Network và Account Management

65 phút

Network và Account Management

Network và Account Management

Account Management

User Lifecycle

1. Onboarding:
   - Request from HR/Manager
   - Create account in AD
   - Assign to groups
   - Provision email
   - Setup MFA
   - Configure access
   - Issue equipment

2. Transfer:
   - Update department
   - Change group memberships
   - Adjust permissions
   - Keep same account
   - Update email signature

3. Offboarding:
   - Disable account (immediately)
   - Forward email to manager
   - Convert to shared mailbox (if needed)
   - Remove from groups
   - Backup data
   - Retrieve equipment
   - Delete account (after 30-90 days)

AD Account Operations

# Create user
New-ADUser -Name "John Doe" `
    -SamAccountName "jdoe" `
    -UserPrincipalName "jdoe@company.com" `
    -EmailAddress "jdoe@company.com" `
    -Path "OU=IT,OU=Users,DC=company,DC=com" `
    -AccountPassword (ConvertTo-SecureString "Welcome@2024" -AsPlainText -Force) `
    -Enabled $true `
    -ChangePasswordAtLogon $true `
    -Department "IT" `
    -Title "Developer" `
    -Manager "CN=Jane Smith,OU=IT,OU=Users,DC=company,DC=com"

# Modify user
Set-ADUser -Identity "jdoe" -Title "Senior Developer" -Department "Engineering"

# Disable account
Disable-ADAccount -Identity "jdoe"

# Enable account
Enable-ADAccount -Identity "jdoe"

# Reset password
Set-ADAccountPassword -Identity "jdoe" `
    -NewPassword (ConvertTo-SecureString "NewPass@2024" -AsPlainText -Force) `
    -Reset `
    -ChangePasswordAtLogon $true

# Unlock account
Unlock-ADAccount -Identity "jdoe"

# Find locked accounts
Search-ADAccount -LockedOut | Select Name, SamAccountName

# Find password never expires
Get-ADUser -Filter {PasswordNeverExpires -eq $true} -Properties PasswordNeverExpires

# Find inactive users (90 days)
$days = (Get-Date).AddDays(-90)
Get-ADUser -Filter {LastLogonDate -lt $days} -Properties LastLogonDate |
    Select Name, SamAccountName, LastLogonDate

# Group membership
Add-ADGroupMember -Identity "IT_Admins" -Members "jdoe"
Remove-ADGroupMember -Identity "IT_Admins" -Members "jdoe" -Confirm:$false
Get-ADPrincipalGroupMembership -Identity "jdoe" | Select Name

# Offboard user
$user = "jdoe"
Disable-ADAccount -Identity $user
Set-ADUser -Identity $user -Manager $null
Get-ADPrincipalGroupMembership -Identity $user | 
    Where {$_.Name -ne "Domain Users"} |
    ForEach { Remove-ADGroupMember -Identity $_.Name -Members $user -Confirm:$false }
Set-ADUser -Identity $user `
    -Description "Offboarded on $(Get-Date -Format 'yyyy-MM-dd')" `
    -EmailAddress $null

Password Reset Best Practices

1. Identity verification:
   - Manager approval (for critical accounts)
   - Personal questions (SSN, DOB, etc.)
   - Video call with ID
   - Phone callback to known number

2. Password requirements:
   - Min 12 chars (or per policy)
   - Complexity: Upper, lower, digit, symbol
   - No dictionary words
   - History: 24
   - Max age: 60-90 days

3. Reset procedure:
   - Notify user of reset
   - Force change at next logon
   - Send password via secure channel
   - Log the action

4. Alert for suspicious:
   - Multiple resets in short time
   - Reset for VIP/Admin
   - After-hours request

Email Management

Exchange / Microsoft 365

# Connect to Exchange Online
Connect-ExchangeOnline -UserPrincipalName admin@company.com

# Mailbox info
Get-Mailbox -Identity "jdoe@company.com" | 
    Select DisplayName, PrimarySmtpAddress, Quota, UseDatabaseQuotaDefaults

