Jump to content

How is your AD structured?  

83 members have voted

  1. 1. How is your AD structured?

    • Single forest, single domain
      80
    • Single forest, multiple domains (staff/student etc)
      2
    • Multiple forests, interforest trust
      1
    • Other
      0


Recommended Posts

Posted (edited)

Hi all,

 

We're just weighing up a few options and wanted to gauge others opinions regarding Active Directory structure. We currently have two forests for staff/students with an interforest trust. This causes some problems with LDAP integrated applications which can only access one LDAP server. Naturally we could try and negate this with an LDAP proxy, but for the sake of balance, I wanted to create a poll to see how others are structuring their Active Directory.

 

If you wish to add any further feedback, please comment in the thread as well as voting in the poll.

 

 

Thanks in advance,

Karl

Edited by aceonbass
Posted (edited)

Wow, 8 votes for single forest and domain.

 

Do you really run staff and students under the same, single domain? I can understand the ease of administration but are there not any security flaws with this set up?

Edited by aceonbass
Posted
Wow, 8 votes for single forest and domain.

 

Do you really run staff and students under the same, single domain. I can understand the ease of administration but are there not any security flaws with this set up?

 

Not when passwords are on post-its and staff logon for students with disabled accounts. Sometimes it's actually easier to secure due to the visibility of permissions without having to remember any trusts etc.

Posted

why split it across domains surely teachers use pupil pcs and vice versa?

i can just about see a reason to split userfils across servers (apart from storage spacw) bot across domains what does it gain apart from more stuff to manage and more points of failure?

Posted

We used to have 2 forests back when RM set things up :( (before my time), this was a pain and as you said some LDAP Apps don't like the trusts, we migrated to a single forest and domain not long after i started.

 

All ours users live under the same Root OU with Staff and Student OU's under that, it makes things very simple when applying group policies that everyone need.

Our Students also have a different email domain to staff.

Posted

I can see the OP's logic with splitting the domains, but it seems analogous to the old curriculum/admin network model in that it's generally thought too unwieldy for modern use. However, a workable scenario in which a compromise in security on the pupil side does not affect operations on the other, be it "all staff" or simply "admin staff", would certainly be very interesting to hear more about.

 

However, as long as you have trusts, the infrastructures are never truly separate and, having observed a security breach that arose from inappropriately-configured trust permissions (first rule of endpoint security: never assume there hasn't been a cock-up upstream), I would imagine the benefits to security are less than might be expected as you have only made something harder to achieve, not impossible.

Posted
I've never seen anyone able to come up with any specific examples of security problems that would reliably be prevented by having split domains. And yet I can think of many examples of headaches such a set-up would cause.
Posted (edited)

Multiple domains does generally double your workload in my experience. A single properly configured domain with the appropriate permissions is the way forward.

 

However having a single domain over multiple WAN links for a cluster of schools or businesses does make things complicated. I think you have to draw a line somewhere in terms of ease of management and whether or not a cluster of schools (for example) actually need to be part of a single domain structure, or would be better off with a separate domain per site with/without a trust.

Edited by Michael
Posted
Hence the need for a forest - perhaps someone in an Academy Federation can comment on how forests (or in fact trees at this level) have been implemented to simplify administration?
Posted
Hence the need for a forest - perhaps someone in an Academy Federation can comment on how forests (or in fact trees at this level) have been implemented to simplify administration?

 

Generally speaking - the biggest issues I've come across whereby an academy has implemented a single domain across multiple WAN links is replication and people with the same name, which is inevitable if you have a common surname. It's also going to create a lot of web traffic if you have many users changing their passwords or you have many admins creating/modifying GPOs. It all adds up. You also have to take upgrades into consideration. Updating servers acting as DCs from 2008 R2 to 2012 at each site needs to be done correctly, otherwise you could 'bugger' the whole domain.

Posted
Wow, 8 votes for single forest and domain.

 

Do you really run staff and students under the same, single domain? I can understand the ease of administration but are there not any security flaws with this set up?

 

What security flaws do you believe there would be? Do you have two separate totally isolated networks as well that staff and students use? If not, then whatever additional security you think you have with using two domains does not really exist. If anything, it would create a false sense of security I fear and lead to security lapses in other areas on the network.

