Jump to content

Recommended Posts

Posted

Our academy is starting to grow and we now have 8 schools. Currently each has its own domain and no school is linked in any way.

 

However we want that to change. We the ability so anyone can login to any school and retrieve their data or data from shared drives.

 

Question is how to do it? Some schools only operate on a 4meg ADSL line and lease lines in these areas are expensive.

 

I am toying with the idea of a single forest with sub domains in each school. However will a 4meg ADSL link support this?

 

What does everyone think?

Posted
So jealous I would love to do this! I wouldn't say a 4meg Adsl would support what you want. However with the schools saving on hardware by being in one domain? Would that make up the cost of the leased lines?
Posted (edited)

Hi,

 

We are a growing trust as well, our model is that all Academies share 1 domain. Primary schools are linked via a 100mb point to point back to the central server farm located at a secondary. Secondary will have a 1GB link. The internet connection, filtering and firewalls is located at the central farm, all schools use these.

 

A primary school has a single server with these virtual servers:

 

1 x DC

1 X SCCM Distribution Point

1 X File Server with DFS replication to the central servers.

 

Secondary another matter.

 

We have staff roaming between sites and it works a treat. Thats people with mobile devices as well as using desktops at each site

 

We share other services as well. Such as Wireless with controllers in the central server room. Digital Signage, Sage, IP phone, email system etc

 

Technical support is 1 big team supporting all schools. Secondary have someone on site all the time.

 

Lets face it 4mb is rubbish, it would be on a home connection, never mind a school.

 

What size schools are we talking here?

Edited by FN-GM
Posted

Smaller schools are about 4 classrooms. Others have more but a faster line.

 

Main thing is AD replication and logon, as a lot of our data is going to OneDrive.

 

10meg leased line at some of the schools will cost around £10k per year. So I don't think this is currently cost effective.

Posted
You can link the domains with two-way trusts to achieve much of what you want. This will make shares and permissions manageable. If you can do anything fresh, each primary on a child domain should be manageable and nicely structured.
  • Thanks 1
Posted (edited)

Hi,

Have you considering moving to Office 365 for the sharing of files. With AD Connect you can connect each AD to the single Office 365 tenant, create them each an area to upload their shares and migrate their file shares to these areas. You can then allow users to see each others content and increase collaboration for both students and teachers. You could also do the same for personal files with OneDrive for Business.

 

With updates coming to windows 10 and Office 365, PCs will be able to authenticate to Office 365 rather than to your local AD and have SSO to all your applications both on-prem and Office 365 (with AD Connect and ADFS).

 

We've started this with a few of our customers already (the files migrations) and getting ready for the windows 10 release for BYOD and client laptops (desktops will stay on local AD).

Edited by apearce
Posted (edited)
Smaller schools are about 4 classrooms. Others have more but a faster line.

 

Main thing is AD replication and logon, as a lot of our data is going to OneDrive.

 

10meg leased line at some of the schools will cost around £10k per year. So I don't think this is currently cost effective.

 

Have you looked at point to points rather than lease lines and share a connection. I have point to point can be a quarter of the price and a quicker connection.

 

EDIT: Also consider cost savings not having multiple Firewalls, filtering etc.

Edited by FN-GM
Posted
Hi,

Have you considering moving to Office 365 for the sharing of files. With AD Connect you can connect each AD to the single Office 365 tenant, create them each an area to upload their shares and migrate their file shares to these areas. You can then allow users to see each others content and increase collaboration for both students and teachers. You could also do the same for personal files with OneDrive for Business.

 

With updates coming to windows 10 and Office 365, PCs will be able to authenticate to Office 365 rather than to your local AD and have SSO to all your applications both on-prem and Office 365 (with AD Connect and ADFS).

 

We've started this with a few of our customers already (the files migrations) and getting ready for the windows 10 release for BYOD and client laptops (desktops will stay on local AD).

