u53f0\u5ba2\u6237\u7aef\u914d\u7f6e IP \u5730\u5740\u4e0e DNS \u670d\u52a1\u5668\u5730\u5740&#xff08;\u5747\u6307\u5411 192.168.1.X&#xff09;&#xff0c;\u968f\u540e\u5b8c\u6210\u57df\u52a0\u5165\u64cd\u4f5c&#xff0c;\u5177\u4f53\u6b65\u9aa4\u5982\u4e0b&#xff1a;<\/p>\n<li>Windows XP \u5ba2\u6237\u7aef\u52a0\u5165\u57df<\/li>\n<p><img decoding=\"async\" src=\"2026-01-27ds5hlnczd2s.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27tzuz43jqzko.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27cvrtltj0051.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27woyxgfzk23b.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27bwbechfc2d3.png\" alt=\"img\" width=\"600\" \/><\/p>\n<li>Windows 7 \u5ba2\u6237\u7aef\u52a0\u5165\u57df<\/li>\n<p><img decoding=\"async\" src=\"2026-01-27xcyoryc4ips.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27rjvqfmbz22w.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27aw03oatuhdi.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27svy3ndzf3ce.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27jz44s2yovjc.png\" alt=\"img\" width=\"600\" \/><\/p>\n<li>\u57df\u63a7\u5236\u5668\u9a8c\u8bc1 \u4e24\u53f0\u5ba2\u6237\u7aef\u6210\u529f\u52a0\u5165\u57df\u540e&#xff0c;\u53ef\u5728\u57df\u63a7\u5236\u5668\u7684 Active Directory \u4e2d\u67e5\u770b\u5230\u5bf9\u5e94\u7684\u8ba1\u7b97\u673a\u4fe1\u606f&#xff0c;\u622a\u56fe\u5982\u4e0b&#xff1a;<\/li>\n<p><img decoding=\"async\" src=\"2026-01-27b0cab3l2bjv.png\" alt=\"img\" width=\"600\" \/><\/p>\n<h4>2.7 \u57df\u7528\u6237\u767b\u5f55\u6743\u9650\u9a8c\u8bc1<\/h4>\n<p>\u5728\u975e\u6388\u6743\u65f6\u95f4\u5185&#xff0c;\u4f7f\u7528 user01 \u8d26\u6237\u5728 Windows XP \u4e0e Windows 7 \u5ba2\u6237\u7aef\u5c1d\u8bd5\u5b8c\u6210\u57df\u767b\u5f55&#xff0c;\u7cfb\u7edf\u5c06\u63d0\u793a\u767b\u5f55\u65f6\u95f4\u9650\u5236\u5e76\u62d2\u7edd\u767b\u5f55&#xff0c;\u9a8c\u8bc1\u622a\u56fe\u5982\u4e0b&#xff1a;<\/p>\n<p><img decoding=\"async\" src=\"2026-01-271hjsweljl5z.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27pl1pyi414fk.png\" alt=\"img\" width=\"600\" \/><\/p>\n<h4>2.8 \u57df\u672c\u5730\u7ec4\u521b\u5efa\u4e0e\u7528\u6237\u6dfb\u52a0<\/h4>\n<p>\u5728\u57df\u63a7\u5236\u5668\u4e2d\u521b\u5efa\u57df\u672c\u5730\u7ec4 shichangs&#xff0c;\u5e76\u5c06 user01 \u7528\u6237\u6dfb\u52a0\u81f3\u8be5\u7ec4\u7684\u6210\u5458\u5217\u8868&#xff0c;\u5177\u4f53\u64cd\u4f5c\u6b65\u9aa4\u5982\u4e0b&#xff1a;<\/p>\n<li>\u57df\u672c\u5730\u7ec4 shichangs \u521b\u5efa<\/li>\n<p><img decoding=\"async\" src=\"2026-01-27y0p5k0furdu.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27zf52o2ft2t4.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27q2rnvxirj53.png\" alt=\"img\" width=\"600\" \/><\/p>\n<li>\u6dfb\u52a0 user01 \u81f3\u7ec4\u6210\u5458<\/li>\n<p><img decoding=\"async\" src=\"2026-01-27psk20v1n3kb.