Re: Empty Root Domain required?



I think it is a bit of a mixed answer.
In part, it is good practice to have an empty root domain and your main
domain as a child. It gives you greater flexibility for expansion and
change, for example by creating a second peer. It also somewhat protects the
core from access and changes. However it also means that you need a minimum
or four DC's instead of two, so in a small network you may just have to do
without.
In terms of migration to a future AD structure of your parent, I doubt there
is any difference between migrating a child domain or a root domain to a
different forest.
However, depending on your relationship with the parent, there is an option
for them to inherit the root you have created and expand it.
On balance, I think the only real purpose of root and child would be if you
need the flexibility in future for yourself,
Anthony


"Beno" <Beno@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:825C16D4-9572-42F2-8417-5C4584A112FB@xxxxxxxxxxxxxxxx
Hello
I want to setup a new AD (Win2k3) for my subsidiary company. We are
autonomous from the our overseas parent company, and the parent company
does
not have a "global AD structure" at this point. I was proposing to create
an
empty root domain in my new local forest, and then have my "production
domain" as a child domain off the empty root domain. If, in the future,
the
parent company created a new global AD that we, as a subsidiary needed to
be
part of, I thought I could "cross-migrate" my child production domain
straight into the parent "global AD forest" off their root domain. Is this
a
good idea, or is the empty child domain in my local forest simply a waste
of
resources?


.



Relevant Pages

  • Re: AD design question
    ... I don't have an empty root domain and I haven't ran into any problems ... else you have to get rid of the child domain, create the parent, then create ... > our buildings to one AD domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Empty Root Domain required?
    ... you cannot CUT and PASTE a domain in a forest to another forest. ... autonomous from the our overseas parent company, ... empty root domain in my new local forest, ... domain" as a child domain off the empty root domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS lookup error at root domain
    ... > The same setting as above with a root domain A and a child domain B. ... > are my findings using nslookup. ... And Subnets are largely unrelated to DNS. ...
    (microsoft.public.windows.server.dns)
  • Re: Help Understanding Scope of Users Created in Child Domain
    ... > 1) Why are these user objects appearing only in the child domain when the ... > namespace they refer to in fully-qualified form of their name points to ... > also show up in Users and Computers on the root domain controller. ... The e-mail type name is the UPN - User Principal Name. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Help Understanding Scope of Users Created in Child Domain
    ... creating the users in the child domain, not the root domain. ... There are no implications of having users in any domain using a UPN from ... within your forest use that UPN. ...
    (microsoft.public.windows.server.active_directory)

Loading