Dan Zabinski
Dan Zabinski
  • 38
  • 8 822
DNS Basics
Covering the basics of how DNS works in an Active Directory environment from start to finish. This video is intended to clarify how everything works without getting into some of the more Microsoft-specific DNS things.
Contents:
00:00 - Intro
03:15 - Domains or Zones
05:38 - Subdomains or Records
09:55 - DNS Lookups
18:37 - Authoritative DNS Servers
22:45 - DNS Search Suffix
30:11 - Ending
Переглядів: 294

Відео

AZ-801 Configuring Failover Clusters part 2
Переглядів 794 місяці тому
We configure a cluster to use Storage Spaces Direct and a Scale Out File Server. I also go over which cluster exam objectives you should know for the AZ 801. Links: Study guide for Exam AZ-801 learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/az-801 When to use Scale-Out File Server learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2...
Instant Active Directory Lab in Azure: Step-by-Step (Part 2)
Переглядів 1765 місяців тому
Using Terraform and DSC, we customize the Microsoft Quickstart template in order to deploy a fully functional Active Directory lab in Azure with additional servers in minutes. A couple of notes: - I included a link below with instructions on how to authenticate to Azure with terraform. - There is a section at 16:25 where I go over a relatively common error you might encounter when deploying thi...
Instant Active Directory Lab in Azure: Step-by-Step (Part 1)
Переглядів 3835 місяців тому
First of a two part series showing how I quickly set up the Azure lab environment that I use for all of the AZ-801 content. This can be used to instantly deploy a complete Active Directory environment for lab testing. I also talk about how much it costs to run the lab (almost nothing) and how to destroy Azure resources so you don't get charged for them. Links My Github Repo - github.com/DanZab/...
AZ-801 Monitoring and Alerting
Переглядів 1395 місяців тому
This video covers performance monitor, event log collection, some Azure monitoring tools, and then monitoring and alerting within Windows Admin Center. We went a little off the rails by the end of the video and I apologize I didn't loop back to the event collection or VM Insights map. Link References: Event Log Collection - learn.microsoft.com/en-us/advanced-threat-analytics/configure-event-col...
AZ-801 Troubleshooting Active Directory
Переглядів 1835 місяців тому
Topics Covered: Directory Services Restore Mode (DSRM) Active Directory Recycle Bin Setting up AD Sites and Services Replication Troubleshooting Active Directory Troubleshooting Link References: Reset DSRM Password - learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/reset-directory-services-restore-mode-admin-pwd DSRM Restore Walkthrough - help.axcient.com/specific-to-windo...
AZ-801 The New Windows Admin Center
Переглядів 2006 місяців тому
As part of the exam objects for AZ-801 Migrating Servers and Workloads, I'm taking a look at the new Windows Admin Center console. I'm critical of it and my skepticism comes out in the video, but I'm curious of your feedback. Network Requirements: learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/network-requirements Contents: 00:00 - Intro 02:18 - Installing the Conso...
AZ-801 Configuring Failover Clusters
Переглядів 2286 місяців тому
The prerequisites and setup of a Failover Cluster, related to the following exam objectives: Implement a Windows Server failover cluster Implement a failover cluster on-premises, hybrid, or cloud-only Create a Windows failover cluster Configure storage for failover clustering Modify quorum options Configure cluster workload options Create an Azure witness Configure a floating IP address for the...
Azure Networking - Virtual Networks and Subnets
Переглядів 1157 місяців тому