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27l4amyyi3bpa.png\" alt=\"img\" width=\"600\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-01-27v3z5nvn1tk2.png\" alt=\"img\" width=\"600\" \/><\/p>\n<li>\u7ec4\u6dfb\u52a0\u540e\u767b\u5f55\u9a8c\u8bc1 \u5c06 user01 \u6dfb\u52a0\u81f3 shichangs \u7ec4\u540e&#xff0c;\u5728\u975e\u6388\u6743\u65f6\u95f4\u5c1d\u8bd5\u767b\u5f55&#xff0c;\u7cfb\u7edf\u4ecd\u5c06\u63d0\u793a\u767b\u5f55\u65f6\u95f4\u9650\u5236&#xff0c;\u622a\u56fe\u5982\u4e0b&#xff1a;<\/li>\n<p><img decoding=\"async\" src=\"2026-01-27pl1pyi414fk.png\" alt=\"img\" width=\"600\" \/><\/p>\n<hr \/>\n<h2>via:<\/h2>\n<ul>\n<li>The Domain, the Tree and the Forest :: https:\/\/ad4noobs.justin-p.me\/terminology_installing_a_active_directory\/domain_tree_forest\/<\/li>\n<li>Active Directory Forest &#8211; Trees and Domain and Sites &#8211; https:\/\/techdirectarchive.com\/2020\/04\/11\/what-is-active-directory-forest-trees-and-domain\/<\/li>\n<li>Install and configure Active Directory Domain Services on Windows https:\/\/techdirectarchive.com\/2021\/11\/30\/how-to-install-configure-active-directory-domain-services-on-windows-server-2022\/<\/li>\n<li>How to add a second Domain Controller https:\/\/techdirectarchive.com\/2020\/01\/08\/how-to-setup-a-dc-adding-a-second-domain-controller\/ &#8211; \u2014<\/li>\n<li>What is Active Directory tree (AD tree)? https:\/\/www.techtarget.com\/searchwindowsserver\/definition\/Active-Directory-tree-AD-tree<\/li>\n<li>\u4f7f\u7528\u7ec4\u7ec7\u57df\u6797\u6a21\u578b | Microsoft Learn https:\/\/learn.microsoft.com\/zh-cn\/windows-server\/identity\/ad-ds\/plan\/using-the-organizational-domain-forest-model \u2014<\/li>\n<li>\u6df1\u5165\u7406\u89e3\u7236\u57df\u3001\u5b50\u57df\u3001\u6811\u57df\u548c\u6797\u57df_\u5b50\u57df\u548c\u6811\u57df\u7684\u533a\u522b-CSDN \u535a\u5ba2 https:\/\/blog.csdn.net\/AIBB_520\/article\/details\/134841147<\/li>\n<li>Windows sever \u4e2d\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u4e4b\u95f4\u7684\u533a\u522b\u4e0e\u8054\u7cfb-CSDN \u535a\u5ba2 https:\/\/blog.csdn.net\/weixin_43028329\/article\/details\/82220876<\/li>\n<li>\u57df\u3001\u57df\u6811\u3001\u57df\u6797\u3001\u6839\u57df_\u57df\u68ee\u6797\u6839\u57df-CSDN \u535a\u5ba2 https:\/\/blog.csdn.net\/Fly_hps\/article\/details\/80635803<\/li>\n<li>\u5173\u4e8e\u6d3b\u52a8\u76ee\u5f55\u57df\u3001\u57df\u6811\u3001\u6811\u6797\u3001\u5b50\u57df_\u5b50\u57df\u548c\u6811\u57df\u7684\u533a\u522b-CSDN \u535a\u5ba2 https:\/\/blog.csdn.net\/qwf869\/article\/details\/104859442<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6ce8&#xff1a;\u672c\u6587\u4e3a \u201cWindows Server | \u57df\u201d \u76f8\u5173\u5408\u8f91\u3002 \u82f1\u6587\u5f15\u6587&#xff0c;\u673a\u7ffb\u672a\u6821\u3002 \u4e2d\u6587\u5f15\u6587&#xff0c;\u7565\u4f5c\u91cd\u6392\u3002&#xff08;\u90e8\u5206\u8d44\u6599\u6709\u70b9\u9648\u65e7&#xff09; \u672a\u6574\u7406\u53bb\u91cd&#xff0c;\u56fe\u7247\u6e05\u6670\u5ea6\u53d7\u5f15\u6587\u539f\u56fe\u6240\u9650\u3002 \u5982\u6709\u5185\u5bb9\u5f02\u5e38&#xff0c;\u8bf7\u770b\u539f\u6587\u3002 THE DOMAIN, THE TREE AND THE FOREST<br \/>\n\u57df\u3001\u57df\u6811\u4e0e\u57df\u6797<br \/>\nDomains, Trees and Forests, what now? I thought<\/p>\n","protected":false},"author":2,"featured_media":66855,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[7076],"topic":[],"class_list":["post-66875","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-server","tag-windows-"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/66875.