# Mailbox size
Get-MailboxStatistics -Identity "jdoe@company.com" | 
    Select DisplayName, TotalItemSize, ItemCount

# Mailbox permissions
Get-MailboxPermission -Identity "jdoe@company.com"
Add-MailboxPermission -Identity "jdoe@company.com" `
    -User "jane@company.com" -AccessRights FullAccess `
    -InheritanceType All

# Send As / Send on Behalf
Add-RecipientPermission -Identity "jdoe@company.com" `
    -Trustee "jane@company.com" -AccessRights SendAs -Confirm:$false
Set-Mailbox -Identity "jdoe@company.com" `
    -GrantSendOnBehalfTo "jane@company.com"

# Forwarding
Set-Mailbox -Identity "jdoe@company.com" `
    -ForwardingSmtpAddress "manager@company.com" `
    -DeliverToMailboxAndForward $true

# Convert to shared mailbox (offboarding)
Set-Mailbox -Identity "jdoe@company.com" -Type Shared
# Remove license after conversion

# Distribution Groups
New-DistributionGroup -Name "IT Team" `
    -Type Distribution -PrimarySmtpAddress "it@company.com"
Add-DistributionGroupMember -Identity "IT Team" -Member "jdoe@company.com"

# Mailbox rules
Get-InboxRule -Mailbox "jdoe@company.com"
"Remove-InboxRule -Mailbox "jdoe@company.com" -Identity "RuleName"";

Email Troubleshooting

Problem: Email not received
Check:
1. Spam folder
2. Junk folder
3. Blocked senders
4. Mailbox rules (auto-delete?)
5. Mailbox full
6. Message trace (admin)

Problem: Cannot send
Check:
1. Mailbox full
2. Attachment too large (>25MB default)
3. Recipient incorrect
4. Blocked by anti-spam
5. SMTP restrictions
6. NDR (Non-Delivery Report)

Message Trace (M365):
```powershell
Get-MessageTrace -SenderAddress "jdoe@company.com" `
    -StartDate (Get-Date).AddDays(-7) `
    -EndDate (Get-Date) |
    Select Received, SenderAddress, RecipientAddress, Subject, Status

## VPN Troubleshooting

### Common Issues
  1. Cannot connect
  2. Connected but no access
  3. Slow connection
  4. Disconnects frequently
  5. Certificate errors
  6. Authentication failures

### Diagnosis
```powershell
# Check VPN connections
Get-VpnConnection

# Test VPN server
Test-NetConnection vpn.company.com -Port 443
Test-NetConnection vpn.company.com -Port 1723  # PPTP

# Check routes
Get-VpnConnection -AllUserConnection | 
    Select Name, ServerAddress, ConnectionStatus

# Event logs
Get-WinEvent -LogName "Microsoft-Windows-RasClient/Operational" -MaxEvents 20

# Test certificate
certmgr.msc  # Personal → Certificates

Troubleshooting Steps

1. Basic connectivity:
   - Ping VPN server
   - Test port: tnc vpn.company.com -Port 443

2. Credentials:
   - Verify username format (domain\user)
   - Check password expiry
   - Test in OWA first

3. Client:
   - Restart VPN client
   - Re-create VPN profile
   - Update client software

4. Network:
   - Test from different network (mobile hotspot)
   - Check firewall at client location
   - ISP blocking? (usually port 443 works)

5. Server:
   - Check VPN server status
   - RADIUS/AD connectivity
   - Certificate validity
   - License limits

6. Split Tunnel:
   - Check routes
   - DNS resolution
   - Firewall rules

Remote Desktop (RDP)

