localzuk Posted November 22, 2014 Posted November 22, 2014 So, I'm doing some theoretical stuff at the moment and one of the things I'm wondering about is as follows. Imagine you have 2 organisations, ran from a single holding company. Each of the organisations has its own network, and its own IT support. The 2 organisations are in different locations, but are legally still part of the same company (so, I suppose a better term would be "divisions" rather than organisations). If the 2 wished to join their networks, to allow staff to move between them easily etc... which method of doing so is currently the best way? Also, bear in mind that this theoretical situation could be 3, 4 or 5 organisations etc... There appear to be many options: 1. A single forest with a domain for each organisation. 2. A single domain, with delegated rights to OUs for each IT team. 3. 2 completely separate networks with ADFS in between 4. 2 completely separate networks with 2 way trusts in between There's probably more. So, which option would you go for and why?
MatthewL Posted November 22, 2014 Posted November 22, 2014 With the above I am tied between 1 and 4 but for ease I would have one domain and just different OU's etc for each company, create a none specific domain as such, doesn't even have to have any resemblance, would be a colour or just "domain". But if you could and had the kit to do it with 1 would be my over all choice I think.
FN-GM Posted November 22, 2014 Posted November 22, 2014 Option 2 for me, I think in the long run it would make things easier for both users and IT staff.
gaz350b Posted November 23, 2014 Posted November 23, 2014 The Thing about this type of business structure it's fairly easy to see that at any point 1 of those businesses could be sold off. In this situation 4 would be best
localzuk Posted November 23, 2014 Author Posted November 23, 2014 The Thing about this type of business structure it's fairly easy to see that at any point 1 of those businesses could be sold off. In this situation 4 would be best Surely option 1 would work for that too? Ie. You just give them a root domain DC and their own DCs and that's it?
FN-GM Posted November 23, 2014 Posted November 23, 2014 Surely option 1 would work for that too? Ie. You just give them a root domain DC and their own DCs and that's it? I would pick 1 over 4. However there is obviously more money and time invested into maintaining the root domain.
3s-gtech Posted November 23, 2014 Posted November 23, 2014 We have done this as a school, with many of the same options. Two entirely separate domains. We put in a two-way trust with DNS replication across sites, which got things going. Users can log on across either site, Exchange, Lync / LDAP etc can all talk between them. Eventual plan is to move to option 2, or at least very similar, using the ADMT.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now