Re: Help with planning large AD structure and schema modifications

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello mkroska,

1. Nothing is built-in for that, you can use scripting for that, windows support lot's of scripting languages.

2.+3. You can create lot's of objects in AD, but how do you like to associate them to users? See here about limit's: http://technet.microsoft.com/en-us/library/cc756101.aspx

If you modify the schema it will be the same as the built-in ones, if you do it the correct way. See also here:
http://technet.microsoft.com/en-us/library/cc759633.aspx http://technet.microsoft.com/en-us/library/cc784557.aspx

Changes for users will be added to existing accounts.

4. See here about hardware planning and monitoring: http://technet.microsoft.com/en-us/library/cc728303.aspx http://technet.microsoft.com/en-us/library/cc787688.aspx http://technet.microsoft.com/en-us/library/cc739728.aspx


In this large network setup do not use DC's for other roles, let them do only there main task's, DNS/GC and maybe DHCP. Power intensiv applications like Exchange and SQL run on member servers also for RRAS use member servers.

5. We only use english, but i think it shouldn't be a problem.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hi all--
I'm on a team for developing a solution for a new AD implementation
and need
help with a few planning questions.
Background:
This is a green-field: this will be rolled out from the ground up.
There will be a minimum of 3 new domains for web-front end traffic,
each in
a distinct forest with a one-way trust from the internal core domain.
The 3 new domains will represent Dev, Test and Prod. We chose to do
each on
a distinct domain since MOSS will be used heavily and we want to
separate the
databases, credentials and workloads.
The prod domain will be the largest (upwards of 100k objects and
growing).
Dev and Test will substantially smaller, so not as big of questions
about
scaling there.
We'd like to use AD for managing end-user accounts (customers) for
e-commerce; and we'll be transitioning our existing customer base from
a legacy database to AD.

Important Questions for Planning:
1. We may need the ability to pull all accounts updated in the last XX
amount of minutes. We were curious if AD has anything built-in to
support
this type of functionality.
2. Are there limitations to creating n-amount of complex objects
associated
with a user?
o Is there a difference between a built-in object like address and a
custom
created object type?
o How does defining a new object affect existing user accounts and
storage?
3. What are the ramifications of modifying an existing object?
o Is existing data dropped and re-created or does it extend the
object
cleanly?
4. How do we know when to scale the active directory server?
o When we hit a # of users?
o When resource utilization is high?
5. How does Active Directory support internationalization character
sets?
Please let me know if I can clarify any questions. Thank you very much
in
advance for any assistance or guidance.
Regards,
Mark


.



Relevant Pages

  • Re: XP Unzip Wizard question
    ... To disable XP's built-in ZIP support. ... regsvr32 /u zipfldr.dll at the prompt and click OK. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Zip Files - Compressed (zipped) Folders - Options
    ... I use the native XP support for zip and,, it behaves just the way I like. ... > This is a serous problem - it automaticaly starts the install ... > BUILT-IN handling of Zip files? ... > Windows for all traces of the built-in ZIP support to disappear. ...
    (microsoft.public.windowsxp.general)
  • Re: OO in Tcl (goodbye tcl)
    ... :needs one supported, built-in, OO mechanism, Look at the ... :source code for Tcl/Tk, it's the best, most readable, easiest to ... Do you agree that for tcl to move towards this goal, ... so that said support is "built-in"? ...
    (comp.lang.tcl)
  • Re: Wanted - Other software
    ... Type regsvr32 /u %windir%\system32\zipfldr.dll at the prompt, ... The change will take effect immediately, but you may have to restart Windows ... If, at any time, you wish to re-enable Windows XP's built-in ZIP support, ...
    (borland.public.delphi.thirdpartytools.general)
  • RE: LDAP issues - mimesweeper for web & Active Directory
    ... OU called Users which is built-in. ... Admin Users (Admin User accounts OU) ... Can you elaborate on the "Accounts root Folder" part of "Created a test OU ... Existing LDAP connections to MS4Web are working ...
    (microsoft.public.windows.server.active_directory)