Setup

# Enable RDP
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' `
    -Name "fDenyTSConnections" -Value 0

# Enable firewall
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"

# Add user to Remote Desktop Users
Add-LocalGroupMember -Group "Remote Desktop Users" -Member "domain\username"

# Configure RDP
# Settings → System → Remote Desktop → On

Troubleshooting

# Test connectivity
Test-NetConnection server01 -Port 3389

# Check RDP service
Get-Service -Name TermService

# Check listener
netstat -an | findstr 3389

# Check RDP settings
Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server' |
    Select fDenyTSConnections

# RDP session info
qwinsta
qwinsta /server:server01

# Log off session
logoff <session-id> /server:server01

# Kill session
rwinsta <session-id> /server:server01

# Check RDP sessions
Get-RDUserSession -ConnectionBroker "rdcb.company.com"

Common RDP Errors

"Cannot connect to the remote computer":
1. Machine offline
2. RDP disabled
3. Firewall blocking
4. Wrong IP/hostname
5. Port changed
6. Network issue

"Credentials did not work":
1. Wrong username format
2. Password expired
3. Account locked
4. User not in RDP Users group
5. NLA issues

"Internal error":
1. Corrupt RDP settings
2. Registry issue
3. Certificate problem
4. Restart needed

Solution:
# Reset RDP
reg delete "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\RCM" /f
# Restart

File Share Access

Troubleshooting

# Check share exists
Get-SmbShare -CimSession server01 | 
    Where Name -eq "Data"

# Check share permissions
Get-SmbShareAccess -Name "Data" -CimSession server01

# Check NTFS permissions
icacls "\\server01\Data"

# Effective permissions
# Advanced Security Settings → Effective Access
# Or: Get-Acl "\\server01\Data"

# Test access
Test-Path "\\server01\Data\file.txt"

# Check connectivity
Test-NetConnection server01 -Port 445
net use Z: \\server01\Data

# Clear credentials
cmdkey /list
cmdkey /delete:server01

Common Issues

"Cannot access \\server\share":
1. Network down: ping server
2. Firewall blocking SMB (445): Test port
3. Wrong credentials: clear cached
4. Permission denied: check ACL
5. Share not exists: verify name
6. SMB version: enable SMB1 (legacy, not recommended)
7. DNS issue: use IP instead

"Access is denied":
1. No permission at share level
2. No permission at NTFS level
3. UAC issues: run as admin
4. Explicit deny somewhere
5. User not in group
6. Kerberos issue

"Credentials conflict":
cmdkey /list  # List cached creds
cmdkey /delete:server01  # Delete

# Or use different credentials
net use \\server01\share /user:domain\user pass

Printer Management

Add Network Printer

# Add by IP
Add-PrinterPort -Name "IP_192.168.1.50" -PrinterHostAddress "192.168.1.50"

Add-Printer -Name "HP LaserJet 01" `
    -DriverName "HP Universal Printing PS" `
    -PortName "IP_192.168.1.50"

# Add by share
Add-Printer -Name "HP-01" `
    -ConnectionName "\\print01\HP-LJ-01"

# Deploy via GPO
# User Config → Preferences → Control Panel → Printers
# Or Computer Config → Policies → Windows Settings → Deployed Printers

# Default printer
Set-Printer -Name "HP-01" -Shared $true
Set-Printer -Name "HP-01" -Published $true

# Permissions
Grant-PrinterAccess -Name "HP-01" `
    -UserName "COMPANY\Sales_Team" `
    -PrinterPermission Print

Troubleshooting

"Printer not found":
1. Ping printer IP
2. Web interface accessible?
3. Print server reachable?
4. Printer powered on?
5. Network config correct?

"Cannot print":
1. Print queue stuck → clear
2. Spooler service → restart
3. Driver issues → reinstall
4. Default printer changed?
5. Print from different app?

"Poor quality":
1. Toner/ink low
2. Print head dirty
3. Paper quality
4. Print settings
5. Transfer belt/roller

Mobile Device Management (MDM)

Intune / MDM

Enrollment:
- Automatic (Azure AD Join)
- User-driven (Company Portal)
- Bulk (Autopilot)

Policies:
- Compliance: OS version, encryption, password
- Configuration: WiFi, VPN, Email, Apps
- Security: Conditional Access, MFA
- Apps: Required, Available, Uninstall

Commands:
- Wipe
- Retire
- Reset Passcode
- Locate device
- Remote lock

Bài tập thực hành

Hãy thực hành Account và Network management!

Bài tập 1