Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory Assessment Inquiry

Status
Not open for further replies.

adfreek

IS-IT--Management
Jul 22, 2003
227
US
Hello,

I've been tasked with having to visit a customer who has a very large Windows platform which from what I've been told "consists of many AD domains and potentially multiple forests". The customer is asking us to come in to perform an assessment because they're starting to realize that they're going down the wrong path with their AD environment (s) and see no light at the end of the tunnell with respect to a "centralized environment". From what I've been told, too many people can simply stand up a domain at will and it's taking place which is reminding them of the old NT 4.0 days.

My question is, can anyone help me out with first hand experience and/or online references as to what type of approach I should take when I sit down with the IT Director or this large organization? It's actually a large College University so if anyone has had to do the same thing for this type of client, that would be great. I guess I'm looking things like: what type of questions to ask ? what approach to take ?

This isn't the actual assessment, but simly a short meeting to learn what's going on.

Regards
 
keep it simple...

always, always start on the basis of one domain, one forest...
and then as you assess, if you have to make it more complicated for good reasons (differing password policies/ political divisions/schema isoation) then do so if unavoidable.

check info on the Designing AD infrastructure courses, good books that prepare the 70-297 MCP explain this in depth

Aftertaf

"Resolve is never stronger than the night before it was never weaker
 
Thanks for your in-depth response. I just hung up from a call with the PM for the company I representing tomorrow during this meeting. He basically said that the client has come out and said that they've deployed far too many AD domains and did not stick with the original design plan. Things have really gotten out of hand with the number of domains, the number of people with admin rights, the GPO's, etc.....

They want to "Collapse thier forest" from what they say. With that being said, any thing in particular I should mention during the meeting tomorrow? Any specifics as to what questions to ask ? What are the pro's & con's to "collapsing a forest" ? Can things come back to bite them ?

Thanks
 
a domain can span different physical sites and networks...
two locations does not justify two domains.

w2k separates logical structure from physical structure
-forests, domains & Organizational Units being logical
-Sites & Domain Controllers being physical

tools exist to consolidate domains into one - ie ADMT: tool that migrates users, groups & PCs from one domain to another.

a design plan needs redoing to assess why there is a need for more than one domain in the first place, or to confirm there isnt a need!



you'll need to study their network setup and plan as few domains as possible, allow for replication between DCs on the sites

Aftertaf

"Resolve is never stronger than the night before it was never weaker
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top