יצירת דומיין

בדף הזה מוסבר איך ליצור דומיין באמצעות שירות מנוהל ל-Microsoft Active Directory.

לפני שמתחילים

  1. נכנסים לחשבון Google Cloud . אם אתם משתמשים חדשים ב- Google Cloud, צרו חשבון כדי שתוכלו להעריך את הביצועים של המוצרים שלנו בתרחישים מהעולם האמיתי. לקוחות חדשים מקבלים בחינם גם קרדיט בשווי 300$ להרצה, לבדיקה ולפריסה של עומסי העבודה.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.

  4. Verify that billing is enabled for your Google Cloud project.

  5. Enable the Managed Microsoft AD, Cloud DNS, and Compute Engine APIs.

    Roles required to enable APIs

    To enable APIs, you need the Service Usage Admin IAM role (roles/serviceusage.serviceUsageAdmin), which contains the serviceusage.services.enable permission. Learn how to grant roles.

    Enable the APIs

  6. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  7. If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.

  8. Verify that billing is enabled for your Google Cloud project.

  9. Enable the Managed Microsoft AD, Cloud DNS, and Compute Engine APIs.

    Roles required to enable APIs

    To enable APIs, you need the Service Usage Admin IAM role (roles/serviceusage.serviceUsageAdmin), which contains the serviceusage.services.enable permission. Learn how to grant roles.

    Enable the APIs

  10. יוצרים רשת חדשה של ענן וירטואלי פרטי (VPC) כדי לפרוס בה את הדומיין, או משתמשים ברשת קיימת. ב-Managed Microsoft AD אין תמיכה ברשתות מדור קודם. חשוב לרשום את שם המשאב המלא של רשת ה-VPC, שצריך לציין במהלך תהליך יצירת הדומיין. הפורמט הוא: projects/PROJECT_ID/global/networks/VPC_NETWORK_NAME
    • לפני שיוצרים רשת VPC, חשוב לקרוא את המאמר בחירת רשתות VPC.
    • חשוב לוודא שמפעילים את ממשקי ה-API ויוצרים את ה-VPC באותו פרויקט שבו הפעלתם את החיוב.

התפקידים הנדרשים

כדי לקבל את ההרשאות שדרושות לביצוע ההפעלה המהירה הזו, צריך לבקש מהאדמין להקצות לכם את תפקידי ה-IAM הבאים בפרויקט:

להסבר על מתן תפקידים, ראו איך מנהלים את הגישה ברמת הפרויקט, התיקייה והארגון.

התפקידים המוגדרים מראש האלה כוללים את ההרשאות שנדרשות כדי להשלים את המדריך למתחילים הזה. כדי לראות בדיוק אילו הרשאות נדרשות, אפשר להרחיב את הקטע ההרשאות הנדרשות:

ההרשאות הנדרשות

כדי להשלים את המדריך למתחילים הזה, נדרשות ההרשאות הבאות:

  • managedidentities.domains.create
  • compute.networks.list

יכול להיות שתקבלו את ההרשאות האלה באמצעות תפקידים בהתאמה אישית או תפקידים מוגדרים מראש אחרים.

איסוף מידע

כדי ליצור את הדומיין, תצטרכו את הפרטים הבאים:

יצירת הדומיין

כדי ליצור דומיין, מבצעים את השלבים הבאים:

המסוף

  1. עוברים לדף Managed Microsoft AD.
    מעבר אל שירות מנוהל ל-Microsoft AD

  2. בוחרים באפשרות יצירת דומיין חדש של Active Directory.

  3. בדף Create new domain (יצירת דומיין חדש), מזינים את המידע שנאסף.

    • מזינים את