P
phil2627
We are in a schol district that is going to AD. We are undecided on
which way to go with our domain model. We have 2 schools with a total
of 4000 students. The schools are connected with a 45 MB line. We
thought about using the "Empty root domain" with child domains - 1 for
students and the other for non students. We realize the following:
For Empty Root Domain
--------------------------
Isolation of Built In Admin accounts
Different password policy for Admin accounts
Against Empty Root Domain
------------------------------
More hardware needed
hacker gets child domain password they can access root domain
eventually
We would like security of not having our students access (or have a
difficult time doing) resources in the non-student domain. We have
looked at the single domain with OUs and multiple domain models, but
would like some input as to why we should do one over the other.
Thanks.
which way to go with our domain model. We have 2 schools with a total
of 4000 students. The schools are connected with a 45 MB line. We
thought about using the "Empty root domain" with child domains - 1 for
students and the other for non students. We realize the following:
For Empty Root Domain
--------------------------
Isolation of Built In Admin accounts
Different password policy for Admin accounts
Against Empty Root Domain
------------------------------
More hardware needed
hacker gets child domain password they can access root domain
eventually
We would like security of not having our students access (or have a
difficult time doing) resources in the non-student domain. We have
looked at the single domain with OUs and multiple domain models, but
would like some input as to why we should do one over the other.
Thanks.