> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/active-directory/lab-setup.md).

# Active Directory 实验室

## 域控制器（DC）的安装与配置

#### 1. Windows Server 安装

* 下载 **Windows Server 2022** ISO

{% embed url="<https://www.microsoft.com/en-us/evalcenter/download-windows-server-2022>" %}

* 选择 **Windows Server 2022 Standard（评估版）**

<figure><img src="/files/72bf73c4c07aac8c5bea754d55608808f9f097df" alt=""><figcaption></figcaption></figure>

* 在虚拟机上安装系统
* 安装程序 **VMware Tools**

<figure><img src="/files/3f33d9596503eb611a7605df7c876a99c72552d3" alt=""><figcaption></figcaption></figure>

#### 2. 初始设置

* 编辑 **机器名称**

<figure><img src="/files/33fb8c918a5f599b83d49c1fc1a1fdfc311f3c1f" alt=""><figcaption></figcaption></figure>

* 配置一个 **静态 IP 地址**

<figure><img src="/files/2fb73a915699f1ffce86a2a001b3283b5298bde6" alt=""><figcaption></figcaption></figure>

#### 3. 安装角色

* 安装角色：
  * **Active Directory 域服务（AD DS）**

<figure><img src="/files/9b430e5b881b349134df39c59e031ab7aa339e92" alt=""><figcaption></figcaption></figure>

#### 4. 提升为域控制器

* 创建一个 **新林**
* 域名： `whoami.local`

<figure><img src="/files/578e7dc7c985f61363722704ae85f6e572cde6a9" alt=""><figcaption></figcaption></figure>

* 配置完成后重启虚拟机

## 在域中安装 Windows 10 机器

{% embed url="<https://software.download.prss.microsoft.com/dbazure/Win10_22H2_Spanish_x64v1.iso?t=8faab265-3c5c-460a-ae83-230703b31fd6&P1=1777739675&P2=601&P3=2&P4=ESZ9seUg91b93n2FgqYLYn08u1otAQpm6KUoqKs%2bPfI%2fRGyaR5gC6Z%2bpXtNfLTnRjZwTh0kYwqPjfq0n6jCpj9JH8gba3jIb3OHetCttHy4inx40XJRc7nvkHlJpxfz9q75MgH%2fJNsc3h9ONnCrJ16sUH9PmqmYXPYzSxRQ%2bVltoOyn%2bgWrRLvWlemNQ3BPk6GRx%2bMaFPHPxZcur%2bobP%2fa2%2bCe%2fnm4Ymh2fbIK4KS1e9mXZMCT4hNto6aLXUoAHE6mkoLtIJVAG0wXB%2bo3koJs%2f3Maq8OTxThJdmIAHaASjxSOdRRuqQzOzDiyjQBpmLtvodrW6VrbRBxNGZ9839Bg%3d%3d>" %}

#### 1. 创建机器

* 创建两台机器：
  * **WS01**
  * **WS02**

<figure><img src="/files/e6e152991d25fb3bf14c867e7b002d71cccb8257" alt=""><figcaption></figcaption></figure>

#### 2. 机器配置

* 更改计算机名称：
  * WS01
  * WS02

<figure><img src="/files/949a8390e37fd11d8258d565d9fbfd93ff1dbafb" alt=""><figcaption></figcaption></figure>

配置 IP 地址，并将 DNS 指向域控制器：

* DNS： `172.16.0.100`

<figure><img src="/files/bec15d2f7b80f1673113dec4d2ac83e39b9a7d7f" alt=""><figcaption></figcaption></figure>

* 更改 **高级共享** 设置（网络和发现）

<figure><img src="/files/146f8bfad5bf737584b1ae130cd56a02a33a531d" alt="" width="563"><figcaption></figcaption></figure>

#### 3. 创建用户

在 **Active Directory 管理中心**:

<figure><img src="/files/641ba527bc4b96b80e73df33ab2ca38aa588cdb1" alt=""><figcaption></figcaption></figure>

创建两个用户：

* user1
* user2

<figure><img src="/files/2a3506280827b660232f42356e689f49e47a6c35" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/a31ea4251a5f64c35149d69f55a451e350a97f69" alt=""><figcaption></figcaption></figure>

#### 4. 域集成

* 前往： **专业或教育访问**

<figure><img src="/files/d3551e1b206b8d928ece7fc49fff4a3973ef302a" alt=""><figcaption></figcaption></figure>

* 选择： **连接到域**
* 输入域名： `whoami.local`
* 使用域账户进行身份验证

<figure><img src="/files/de50566c02a2f8afbb0869726670a70879d4175c" alt="" width="535"><figcaption></figcaption></figure>