 

This is an option. We will use Office 365 for some bits but not everything.

 

At another school of mine (a Microsoft Showcase School) we found the OneDrive for Business client not great. Lots of sync issues when we decided to move everything to Sharepoint sites. In the end everything went back to local server shares.

 

Windows 10 is an option, but a long way off yet.

Posted
This is an option. We will use Office 365 for some bits but not everything.

 

At another school of mine (a Microsoft Showcase School) we found the OneDrive for Business client not great. Lots of sync issues when we decided to move everything to Sharepoint sites. In the end everything went back to local server shares.

 

Windows 10 is an option, but a long way off yet.

 

I agree, the sync tool is not good and I don't recommend it - but I'll post back later today as they'll be showing the new sync today at Ignite

Posted

The thing you have to question, is what does a single Academy domain achieve? In my experience, just because schools are part of the same Academy Trust doesn't mean they proactively communicate and share data, quite the opposite - yet being all part of the same domain does introduce problems - lots of replication data, then you have the issue of delegating rights to only part of the AD structure.... it starts to become very messy and complicated. Even worse, one false move on the PDC and you could in theory take the whole network down.

 

It's the same as Local Authorities - typically they're all part of the same intranet, but with separate domains. Again, what does this achieve, what are the pros and cons?

 

Having separate domains with/without a trust is a better or more sensible option. It also means upgrades can be performed/targeted on a site basis and not the whole single domain. Cloud storage is becoming more popular and more flexible - easier to share data and the original purpose/point of a single Academy domain then becomes redundant.

Posted
The thing you have to question, is what does a single Academy domain achieve? In my experience, just because schools are part of the same Academy Trust doesn't mean they proactively communicate and share data, quite the opposite - yet being all part of the same domain does introduce problems - lots of replication data, then you have the issue of delegating rights to only part of the AD structure.... it starts to become very messy and complicated. Even worse, one false move on the PDC and you could in theory take the whole network down.

 

It's the same as Local Authorities - typically they're all part of the same intranet, but with separate domains. Again, what does this achieve, what are the pros and cons?

 

Having separate domains with/without a trust is a better or more sensible option. It also means upgrades can be performed/targeted on a site basis and not the whole single domain. Cloud storage is becoming more popular and more flexible - easier to share data and the original purpose/point of a single Academy domain then becomes redundant.

 

We are just in the same process, a root domain then a new child domain for each school, 2 secondary and 4 primaries.

 

I would have to disagree with you. A multi domain network trusting each other allows us as the IT Team for the whole MAT the ability to control each site independently.

 

Consistency across all sites, no matter where he user goes everything will be the same or follow the same structure. Each domain is a security boundary also.

 

SCCM will be centralised and able to cater for the needs of all networks without the need to be setup on each network if they were independent.

 

Lots of other things just flow.

 

It's a lot of hard work but it's got to be better than having different setups and inconsistent accounts and permissions etc etc all over different sites.

Posted
The thing you have to question, is what does a single Academy domain achieve? In my experience, just because schools are part of the same Academy Trust doesn't mean they proactively communicate and share data, quite the opposite - yet being all part of the same domain does introduce problems - lots of replication data, then you have the issue of delegating rights to only part of the AD structure.... it starts to become very messy and complicated. Even worse, one false move on the PDC and you could in theory take the whole network down.

 

It's the same as Local Authorities - typically they're all part of the same intranet, but with separate domains. Again, what does this achieve, what are the pros and cons?

 

Having separate domains with/without a trust is a better or more sensible option. It also means upgrades can be performed/targeted on a site basis and not the whole single domain. Cloud storage is becoming more popular and more flexible - easier to share data and the original purpose/point of a single Academy domain then becomes redundant.

 

Management is a lot easier though. Don't have separate phone systems, SCCM, wireless, Digital Signage and that makes life easy. The IT techs will have a hard time swathing between multiple domains etc. Upgrades would be difficult. I wouldn't want to update to SCCM 2016 6 times!

