Oliver,

Personally, unless there is a specific security (minimal protection
anyway....but it's a 'feature) or password / account lockout issue that
would require a new domain, the benefit is minimal.  There is
replication boundary to consider, but unless you're talking many, many
changes and many objects, it's not worth the added effort, expense
(multiple DC's per domain), etc. of maintaining a bunch of added
domains.

My company has 4 domains - an empty root and three child domains.  The
children were created for specific independent operating units.  A
separation of church and state, if you will.

In our largest domain, we have ~ 16k users and workstations.  In that
one domain, I have 15 remote sites spread around the country - from
Virginia to Nevada.  We separate all of these sites out by OU because we
can:

*  Manage them independently
*  Apply Group Policy as necessary
*  Use Delegation to give the remote site personnel the proper authority

Now, we don't have a speed of replication issues as all of our sites are
connected via either multiple T-1s, T-3s, or ATM.

I guess what I'm saying is if you're dealing with Branch Office
scenarios (I support anywhere from 150 to 1000 people in a per site
basis - depending on which one), domains are not the right solution
unless password / account lockout are the real problem.  And, in most
cases, replication traffic is not the reason to create domains over OUs.
The only traffic that you're saving is the domain-related traffic.
Global catalog and schema are still replicated to all DC's in the
forest.

Rick Kingslan  MCSE, MCSA, MCT
Microsoft MVP - Active Directory
LAN Administration - Windows 2000
West Corporation
[EMAIL PROTECTED]


-----Original Message-----
From: Oliver Marshall [mailto:[EMAIL PROTECTED] 
Sent: Monday, October 20, 2003 3:45 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Remote network AD setup


We have an head office running an AD based network. We have several
smaller satellite offices running workgroup based networks.

We now need to integrate all the offices into one AD so that users can
move able with the same logons, and that all the AD management and
maintainance can be done from one place.

I was thinking of settup up the smaller offices as child domains of the
main one, so small_office1.mydomain.com etc, which, as I understand it,
should allow me to manage all the user accounts from one place. I was
also going to have a GC at each small office so that they can still
logon etc if the lines are disconnected.

The question I have though is (maybe) a simple one. How do I setup the
DNS so that the DCPROMO applet in each satellite office will work ?
Currently the sites are connected via VPN, and each satellite office has
forward and reverse DNS entries pointing to the Head Offices domain
(using the internal IP's). However, when we enter the domain into the
domain section of the DCPROMO applet, it barfs a lung.

I know that im missing something, or coming at this the wrong way, but I
have no idea where to start. If you could help that would be great.

Olly
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to