Re: How to setup authentication across domains within a forest?
From: Ulf B. Simon-Weidner [MVP] (nospam2-ulf_at_usw-consulting.com)
Date: 04/12/04
- Next message: Laura E. Hunter [MVP]: "Re: DC not demoted and removed out of AD"
- Previous message: Me: "Re: Using DNS & DHCP in multiple sites..."
- In reply to: Ed Levis: "How to setup authentication across domains within a forest?"
- Next in thread: anonymous_at_discussions.microsoft.com: "Re: How to setup authentication across domains within a forest?"
- Reply: anonymous_at_discussions.microsoft.com: "Re: How to setup authentication across domains within a forest?"
- Messages sorted by: [ date ] [ thread ]
Date: Mon, 12 Apr 2004 23:56:39 +0200
Ed Levis says...
> We are thinking of configuring 3 regional [NA|EU|AP]
> domains within a single AD forest. Our primary goal is
> efficient replication; secondary goal is domain level
> resource management. Our biggest concern re: this
> approach is the need to deploy one or more DCs for each
> domain in each region or the risk of users encountering
> authentication problems when traveling between regions.
> Is there some way we can design our AD environment such
> that all DCs share a local copy of a forest-wide
> authentication db (??) and users authenticate to the
> closest DC in the forest, regardless of the domain in
> which it resides? Any suggestions would be much
> appreciated.
>
Hello Ed,
I'd suggest reading a good AD Book or visit the MOC-Course for
designing Active Directory. Or read the Ressource Kit or Deployment
Kits online. There are not that many reasons why you need multiple
domains, and resource management is not one of them (usually, there may
be exceptions). You are able to split resource management by using OUs
in the Active Directory.
Common Reasons for splitting up into multiple Domains are usually:
- Different Account Policies, like Password Complexity
- Different Security Boundaries (somewhat)
- Partitioning of AD DB-Size
BTW - the ressource kits are online available at
www.reskit.com
Gruesse - Sincerely,
Ulf B. Simon-Weidner
- Next message: Laura E. Hunter [MVP]: "Re: DC not demoted and removed out of AD"
- Previous message: Me: "Re: Using DNS & DHCP in multiple sites..."
- In reply to: Ed Levis: "How to setup authentication across domains within a forest?"
- Next in thread: anonymous_at_discussions.microsoft.com: "Re: How to setup authentication across domains within a forest?"
- Reply: anonymous_at_discussions.microsoft.com: "Re: How to setup authentication across domains within a forest?"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|