Jump to content

Recommended Posts

Posted

Hi

 

Looking into redesigning our AD. All schools currently have there own forest.

 

Was thinking either creating a new forest and using the OU per school

 

Or

 

One forest and each school has there own sub domain in the forest.

 

Question is what’s more beneficial/manageable in the long run if we expand?

 

Cheers

 

Mark

Posted (edited)

We use the second one. the majority of schools have local technical staff who are domain admins for their respective school domains. Then central trust tech support are domain admins for the trust offices subdomain and DA/EA for the forest root domain.

 

Edit: We've 69 schools at the last time I bothered to count them, originally we'd have had to be multi domain for each school to pick their own password policy but less of an issue now that password policies can be applied per group rather than per domain. You've also got to mess with permissions more if you have local tech staff at each school, rather than giving them domain admin and leaving them to manage that themselves.

Edited by Katy
  • Thanks 1
Posted
We use the second one. the majority of schools have local technical staff who are domain admins for their respective school domains. Then central trust tech support are domain admins for the trust offices subdomain and DA/EA for the forest root domain.

 

Edit: We've 69 schools at the last time I bothered to count them, originally we'd have had to be multi domain for each school to pick their own password policy but less of an issue now that password policies can be applied per group rather than per domain. You've also got to mess with permissions more if you have local tech staff at each school, rather than giving them domain admin and leaving them to manage that themselves.

 

69 Schools??!! :eek:

 

How on earth do you manage all that? How big is your IT team?

  • Thanks 1
Posted
We use the first option in our MAT. The latter provides no additional benefits and makes things more complex.

 

Thanks that’s the route I think I am leaning towards.

Posted
69 Schools??!! :eek:

 

How on earth do you manage all that? How big is your IT team?

I work at one of the schools rather than centrally, think the central team is about 6 but every school or cluster of schools has its own local IT staff. So we've got myself (systems manager) and a technician, most of the schools have similar, those in clusters have a cluster network manager then usually a deputy and some techs.

 

So central IT staff very rarely have anything to do with an individual school's IT systems (usually the only thing I need from them is when an installer demands Enterprise Admin rights, which I don't have)

Posted (edited)

General rule of thumb is to start with a flat AD infrastructure, then let the business and or technical/ legal reasons define the need for additional domains.

 

Look for the MS solution accelerators for AD architecture they will point you in the right direction.

Edited by HPlum78
Posted

We went for a single domain. Our IT is centralised too though, so we don't really do 1 OU per school either. An increasing number of our staff are working across more than 1 school, so we've had to come up with a better way of providing accounts that people use at multiple schools.

 

We have been removing servers from the other schools - we have 5 schools and 3 nurseries running from our central cluster now, with the final school moving to it during Easter.

  • Thanks 1
Posted

All depends on the organisational split, to cope with companies merging etc.

 

What's shared between the schools (hardware, software, pupils, staff, files, IT support, lawyers, online services, web domains, email), and what's not?

Posted
Thanks for this info,

how have you setup your WAN? are you centralising your internet connection?

We are on the second iteration of our WAN.

 

The first one, we installed internet connections in every school, and a local UTM for firewall/filtering, then VPN back to central site.

 

This turned out to be more work than it is worth, so we have replaced it with Ethernet P2P lines through Exa. 1Gbit from each school back to the central site, then 1Gbps leased line out to the internet, with a central UTM. Worked out a little cheaper, and allows us to centralise everything.

  • Thanks 1
Posted
What's shared between the schools (hardware, software, pupils, staff, files, IT support, lawyers, online services, web domains, email), and what's not?

 

hardware - All servers shared, unifi switch controller shared, ruckus wireless centrally managed and shared, phones centrally managed etc...

software, - Single MS OVS-ES license

pupils, - no

staff, - about 10% of our staff work across multiple schools now

files, - An increasing amount

IT support, - central team

lawyers, - outsourced, central

online services, - varies, depending on needs

web domains, - each school has its own website domain, but central services share a domain which all schools use

email - single office 365 tenancy

 

So, a *lot* of our Trust shares stuff.

  • Thanks 1
Posted

Sounds like you just need 1 domain then, don't need domain admins who can't access other parts of the network, which is what forests are for.

 

I set mine up as computer>school>room, but users>type>school. Then I can apply a pupil policy to all pupils, but computer policies are more per school (custom mst settings, specific ip settings etc)

  • Thanks 1
Posted

I would say the main benefit of one forest would be staff/students moving between sites but for most schools I would say this is very small (not including head office staff), if this started to happen maybe a trust between sites would work ?

 

We have a mix of schools on a WAN and the rest on VPNs between sites all with separate forests.

 

As you move more towards Gsuite or Office365 local AD domains will become less relevant

 

I would be interested to see the cost savings of putting sites on 1Gb p2p vs their own broadband as a few MATs have mentioned this but I cant see the savings.

