Jump to content

Recommended Posts

Posted (edited)

Hi all,

 

We currently have a .local domain. As we're making loads of other changes this summer, we've decided to start afresh with a new domain following the [schoolname].co.uk format.

 

At the moment, we have all the students and teachers on [schoolname].local, then our admin team and servers on admin.[schoolname].local.

 

Under the new setup, we're thinking of having school.[schoolname].co.uk and admin.[schoolname].co.uk.

 

We're just commissioning the first DC and I'm not sure what I should put in as the forest.

 

I think I should have this DC as the [schoolname].co.uk forest, then have two DCs each for school.[schoolname].co.uk and admin.[schoolname].co.uk under it in the same forest, so five DCs in total. Is this correct?

(Going from "Dedicated forest root domain" here: https://technet.microsoft.com/en-us/library/cc726016.aspx

 

Or should I just have two DCs for school.[schoolname].co.uk and two for admin.[schoolname].co.uk and set up a trust between them?

 

Any advice would be appreciated :)

 

Thank you!

Edited by Valyyn
Posted

Any particular reason for having the two separate child domains, or a root and child? We have a root and child with two way trust - works absolutely fine but it was migrated from a very old legacy system, and if building fresh I wouldn't do it that way for simplicity's sake. I had to do a fair bit of work to make sure all of the trust settings were bombproof, and this was many years back now.

 

I believe you'll need a forest root domain, with DCs, for this setup - you need to have the domain [schoolname].sch.uk before you can have sub-domains. So, three DCs minimum. I always like having at least two DCs in each domain, so that would be six. Adds up fast.

 

We have students in the forest root, so we have [schoolname].sch.uk with admin.[schoolname].co.uk as a trusted child domain. Means fewer DCs and trusts. You can just ditch the lot and go flat though.

  • Thanks 1
Posted
Similar to you I think, we've got the admin. as a seperate child domain as a legacy thing, originally for security I believe, but now you've said it you have got me wondering if we really need it these days or if we do just go with the one domain. Would make it easiest to manage, plus less DCs and trusts to worry about...
Posted
Similar to you I think, we've got the admin. as a seperate child domain as a legacy thing, originally for security I believe, but now you've said it you have got me wondering if we really need it these days or if we do just go with the one domain. Would make it easiest to manage, plus less DCs and trusts to worry about...

 

I would go with one domain. I can't see any reason at all to separate them.

  • Thanks 2
Posted

We do internaldomain.school.county.sch.uk on a single forest + domain. Using the child domain(s) as a security boundary doesn't really gain you anything that setting sensible permissions to start with wouldn't.

 

When we migrated to a single domain (from two completely separate domains with a one-way trust between admin and curriculum) I gathered SLT round a table with SLT-friendly diagrams and said "I think we should integrate the domains for $list_of_reasons*, these are the $list_of_implications**, but ultimately it's your heads on the block if something goes wrong so what do you want to do?"

 

*Simplicity, ease of maintenance, clearer permissions, less duplication of resources/hardware, getting rid of legacy cruft, one account for everyone. More IT time to do useful things.

**None really. All the failure modes caused by misconfiguration, slinging something on the wrong network share etc were present in the two-domain model due to the one-way trust.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...