Maxell Posted October 1, 2007 Author Posted October 1, 2007 Thanks to everyone for their input - plenty of scenarios to think about, but the majority view seems to be for a single network and domain... Mark.
Grommit Posted October 2, 2007 Posted October 2, 2007 Thanks to everyone for their input - plenty of scenarios to think about, but the majority view seems to be for a single network and domain... Mark. It's abput 80 - 20 for a Single Domain for a Single School.... So only 20% are making additional work for themselves...
ajbritton Posted November 5, 2007 Posted November 5, 2007 Thanks to everyone for their input - plenty of scenarios to think about, but the majority view seems to be for a single network and domain... Mark. It's abput 80 - 20 for a Single Domain for a Single School.... So only 20% are making additional work for themselves... ... and the other 80% not doing their jobs properly :twisted:
Michael Posted November 5, 2007 Posted November 5, 2007 In the days of Windows 95, it was recommended to have separate Admin and Curriculum networks, but now (for many years) adopting Windows Server 2003 and Active Directory, I operate one domain for all. As a few of you have already mentioned - Pupils, Staff and Admin Staff are all in their own OUs. NTFS of course controls access to shares and if setup correctly works just fine. All the schools I support have one Curriculum server, one Admin server and a proxy server. Especially now with SQL 2005, the Admin side of things definitely needs its own server. The problem I see with two separate domains, is two of everything else! It does increase the workload in my opinion. Active Directory is a marvellous tool
Oops_my_bad Posted November 5, 2007 Posted November 5, 2007 god will this issue ever go away :twisted:
Guest Posted November 5, 2007 Posted November 5, 2007 when i 1st started we had admin and curr networks but we kinda merged into 1 last few years, i was thinking of splitting it again for security soon but after reading this i wont bother :-)
contink Posted June 11, 2008 Posted June 11, 2008 Sorry to do a Lazarus on this topic .. but I have a slight twist on the old scenario... I have taken on board the curriculum side of things at all of my schools but when it comes to the admin side I'd prefer to be hands off as much as possible. My query at this point relates to one specific, quite large school where a server HD failure was made worse due to the lack of a system state backup and the fact that admin accounts relied in part on the curriculum domain. Original plan was to create an admin specific domain and then possibly allow a one way trust relationship onto the curriculum network to allow printing, etc... but I'm realising from reviewing this and other topics that perhaps that's less ideal as well as somewhat redundant. My concern is that I could end up in a blame game war if something should go wrong with the admin accounts so has anyone got any suggestions on how best to proceed? So far I'm now thinking that perhaps the smartest move is to setup an OU for all admin account and a file server specifically for admin files. I can use the other servers to store SFG backups in encrypted form and intend to run a seperate backup tape system on the admin file server too... Beyond that, I'd get county IT to sort out the client machines with the relevant software, image them once they're done and then keep them for disaster recovery in case county don't. Am I missing anything?
imiddleton25 Posted June 11, 2008 Posted June 11, 2008 We merged 3 NT4 domain many years ago into one on server 2003 remember Domains are no longer security boundaries in server 2003 but instead it is now the forest that is security boundary. see bellow Security boundary A boundary that defines a container for which no administrator external to the container can take control away from administrators within the container. For example, a forest is a security boundary. No administrators from outside the forest can control access to information inside the forest unless first given permission to do so by the administrators within the forest. By contrast a domain is not a security boundary because within a forest it is not possible for administrators from one domain to prevent a malicious administrator from another domain from accessing data in their domain.
contink Posted June 11, 2008 Posted June 11, 2008 Erm... I did actually have a specific question here: http://www.edugeek.net/forums/windows/11365-admin-network-3.html#post203140 I'm wondering if I should have just started a new topic and referred back to this if all I've done is recreate the same old arguement
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now