Jump to content

Anyone hosting a forest root DC in the cloud, or something else?


Recommended Posts

Posted

I am once again planning, after the last scheme our school was pursuing fell apart and we now have another, different but similar, scheme to become a MAT. As part of this, I am looking at what best to do to link the networks of multiple schools together.

 

I am currently thinking one of 2 structures:

 

1. Multi domain forest.

 

Put forest root DCs in the cloud on VMs in Azure. Won't cost much.

Put 2 domain controllers for each school in each school.

 

This would reduce replication issues, as far as I can see, but introduces increased complexity. Gives each school a somewhat unique identity.

 

2. Single domain, multiple sites

 

Put domain DCs in the cloud on VMs.

Put a single DC in each school.

Set up each school as a site within the domain.

 

Reduces the complexity of moving staff around, should they move from one school to another. But will increase replication issues.

 

So, which would you go with?

Posted

If I was building a new single domain for a MAT tomorrow, I'd configure it as follows:

 

MAT.pri (Root/parent domain)

MAT.school1.pri (child domain)

MAT.school2.pri (child domain)

MAT.school3.pri (child domain)

 

This keeps the configuration simple, but it also means replication is kept to a minimum too. As for the configuration of Domain Controllers, (depending on size), a minimum of two DCs - physical or virtual would be advisable. Depending on how you intend to delegate/manage control, all DCs other than the parent could be made Read Only. If there are other Techs working on the network, you can easily allow/disallow them access to particular child domains quite easily. Delegation within one single domain is problematic.

 

You also have to consider (worse case scenario), that if all sites were under one domain and you or someone made an error, you could (in theory) take out the domain for everyone.

 

Another consideration are upgrades - you can perform upgrades in a test child domain (for example), rather than upgrade everyone at once and then discover it hasn't quite gone to plan.

 

Of course another solution which is dead easy is to create Trusts between all existing domains where appropriate.

Posted

I have done both. More recently option 2 and this was the better one for the reasons you stated. Its also requires less time in setting everything up.

 

We had issues with multiple domain forest with many applications that simply where not developed with that in mind.

 

Also with Windows 7 you can't select a domain from a drop down box. Makes things hard for roaming users.

Posted

Another consideration is if it's data sharing you're after, then O365 OneDrive is probably the way to go between sites in a MAT.

 

Permissions can easily be configured enough between different O365 domains or tenancies.

Posted

Just be careful when making any "important" server an Azure VM. From memory there is no console view in azure (admittedly I may be a little out of date on this info). This means if the server was to go wrong there is no easy way to troubleshoot. You had to download the VM from Azure to a device in your office then try to fire it up and see the error and fix, before re-uploading back to azure once you were happy. Now if you have time to do all that then great, but if the server that fails is running a critical service it just not worth the hassle of everyone breathing down your neck to get it back up and running.

 

Last I spoke to Microsoft, adding a console view is not nothing they had\have planned for the future :-/

Posted

Don't think I'd rule Azure out - can't remember the last time I needed to Console into a server - especially when its comes a DC. If you got corruption, you'd just restore from backup.

@localzuk - I think the choice will be political. Depending who the other school(s) are and how willing they are to trust and work with you. Bit pointless creating a single cross school forest if they don't want to give you full control over their network. Still I think the single forest with child domains for each school is the way to go - if they don't trust you \ want to work - each enter half the password for the forest top-level domain administrator password ( :p ) and do everything at the local child domain.

 

If I was building a new single domain for a MAT tomorrow, I'd configure it as follows:

 

Don't you mean

MAT.pri (Root/parent domain)

school1.MAT.pri (child domain)

school2.MAT.pri (child domain)

school3.MAT.pri (child domain)

Posted
Don't think I'd rule Azure out - can't remember the last time I needed to Console into a server - especially when its comes a DC. If you got corruption, you'd just restore from backup.

@localzuk - I think the choice will be political. Depending who the other school(s) are and how willing they are to trust and work with you. Bit pointless creating a single cross school forest if they don't want to give you full control over their network. Still I think the single forest with child domains for each school is the way to go - if they don't trust you \ want to work - each enter half the password for the forest top-level domain administrator password ( :p ) and do everything at the local child domain.

 

Don't you mean

MAT.pri (Root/parent domain)

school1.MAT.pri (child domain)

school2.MAT.pri (child domain)

school3.MAT.pri (child domain)

 

Yes, but you guys knew what I meant. I spotted the error after I posted the original message :)

Posted
Don't think I'd rule Azure out - can't remember the last time I needed to Console into a server - especially when its comes a DC. If you got corruption, you'd just restore from backup.

@localzuk - I think the choice will be political. Depending who the other school(s) are and how willing they are to trust and work with you. Bit pointless creating a single cross school forest if they don't want to give you full control over their network. Still I think the single forest with child domains for each school is the way to go - if they don't trust you \ want to work - each enter half the password for the forest top-level domain administrator password ( :p ) and do everything at the local child domain.

 

Politically, the networks will likely belong to the trust, and not the schools - so decisions about them will be made by the COO and myself, with the views of the schools taken into consideration.

Posted
Don't think I'd rule Azure out - can't remember the last time I needed to Console into a server - especially when its comes a DC. If you got corruption, you'd just restore from backup.

@localzuk - I think the choice will be political. Depending who the other school(s) are and how willing they are to trust and work with you. Bit pointless creating a single cross school forest if they don't want to give you full control over their network. Still I think the single forest with child domains for each school is the way to go - if they don't trust you \ want to work - each enter half the password for the forest top-level domain administrator password ( :p ) and do everything at the local child domain.

