Solved

Splitting company, AD / Mailflow

Posted on 2008-09-29
7
217 Views
Last Modified: 2010-04-21
Hello.

We are asked to separate a department of the company because it's going to be an independent unit (new company). This means seperate AD / networks, but common e-mail addresses. The company have a single domain today and don't want to change e-mail adresses.
Any suggestions how to achieve this?

I have thought of a possible solution with one front end Exchange to handle webmail, etc. And two other servers for mailbox storage, one for each network. And I intend to let the main company keep it's original AD domain (company.com), and establish a new iAD domain for the new company (e.g. company.net, separate forest). Is this a reasonable approach?

Suggestions / comments appreciated.
0
Comment
Question by:riegsa
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 5

Expert Comment

by:NutrientMS
ID: 22600523
Hi,

Yes, I would do as you suggested.  Split the Business Unit out to a new domain (either I child domain or new forest with trust permissions if necessary).  That way the child domain / other domain has access to the Exchange System / normal @domain.com space and can easily be permanently split if the company goes separate ways.
0
 
LVL 8

Expert Comment

by:Icetoad
ID: 22603200
The only reason to have a separate internal domain is to have different security password policies.  Creating different internal domains only makes your internal setup more complicated, DNS more complicated and exchange more difficult to run and configure.  You would also need to have additional Active directory servers available for the stub/sub domain.

The more reasonable solution( and less complicated) would be to create a different OU for them.  You can then apply GPOs directly to the domain.  You can do the same for their computers and servers.

If you need more exchange space or additional servers, i would recommend clustering them to obtain higher availablity, responsiveness and capacity.

To be clear, its highly recommended that you do not create a new stub/sub domain for this company.
0
 
LVL 2

Expert Comment

by:datatechas
ID: 22603265
I have also tought about Icetoads solution and that would of course be the easiest and most efficient solution. But there are a few legal and public policies so no user "traffic" is allowed between the two networks.
Can this be implemented and still full security be applied?
And what if one of the companies later should be fully separated (e.g. name change); can one OU be converted to an independent domain in a simple way?
0
Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

 
LVL 8

Expert Comment

by:Icetoad
ID: 22603313
Sounds like it would be easier to have completely separate forests with separate internal and external IPs.  Thats the only way to be sure there is no intermingling.

You would also want routers/firewalls between the server farms to ensure no traffic is passed from end users of one domain to another.  If its a small company, you can run DNS/exchange/AD on the same server or use SBS( its a PIA though ).   I highly recommend a second server OR use one or two phsycial servers with VMWare and run all the different servers as instances on those two physical boxes.  Gives you high availablity, flexibility and mobility.

You would also want completely separate email servers.
0
 
LVL 2

Expert Comment

by:datatechas
ID: 22603328
But can the companies still have the same "@company.com" in their e-mail addresses? Or do we have to setup some sort of forwarding....?
0
 
LVL 8

Accepted Solution

by:
Icetoad earned 400 total points
ID: 22606643
Well the external domain name doesnt have any bearing on the internal domain structure.  You would have to setup routing groups to accomplish what you want though.

My suggestion would be to talk to sembee(hes in the UK) or find a local exchange expert who can sit down at a table with you and discuss the architecture you want.. that person should be able to provide you with a deployment plan that can do what your asking.  They could even deploy it.  The process shouldnt take long and the discussion should result in a future proof plan.. because you want to do it right the first time.

Have a look at some of the MS DOcs here:
http://technet.microsoft.com/en-us/library/bb123872(EXCHG.65).aspx



0
 

Author Closing Comment

by:riegsa
ID: 31501350
Thanks for your assistance :-)
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question