Posted

The ultimate question - if all these MATS are creating a single forest, what would you do if a single school was to break away from the forest? surely that makes things more complicated breaking away?

Why not just keep all the sites forests separate and create trust relationships instead?

  • Thanks 1
Posted
The ultimate question - if all these MATS are creating a single forest, what would you do if a single school was to break away from the forest? surely that makes things more complicated breaking away?

Why not just keep all the sites forests separate and create trust relationships instead?

Defining your ongoing business structure "just in case" a school ends up leaving is terrible practice. You're basically tying your hands behind your back for a what if. Especially as school's breaking away is extremely rare.

 

The local authority in Bristol built a city-wide single domain system when they went through BSF. When the company that did the support contract pulled out, that domain was split up and IT handed back to each school. They resolved it by adding a bunch of DCs to the domain - 2 in each school, then broke the links to the central cluster. So, each school was then running a full copy of that domain. They then deleted all the irrelevant OUs at each school. Worked fine. (Well, it would've been fine if they had remembered the enterprise CA when doing it but that was an oversight rather than a fundamental issue).

Posted
I am with @localzuk on this, and TBH I would argue that it would be less painful to have a school split away from a flat domain and have them stand up a couple of DC's than splitting up a forest.... and as already noted you cannot live your life worrying about what might be as this will 1, cost you more money to deliver a service and 2, slow you down and stop you being transformational in what you are delivering (you will only ever administer your infrastructure). I am sure I have said this in more than one post on here!
Posted
Why would it cost more to deliver a service? Still able to remotely administer and access all sites networks and all sites have remote access.
Posted (edited)
Defining your ongoing business structure "just in case" a school ends up leaving is terrible practice. You're basically tying your hands behind your back for a what if. Especially as school's breaking away is extremely rare.

 

The local authority in Bristol built a city-wide single domain system when they went through BSF. When the company that did the support contract pulled out, that domain was split up and IT handed back to each school. They resolved it by adding a bunch of DCs to the domain - 2 in each school, then broke the links to the central cluster. So, each school was then running a full copy of that domain. They then deleted all the irrelevant OUs at each school. Worked fine. (Well, it would've been fine if they had remembered the enterprise CA when doing it but that was an oversight rather than a fundamental issue).

 

It worked fine for about 6 months and then on some sites the domain kept failing. Nearly all of the Bristol schools with the schools.bristolbsf.net domain ended up having to start from scratch 12 months later, that said a lot of schools who move from one MAT to another would then switch to the new MAT's domain for operational reasons so that pretty much covers schools breaking away.

Edited by jimmy_2k
Posted
First thing that springs to mind is we have a number of bits of software that if we want to run them in multiple domains costs us more in licensing, and additional hardware to run those bits of software. Even if you don't have software there are extra DC's that are associated with a multiple forest/domain setups or are we not including those as a cost these days? And with those extra DC's comes a schema and a bunch of extra FSMO roles identity Mangment (add any number of bits of undying infrastructure here) and ultimately you or your technicians time again you could argue that your time is a sunk cost but that's why you will only ever administer IT!
Posted

I know staff at schools where their IT is centralised at one site for the trust. that site had issues which meant the school had no internet, phones, or access to network drives!

talk about putting all your eggs in one basket!

Posted
I know staff at schools where their IT is centralised at one site for the trust. that site had issues which meant the school had no internet, phones, or access to network drives!

talk about putting all your eggs in one basket!

 

We do this, though each school has local dc/fileserver for just incase - phones are now voip and run over the centralised broadband network - havent had any connectivity downtime since 2011? except the times i have to swap the central smoothwall etc for a new one

Posted

Again the fear of what might happen, I might step out into the road and get hit by a bus... You may update the schema in your root forest and break your entire world. It's all about risk assessment, identifying those risks and having a sensible approche to mitigation and recovery.

 

We all know of the place/ person who got hit by the bus and we modify our pratices so not to get wiped out. That should not be never cross the road or remove the buses!

Posted (edited)
Again the fear of what might happen, I might step out into the road and get hit by a bus... You may update the schema in your root forest and break your entire world. It's all about risk assessment, identifying those risks and having a sensible approche to mitigation and recovery.

 

We all know of the place/ person who got hit by the bus and we modify our pratices so not to get wiped out. That should not be never cross the road or remove the buses!

 

or the intersite links havent been upgraded to gb yet as we haven't felt the need to upgrade so we need the downstream fileservers for now... and theyre all on the same forest just secondaries.

 

we're moving to google anyway so they will be going the journey eventually.

Edited by DGardiner
Posted
I know staff at schools where their IT is centralised at one site for the trust. that site had issues which meant the school had no internet, phones, or access to network drives!

talk about putting all your eggs in one basket!

 

This can also happen with a local IT service. This is down to poor management not down to the physical location of the infrastructure.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...