65 phút
Network và Account Management
Network và Account Management
Account Management
User Lifecycle
1. Onboarding:
- Request from HR/Manager
- Create account in AD
- Assign to groups
- Provision email
- Setup MFA
- Configure access
- Issue equipment
2. Transfer:
- Update department
- Change group memberships
- Adjust permissions
- Keep same account
- Update email signature
3. Offboarding:
- Disable account (immediately)
- Forward email to manager
- Convert to shared mailbox (if needed)
- Remove from groups
- Backup data
- Retrieve equipment
- Delete account (after 30-90 days)
AD Account Operations
# Create user
New-ADUser -Name "John Doe" `
-SamAccountName "jdoe" `
-UserPrincipalName "jdoe@company.com" `
-EmailAddress "jdoe@company.com" `
-Path "OU=IT,OU=Users,DC=company,DC=com" `
-AccountPassword (ConvertTo-SecureString "Welcome@2024" -AsPlainText -Force) `
-Enabled $true `
-ChangePasswordAtLogon $true `
-Department "IT" `
-Title "Developer" `
-Manager "CN=Jane Smith,OU=IT,OU=Users,DC=company,DC=com"
# Modify user
Set-ADUser -Identity "jdoe" -Title "Senior Developer" -Department "Engineering"
# Disable account
Disable-ADAccount -Identity "jdoe"
# Enable account
Enable-ADAccount -Identity "jdoe"
# Reset password
Set-ADAccountPassword -Identity "jdoe" `
-NewPassword (ConvertTo-SecureString "NewPass@2024" -AsPlainText -Force) `
-Reset `
-ChangePasswordAtLogon $true
# Unlock account
Unlock-ADAccount -Identity "jdoe"
# Find locked accounts
Search-ADAccount -LockedOut | Select Name, SamAccountName
# Find password never expires
Get-ADUser -Filter {PasswordNeverExpires -eq $true} -Properties PasswordNeverExpires
# Find inactive users (90 days)
$days = (Get-Date).AddDays(-90)
Get-ADUser -Filter {LastLogonDate -lt $days} -Properties LastLogonDate |
Select Name, SamAccountName, LastLogonDate
# Group membership
Add-ADGroupMember -Identity "IT_Admins" -Members "jdoe"
Remove-ADGroupMember -Identity "IT_Admins" -Members "jdoe" -Confirm:$false
Get-ADPrincipalGroupMembership -Identity "jdoe" | Select Name
# Offboard user
$user = "jdoe"
Disable-ADAccount -Identity $user
Set-ADUser -Identity $user -Manager $null
Get-ADPrincipalGroupMembership -Identity $user |
Where {$_.Name -ne "Domain Users"} |
ForEach { Remove-ADGroupMember -Identity $_.Name -Members $user -Confirm:$false }
Set-ADUser -Identity $user `
-Description "Offboarded on $(Get-Date -Format 'yyyy-MM-dd')" `
-EmailAddress $null
Password Reset Best Practices
1. Identity verification:
- Manager approval (for critical accounts)
- Personal questions (SSN, DOB, etc.)