Additional note about DNS, if you have Custom DNS servers specified on a vNet, your VMs on that vNet will not resolve linked DNS zones. 0:00 - Intro 2:06 - VNets and IP Space 7:00 - IP Capacity Planning 9:50 - Special Subnet Scenarios 14:28 - VNet Sizing Recommendations 15:12 - VNet Peering 17:23 - Network Topology 23:12 - Configure Hub and Spoke 26:08 - Mesh 27:50 - Azure Routing 30:45 - Route...
Azure Networking - Azure Firewall
Переглядів 1047 місяців тому
A couple of notes on this, I get protocols confused with ports at one point and correct myself later. Also, according to Microsoft's docs, Azure Firewall does deny all traffic by default. Meaning you need to specifically allow the traffic (outbound or inbound) that you need.) learn.microsoft.com/en-us/azure/firewall/rule-processing 00:00 - Intro 01:50 - Azure Firewall Prerequisites 08:11 - Fire...
Azure Networking Intro
Переглядів 287 місяців тому
An overview of Azure Networking, covers the skills you would likely need to get the applied skills credential "Configure secure access to your workloads using Azure networking": learn.microsoft.com/en-us/credentials/applied-skills/configure-secure-workloads-use-azure-virtual-networking/ - Azure Virtual Networks and Subnets - Azure Firewall - On Premises Connectivity - Other Network Security Res...
Azure Policy - Policy Definitions
Переглядів 2007 місяців тому
Goes over the structure of Azure Policy definition objects, and how to create custom policies. This topic can get complicated quickly, let me know if there's any information missing or that I could clarify. Enterprise Policy as Code: azure.github.io/enterprise-azure-policy-as-code/
Azure Policy - Policy Management
Переглядів 877 місяців тому
Operational tasks related to the creation and management of Azure Policy from an operational standpoint
Azure Policy - Policy Overview
Переглядів 697 місяців тому
Basic elements of Azure Policy
Azure Policy - Platform Management
Переглядів 587 місяців тому
This video is a recap of Azure Platform elements that are related to Azure Policy. Microsoft Cloud Adoption Framework: learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/
Azure Policy - Introduction
Переглядів 1107 місяців тому
Azure Policy - Introduction
AZ-801 Secure Servers (5/7): Hybrid Security - Defender for Cloud
Переглядів 1207 місяців тому
AZ-801 Secure Servers (5/7): Hybrid Security - Defender for Cloud
AZ-801 Secure Servers (6/7): Hybrid Security - Bitlocker
Переглядів 1087 місяців тому
AZ-801 Secure Servers (6/7): Hybrid Security - Bitlocker
AZ-801 Secure Servers (3/7): Hybrid Security - Intro
Переглядів 1267 місяців тому
AZ-801 Secure Servers (3/7): Hybrid Security - Intro
AZ-801 Secure Servers (4/7): Hybrid Security - Sentinel
Переглядів 1847 місяців тому
AZ-801 Secure Servers (4/7): Hybrid Security - Sentinel
AZ-801 Secure Servers (7/7): Hybrid Security - Azure Disk Encryption
Переглядів 947 місяців тому
AZ-801 Secure Servers (7/7): Hybrid Security - Azure Disk Encryption
Entra Identities Part 2 - Applications
Переглядів 237 місяців тому
Entra Identities Part 2 - Applications
Entra, Microsoft 365 and Azure
Переглядів 277 місяців тому
Entra, Microsoft 365 and Azure
Entra Overview - Intro
Переглядів 207 місяців тому
Entra Overview - Intro
DNS and IPAM
Переглядів 387 місяців тому
DNS and IPAM
DNS and Load Balancing
Переглядів 207 місяців тому
DNS and Load Balancing
DNS Scenarios Part 2
Переглядів 217 місяців тому
DNS Scenarios Part 2
DNS Scenarios Part 1
Переглядів 257 місяців тому
DNS Scenarios Part 1
AZ-801 Secure Servers (1/7): Secure Windows Server Operating Systems Intro
Переглядів 1607 місяців тому
AZ-801 Secure Servers (1/7): Secure Windows Server Operating Systems Intro
DNS Review
Переглядів 858 місяців тому
DNS Review

КОМЕНТАРІ

  • @SebyGamerZROZ
    @SebyGamerZROZ 13 днів тому

    This video is really helpful, thanks

  • @hannahprobably5765
    @hannahprobably5765 22 дні тому

    Hi thanks !

    • @DanZabinski
      @DanZabinski 21 день тому

      You're absolutely welcome!

