Jump to content

One Domain or Two?!  

50 members have voted

  1. 1. One Domain or Two?!



Recommended Posts

Posted
And what if someone got the domain admin password for your curriculum domain?

 

You could say that for anything though - it just means you have to follow a good password policy and a good security policy. We have a single domain system and have never had a problem with people getting hold of admin passwords - there are only 2 people who know that password, and as such it is extremely unlikely that someone will get hold of it here.

 

That's like saying 'what if someone got hold of the master key for the locks' - and that is more likely than getting an admin password.

Posted

Why not one Forest and then 2 sub domains if you’re really worried about security or someone else is more to that fact. Also 'if' a student etc does get one of the domain passwords it only affects that domain. Unless they get the Enterprise domain admin password!

 

Just a though.

Posted

No point in having 2 domains or networks any more, that was just done in the past for historical reasons that do not apply any more. Security and active directory technology have moved on.

 

I moved 2 years ago to 1 domain and could not be happier. Far to many things overlapped to make it worth while.

  • 2 weeks later...
Posted
Security and active directory technology have moved on.

In what way? Do you mean thet AD has MOVED ON from NT, OR has AD had a security revolution I did'nt get the newsletter for?

 

No point in having 2 domains or networks any more, that was just done in the past for historical reasons that do not apply any more.

 

SORRY, I fail to see your logic. To say that you only require one domain seems quite naive to me. I agree that with good administration a domain can be locked down tightly, however two words echo in my geek bones… ‘Security Realms’.

 

As a MCSE who has bothered to take the 4 hour AD Design exam I can tell you that one domain is not the 'preached' way, I am certainly not a MS fanboy, and what you learn for MS Exams are throwaway knowledge BUT the reality of security realms are not.

 

I moved 2 years ago to 1 domain and could not be happier. Far to many things overlapped to make it worth while

 

Being challenged for authentication only gives me a warm fuzzy feeling :) Scripts do the rest.

 

TBH managing three domains causes me no problems at all. I defiantly would not consider amalgamating them to one domain..

 

 

I truly do appreciate any opinions that others have, there are many paths to the same goal.

 

Thanks, Chris !!

Posted

The trouble with some of the MCSE stuff is that it assumes you're running a world wide network with tens or hundreds of thousands of users (and the staff to support it!) It's not necessarily the best setup for a small organisation.

 

Having said that, we do have 3 domains (staff, student and a resource domain "in the middle" - this is currently only used for photocopiers but we will move other resources onto it soon)

Posted

Agreed, but I don’t call 600pc's + over a 1,000 users a 'small' organisation.

As much as I hate M$ the exams are aimed to reinforce best practices and the solutions most secondary’s implement are most definitely enterprise level.

 

You can quite legitimately have a need for two (or more) security realms and only a dozen users in each, it doesn’t have to be a multiple site setup at all.

 

[align=center]- SECURITY REALMS -

That’s the point I was trying to make.[/align]

 

I’m not saying that two/three/four domains are better than one, that would be evaluated at the design level.

 

It’s just when people say you ONLY need one domain I can’t stop the little voice inside of me that starts screaming, THAT’S JUST NOT RIGHT. I cant help feeling what these people actually mean ‘I used to have two NT4 domain in the old days, now I only have one. Isn’t it great”

 

 

^^^ Please don’t read that as a confrontational post, it's not. I'm just trying to state the security principles behind our setup, we are an inner city school with our share of ’challenging’ students, We also share our plot of land with one of the biggest universities in the area (paranoia mode cuts in when a group of computer science students with laptops start pointing at the wifi aerials lol.)

Posted
BKGarry: There must be a better way. None of our staff need local admin rights for SIMS.

 

He's almost right. SIMS 'can' work if the users are local Power Users, but you have to give them full control to a lot of local folders to work and even then it is hit and miss. Local Admin is the easiest way to do it :Cry:

Posted

You could always look at it that a single domain is as securable and usable as 2 NT4 domains on the same physical LAN.

 

You could even say that for most institutes a single domain is prefectly acceptable with minimal security risks as long as some good practice is remembered (rules on password complexity / length / age as well as the use of elevated user accounts instead of always logging in as administrator to do everything!)

Posted

But why have one domain when two is actually better.

 

You can isolate SIMS and have greater flexibility with domain level security (password policies).

 

If you have a single domain and it goes kaput, then that's your whole school system down for as long as it takes to fix it.

 

The only argument that I've heard is that a single domain is 'easier' to manage or maintain. Why? Management is all done through ADUC or GPMC which can easily switch between domains.

