Need reasons for 2008 Domain Controller rather than 2003.
my boss made comment "sure can deploy (windows) 2008 servers...just not domain controllers"
in labs tests i've run myself since beta have been impressed 2008 in aspects , highly recommending it, need "ammo" meeting on monday discuss.
what sort of insights other users have make case 2008 functional level and/or dcs
we'll standalone forest may establish trust 2003 forest have support app.
thanks!
hi,
check :
the following features available @ windows server 2008 domain functional level:
- universal groups
- group nesting
- group type conversion
- sid history
- constrained delegation, application can use take advantage of secure delegation of user credentials
by means of kerberos authentication protocol.
- lastlogontimestamp updates: lastlogontimestamp attribute is updated last logon time of user or
computer, , is replicated throughout domain.
- the ability set userpassword attribute effective password on inetorgperson , user objects.
- the ability redirect users , computers containers to define new well-known location user , computer
accounts.
new
- distributed file system replication support sysvol, which provides more robust , granular
replication of sysvol contents.
- advanced encryption services (aes 128 , 256) support the kerberos protocol.
- last interactive logon information, displays time of the last successful interactive logon a
user, number of failed logon attempts since last logon, , time of last failed logon.
- fine-grained password policies, make possible for password , account lockout policies
specified users and global security groups in domain.
hth,
tarek
_____________________________
tarek majdalani
mvp -- isa firewalls
http://www.elmajdal.net/win2k8/
Windows Server > Directory Services
Comments
Post a Comment