Windows server 2019 setup -- 2
Budget: $750 – $1,500 USD
Windows Server 2019 ( Tasks )
Setup VPN
The task involves installing Windows Server 2019 on a Virtual Machine (VM) within Hyper-V, running on a regular PC named Pakerver with the following specifications: Intel Core i5 CPU clocked at 4.10GHz and 40GB RAM.
The objective is to set up a VPN network on Pakerver, allowing employees to remotely access the main server, DC01, and work with data files securely from anywhere in the world.
Here's a summarized plan of the task:
1. Install Hyper-V on Pakerver: Begin by enabling the Hyper-V feature on Pakerver, which will allow the creation and management of virtual machines.
2. Create a Virtual Machine: Within Hyper-V, set up a Virtual Machine and install Windows Server 2019 as the operating system.
3. Configure VM Networking: Ensure that the VM has a network adapter and is connected to the internal network for seamless communication with other resources.
4. Install VPN Software: Install a reputable VPN software on the Windows Server 2019 VM. Configure it to establish a secure connection with the server, DC01.
5. Set Up VPN Access: Define VPN access credentials for employees, allowing them to connect remotely to the server from any location.
6. Enable Remote Access to DC01: On the DC01 server, ensure that it allows remote access via the VPN connection.
7. Secure Data Access: Implement appropriate security measures, such as user authentication and access controls, to safeguard the data on DC01.
8. Test Remote Access: Conduct thorough testing to ensure that employees can successfully connect to DC01 through the VPN and access data files.
9. Provide Instructions: Create user-friendly guidelines or instructions for employees on how to use the VPN to access the server remotely.
10. Monitor and Maintain: Regularly monitor the VPN and server to ensure smooth functionality and address any issues promptly.
With this setup, employees will be able to access DC01 and work on data files securely from anywhere in the world, as long as they have an internet connection and use the provided VPN credentials.
Control Policy
To achieve the desired file control policy for employees on the Windows Server 2019 (DC01), we need to configure the appropriate permissions and security settings. Here's a step-by-step guide to implementing the policy:
1 . Setting Up File Sharing and Permissions:
Create a shared folder on DC01 where all the files will be stored.
Assign full read, write, and modify permissions to all employees for this shared folder so they can work on the files.
For added security, create a separate admin account and give it full control over the shared folder.
2. Restricting File Deletion:
Modify the permissions for the shared folder to allow only the admin account to delete files.
For other users, grant read, write, and modify permissions but deny the "Delete" permission.
3 . Error Message on File Deletion:
Implement a custom error message through scripting or Group Policy that appears when users attempt to delete files. The message should prompt them to enter the admin username and password for file deletion.
4. Preventing File Moves without Password:
Create a separate folder within the shared folder that requires a password to move files.
Modify the permissions for this folder to allow only the admin account to move files.
For other users, grant read, write, and modify permissions but deny the "Move" permission.
5 . File Backup:
Set up a scheduled backup system to create daily backups of the shared folder's contents.
Configure backup retention policies to retain the backups for a specific period, allowing easy retrieval if needed.
Note: Always make sure to have proper backups and a contingency plan in case any issues arise during the implementation process.
Make Right and control policy according to Group
Setup role rights and control base on group members like Pakistan team and UK team so Few folders Pakistan team won’t be able to see and also these limitation can be change any time .
One Drive and Share point Tasks
To set up SharePoint Online with the key point of preventing multiple users from opening the same file simultaneously, follow these steps:
1. Create a SharePoint Online Site:
• Sign in to your SharePoint Online account as an administrator.
• Create a new site or use an existing site to organize your files and documents.
2. Upload Files to SharePoint:
• Upload all the files and documents that users need to access and collaborate on to the appropriate document libraries in SharePoint.
3. Enable Versioning:
• For each document library, enable versioning to keep track of changes made to files over time.
4. Require Check Out:
• In the document library settings, enable the "Require documents to be checked out before they can be edited" option.
• This will ensure that only one user can edit a file at a time.
5. Configure Co-Authoring Settings:
• Go to the SharePoint admin centre and under "Settings," select "Document library settings."
• Set the co-authoring settings to allow multiple users to edit the same document at the same time, but only if they are using Office applications (Word, Excel, PowerPoint) from their computers or devices.
• This way, online editing (via browser) will show an error if the file is already being edited.
6. Set Document Lock Duration:
• By default, SharePoint Online locks documents for 10 minutes after a user checks out a file.
• You can adjust this duration based on your organization's needs to prevent contention for editing.
7. Train Users:
• Educate users on the need to check out files before editing them to avoid conflicts.
• Encourage them to check in files promptly after making changes to release the lock for others.
By implementing these steps, users will be able to access SharePoint Online from outside the office and work on files collaboratively. SharePoint will manage file locking and co-authoring to prevent multiple users from opening the same file simultaneously, reducing conflicts and ensuring a seamless collaborative experience.