  • Thanks 1
Posted
We are just in the same process, a root domain then a new child domain for each school, 2 secondary and 4 primaries.

 

I would have to disagree with you. A multi domain network trusting each other allows us as the IT Team for the whole MAT the ability to control each site independently.

 

Consistency across all sites, no matter where he user goes everything will be the same or follow the same structure. Each domain is a security boundary also.

 

SCCM will be centralised and able to cater for the needs of all networks without the need to be setup on each network if they were independent.

 

Lots of other things just flow.

 

It's a lot of hard work but it's got to be better than having different setups and inconsistent accounts and permissions etc etc all over different sites.

 

Well just to clarify, I did mean literally one domain, with different sites separated or divided into separate OUs - Yes I have seen it done this way! :) I do agree with you that a parent domain with child domains or domains connected via a trust is much better. In both situations replication is kept to a minimum.

  • Thanks 1
Posted
Well just to clarify, I did mean literally one domain, with different sites separated or divided into separate OUs - Yes I have seen it done this way! :) I do agree with you that a parent domain with child domains or domains connected via a trust is much better. In both situations replication is kept to a minimum.

 

Ah ha I see, my apologies!

Posted
Well just to clarify, I did mean literally one domain, with different sites separated or divided into separate OUs - Yes I have seen it done this way! :) I do agree with you that a parent domain with child domains or domains connected via a trust is much better. In both situations replication is kept to a minimum.

 

I see what you mean now. Yes I agree with that method

Posted (edited)

I've thought more about this.

 

What if we had a DC in Azure, and a DC in each school, this would create a single domain without the need for a faster connection between the school.

 

Obviously data wouldn't replicate, but if it it is Office 365 then that's fine.

Edited by snagrat
Posted
I've thought more about this.

 

What if we had a DC in Azure, and a DC in each school, this would create a single domain without the need for a faster connection between the school.

 

Obviously data wouldn't replicate, but if it it is Office 365 then that's fine.

 

Do be aware though most applications cannot save directly into OneDrive, unless you can create mapped drive to OneDrive?

Posted
How about a single domain with RODCs on the Primary sites. Replication will only happen in one direction (apart from passwords).
Posted
How about a single domain with RODCs on the Primary sites. Replication will only happen in one direction (apart from passwords).

 

Yes thought about that. Not a bad idea and would save on upload bandwidth.

 

Would you recommend one or two normal DCs in Azure?

  • 1 month later...
Posted

We are one of the leading academy groups in the country running 38 academies with a single domain running the following centrally:

 

Single AD\Domain

Exchange (2010)

SharePoint (2013)

Central Wireless (Cisco)

Proxy Servers (Barracuda)

Backup (DPM)

SCCM

etc

etc

 

Each site is connected via a 100mb/s link with a ADSL failover.

  • 2 weeks later...
Posted
We are one of the leading academy groups in the country running 38 academies with a single domain running the following centrally:

 

Single AD\Domain

Exchange (2010)

SharePoint (2013)

Central Wireless (Cisco)

Proxy Servers (Barracuda)

Backup (DPM)

SCCM

etc

etc

 

Each site is connected via a 100mb/s link with a ADSL failover.

 

What's the mix of secondary and primary? We are primaries only and so budgets are a bit tighter

Posted

When you say not linked in any way, are all the schools broadband links no all on the same schools network?

in Lincolnshire, all schools are part of the emPSN network and ACL rules can be lifted so that you can access resources on other IP ranges in other schools.

Posted
Single forest makes sense. What's your IT support structure? If you have someone at each site I'd go for a Child domain at each school. You can devolve admin to each school while retaining overall admin control from your own DC. Bear in mind that if a school breaks away they'll have to set up their own Forest Root server and domain. Which will involve a full network rebuild and migration. But as they'd be moving away from you it's not really your worry. :D

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...