GeekyPete Posted July 23, 2015 Posted July 23, 2015 (edited) The situation: I work for IT supplier A who's contract ends in Sept. I'll then work for the school. The school have decided to go with IT Supplier B. Because I still work for A I have been excluded from all design aspects for B's solution. Now that the summer is here and they are starting migration I've found out that B are not setting up a School domain but are instead making the school's network a child domain of their Domain. They can then access their own mapped drives, manage the school from their own AD at their offices. We will have a DC on site but they will have the forest root at their offices. All this doesn't sit easy with me as I like to be in control. My main concern is if we lose contact with the forest root. We might decide to go with supplier C, B might go bankrupt, their offices might burn down etc. From what I understand the network would carry on as normal for the most part. We wouldn't have two FSMO roles, Schema Master and Domain Name Master. So providing we didn't want to change anything major we should be OK indefinitely. We could re-connect to the domain as long as it was within the tombstone period (60 days by default). If we wanted to regain full control of the domain we'd have to set up a new Forest root server and a new domain and migrate to it. My questions? Am I over reacting? Am I being a control freak? Will it effect any day to day operation is we lose contact to the FR? Does not connecting to the FR for a period longer than the tombstone have any impact on disaster recovery? Is there anything else I've missed that I really need to be aware of from a business continuity angle? Cheers Edited July 23, 2015 by GeekyPete
Sagima Posted July 23, 2015 Posted July 23, 2015 To be honest I would feel the same but I've managed my own forest for 15 years. The tombstone time can be modified from its default 6 months to something a bit longer. The bit I would be worried about is the lack of your own schema master - you'll have to get them to do the schema updates every time you want to update a product with schema changes (exchange and sccm) for example. I would hate having to put in requests for things just so I can use my own software 1
GeekyPete Posted July 23, 2015 Author Posted July 23, 2015 Thanks @Sagima Exchange isn't an issue, We use O365 and we are not breaking the current federation (RM Unify) so we are setting up DirSync. SCCM, I would like to install this, they don't use it though and seem to do everything from either GPOs or Impero. Having not used SCCM I wonder if there are any issues setting it up just in a child domain. I think they licence their whole forest for things like Smoothwall and Impero so I'd need to check who holds the licences.
Roberto Posted July 23, 2015 Posted July 23, 2015 (edited) I have to say that I would have serious misgivings about the school being a part of someone else's domain - The AD Forest (not domain) is a 'natural' security boundary and I would worry about permissions issues. If they do this for a number of organisations then there's a possibility for a permissions fubar to expose detail from one organisation to users from another totally separate organisation (including the supplier themselves - while their technical staff would require access to the school's systems to administer it, their accounts department would not and should not have this access, for example) and that would be a huge red flag for me. While the probability of this kind of error occurring might be very low, the potential impact could be huge depending on what gets exposed. Of course, it may be that the reduced costs from only administering one domain are what help to drive the costs down for this supplier and that is something that the school considers very important. I'm sure the SLT members who signed this contract are well aware of the technical ramification of this design choice and have made an informed decision after a technically comprehensive risk assessment that has considered safeguarding, data protection and other important areas... Right? ;-) Edited July 23, 2015 by Roberto
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now