Re: AD Design



If you are the only admins, then multi-domains does not achieve anything
(much). If you share admin with your clients, then sharing the same forest
exposes each company to the others, which they may not have had in mind when
using you.
You also need to think about physical security, since you are exposing each
client to the security of the weakest site. So if you went down the domain
sharing route, you might want to look at the hardening of the DC, e.g BIOS
password
Anthony


"Paul Williams [MVP]" <ptw2001@xxxxxxxxxxx> wrote in message
news:Oxs99yd1GHA.4264@xxxxxxxxxxxxxxxxxxxxxxx
It's possible, but not recommended. If these are different companies,
there's major security considerations that need to be taken. Multiple
domains in the same forest aren't recommended if we're talking about
different sets of service admins or if there's confidential data in any of
the domains.

Single forests that share a contiguous namespace is fine, but somewhat
rare.

Check out the Designing and deploying directory and security services book
(Google -there's an online soft copy).

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net





.



Relevant Pages

  • RE: Active Directory network security
    ... In fact the only true security boundary in AD is a forest. ... Domain Admins must be fully trusted. ... use group policies like crazy. ...
    (Focus-Microsoft)
  • Re: Delegate certain rights to a single Domain Controller
    ... > If you think your domain admins can only modify stuff in their own domain, ... each domain in our forest has their own domain admins and they ... >> cannot modify DCs across domains. ... >> how every network security model should be setup. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Secure domain from higher
    ... This goes against the entire domain security model. ... you don't trust them then don't make them a child domain. ... the Enterprise admins account is that it has access to everything in the ... new domain tree in the same forest. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Site or Domain
    ... Domain aren't security Boundaries, ... forest, and they are not themselves the ultimate security boundary. ... Each Active Directory domain is authoritative for the ... Domain controller hardware and security facilities Each Windows Server ...
    (microsoft.public.windows.server.active_directory)
  • RE: Active Directory network security
    ... >Subject: RE: Active Directory network security ... >X-Mailer: Microsoft Outlook, Build 10.0.2627 ... In fact the only true security boundary in AD is a forest. ... >Domain Admins must be fully trusted. ...
    (Focus-Microsoft)

Quantcast