Posted
For the reasons above, I couldn't see a reason to use multiple forests or domains these days with exception to where business requirements or the facilities differ - for instance, if a nursery attached to a school is financed/ran separately but physically connected and sharing a system perhaps, if that were to help with data requirements. Naturally it'd also be a different case for WAN connected schools (academy chains being a popular example) - I would hope that should such a chain wish to connect in that manner, it would be via a parent and child domain setup where the local school had full control over the child domain, ensuring that should the WAN link separate the school or its adminstrators would have no difficulty in continuing to run their system as required. Synchronisation could, if required, be set to occur a couple of times a day rather than being live.
Posted

Do you really run staff and students under the same, single domain?

 

We went to single domain 8 1/2 years ago. Much simpler.

Posted

I believe back when Sims originally came out it was a recommendation that Sims sat in a separate Admin domain to the students.

 

The only way I can see have a single Forest would be good in an Academy Federation as mentioned above, Having 1 forest but say each secondary school having its own domain.

 

Having 2 forests and then multiple domains doesn't make sense personally in my head.

 

But I have also have a client spread all over the south east at 10 sites using a single domain and DFS replicating user data back to the HQ for backing up. A common data folder is then replicated between all sites.

Posted (edited)
What security flaws do you believe there would be? Do you have two separate totally isolated networks as well that staff and students use? If not, then whatever additional security you think you have with using two domains does not really exist. If anything, it would create a false sense of security I fear and lead to security lapses in other areas on the network.

 

Well right now, if a student domain admin account was compromised, no changes could be make to the staff domain. If we had a single domain and a domain admin was compromised then they have access to EVERYTHING.

 

The networks aren't completely isolated, just different VLANs.

 

 

Edit: Just to clarify, this is a set up the current team has inherited. We're giving everything a big review, and thought we'd put the question out to compare organisations. We expected single forest with multiple domains to be the most popular answer so we've been pleasantly surprised.

Edited by aceonbass
Posted
Well right now, if a student domain admin account was compromised, no changes could be make to the staff domain. If we had a single domain and a domain admin was compromised then they have access to EVERYTHING.

 

You're enduring a lot of administrative pain and overhead to gain what is not a substantial security advantage. If your organisation is like most places admin usernames and passwords likely follow a pattern (usernames more than passwords). So, if someone has gotten an admin login for one domain they can probably use the same techniques for getting the others. Once you know the username you're halfway there. Passwords can be broken without a great deal of trouble with the right software, time, and access. Compromises are more frequently from social engineering or carelessness though, and if an organisation loses one login that way, the others are likely to fall in the same way shortly afterward.

 

If you have extremely robust and obscure usernames and passwords, change passwords frequently, and limit access to them to a very small number of people, the logins for both domains are not known by any single person, personnel are highly trained in security procedures and follow them, etc. - then it would heighten your security posture. That's not the case for most organisations though. A more simple, easily managed environment with time spent on security training and ensuring that reasonable and not overly complex security procedures are followed is the way to go for most organisations. I would definitely recommend a single domain for most environments.

 

NOTE: I worked for the NSA for eight years (in the 90s) in the business of obtaining and analysing information that the other side was trying to keep secret and secure. Good security is hard and the human element is the weakest link. Having overly complex systems exacerbates any security weaknesses, we took advantage of this all the time.

Posted

We have separate domains, no trust between them.

 

See, for a student to compromise a admin account they would need access to a PC on the Admin domain. Which are all in offices that are locked. If we had everything on one domain, PC in lab could be used with a compromised account. And there is more, we didn't set it up that way, but this is a result. And yes, we could GPO prevent admin OU from logging into certain PCs if we wanted.

Posted

Thanks all for your responses. It's looking more and more like a huge summer project next year.

 

Personally, the temptation to start again with minimal migration is overwhelming - in reality, however....

Posted

Seems I'm the only one that put multi forest multi domain. Granted I don't work for a school, so my requirements are probably a lot different.

 

We have a full trust between our forests, which works great, I think you're issues with LDAP can be over come with a few permission changes. As well as having the trust in place, we allow our DC's the credentials to authenticate with each other..e.g under the security menu for a DC, add the dc from the other forest and select the option "allow to authenticate"

 

The forests are split with firewalls, and the relevant holes punched through to allow the DC's to communicate. With this in place we find that our LDAP works perfectly

Posted

Hving multiple domains, and even multiple forests, shouldn't prevent the sharing of data. This is what the trusts should help resolve.

 

Granted in a school setup, a single domain approach might be preferred.

  • 2 months later...
Posted
Extremely delayed reply, but thanks again for all the responses. As per a previous post, I've been very surprised by the amount of votes for single domain (expecting multi domains in a single forest). It's now clear which way I'd like to take the network forward, but as I'm neither the overall manager or network admin this decision does not rest with me...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...