One drive Backup
Setting up backup on cloud using OneDrive for Business and SharePoint Online requires careful planning and configuration. Here's a step-by-step guide to achieve this, along with some tips on managing control-related tasks:
Step 1: Assess Data and Storage Requirements
• Analyze your data storage needs and identify critical data that requires frequent backups.
• Calculate the amount of storage you'll need on OneDrive for Business and SharePoint Online.
Step 2: Sign Up for Microsoft 365 Business Plan
• Ensure your organization has a Microsoft 365 Business plan that includes OneDrive for Business and SharePoint Online.
Step 3: Enable OneDrive Sync and SharePoint Sync
• In the Microsoft 365 Admin Center, enable OneDrive and SharePoint for your users.
Step 4: Install OneDrive Sync Client
• Instruct users to install the OneDrive Sync client on their computers and devices.
• Set up the sync client to synchronize selected folders from their local devices to OneDrive.
Step 5: Set Up SharePoint Libraries
• Create SharePoint libraries for different departments or projects.
• Determine access rights and permissions for each library.
Step 6: Train Users on OneDrive and SharePoint
• Provide training to your users on how to use OneDrive for individual file storage and sharing.
• Educate users on SharePoint usage for team collaboration and document management.
Step 7: Schedule Regular Backups
• Microsoft 365 has built-in backup and retention features, but it's essential to create an additional backup strategy for critical data.
• Explore third-party backup solutions that can provide additional data protection and long-term retention.
Step 8: Set Up Retention Policies
• Define retention policies in Microsoft 365 to retain important data for the required duration.
• Ensure that backup and retention policies align with your organization's data retention policies.
Step 9: Monitor and Manage
• Regularly monitor storage usage on OneDrive and SharePoint.
• Review access permissions and make adjustments as needed.
Step 10: Disaster Recovery Planning
• Create a disaster recovery plan to handle data loss or accidental deletions.
• Test the recovery process to ensure that data can be retrieved successfully even after a year or more.
Step 11: Document Control Guidelines
• Establish guidelines for document naming conventions and folder structures to maintain organization and ease of retrieval.
• Implement version control practices to track changes and avoid overwriting important data.
Step 12: Security and Compliance
• Educate users on data security best practices, such as strong passwords and two-factor authentication.
• Monitor and enforce compliance with data security policies to prevent data breaches.
Remember to regularly review and update your backup and data management strategies to accommodate changes in your organization's needs and data growth.
Additionally, consider seeking assistance from a Microsoft 365 consultant or IT expert to guide you through the setup process and provide personalized training for your organization.
.
Setup VPN
The task involves installing Windows Server 2019 on a Virtual Machine (VM) within Hyper-V, running on a regular PC named Pakerver with the following specifications: Intel Core i5 CPU clocked at 4.10GHz and 40GB RAM.
The objective is to set up a VPN network on Pakerver, allowing employees to remotely access the main server, DC01, and work with data files securely from anywhere in the world.
Here's a summarized plan of the task:
1. Install Hyper-V on Pakerver: Begin by enabling the Hyper-V feature on Pakerver, which will allow the creation and management of virtual machines.
2. Create a Virtual Machine: Within Hyper-V, set up a Virtual Machine and install Windows Server 2019 as the operating system.
3. Configure VM Networking: Ensure that the VM has a network adapter and is connected to the internal network for seamless communication with other resources.
4. Install VPN Software: Install a reputable VPN software on the Windows Server 2019 VM. Configure it to establish a secure connection with the server, DC01.
5. Set Up VPN Access: Define VPN access credentials for employees, allowing them to connect remotely to the server from any location.
6. Enable Remote Access to DC01: On the DC01 server, ensure that it allows remote access via the VPN connection.
7. Secure Data Access: Implement appropriate security measures, such as user authentication and access controls, to safeguard the data on DC01.
8. Test Remote Access: Conduct thorough testing to ensure that employees can successfully connect to DC01 through the VPN and access data files.
9. Provide Instructions: Create user-friendly guidelines or instructions for employees on how to use the VPN to access the server remotely.
10. Monitor and Maintain: Regularly monitor the VPN and server to ensure smooth functionality and address any issues promptly.
With this setup, employees will be able to access DC01 and work on data files securely from anywhere in the world, as long as they have an internet connection and use the provided VPN credentials.
Control Policy
To achieve the desired file control policy for employees on the Windows Server 2019 (DC01), we need to configure the appropriate permissions and security settings. Here's a step-by-step guide to implementing the policy:
1 . Setting Up File Sharing and Permissions:
Create a shared folder on DC01 where all the files will be stored.
Assign full read, write, and modify permissions to all employees for this shared folder so they can work on the files.
For added security, create a separate admin account and give it full control over the shared folder.
2. Restricting File Deletion:
Modify the permissions for the shared folder to allow only the admin account to delete files.
For other users, grant read, write, and modify permissions but deny the "Delete" permission.
3 . Error Message on File Deletion:
Implement a custom error message through scripting or Group Policy that appears when users attempt to delete files. The message should prompt them to enter the admin username and password for file deletion.