- Video call with ID
- Phone callback to known number
2. Password requirements:
- Min 12 chars (or per policy)
- Complexity: Upper, lower, digit, symbol
- No dictionary words
- History: 24
- Max age: 60-90 days
3. Reset procedure:
- Notify user of reset
- Force change at next logon
- Send password via secure channel
- Log the action
4. Alert for suspicious:
- Multiple resets in short time
- Reset for VIP/Admin
- After-hours request
Email Management
Exchange / Microsoft 365
# Connect to Exchange Online
Connect-ExchangeOnline -UserPrincipalName admin@company.com
# Mailbox info
Get-Mailbox -Identity "jdoe@company.com" |
Select DisplayName, PrimarySmtpAddress, Quota, UseDatabaseQuotaDefaults
# Mailbox size
Get-MailboxStatistics -Identity "jdoe@company.com" |
Select DisplayName, TotalItemSize, ItemCount
# Mailbox permissions
Get-MailboxPermission -Identity "jdoe@company.com"
Add-MailboxPermission -Identity "jdoe@company.com" `
-User "jane@company.com" -AccessRights FullAccess `
-InheritanceType All
# Send As / Send on Behalf
Add-RecipientPermission -Identity "jdoe@company.com" `
-Trustee "jane@company.com" -AccessRights SendAs -Confirm:$false
Set-Mailbox -Identity "jdoe@company.com" `
-GrantSendOnBehalfTo "jane@company.com"
# Forwarding
Set-Mailbox -Identity "jdoe@company.com" `
-ForwardingSmtpAddress "manager@company.com" `
-DeliverToMailboxAndForward $true
# Convert to shared mailbox (offboarding)
Set-Mailbox -Identity "jdoe@company.com" -Type Shared
# Remove license after conversion
# Distribution Groups
New-DistributionGroup -Name "IT Team" `
-Type Distribution -PrimarySmtpAddress "it@company.com"
Add-DistributionGroupMember -Identity "IT Team" -Member "jdoe@company.com"
# Mailbox rules
Get-InboxRule -Mailbox "jdoe@company.com"
"Remove-InboxRule -Mailbox "jdoe@company.com" -Identity "RuleName"";
Email Troubleshooting
Problem: Email not received
Check:
1. Spam folder
2. Junk folder
3. Blocked senders
4. Mailbox rules (auto-delete?)
5. Mailbox full
6. Message trace (admin)
Problem: Cannot send
Check:
1. Mailbox full
2. Attachment too large (>25MB default)
3. Recipient incorrect
4. Blocked by anti-spam
5. SMTP restrictions
6. NDR (Non-Delivery Report)
Message Trace (M365):
```powershell
Get-MessageTrace -SenderAddress "jdoe@company.com" `
-StartDate (Get-Date).AddDays(-7) `
-EndDate (Get-Date) |
Select Received, SenderAddress, RecipientAddress, Subject, Status
## VPN Troubleshooting
### Common Issues
- Cannot connect
- Connected but no access
- Slow connection
- Disconnects frequently
- Certificate errors
- Authentication failures
### Diagnosis
```powershell
# Check VPN connections
Get-VpnConnection
# Test VPN server
Test-NetConnection vpn.company.com -Port 443
Test-NetConnection vpn.company.com -Port 1723 # PPTP
# Check routes
Get-VpnConnection -AllUserConnection |
Select Name, ServerAddress, ConnectionStatus
# Event logs
Get-WinEvent -LogName "Microsoft-Windows-RasClient/Operational" -MaxEvents 20
# Test certificate
certmgr.msc # Personal → Certificates
Troubleshooting Steps
1. Basic connectivity:
- Ping VPN server
- Test port: tnc vpn.company.com -Port 443
2. Credentials:
- Verify username format (domain\user)
- Check password expiry
- Test in OWA first
3. Client:
- Restart VPN client
- Re-create VPN profile
- Update client software
4. Network:
- Test from different network (mobile hotspot)
- Check firewall at client location
- ISP blocking? (usually port 443 works)
5. Server:
- Check VPN server status
- RADIUS/AD connectivity
- Certificate validity
- License limits
6. Split Tunnel:
- Check routes
- DNS resolution
- Firewall rules
Remote Desktop (RDP)
Setup
# Enable RDP
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' `
-Name "fDenyTSConnections" -Value 0
# Enable firewall
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
# Add user to Remote Desktop Users
Add-LocalGroupMember -Group "Remote Desktop Users" -Member "domain\username"