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u6ce8&#xff1a;\u672c\u6587\u4e3a \u201cWindows Server | \u57df\u201d \u76f8\u5173\u5408\u8f91\u3002 \u82f1\u6587\u5f15\u6587&#xff0c;\u673a\u7ffb\u672a\u6821\u3002 \u4e2d\u6587\u5f15\u6587&#xff0c;\u7565\u4f5c\u91cd\u6392\u3002&#xff08;\u90e8\u5206\u8d44\u6599\u6709\u70b9\u9648\u65e7&#xff09; \u672a\u6574\u7406\u53bb\u91cd&#xff0c;\u56fe\u7247\u6e05\u6670\u5ea6\u53d7\u5f15\u6587\u539f\u56fe\u6240\u9650\u3002 \u5982\u6709\u5185\u5bb9\u5f02\u5e38&#xff0c;\u8bf7\u770b\u539f\u6587\u3002 THE DOMAIN, THE TREE AND THE FOREST \u57df\u3001\u57df\u6811\u4e0e\u57df\u6797 Domains, Trees and Forests, what now? I thought\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/66875.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-27T11:33:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113340-6978a29446b48.png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"38 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/66875.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/66875.html\",\"name\":\"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-01-27T11:33:46+00:00\",\"dateModified\":\"2026-01-27T11:33:46+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/66875.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/66875.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/66875.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/66875.html","og_locale":"zh_CN","og_type":"article","og_title":"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u6ce8&#xff1a;\u672c\u6587\u4e3a \u201cWindows Server | \u57df\u201d \u76f8\u5173\u5408\u8f91\u3002 \u82f1\u6587\u5f15\u6587&#xff0c;\u673a\u7ffb\u672a\u6821\u3002 \u4e2d\u6587\u5f15\u6587&#xff0c;\u7565\u4f5c\u91cd\u6392\u3002&#xff08;\u90e8\u5206\u8d44\u6599\u6709\u70b9\u9648\u65e7&#xff09; \u672a\u6574\u7406\u53bb\u91cd&#xff0c;\u56fe\u7247\u6e05\u6670\u5ea6\u53d7\u5f15\u6587\u539f\u56fe\u6240\u9650\u3002 \u5982\u6709\u5185\u5bb9\u5f02\u5e38&#xff0c;\u8bf7\u770b\u539f\u6587\u3002 THE DOMAIN, THE TREE AND THE FOREST \u57df\u3001\u57df\u6811\u4e0e\u57df\u6797 Domains, Trees and Forests, what now? I thought","og_url":"https:\/\/www.wsisp.com\/helps\/66875.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-01-27T11:33:46+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/01\/20260127113340-6978a29446b48.png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"38 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/66875.html","url":"https:\/\/www.wsisp.com\/helps\/66875.html","name":"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-01-27T11:33:46+00:00","dateModified":"2026-01-27T11:33:46+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/66875.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/66875.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/66875.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"Windows Server | \u57df\u5c42\u7ea7\u7ba1\u7406\uff1a\u57df\u3001\u57df\u6811\u3001\u57df\u68ee\u6797\u6982\u5ff5\u53ca\u57df\u670d\u52a1\u914d\u7f6e"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/66875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=66875"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/66875\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media\/66855"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=66875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=66875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=66875"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=66875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}