D
DjP
Hi, What I know about AD can be written on the back of a postage
stamp, so please bear with me.
I have a domain structure that looks a bit like this:
domain.com
finance.domain.com
corporate.domain.com
legal.domain.com
domain.com contains no users and each of the child domains contains
their "own" users. That is, the people that are in finance.domain.com
are not also in corporate.domain.com. There is no replication between
domains. Each child domain administers users in their own domain.
e.g. an admin in finance has no ability to change users in legal. We
want to preserve this "devolved administration" model.
What I want to do is have a single domain with a "read-only"
(apologies if I am not using the correct terminology) copy of the
users from all domains. To my mind we can achieve this in one of two
ways:
1. create a "dummy" domain called global.domain.com and replicate the
contents of each domain into global.
2. replicate each of the domains into the root domain.
Essentially the aims are to get everyone in a single domain and not
allow anyone in a child domain to be able to add or update in another
child domain.
Is this a standard feature of AD? Am I approaching it in the correct
manner? Is one or other of the approaches I have outlined above
suitable or is there another, preferred method? Is there any
significant difference between AD in 2000 and AD in 2003?
Many thanks to anyone who takes the time to help me out.
DjP
stamp, so please bear with me.
I have a domain structure that looks a bit like this:
domain.com
finance.domain.com
corporate.domain.com
legal.domain.com
domain.com contains no users and each of the child domains contains
their "own" users. That is, the people that are in finance.domain.com
are not also in corporate.domain.com. There is no replication between
domains. Each child domain administers users in their own domain.
e.g. an admin in finance has no ability to change users in legal. We
want to preserve this "devolved administration" model.
What I want to do is have a single domain with a "read-only"
(apologies if I am not using the correct terminology) copy of the
users from all domains. To my mind we can achieve this in one of two
ways:
1. create a "dummy" domain called global.domain.com and replicate the
contents of each domain into global.
2. replicate each of the domains into the root domain.
Essentially the aims are to get everyone in a single domain and not
allow anyone in a child domain to be able to add or update in another
child domain.
Is this a standard feature of AD? Am I approaching it in the correct
manner? Is one or other of the approaches I have outlined above
suitable or is there another, preferred method? Is there any
significant difference between AD in 2000 and AD in 2003?
Many thanks to anyone who takes the time to help me out.
DjP