Active Directory design recommended practices Mark Cribben Consultant.

Slides:



Advertisements
Similar presentations
Accelerating Content Management Server solutions with MCMS.RAPID Mark Harrison – Microsoft Tony Sloggett.
Advertisements

Active Directory: Beyond The Basics
Active Directory Fundamentals
Service Manager for MSPs
Windows Server ® 2008 and Windows Server ® 2008 R2 Active Directory ® Domain Services Infrastructure Planning and Design Published: February 2008 Updated:
Remote Desktop Services
Introduction to Systems Management Server 2003 Tyler S. Farmer Sr. Technology Specialist II Education Solutions Group Microsoft Corporation.
Active Directory Fundamentals Thomas Lee Chief Technologist QA
Module 14: Implementing an Active Directory Infrastructure.
Windows Server ® 2008 Active Directory ® Domain Services Infrastructure Planning and Design Series Published: February 2008 Updated: July 2009.
70-297: MCSE Guide to Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure Chapter 2: Developing the Active Directory.
Dan Stolts IT Pro Evangelist US DPE - North East Microsoft Corporation
More Control and Flexibility Vitalis Konopelec Technology Solution Professional Microsoft Slovakia s.r.o.
Michael Kleef Technology Advisor | Microsoft Australia
F5 solution for Microsoft Exchange
Kalpesh Patel Ramprabhu Rathnam
Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason blog.configmgrftw.com m Wally.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Making Identity and Access Management Real – The Early Days Brian Lauge Pedersen Senior Technology Specialist.
Understanding Active Directory
Migrating your Novell Environment to Windows Server 2003 Steve Plank – Microsoft UK Darren Catterrall – Quest Software.
Winter Consolidated Server Deployment Guide for Hosted Messaging and Collaboration version 3.5 Philippe Maurent Principal Consultant Microsoft.
Hands-On Microsoft Windows Server 2008
Advanced Active Directory Deployments Rick Claus IT Pro Advisor Microsoft Canada
Vikram Thakur Introduction to Active Directory Structure.
Active Directory Implementation Class 4
Welcome to this evening’s TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information and.
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
Designing Active Directory Child Domain Sainath K.E.V Directory Services MVP 5/Aug/2015.
Windows Server 2008 Chapter 4 Last Update
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
(ITI310) By Eng. BASSEM ALSAID SESSIONS
Module 1: Server Roles and Initial Configuration Tasks
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
Designing Active Directory for Security
TNT Welcome to this evening’s TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information.
Module 2 Designing Microsoft® Exchange Server 2010 Integration with the Current Infrastructure.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
Module 5: Designing a Terminal Services Infrastructure.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
DEP313 Active Directory Restructuring with ADMT v-2
Module 11: Implementing ISA Server 2004 Enterprise Edition.
Managing Windows Server 2003 and Active Directory Best Practices ธนินทร์ น้อยรังษี Tanin Noirungsee Technology Specialist Microsoft (Thailand)
Module 11: Read-Only Domain Controllers. Overview Describe the Read-Only Domain Controllers role Use Read-Only Domain Controllers.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
Hands-On Microsoft Windows Server 2008 Chapter 4-Part 1 Introduction to Active Directory and Account Manager.
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Security Configuration Wizard Keith D Miller Microsoft European Support Readiness Manager.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Microsoft Deployment Workshop Deploying Office 2003 Editions Joe Liptrot Linkpad Limited.
Module 8: Planning for Windows Server 2008 Active Directory Services.
Welcome to this TechNet Event FREE bi-weekly technical newsletter FREE regular technical events hosted across the UK FREE weekly UK & US led technical.
Microsoft Deployment Workshop Deploying Office 2003 Editions Joe Liptrot Linkpad Limited.
Unit 7 ITT TECHNICAL INSTITUTE NT1330 Client-Server Networking II Date: 2/3/2016 Instructor: Williams Obinkyereh.
Group Policy in Windows Vista. Group Policy Administration Group Policy with Windows Vista QoS Policies What Will We Cover?
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Module 11 Configuring and Managing Distributed File System.
Secure Connected Infrastructure
Microsoft Deployment Workshop Deploying Office 2003 Editions
Implementing Active Directory Domain Services
SaaS Application Deep Dive
MCSA VCE
Microsoft Virtual Academy
M318.
2/25/2019 Desktop Virtualization Corey Hynes Kyle Rosenthal President Technical Lead HynesITe Inc Spider Consulting @windowspcguy.
5/12/2019 2:57 PM © Microsoft Corporation. All rights reserved.
Microsoft Virtual Academy
Microsoft Deployment Workshop Deploying Office 2003 Editions
Presentation transcript:

Active Directory design recommended practices Mark Cribben Consultant

Agenda Forest design principles Domain design principles Name space design recommendations Site / Physical design OU design Base security considerations Branch scenarios Management

Forest design principles Identify security boundaries – The forest is the security boundary Start with single forest. Considerations: – Acquisition and divesting pattern of the organisation – Schema ownership – Security – Legal considerations (typical in banking scenarios but by no means exclusive to them.)

Domain design principles Start with a single domain. Considerations are: – Replication boundaries – Account policy requirements – Political So what about a placeholder / empty forest root domain? – Design recommendations changed within 18 months of Windows 2000 launching but the message seems to be taking a long time to get out. – There is no additional security to be gained through an empty forest root domain.

Name space design How to name an AD – So what’s in a name? How important is it after all? Where to put name servers – Understand the importance of _msdcs. zone How to replicate DNS information – Where possible try and use AD integrated as it increases the security and reduces the management of replicating the information – Allows for multi master DNS How to configure the DC’s and clients – Advice is different for Windows 2000 and Windows Server 2003 DC’s – Clients should be configured to use their local DNS server as the primary. Nearest hub / data centre as the alternate

Site / Physical design (1) Identify your deployment model: – Centralised – Distributed – Branch – Combination Define sites and subnets. Consider: – Data Centre failure – Redundancy – Client and application needs

Site / Physical design (2) Domain controllers: – Location – Security – Function – Administration Designing for discovery and failover – SRV registration strategy – Autositecoverage decisions

Site / Physical design (3) Replication: – Load balancing on BH Servers – Schedule and Interval – Compression value – TombstoneLifetime

OU design OU’s have two primary roles: – Delegation of admin – Application of Group Policy Most common (sensible!) OU design approaches: – Device / object type Try to avoid: – Too many OUs / levels of nesting – Following your org chart

Branch Scenarios Bear in mind that Branch Office does not automatically mean retail banking! Primarily a scenario where you have lots of remote locations that have users but not necessarily a large number of them or good quality, high bandwidth connections. Key issues: – Administration – Placement of Domain Controllers / GC’s – Applications at the remote site – Available bandwidth – Replication including BH Server load balancing, replication scheduling, convergence

Management Do not even think about deploying Active Directory without providing management support. – We have seen too many situations where customers have problems that could so easily have been avoided with even a basic monitoring solution / process! Managing the Directory Service: – MOM is an option – If MOM cannot be deployed then provide processes, scripts and tools to allow ongoing management Group Policy – At the very least install GPMC!

©2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Welcome to this TechNet Event FREE bi-weekly technical newsletter FREE regular technical events hosted across the UK FREE weekly UK & US led technical webcasts FREE comprehensive technical web site Monthly CD / DVD subscription with the latest technical tools & resources FREE quarterly technical magazine We would like to bring your attention to the key elements of the TechNet programme; the central information and community resource for IT professionals in the UK: To subscribe to the newsletter or just to find out more, please visit or speak to a Microsoft representative during the break