Guest monkeyx
Posted
You can isolate SIMS and have greater flexibility with domain level security (password policies).

 

You can set password Security/GPO at an OU level as well domain ?

 

 

If you have a single domain and it goes kaput, then that's your whole school system down for as long as it takes to fix it.

 

By having two domain controllers in a single domain you provide more resilience for that single domain, so if a single DC fails it is no big issue?

 

I guess it personal choice, but I think putting more money into a single domain instead of spreading it accross 2, gives our school a more resilient and secure system.

Posted

Two domains here

Actually completely unrelated, as the council maintain the admin side (I am not allowed to touch it) and the curriculum side is all mine.

Some local schools seem to be integrating theirs into one, and the next authority along has just announced that it will no longer be supporting the admin network so they are going to have to move to one domain. What they do, eventually we do as well, so I expect one domain will come to me soon.

If I have to support the admin side, with all that entails, I shall want more hours and more money!!

Posted

Over Easter we merged our Admin and Curriculum domains with great success.

 

It has helped the teachers to share their information/resources with each other as well as introducing the concept of "file security" to our secretaries.

 

Our domains were previously not connected to eachother as the council blocked the trust so managing these was very complicated.

 

Like monkeyx said, we can now put more money into making our single domain more ressilient

 

P.S. We transferred 100 users and 60 PCs from admin to the existing curriculum domain already containing 1100 users and 450 devices

Posted
You can set password Security/GPO at an OU level as well domain ?

 

No. As I understand it, password policies are not user settings, they're machine settings. The users don't authenticate against the local machine, they authenticate against the DC. The DC holds the password policy and therefore you can only have one password policy per domain. You can't get round this restriction unless you use third party software.

 

By having two domain controllers in a single domain you provide more resilience for that single domain, so if a single DC fails it is no big issue?

 

Depends on the DC that fails. If it holds the FSMO roles, you're pretty buggered until you can get them transferred. Still, at least you'd have another DC to transfer them to.

 

I guess it personal choice, but I think putting more money into a single domain instead of spreading it accross 2, gives our school a more resilient and secure system.

 

I'm inclined to agree. It's also a damn site less work :)

Posted

We had two domains each with its own DC, and when SIMS Lesson Monitor was introduced we had a trust relationship between the two so that teaching staff logging onto the Curriculum domain could access SIMS resources on Admin. Our SMT & admin staff could log onto both domains, frequently did, and frequently lost track of where they had stored data, which passwords to use on which domain etc etc. Sharing resources between teaching staff & SMT was a problem because SMT often stored them on admin drives not accessible from curriculum, or complained when they had to log off from admin to access curriculum. As the school employed more and more support staff with greater dependancies on both admin & curriculum access things got progressively worse.

 

It became apparent that in our environment a single domain with two DCs and SIMS on a dedicated server would better suit our way of working. It has been like that for almost three years now.

 

I think the choice of 1 or 2 domains depends upon how you want to work and what best suits your end-users. Both have advantages & disadvantages, just make an informed decision :)

Posted

Issues relating to saving things on drives that are not accessible to other users are nothing whatsoever to do with how many domains you have, they are simply to do with configuration or having more one server.

 

As long as the domains trust each other (implicit when the domains are in the same forest), rights can be assigned to users and groups from either forest, so the issue is really where the files are located, not who can be made to access them.

 

There is nothing to stop users who have accounts on an 'admin' domain having access to folders on a server in the 'curric' domain and vice versa.

 

As regards to resilience, it's easy enough these days to run a virtual DC as an additional domain controller to provide resiliency. How about this scenario for a small site;

 

2 servers (call them A and C)

- Server A is the DC for the admin domain

- Server C is the DC for the curric domain

 

Install VMWare server on both servers

Install a virtual server on each server and make it an additional DC for the other domain (eg Server A hosts a VM which is a DC for the curric domain)

 

That way you get 2 servers, 2 domains and resilience.

 

I agree with broc about 'making an informed decision', but lots of people seem to think that 2 domains make it harder to share information and that is simply not the case.

 

EDIT: As regards to logon issues, if both domains are in the same forest, then the 'user principal name' can be used, so that users don't have to worry about which domain they are logging on to. The UPN is unique throughout the forest.

Posted

I should perhaps make it clear that I support a lot of primary schools. It's rather difficult enforcing a secure password policy on primary school teachers.

 

..and primary school kids as well of course ;)

Guest monkeyx
Posted

I know that Longhorn is likely to allow multiple password policies.

 

I am also aware of this article , but have never actually tried to test what it is suggesting.

 

Would be interested to know if it works though :) May try and give it a whirl on our test server.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...