G
Guest
Guys,
I'm trying to bottom out the definitive answer to creating a dedicated root
domain OR not…
Having an empty root domain seems to be AD / Win 2000 design best practice,
however since 2003 the idea appears to have faded away..
I'm looking at creating a pristine forest for the migration of 4 MUD's (2200
users approx..) and a couple of Exchange 5.5 sites.. The organisation is
largely centrally managed by a 3rd party however has a few in-house teams
responsible for their own Wintel systems..
So, for my new pristine forest should I go for a dedicated root (which will
in turn will be namespace root for subsequent children domains, which I plan
only to create one). Hardware costs aside, (the cost of 2 low end servers)
what else is holding me back? Right now I see it as a sensible step to secure
the EA and Schema forest wide groups…
If I didn't go for a dedicated root (as I've read a few people are starting
to do) how should you secure the forest wide groups? OR is the back to the
point that your Domain Admin group should contain few users and you delegate
control over OU's for specific functionality!
Comments and thoughts would be most appreciated!
Mikey.
I'm trying to bottom out the definitive answer to creating a dedicated root
domain OR not…
Having an empty root domain seems to be AD / Win 2000 design best practice,
however since 2003 the idea appears to have faded away..
I'm looking at creating a pristine forest for the migration of 4 MUD's (2200
users approx..) and a couple of Exchange 5.5 sites.. The organisation is
largely centrally managed by a 3rd party however has a few in-house teams
responsible for their own Wintel systems..
So, for my new pristine forest should I go for a dedicated root (which will
in turn will be namespace root for subsequent children domains, which I plan
only to create one). Hardware costs aside, (the cost of 2 low end servers)
what else is holding me back? Right now I see it as a sensible step to secure
the EA and Schema forest wide groups…
If I didn't go for a dedicated root (as I've read a few people are starting
to do) how should you secure the forest wide groups? OR is the back to the
point that your Domain Admin group should contain few users and you delegate
control over OU's for specific functionality!
Comments and thoughts would be most appreciated!
Mikey.