Child Domain Setup Quiestion



Hi,
I have a scenario where I have a company that is devided into to seperate
parts. I need to create an Active Directory domain structure that will meet
our needs. We need to have the sturcture set up that one area is independant
of the other area in all aspects including Adminstration by IT Staff and yet
still be able to have an IT Super group that can administrate all parts of
the company and some other special users that will need access to both parts
of the company. I had two ideas on how I thought we could do this but I am
not sure of how to achive the result.

Option 1: Create a parent Domain (ie ourcompany.com), then create 2 child
Domains (ie parta.ourcompany.com and partb.ourcompany.com) each child domain
should be able to access the parent domain but not the other child domain.
The parent domain should be able to access the 2 child domains.

I think that this option is the better but am unsure of how to set it up.
Are the follow steps correct.

1. Install Windows Server on First Server.
2. Run "dcpromo" and create the ourcompany.com domain. Including DNS Server.
3. Install Windows Server on second server and join ourcompany.com as a
member server.
4. Run "dcpromo" on second server and create the parta.ourcompany.com
domain.
3. Install Windows Server on third server and join ourcompany.com as a
member server.
4. Run "dcpromo" on third server and create the partb.ourcompany.com domain.
5. Fine tune and remaining details.

Option 2: Create 2 Domains in the 1 forest and then setup some sort of trust
between the domains.

Thanks for any help provided.
Kenneth Keeley



.



Relevant Pages

  • Re: Unable to Raise Domain Functional Level
    ... that directory replication is healthy on multiple test passes. ... Should I check the remaining child domain and root domain to ... The server that DCDiag complains about is CNR-PR-DOMA00 ... are indicating the servers are receiving their DNS settings via DHCP. ...
    (microsoft.public.windows.server.migration)
  • Re: Replication Headache - Urgent please Assist!
    ... Creating a child domain creates more admin overhead. ... 1.Manually created a delegation for the child domain on our root server ... 2.Installed DNS on the child domain server ... You must make sure there are no existing net use connections, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Unable to Raise Domain Functional Level
    ... Check if this server is deleted, and if so clean up this DCs ... The same error always appears regardless of which DC in the child domain I ... The Root domain is an AD integrated DNS zone. ...
    (microsoft.public.windows.server.migration)
  • Re: Share access problem 2003 member server
    ... but they do not have rights or permissions unless ... can't even view the share on this server. ... Account John is a member of child domain called West.newtrader.co.uk ...
    (microsoft.public.windows.server.general)
  • Re: DC of the Parent Domain cant Ping the hostname of the DC Chil
    ... I didn't know we still have to setup WINS between Parent - Child domains. ... name not a dns name, so pinging a FQDN that works tells me that your dns is ... sake of argument" also acting as File Server in head office with all ... The Parent, host1, knows about the child domain and its DC in the DNS ...
    (microsoft.public.windows.server.active_directory)