Re: Child Domain

Tech-Archive recommends: Fix windows errors by optimizing your registry



Tim wrote:
> Thanks Robert.
>
> Right now, all student computers log in automatically with a generic
> account.
>
> The plans are to give students a login account (better way to track
> them\disable them) and give them an email address. The main idea was
> to keep the staff and students separated. The child domain was for
> security purposes. Now that you mention it is not secure, that will
> change things.

I wouldn't say that its insecure, just that its not a hard "security
boundary"; there remains a chance that a determined and experienced attacker
in one domain could leverage what they have in that domain to mount an
attack on the other domain/the whole forest.

How much of a threat are your students likely to be? The answer to that
question might show that the 2 domain design might be "secure enough". It
might even be "more secure than you need", only you can decide that of
course.

> If you care to volunteer any more info on the subject, I would really
> appreciate this.

Well the stuff on security boundaries is documented in Microsoft's AD design
stuff on their website, so rather than repeat that or drown you in links,
I'll offer up the fact that I too work in education, and have a multi-domain
AD. We've placed all our user accounts both staff and student, in one
domain, and not had any problems.


.



Relevant Pages

  • Re: Unicycle articles (but wait theres more...)
    ... I was issued my X.500 account. ... undergraduate students fail to set up forwarding systems and, instead, ... reciprocity doesn?t just go forward by itself as I found out when I ... North Dakota. ...
    (rec.sport.unicycling)
  • Re: Overhelmed by student password resets. Discussions on best way to let students use .asp page pas
    ... > 1) New students would receive the windows AD account and temporary ... > is information entered accordingly in SQL db for such student account. ... > and request password reset right there. ... > would be sent to the lab manager upon each request for password recovery. ...
    (microsoft.public.win2000.security)
  • Re: Disable multiple computers logon
    ... your plan would not make it impossible for students ... > disable this multiple logon function. ... >> they are not leaving one open for others to use their account), ... whether of an operational nature or regarding security. ...
    (microsoft.public.windows.server.scripting)
  • Re: Stolen computer recovered but has password
    ... Re-install Windows XP from scratch after formatting the drive. ... Microsoft makes it way too difficult to secure a computer properly. ... administrator account and your personal account ... > students who came into the building late in the afternoon. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Stolen computer recovered but has password
    ... operating system to a pristine state after backing up your data files [and ... > students who came into the building late in the afternoon. ... > account. ...
    (microsoft.public.windowsxp.security_admin)