  • @adriantepes-qu8wm
    @adriantepes-qu8wm 26 днів тому

    DHCP (Preview) ? lol

  • @cel95
    @cel95 29 днів тому

    Thanks for this awesome video! Would be nice to step even deeper into more advanced policy management with EPAC

    • @DanZabinski
      @DanZabinski 22 дні тому

      I can definitely do something on that, managing policy with EPAC is 100x better than using the portal, but it does have its quirks.

  • @Shrew_Bucket
    @Shrew_Bucket Місяць тому

    huge! 🔥

  • @Shadeborn
    @Shadeborn Місяць тому

    Is it possible to add AD groups to an Authentication Policy Silo or are you limited to individual accounts?

  • @raymonddersch4195
    @raymonddersch4195 2 місяці тому

    Was looking for exactly this. Thank you!

  • @MrMisunderestimated
    @MrMisunderestimated 2 місяці тому

    very helpful , thank you very much!

  • @selfspider7644
    @selfspider7644 3 місяці тому

    Thank you

  • @mitchellmallory6524
    @mitchellmallory6524 3 місяці тому

    This is one of the most helpful videos I have seen on Azure Policy. Thanks so much

    • @DanZabinski
      @DanZabinski 3 місяці тому

      Awesome, glad to hear it! Let me know if you have any questions or anything I can clear up.

  • @lee161a
    @lee161a 3 місяці тому

    Are you able to use kinit from a linux/mac system to grab a tgt, using your DA account, and then edit anything (ldapedit/ldapmodify) in AD using the credential remotely. I guess I'm asking how comprehensively does an authentication policy silo apply. I have found the some AD restrictions are only honored by windows devices (my recollection is logon workstation restrictions or group policy deny logon policy, can be gotten around easily this way).

  • @wcalixte
    @wcalixte 4 місяці тому

    Hello, thank you for the video: I have the following error -> Error: creating/updating Security Rule->performing CreateOrUpdate: unexpected status 400 (400 Bad Request) with error: SecurityRuleInvalidAddressPrefix: invalid address prefix Not really sure what that's about.

    • @DanZabinski
      @DanZabinski 4 місяці тому

      Your NSG rule in main.tf (lines 80-92 by default) have an invalid address. I don't know what you have modified, but there are three steps it uses to define that IP: 1. It uses the data block in main.tf, lines 61-63 to look up your current IP address 2. It adds a /32 to the end of it in main.tf, line 43 3. It uses the variable from line 43 to set the rule.

  • @imran2you
    @imran2you 4 місяці тому

    Great Explenation, Thanks Dan

  • @TheBash000
    @TheBash000 4 місяці тому

    About time someone deciphered the MS documentation, great video, clear explanation and appreciate your efforts despite the repetitive and nuanced language required to explain this complexity.

  • @hannahprobably5765
    @hannahprobably5765 4 місяці тому

    Thank you sir, comment for growing up

  • @hannahprobably5765
    @hannahprobably5765 4 місяці тому

    Comment for growing up big thanks!

  • @hannahprobably5765
    @hannahprobably5765 4 місяці тому

    Mega thanks!

  • @Ha-nv2if
    @Ha-nv2if 5 місяців тому

    Thank you, Keep It up

  • @hannahprobably5765
    @hannahprobably5765 5 місяців тому

    Huge thanks

    • @DanZabinski
      @DanZabinski 5 місяців тому

      I hope it's useful, please let me know if you use this and run into any issues!

  • @deltabravo9903
    @deltabravo9903 5 місяців тому

    Thank you

    • @DanZabinski
      @DanZabinski 5 місяців тому

      Absolutely, let me know if you have any questions!

  • @jhonytrujillo6174
    @jhonytrujillo6174 5 місяців тому

    Excelente video. Muy buena explicacion . Gracias por compartirla.

  • @DanZabinski
    @DanZabinski 6 місяців тому

    Glad to help out in any way I can, do you want to reach out to me on LinkedIn and we can set something up? Sorry, I don't have a great mechanism figured out for direct messages yet.