 

 

 

Don't you mean

MAT.pri (Root/parent domain)

school1.MAT.pri (child domain)

school2.MAT.pri (child domain)

school3.MAT.pri (child domain)

 

Hopefully you never need to console into a server, but it's good to have the option if something goes wrong. It only takes 1 erroneous MS update to fubar the OS. We created a small test environment in Azure, and we actually lost total access after 1 Azure maintenance window. I'm not entirely sure what caused the problem, but it wasn't meant to touch our servers, just a platform update. It ended up screwing our network config which domain accounts would not work. We managed to recover most servers, but the DC's had to be all recreated (as it was test it was easier to do this then try and fix by downloading)

Posted

I totally agree though, a lot of the choices are political as a single domain, or even a single forest with child domains essentially locks you in to that setup. Either way, if a school left the trust, they'd have to build their network domain from scratch.

 

If this is the case, separate domains via a two way trust is the only way you can stay 'as is', but go your separate ways if ever there was a need.

 

I do wonder sometimes if the Government want to make all schools Academies (in some form), then surely it will be more common place to see schools chopping and changing their sponsor or moving from trust to trust, rather than staying with just one? For example there are schools who have become Academies who consequently fall short of standards (for whatever reason), and then require a new sponsor. The idea of a single MAT network domain then seems unrealistic, as it would create a lot of work.

Posted

It takes a considerable amount of work to leave/join a MAT. Chopping and changing is, therefore, expensive.

 

The government do want all schools to become academies, I believe they've even said that at one point.

 

Thing is - if you can't harmonise networks across schools in a MAT, how can you effectively manage them without costing more money? Part of the point of being a MAT is centralisation and consolidation of costs, with the goal of saving money.

Posted (edited)

@Firefox - Should be ok if its a secondary DC - re network config - I assume you read the thing about the IPs being dynamic and it losing its IP when its hard reboots (deprovisioned\reprovisioned)?

@localzuk - Still political. So this MAT will be controlled by a single (Middle school) with primary schools under it (kinda like a mini LA) with a single boss - rather then multiple (primary) joining together on a equal footing with multiple bosses agreeing.

 

it will be more common place to see schools chopping and changing their sponsor or moving from trust to trust, rather than staying with just one?

 

Isn't this the ADFS idea?

 

The government do want all schools to become academies, I believe they've even said that at one point.

 

And if Labour comes in, they'll go back to LA maintained.

 

Part of the point of being a MAT is centralisation and consolidation of costs, with the goal of saving money.

 

Sorry, isn't this just a LA. Group local schools together under a government (so not for profit) department then buy\do in bulk

Edited by matt40k
Posted

ADFS allows you to share data across organisations, but they still need to be joined in some form regardless.

 

I suppose a MAT is a mini LA you're right and one of its purposes to share/collaborate good practice and standardise policies across the trust. This would of course include the IT in some capacity, but it's by no means high up the chain in terms of priorities. Granted we all see it as important and it can change the way Staff and Pupils work, but in reality, the people making such decisions really don't care how IT is managed in the background.

Posted
@localzuk - Still political. So this MAT will be controlled by a single (Middle school) with primary schools under it (kinda like a mini LA) with a single boss - rather then multiple (primary) joining together on a equal footing with multiple bosses agreeing.

 

The structure will be, I believe, WSAT trust controlling strategy, ofsted, curriculum and centralised services. Each school would then have a head of school which manages the day to day running of the school.

 

So, it wouldn't be one school running others - the CEO will be separated from the day to day running entirely. Same with COO etc...

 

Sorry, isn't this just a LA. Group local schools together under a government (so not for profit) department then buy\do in bulk

 

Depends on your geographical area. When you've got a huge geographical area, LEAs were a pain - what worked for schools in their local town often worked horribly for rural schools. Here, all the schools are rural, and have very similar issues they face day to day. There aren't any plans to add schools that aren't near to us.

Posted
Depends on your geographical area. When you've got a huge geographical area, LEAs were a pain - what worked for schools in their local town often worked horribly for rural schools. Here, all the schools are rural, and have very similar issues they face day to day. There aren't any plans to add schools that aren't near to us.

 

I think that more depends on your LA. If your a largely urban LA with one rural school, yer, its going to be poor service. I still think the geographical area idea is pretty dated for some things, things that require a physical presence onsite makes sense - assuming the grouping is correct - I know we have schools that are closer to other LAs that a partnership between the two would make more sense. Still it'll be a good to see virtual "LAs" appearing - I've spoken with schools where they feel isolated and there situation is unique but I know there are loads of other schools going through the same thing, not always within the same LA. Often it is the low-end of the social scale in rural areas where its more a question of inspiring the children then anything. It's surprising what effort being around successful people in nice buildings does vs shelf stackers \ council houses.

 

Fully off topic now :)

Posted
@Firefox - Should be ok if its a secondary DC - re network config - I assume you read the thing about the IPs being dynamic and it losing its IP when its hard reboots (deprovisioned\reprovisioned)?

 

As a secondary DC I could probably live with this as it's fairly easy to trash it and rebuild. But this goes back to my earlier comment about not putting an "important" server into Azure. I'm sure many companies are happy to take that risk. I'm a fan as of using the cloud for SaaS but not sure it's quite there (with Azure atleast) for a reliable IaaS.

 

Again it could just be my paranoia kicking in, but if I'm going to be the one responsible for fixing it, then I like to have more control over it. ;)

Posted
I think its is safer personally. They take a lot of responsibility (and thus problems) away. That said, you can't just fling a server up in Azure and get on with it. It has limitations you need to be aware of, so yes, I wouldn't put anything "important" up in the cloud for my first attempt but I wouldn't see not having access to the (virtual) bios as a problem :p

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...