Jump to content

Recommended Posts

Posted

Thanks to everyone for their input - plenty of scenarios to think about, but the majority view seems to be for a single network and domain...

 

Mark.

Posted
Thanks to everyone for their input - plenty of scenarios to think about, but the majority view seems to be for a single network and domain...

 

Mark.

 

It's abput 80 - 20 for a Single Domain for a Single School.... So only 20% are making additional work for themselves...

  • 1 month later...
Posted
Thanks to everyone for their input - plenty of scenarios to think about, but the majority view seems to be for a single network and domain...

 

Mark.

 

It's abput 80 - 20 for a Single Domain for a Single School.... So only 20% are making additional work for themselves...

 

... and the other 80% not doing their jobs properly :twisted:

Posted

In the days of Windows 95, it was recommended to have separate Admin and Curriculum networks, but now (for many years) adopting Windows Server 2003 and Active Directory, I operate one domain for all.

 

As a few of you have already mentioned - Pupils, Staff and Admin Staff are all in their own OUs. NTFS of course controls access to shares and if setup correctly works just fine. All the schools I support have one Curriculum server, one Admin server and a proxy server. Especially now with SQL 2005, the Admin side of things definitely needs its own server.

 

The problem I see with two separate domains, is two of everything else! It does increase the workload in my opinion. Active Directory is a marvellous tool :)

Posted
when i 1st started we had admin and curr networks but we kinda merged into 1 last few years, i was thinking of splitting it again for security soon but after reading this i wont bother :-)
  • 7 months later...
Posted

Sorry to do a Lazarus on this topic :bored:.. but I have a slight twist on the old scenario...

 

I have taken on board the curriculum side of things at all of my schools but when it comes to the admin side I'd prefer to be hands off as much as possible. My query at this point relates to one specific, quite large school where a server HD failure was made worse due to the lack of a system state backup and the fact that admin accounts relied in part on the curriculum domain.

 

Original plan was to create an admin specific domain and then possibly allow a one way trust relationship onto the curriculum network to allow printing, etc... but I'm realising from reviewing this and other topics that perhaps that's less ideal as well as somewhat redundant.

 

My concern is that I could end up in a blame game war if something should go wrong with the admin accounts so has anyone got any suggestions on how best to proceed?

 

 

 

So far I'm now thinking that perhaps the smartest move is to setup an OU for all admin account and a file server specifically for admin files. I can use the other servers to store SFG backups in encrypted form and intend to run a seperate backup tape system on the admin file server too... Beyond that, I'd get county IT to sort out the client machines with the relevant software, image them once they're done and then keep them for disaster recovery in case county don't.

 

Am I missing anything?

Posted

We merged 3 NT4 domain many years ago into one on server 2003 remember

Domains are no longer security boundaries in server 2003 but instead it is now the forest that is security boundary.

 

see bellow

 

Security boundary

A boundary that defines a container for which no administrator external to the container can take control away from administrators within the container. For example, a forest is a security boundary. No administrators from outside the forest can control access to information inside the forest unless first given permission to do so by the administrators within the forest. By contrast a domain is not a security boundary because within a forest it is not possible for administrators from one domain to prevent a malicious administrator from another domain from accessing data in their domain.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...