Jump to content

Recommended Posts

Posted

Looking for best practice on this one. Just taken on a MAT of over a dozen schools.

Staff and teachers will all use the same domain to make moves easier. Students will use the individual school's domain.

 

Using ACM to sync SIMS to 365 then use the Google connector to auto provision users to the Google tenant. I now need to find the best way to organise users and devices in Google. I have seen various ways to structure AD in corporate environments but I'm hoping to get peoples thoughts specifically for a MAT's Google tenant. I've outlined below what I have come up with and what has been suggested by others but I'm open to suggestions from someone with experience in this. Many thanks!

 

Site then object (this makes sense at first but then not so much when policies get applied to object types across the MAT):

  • School 1
    • Users
      • Teachers
      • Students

       

      [*]Devices

      • Teacher devices
      • Student devices

     

    [*]School 2

    • Users
      • Teachers
      • Students

       

      [*]Devices

      • Teacher devices
      • Student devices

 

Site then user (after writing this I realised it probably isn't ideal):

  • School
    • Teachers
      • users
      • devices

       

      [*]Students

      • users
      • devices

Object then user (makes sense but the structure will end up being huge with 15 schools):

  • Users
    • Teachers
      • School 1
      • School 2

       

      [*]Students

      • School 1
      • School 2

     

    [*]Devices

    • Teacher devices
      • School 1
      • School 2

       

      [*]Student Devices

      • School 1
      • School 2

 

Object then site (I think this is the one might be the better option?):

  • Users
    • School 1
      • Teachers
      • Students

       

      [*]School 2

      • Teachers
      • Students

     

    [*]Devices

    • School 1
      • Teacher devices
      • Student devices

       

      [*]School 2

      • Teacher devices
      • Student devices

 

My next hurdle is automatically putting the users in the right OUs when 365 provisions them but that's one for another day.

Posted
I would honestly go with the last one. It allows you to set "all users" and "all devices" level settings easily, whilst also then allowing easy school/role specific settings underneath. Its how we do it here anyway.
  • Thanks 1
Posted
A lot depends on your policies. There is no rule that says the structure has to be the same for users and devices. Are you going to have the same policies for all students, regardless of the school? If so then having them all under one OU, so you only have to apply those policies once makes sense. I would assume devices will have geographic policies applied - so machines in school 1 will have different printers applied than machines in school 2 - so they need to be in different OUs. Maybe turn around how you are looking at this, and let easy of policy management determine how your OUs will look.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...