Re: Place holder root domain advantage



That is the recommend course strategy, but to be honest we don't follow
that. I don't know if it was security related or just the fact you need to
be able to manage dns and not expose your internal boxes ip addresses, which
we do both.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"jacksors" <jacksors@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:18547956-7C98-47CB-8982-22440B57271D@xxxxxxxxxxxxxxxx
Paul,

I have a follow up question. Old best practice said to not use your
routeable internet domain name as the domain for your forest root domain.
Is
that still a best practice or do to enhanced security does that no longer
matter as well?

Thanks.

"Paul Bergson [MVP-DS]" wrote:

If I recall correctly it started with the release of AD (2000).

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

"jacksors" <jacksors@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8E3E3EA0-B153-42EF-A814-1FFCD6D713AF@xxxxxxxxxxxxxxxx
Thanks Paul. What AD version prompted this best practice change?

"Paul Bergson [MVP-DS]" wrote:

This is no longer a recommended strategy. Microsoft now recommends to
keep
it as simple as possible with as few domains as your enterprise can
use.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

"Randy Jackson" <jacksors@xxxxxxxxx> wrote in message
news:O9fddT29IHA.4004@xxxxxxxxxxxxxxxxxxxxxxx
I've been struggling with a domain design to choose. I've always
read
that
it is best practice design to create an empty place holder root
domain
to
hold the enterprise admin group and to hold the forest schema
operations
role. Then have another domain to hold all users/groups/computers.
The
alternative being one domain, that holds all of the above.

There is obviously additional hardware costs associated with the
empty
place holder domain, but there isn't going to be much administrative
overhead since the domain is going to me basically unused.

What are the underlying reasons why the place holder root domain is
setup
and should this domain design be favored in a large enterprise
organization vs the single domain model?

Thank you.









.



Relevant Pages

  • Re: Place holder root domain advantage
    ... Old best practice said to not use your ... routeable internet domain name as the domain for your forest root domain. ... What are the underlying reasons why the place holder root domain is ...
    (microsoft.public.windows.server.active_directory)
  • Re: PKI Question
    ... "Best practice" for enterprise doesn't always apply to small site/small ... > I am in charge of a PKI Enterprise Root CA that issues out certs for a ift ... > not going to be very secure (andyone can log on to the server powerup the ...
    (microsoft.public.security)
  • Re: IPSEC
    ... that's why I said best practice. ... personal firewall for 2000, it's just that not many of them are "enterprise" ... >> Best practice is to use the Windows Firewall to provide that statefulness ...
    (microsoft.public.win2000.security)
  • Re: IPSEC
    ... that's why I said best practice. ... personal firewall for 2000, it's just that not many of them are "enterprise" ... >> Best practice is to use the Windows Firewall to provide that statefulness ...
    (microsoft.public.win2000.general)

Quantcast