drkmccy Posted March 9, 2022 Posted March 9, 2022 Looking for best practice on this one. Just taken on a MAT of over a dozen schools. Staff and teachers will all use the same domain to make moves easier. Students will use the individual school's domain. Using ACM to sync SIMS to 365 then use the Google connector to auto provision users to the Google tenant. I now need to find the best way to organise users and devices in Google. I have seen various ways to structure AD in corporate environments but I'm hoping to get peoples thoughts specifically for a MAT's Google tenant. I've outlined below what I have come up with and what has been suggested by others but I'm open to suggestions from someone with experience in this. Many thanks! Site then object (this makes sense at first but then not so much when policies get applied to object types across the MAT): School 1 Users Teachers Students [*]Devices Teacher devices Student devices [*]School 2 Users Teachers Students [*]Devices Teacher devices Student devices Site then user (after writing this I realised it probably isn't ideal): School Teachers users devices [*]Students users devices Object then user (makes sense but the structure will end up being huge with 15 schools): Users Teachers School 1 School 2 [*]Students School 1 School 2 [*]Devices Teacher devices School 1 School 2 [*]Student Devices School 1 School 2 Object then site (I think this is the one might be the better option?): Users School 1 Teachers Students [*]School 2 Teachers Students [*]Devices School 1 Teacher devices Student devices [*]School 2 Teacher devices Student devices My next hurdle is automatically putting the users in the right OUs when 365 provisions them but that's one for another day.
localzuk Posted March 10, 2022 Posted March 10, 2022 I would honestly go with the last one. It allows you to set "all users" and "all devices" level settings easily, whilst also then allowing easy school/role specific settings underneath. Its how we do it here anyway. 1
clareq Posted March 10, 2022 Posted March 10, 2022 A lot depends on your policies. There is no rule that says the structure has to be the same for users and devices. Are you going to have the same policies for all students, regardless of the school? If so then having them all under one OU, so you only have to apply those policies once makes sense. I would assume devices will have geographic policies applied - so machines in school 1 will have different printers applied than machines in school 2 - so they need to be in different OUs. Maybe turn around how you are looking at this, and let easy of policy management determine how your OUs will look.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now