# Configure RDP
# Settings → System → Remote Desktop → On
Troubleshooting
# Test connectivity
Test-NetConnection server01 -Port 3389
# Check RDP service
Get-Service -Name TermService
# Check listener
netstat -an | findstr 3389
# Check RDP settings
Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' |
Select fDenyTSConnections
# RDP session info
qwinsta
qwinsta /server:server01
# Log off session
logoff <session-id> /server:server01
# Kill session
rwinsta <session-id> /server:server01
# Check RDP sessions
Get-RDUserSession -ConnectionBroker "rdcb.company.com"
Common RDP Errors
"Cannot connect to the remote computer":
1. Machine offline
2. RDP disabled
3. Firewall blocking
4. Wrong IP/hostname
5. Port changed
6. Network issue
"Credentials did not work":
1. Wrong username format
2. Password expired
3. Account locked
4. User not in RDP Users group
5. NLA issues
"Internal error":
1. Corrupt RDP settings
2. Registry issue
3. Certificate problem
4. Restart needed
Solution:
# Reset RDP
reg delete "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\RCM" /f
# Restart
File Share Access
Troubleshooting
# Check share exists
Get-SmbShare -CimSession server01 |
Where Name -eq "Data"
# Check share permissions
Get-SmbShareAccess -Name "Data" -CimSession server01
# Check NTFS permissions
icacls "\\server01\Data"
# Effective permissions
# Advanced Security Settings → Effective Access
# Or: Get-Acl "\\server01\Data"
# Test access
Test-Path "\\server01\Data\file.txt"
# Check connectivity
Test-NetConnection server01 -Port 445
net use Z: \\server01\Data
# Clear credentials
cmdkey /list
cmdkey /delete:server01
Common Issues
"Cannot access \\server\share":
1. Network down: ping server
2. Firewall blocking SMB (445): Test port
3. Wrong credentials: clear cached
4. Permission denied: check ACL
5. Share not exists: verify name
6. SMB version: enable SMB1 (legacy, not recommended)
7. DNS issue: use IP instead
"Access is denied":
1. No permission at share level
2. No permission at NTFS level
3. UAC issues: run as admin
4. Explicit deny somewhere
5. User not in group
6. Kerberos issue
"Credentials conflict":
cmdkey /list # List cached creds
cmdkey /delete:server01 # Delete
# Or use different credentials
net use \\server01\share /user:domain\user pass
Printer Management
Add Network Printer
# Add by IP
Add-PrinterPort -Name "IP_192.168.1.50" -PrinterHostAddress "192.168.1.50"
Add-Printer -Name "HP LaserJet 01" `
-DriverName "HP Universal Printing PS" `
-PortName "IP_192.168.1.50"
# Add by share
Add-Printer -Name "HP-01" `
-ConnectionName "\\print01\HP-LJ-01"
# Deploy via GPO
# User Config → Preferences → Control Panel → Printers
# Or Computer Config → Policies → Windows Settings → Deployed Printers
# Default printer
Set-Printer -Name "HP-01" -Shared $true
Set-Printer -Name "HP-01" -Published $true
# Permissions
Grant-PrinterAccess -Name "HP-01" `
-UserName "COMPANY\Sales_Team" `
-PrinterPermission Print
Troubleshooting
"Printer not found":
1. Ping printer IP
2. Web interface accessible?
3. Print server reachable?
4. Printer powered on?
5. Network config correct?
"Cannot print":
1. Print queue stuck → clear
2. Spooler service → restart
3. Driver issues → reinstall
4. Default printer changed?
5. Print from different app?
"Poor quality":
1. Toner/ink low
2. Print head dirty
3. Paper quality
4. Print settings
5. Transfer belt/roller
Mobile Device Management (MDM)
Intune / MDM
Enrollment:
- Automatic (Azure AD Join)
- User-driven (Company Portal)
- Bulk (Autopilot)
Policies:
- Compliance: OS version, encryption, password
- Configuration: WiFi, VPN, Email, Apps
- Security: Conditional Access, MFA
- Apps: Required, Available, Uninstall
Commands:
- Wipe
- Retire
- Reset Passcode
- Locate device
- Remote lock
Bài tập thực hành
Hãy thực hành Account và Network management!