模擬的網域控制站技術參考附錄Virtualized Domain Controller Technical Reference Appendix

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

本主題涵蓋:This topic covers:

詞彙Terminology

  • 快照-一樣,在特定時間點的狀態。Snapshot - The state of a virtual machine at a particular point in time. 它是和模擬平台上鏈結的上一個快照、 上的硬體相關。It is dependent on the chain of previous snapshots taken, on the hardware, and on the virtualization platform.

  • 複製-完成,不同的一樣。Clone - A complete and separate copy of a virtual machine. 它是 virtual 硬體 (hypervisor) 而定。It is dependent on the virtual hardware (hypervisor).

  • 完整複製-完整複製是獨立複製操作之後會與家長一樣共用不資源一樣複本。Full Clone - A full clone is an independent copy of a virtual machine that shares no resources with the parent virtual machine after the cloning operation. 完整的複製執行的作業會完全分開家長一樣。Ongoing operation of a full clone is entirely separate from the parent virtual machine.

  • 差異磁碟-一份執行的方式會與家長一樣共用 virtual 磁碟一樣。Differencing disk - A copy of a virtual machine that shares virtual disks with the parent virtual machine in an ongoing manner. 這通常是節省磁碟空間,可使用相同的軟體安裝多個虛擬電腦。This usually conserves disk space and allows multiple virtual machines to use the same software installation.

  • VM 複製-檔案系統複本相關的所有檔案和資料夾的一樣。VM Copy- A file system copy of all the related files and folders of a virtual machine.

  • VHD 複製檔案-一樣 VHD 複本VHD File Copy - A copy of a virtual machine's VHD

  • VM 代 ID -128 元整數 hypervisor 所提供給一樣。VM Generation ID - a 128-bit integer given to the virtual machine by the hypervisor. 這個 ID 是儲存在記憶體中,每次快照套用重設。This ID is stored in memory and reset every time a snapshot is applied. 設計使用 hypervisor 無關機制則新一代 VM 中的 ID 一樣。The design uses a hypervisor-agnostic mechanism for surfacing the VM-Generation ID in the virtual machine. HYPER-V 實作公開中 ACPI 一樣的來電顯示。The Hyper-V implementation exposes the ID in the ACPI table of the virtual machine.

  • 匯入日匯出-A HYPER-V 功能,可讓使用者儲存整個一樣 (VM 的檔案、 VHD 和電腦組態)。Import/Export - A Hyper-V feature that allows the user to save the entire virtual machine (VM files, VHD and the machine configuration). 然後可讓使用者將電腦相同 VM (還原),以相同的電腦上使用該檔案的設定為相同的 VM (移) 或新增 VM (複製) 是不同的電腦上It then allows users to using that set of files to bring the machine back on the same machine as the same VM (Restore), on a different machine as the same VM (Move), or a new VM (copy)

FixVDCPermissions.ps1FixVDCPermissions.ps1

# Unsigned script, requires use of set-executionpolicy remotesigned -force  
# You must run the Windows PowerShell console as an elevated administrator  

# Load Active Directory Windows PowerShell Module and switch to AD DS drive  
import-module activedirectory  
cd ad:  

## Get Domain NC  
$domainNC = get-addomain  

## Get groups and obtain their SIDs   
$dcgroup = get-adgroup "Cloneable Domain Controllers"  

$sid1 = (get-adgroup $dcgroup).sid  

## Get the DACL of the domain  
$acl = get-acl $domainNC  

## The following object specific ACE grants extended right 'Allow a DC to create a clone of itself' for the CDC group to the Domain NC  
## 3e0f7e18-2c7a-4c10-ba82-4d926db99a3e is the schemaIDGuid for 'DS-Clone-Domain-Controller"  

$objectguid = new-object Guid 3e0f7e18-2c7a-4c10-ba82-4d926db99a3e  
$ace1 = new-object System.DirectoryServices.ActiveDirectoryAccessRule $sid1,"ExtendedRight","Allow",$objectguid  

## Add the ACE in the ACL and set the ACL on the object   

$acl.AddAccessRule($ace1)  
set-acl -aclobject $acl $domainNC  
write-host "Done writing new VDC permissions."  
cd c: