Re: Peer-Root and Placeholder Domain Model

From: Chriss3 [MVP] (noSpamHere_at_chrisse.se)
Date: 08/22/04


Date: Mon, 23 Aug 2004 00:46:32 +0200

Todd this dose not give you a more secure environment in anyway, the only
security boundary is a forest, if you require isolation then you should
create another forest.

-- 
Regards
Christoffer Andersson
Microsoft MVP - Directory Services
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"Todd Ouimet" <touimet@(nospam)advantageprofessionals.com> skrev i 
meddelandet news:e7WslT$hEHA.2544@TK2MSFTNGP10.phx.gbl...
> The SAM book "Designing a Windows Server 2003 Active Directory" which can 
> be
> found:
> http://www.samspublishing.com/articles/article.asp?p=32080
>
> talks about Peer-Root Domain Model and Placeholder Domain Model adding
> additional security.
>
> Could anyone tell me if indeed this "REALLY" adds solid security which is
> well worth the additional hardware and software licenses or is it just 
> more
> of a perceived security boundary.
>
> Thanks,
> Todd
>
> 


Relevant Pages

  • Re: Peer-Root and Placeholder Domain Model
    ... I have an article with information about the security of deploying ... another forest instead of create domain in a existing forest. ... "Todd" skrev i meddelandet ... >>> talks about Peer-Root Domain Model and Placeholder Domain Model adding ...
    (microsoft.public.windows.server.active_directory)
  • Re: SMTP queues filled with domains..how to delete
    ... Todd posted their thoughts, ... Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP ... Microsoft Windows MVP - Active Directory ...
    (microsoft.public.exchange2000.admin)
  • Re: DNS and Active Directory
    ... >dcpromo. ... Now I have Active Directory, but my DNS>zones aren't ad ... Todd J Heron, MCSE ...
    (microsoft.public.windows.server.dns)
  • Re: Empty Root, Peer-Root, and/or Placeholder Domain
    ... forest and the the DC within the new Domain Tree? ... > Joe Richards Microsoft MVP Windows Server Directory Services ... > Todd wrote: ... >> domain will be the root domain containing all the users from the old NT ...
    (microsoft.public.windows.server.active_directory)
  • Re: How do I know if I have one or two AD Forests?
    ... "Todd J Heron" wrote: ... >>I have inherited a Microsoft 2000 Network and I know I have two domains. ... I'm not sure if they are in one forest or separate>forests. ...
    (microsoft.public.windows.server.active_directory)