## Active Directory 功能：用户、组和 OU

在 **Active Directory 用户和计算机**，你可以管理和修改林及对象的配置。

<figure><img src="/files/644d09f2bfb5d27f9542cbaf8df9a815069deb5b" alt="" width="466"><figcaption></figcaption></figure>

#### 用户和 OU 管理

<figure><img src="/files/c9110eb6336767dd2d28f802144ebdce5a0f99e9" alt="" width="418"><figcaption></figcaption></figure>

#### 示例：创建一个部门

<figure><img src="/files/ad92db01b06f9afeebc21e1f3e95bdbfdf070a97" alt=""><figcaption></figcaption></figure>

创建一个 **组织单位（OU）**，例如：

* *图卢兹*
* 将现有用户移动到此 OU 中，以组织结构。

<figure><img src="/files/994089e37b3860987fbba94441353a1b2f7a3749" alt=""><figcaption></figcaption></figure>

#### 组管理

* 创建组，例如：

  * **IT**

  将用户添加到该组。

<figure><img src="/files/19da9bb7e82811df2e344e1b7f85867dfe2ab0b8" alt=""><figcaption></figcaption></figure>

一个组可以是 **另一个组的成员**.

* 示例：
  * 该 *IT* 组可以成为 *Administrators* 组

然后用户会继承 **权限** 来自父组。

<figure><img src="/files/d11c38b7e92db080a3cf1cdfb8f14f80947de3cc" alt=""><figcaption></figcaption></figure>

#### GPO 管理（组策略对象）

**GPO** 允许你管理配置策略。

<figure><img src="/files/41ff2b2f0a2ff1023a0f66945d4026091a13f303" alt=""><figcaption></figcaption></figure>

#### 创建 GPO

* 前往： **组策略管理**

<figure><img src="/files/084d3ac94272a49738bf77076586f75a7cf7cf74" alt="" width="475"><figcaption></figcaption></figure>

* 单击 OU，例如 **图卢兹**
* 创建一个新的 **GPO**

<figure><img src="/files/935ea536c86854483e18e4ea18db5ad060bb4412" alt=""><figcaption></figcaption></figure>

* 编辑策略

<figure><img src="/files/4460bb8f51bbd43e258ae8d547abaff04f839390" alt=""><figcaption></figcaption></figure>

#### 策略类型

GPO 可以根据以下内容应用：

* **用户**
* **计算机**

<figure><img src="/files/da0bc7dac8ac2cf4a52401df2a24e6dc861d0e89" alt=""><figcaption></figcaption></figure>

#### 示例：在会话开始时运行脚本

* 前往：/ **用户配置 → Windows 设置 → 脚本（登录）**
* 创建一个 `script.bat` 包含以下内容的文件

{% code overflow="wrap" %}

```bash
calc.exe
```

{% endcode %}

<figure><img src="/files/1afce735a7c7093ac0fa2c12e9c9a94f99b145f7" alt=""><figcaption></figcaption></figure>

结果：用户登录时会打开计算器。

<figure><img src="/files/e8a8537adae0a7d4eb75656f3a4e14b92304848c" alt=""><figcaption></figcaption></figure>

#### 共享资源（SMB）

创建共享

* 前往：/ **服务器管理器 → 文件和存储服务 → 共享**

<figure><img src="/files/f200babd12338e9466f0b846ed7df104847d65f5" alt=""><figcaption></figcaption></figure>

* 创建一个新的 SMB 共享，例如：
  * 本地文件夹： `C:\Shares\it`
  * 网络路径： `//DC01/it`

<figure><img src="/files/819309d283860b6f8e1d8df8dfb1e53d91c8b72c" alt=""><figcaption></figcaption></figure>

#### 通过 GPO 自动挂载

要自动连接共享：

<figure><img src="/files/4a59d55cafccaa8729246085006489467f65139a" alt=""><figcaption></figcaption></figure>

* 使用脚本：

{% code overflow="wrap" %}

```bash
net use t: //172.16.0.100/it
```

{% endcode %}

<figure><img src="/files/eba9c7b3a513b5ae87bccc6d07e81444d1dd7404" alt=""><figcaption></figcaption></figure>

结果：网络驱动器会自动出现在工作站上。

<figure><img src="/files/b56116852cfebd3e3aa737f6d875b92084499e8f" alt=""><figcaption></figcaption></figure>

#### 注意事项（安全）

注意这些文件夹：

* **NETLOGON**
* **SYSVOL**

<figure><img src="/files/eb697b357a87b158b9f65ed6ba761c165deb8f09" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/active-directory/lab-setup.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
