Spread the word.

Share the link on social media.

Share
  • Facebook
Have an account? Sign In Now

Sign Up

Create your WindowsTechno Community account. It’s free and only takes a minute.

Have an account? Sign In
Continue with Facebook
Continue with Google
or use

Have an account? Sign In Now

Sign In

Continue with Facebook
Continue with Google
or use

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Continue with Facebook
Continue with Google
or use

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

WindowsTechno Community

WindowsTechno Community Logo WindowsTechno Community Logo

WindowsTechno Community Navigation

  • Home
  • About Us
  • Write For Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • About Us
  • Write For Us
Home/ Questions/Q 2897
Next
Anonymous
  • 0
Anonymous
Asked: April 22, 20232023-04-22T00:24:11+05:30 2023-04-22T00:24:11+05:30In: Active Directory

Thought Exercise: AD Greenfield

  • 0

Thought Exercise: AD Greenfield

As a though exercise and to improve my mental model of AD security & resilience, I tasked myself to plan a re-design of our AD environment (think international company, complex multi-forest, multi domain, cloud-connected ecosystem).

I have the following items on my game plan:

[Design]

  • Forest model (numbers, function)

  • Domain model

  • Trusts

  • Network (Zones, Connections, Routes)

  • Security Boundaries (Between Forests, Networks, Users, Servers)

  • Failover & Redundancy

  • Break-Glass & Emergency Access

  • Cloud connection

[Architecture]

  • Forest and Domain Hierarchy

  • FSMO Roles

  • Replication & Sites

  • TIER Architecture

  • AD Object Hierarchy and Containment (OUs, Groups, Users, …)

  • Network segregation & Firewall Rules

  • Device Management

[Migration]

  • ?

(a few more minor items, but I’d rather have room for ideas, so let’s leave it at this)
I’m interested in feedback: What else would you have on your list, what else would you consider, what other design/architecture/migration/test-phases would you set up.

  • 0 0 Answers
  • 9 Views
  • 0 Followers
  • 0
Share
  • Facebook

    Leave an answer
    Cancel reply

    You must login to add an answer.

    Continue with Facebook
    Continue with Google
    or use

    Forgot Password?

    Need An Account, Sign Up Here
    Continue with Facebook
    Continue with Google

    Sidebar

    Ask A Question

    Stats

    • Questions : 119
    • Answers : 26
    • Posts : 15
    • Comment : 1
    • Best Answers : 4
    • Users : 8
    • Groups : 2
    • Group Posts : 0
    • Popular
    • Comments
    • Tags
    • Vipan Kumar

      DFSR no longer replicates files

      • 1 Comment
    • Vipan Kumar

      Wintel Administrator Interview Questions

      • 0 Comments
    • Vipan Kumar

      What is Active Directory?

      • 0 Comments
    • Vipan Kumar

      Active Directory Domain Services Overview

      • 0 Comments
    • Vipan Kumar

      How to fix the issue with the slow authentication

      • 0 Comments
    • Manoj
      Manoj added a comment Nice explanation ? February 4, 2023 at 11:21 am

    Users

    Shawn Davis

    Shawn Davis

    • 0 Questions
    • 0 Answers
    Manoj Kumar

    Manoj Kumar

    • 0 Questions
    • 0 Answers
    Vipan Thakur

    Vipan Thakur

    • 0 Questions
    • 0 Answers

    Explore

    • Home
    • Questions

    Footer

    © 2023 WindowsTechno. All Rights Reserved
    by WindowsTechno.