  • @DaveLBier
    @DaveLBier 6 місяців тому

    Good job on the video - I tested this 2 or 3 years ago and also found it underwhelming, frustrating, and often slow - and that is just managing on prem servers. Doesn't really look like it is worth switching to still. We have 1100 application/infra windows servers and it was crazy inefficient to use and manage this tool.

    • @DanZabinski
      @DanZabinski 6 місяців тому

      Thanks for watching! I completely agree with you, the main problem this concept seems to have is scalability, if you're managing more than 10-20 servers, there are much less frustrating methods for administration.

  • @JLM_Tech
    @JLM_Tech 6 місяців тому

    Hey man I’m studying for my AZ104 I have around 6/7 years experience I’d like to connect and learn more from you, do you offer video calls?

  • @bartoszm4290
    @bartoszm4290 6 місяців тому

    Thank you, the topic I have been waiting for the most!

    • @DanZabinski
      @DanZabinski 6 місяців тому

      Feel free to let me know if there is content you are waiting for. I've got a couple following cluster videos and some Backup/Restore content coming.

  • @JLM_Tech
    @JLM_Tech 6 місяців тому

    Sub 👍 I’ve got my Az-104 coming up great video

    • @DanZabinski
      @DanZabinski 6 місяців тому

      Thanks, glad to help out in any way!

  • @stu4321
    @stu4321 7 місяців тому

    I was investigating Kerberos armouring and came across your video, Really interesting stuff, well put together video. I am currently implementing the tiered admin model within our AD this sounds like it would be very useful to prevent our tier 0s from logging into tier 1 servers. I was wondering in the scenario you created in the video would you still be able to log into the DC with a account not tagged with the authentication policy? Thinking of break glass accounts.

    • @DanZabinski
      @DanZabinski 7 місяців тому

      I think that any user with DC permissions can still log into them if they are not linked to the Auth Policy, though I can't recall if I tested that. I am probably going to put up some videos soon that go over how I've been standing up my lab environment for AD so people can try things like this easily.

  • @bartoszm4290
    @bartoszm4290 7 місяців тому

    Great stuff about Azure Policy, thanks!

    • @DanZabinski
      @DanZabinski 7 місяців тому

      Thanks! Let me know if there's anything I can clarify

  • @risunantony
    @risunantony 7 місяців тому

    Wouldnt Adding domain controllers to authentication silos prevent regular users from being able to get a ticket for their own sso?

    • @DanZabinski
      @DanZabinski 7 місяців тому

      Thanks for the question. No, these policies will not interfere with DC authentication attempts.

  • @bartoszm4290
    @bartoszm4290 7 місяців тому

    I learned perfectly just how much is needed, thanks!

  • @eximo5346
    @eximo5346 7 місяців тому

    I was reading a MS blog post about Auth Policies and Silos being the recommended way to control which servers Domain Admins should be logging in to rather than the GPO lockdown method previously recommended. I do wonder restricting kerberos auth would this also impact IIS and other servers that use the domain controllers for authentication of users? Assuming if all clients are on the latest OS's they support kerberos arming and protection.

    • @DanZabinski
      @DanZabinski 7 місяців тому

      The Authentication Silos would only apply to the users and computers linked to it, so it shouldn't have any impact to other services that need to interact with DCs. But like anything affecting your DCs, you would want to make sure you test thoroughly for impact.

  • @anthonydotmoe
    @anthonydotmoe 8 місяців тому

    Thanks for the explanation on this topic! I started reading the MS documentation on it and didn’t really get the big picture of what these features were trying to accomplish. One thing, at 16:27 when trying to log onto that web-p1 server with the DA account. If that account is a member of the protected users group then it’s possible that NTLM auth being blocked was preventing you from logging on, as opposed to the authentication silo because Kerberos isn’t used when specifying a service address by IP.

  • @scottneal5884
    @scottneal5884 9 місяців тому

    Thanks for creating the videos!