官术网_书友最值得收藏!

Domain Design: Single Forest, Single Domain, Empty Root, Star Shaped

Even though this architecture is no longer recommended, there are still quite a lot of companies that either use it or implement it. This is almost the same design as the previous one, except that it includes an empty root domain. Basically, it implies that the root of your forest is empty, meaning that there will be no computer accounts and no user accounts other than the Enterprise Administrators located in this domain. Within AD, a domain is not a security boundary. A forest, however is, so a multi-forest architecture would provide more security. An empty root domain has good and not-so-good points. The point is that this is a fairly safe design, which still adds layers of security. The other domain under the root domain - the child domain-will contain all of the user and computer accounts. This setup is beneficial from a security perspective in that the Enterprise and Schema Administrators groups are isolated from the other users and administrators. With this design, a few administrators can be selected to control the Enterprise and Schema Administrator groups, and all the other administrators reside in the child domains, configured to be Domain Administrators.

This will add a proper layer of security to the whole structure and will allow an easier structural change, should:

  • New companies be acquired and need transitional access, or
  • A separate AD be required for special access etc.

There has been some controversy about the necessity of an empty root domain. When Windows 2000 came out, the empty root was all the rage and everyone was doing it.

Domain Design: Single Forest, Single Domain, Empty Root, Star Shaped
主站蜘蛛池模板: 将乐县| 嘉禾县| 修文县| 阳泉市| 河北省| 岚皋县| 荥阳市| 岳西县| 原平市| 松潘县| 宜城市| 昭通市| 通化县| 那坡县| 满城县| 扶绥县| 手机| 瑞金市| 大足县| 保定市| 博白县| 特克斯县| 洞头县| 京山县| 连平县| 治多县| 安远县| 南靖县| 富裕县| 萍乡市| 襄樊市| 五寨县| 承德市| 徐水县| 巴楚县| 康马县| 咸阳市| 庄浪县| 双流县| 兖州市| 余干县|