4. Preventing File Moves without Password:
Create a separate folder within the shared folder that requires a password to move files.
Modify the permissions for this folder to allow only the admin account to move files.
For other users, grant read, write, and modify permissions but deny the "Move" permission.
5 . File Backup:
Set up a scheduled backup system to create daily backups of the shared folder's contents.
Configure backup retention policies to retain the backups for a specific period, allowing easy retrieval if needed.
Note: Always make sure to have proper backups and a contingency plan in case any issues arise during the implementation process.
Make Right and control policy according to Group
Setup role rights and control base on group members like Pakistan team and UK team so Few folders Pakistan team won’t be able to see and also these limitation can be change any time .
One Drive and Share point Tasks
To set up SharePoint Online with the key point of preventing multiple users from opening the same file simultaneously, follow these steps:
1. Create a SharePoint Online Site:
• Sign in to your SharePoint Online account as an administrator.
• Create a new site or use an existing site to organize your files and documents.
2. Upload Files to SharePoint:
• Upload all the files and documents that users need to access and collaborate on to the appropriate document libraries in SharePoint.
3. Enable Versioning:
• For each document library, enable versioning to keep track of changes made to files over time.
4. Require Check Out:
• In the document library settings, enable the "Require documents to be checked out before they can be edited" option.
• This will ensure that only one user can edit a file at a time.
5. Configure Co-Authoring Settings:
• Go to the SharePoint admin centre and under "Settings," select "Document library settings."
• Set the co-authoring settings to allow multiple users to edit the same document at the same time, but only if they are using Office applications (Word, Excel, PowerPoint) from their computers or devices.
• This way, online editing (via browser) will show an error if the file is already being edited.
6. Set Document Lock Duration:
• By default, SharePoint Online locks documents for 10 minutes after a user checks out a file.
• You can adjust this duration based on your organization's needs to prevent contention for editing.
7. Train Users:
• Educate users on the need to check out files before editing them to avoid conflicts.
• Encourage them to check in files promptly after making changes to release the lock for others.
By implementing these steps, users will be able to access SharePoint Online from outside the office and work on files collaboratively. SharePoint will manage file locking and co-authoring to prevent multiple users from opening the same file simultaneously, reducing conflicts and ensuring a seamless collaborative experience.
One drive Backup
Setting up backup on cloud using OneDrive for Business and SharePoint Online requires careful planning and configuration. Here's a step-by-step guide to achieve this, along with some tips on managing control-related tasks:
Step 1: Assess Data and Storage Requirements
• Analyze your data storage needs and identify critical data that requires frequent backups.
• Calculate the amount of storage you'll need on OneDrive for Business and SharePoint Online.
Step 2: Sign Up for Microsoft 365 Business Plan
• Ensure your organization has a Microsoft 365 Business plan that includes OneDrive for Business and SharePoint Online.
Step 3: Enable OneDrive Sync and SharePoint Sync
• In the Microsoft 365 Admin Center, enable OneDrive and SharePoint for your users.
Step 4: Install OneDrive Sync Client
• Instruct users to install the OneDrive Sync client on their computers and devices.
• Set up the sync client to synchronize selected folders from their local devices to OneDrive.
Step 5: Set Up SharePoint Libraries
• Create SharePoint libraries for different departments or projects.
• Determine access rights and permissions for each library.
Step 6: Train Users on OneDrive and SharePoint
• Provide training to your users on how to use OneDrive for individual file storage and sharing.
• Educate users on SharePoint usage for team collaboration and document management.
Step 7: Schedule Regular Backups
• Microsoft 365 has built-in backup and retention features, but it's essential to create an additional backup strategy for critical data.
• Explore third-party backup solutions that can provide additional data protection and long-term retention.
Step 8: Set Up Retention Policies
• Define retention policies in Microsoft 365 to retain important data for the required duration.
• Ensure that backup and retention policies align with your organization's data retention policies.
Step 9: Monitor and Manage
• Regularly monitor storage usage on OneDrive and SharePoint.
• Review access permissions and make adjustments as needed.
Step 10: Disaster Recovery Planning
• Create a disaster recovery plan to handle data loss or accidental deletions.
• Test the recovery process to ensure that data can be retrieved successfully even after a year or more.
Step 11: Document Control Guidelines
• Establish guidelines for document naming conventions and folder structures to maintain organization and ease of retrieval.
• Implement version control practices to track changes and avoid overwriting important data.
Step 12: Security and Compliance
• Educate users on data security best practices, such as strong passwords and two-factor authentication.
• Monitor and enforce compliance with data security policies to prevent data breaches.
Remember to regularly review and update your backup and data management strategies to accommodate changes in your organization's needs and data growth.
Additionally, consider seeking assistance from a Microsoft 365 consultant or IT expert to guide you through the setup process and provide personalized training for your organization.
.
Related categories:
System Admin
Web Security
Computer Security
Windows Server
Network Administration