Jump to content

Multiple domains, federated domains, single domain multi-site, etc...? Which?


Recommended Posts

Posted

So, I'm doing some theoretical stuff at the moment and one of the things I'm wondering about is as follows.

 

Imagine you have 2 organisations, ran from a single holding company. Each of the organisations has its own network, and its own IT support. The 2 organisations are in different locations, but are legally still part of the same company (so, I suppose a better term would be "divisions" rather than organisations).

 

If the 2 wished to join their networks, to allow staff to move between them easily etc... which method of doing so is currently the best way? Also, bear in mind that this theoretical situation could be 3, 4 or 5 organisations etc...

 

There appear to be many options:

 

1. A single forest with a domain for each organisation.

2. A single domain, with delegated rights to OUs for each IT team.

3. 2 completely separate networks with ADFS in between

4. 2 completely separate networks with 2 way trusts in between

 

There's probably more.

 

So, which option would you go for and why?

Posted

With the above I am tied between 1 and 4 but for ease I would have one domain and just different OU's etc for each company, create a none specific domain as such, doesn't even have to have any resemblance, would be a colour or just "domain".

 

But if you could and had the kit to do it with 1 would be my over all choice I think.

Posted

The Thing about this type of business structure it's fairly easy to see that at any point 1 of those businesses could be sold off.

 

In this situation 4 would be best

Posted
The Thing about this type of business structure it's fairly easy to see that at any point 1 of those businesses could be sold off.

 

In this situation 4 would be best

 

Surely option 1 would work for that too? Ie. You just give them a root domain DC and their own DCs and that's it?

Posted
Surely option 1 would work for that too? Ie. You just give them a root domain DC and their own DCs and that's it?

 

I would pick 1 over 4. However there is obviously more money and time invested into maintaining the root domain.

Posted

We have done this as a school, with many of the same options. Two entirely separate domains. We put in a two-way trust with DNS replication across sites, which got things going. Users can log on across either site, Exchange, Lync / LDAP etc can all talk between them.

 

Eventual plan is to move to option 2, or at least very similar, using the ADMT.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...