Solved

Multi-child domain vs multi-child domain with new tree

Posted on 2010-11-12
9
549 Views
Last Modified: 2012-05-10
Hi,
I start a Windows 2008 R2  Datacenter with a corporated AD Forest that will host many customer Domain.
 Each domain will need to be entirely independant for the others, meaning that all accounts, security, Exchange, Terminal server, AD etc...must not be view or available to the other domains.
Important, these domain must be linked to the corporated Forest because they will be monitor by SCCM that will be installed on the Root Domain.
For now i have 2 child domain(not with new tree) and it goes well ,but the trouble is that Exchange 2010 see all the AD account of the other domain and  this is bad.
There is no way to remove transitive replication on the root domain.
 So my question is, "What is the best way to configure the security of my actual setup or what is the best way to restart my entire Forest considering that many independant Domain will be install in the corporate Forest in the futur?"
0
Comment
Question by:DirectImpact
  • 4
  • 4
9 Comments
 

Author Comment

by:DirectImpact
Comment Utility
Thanks a lot
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
When you say security has to be independent that is not possible with domains in the same forest.  The forest is the security boundary.   Joe Richards has a great quick blog on it   http://blog.joeware.net/2008/07/17/1406/

So in terms of configuring security if you want t true security boudnary you have to have them in separate forests.

Thanks

Mike
0
 
LVL 5

Expert Comment

by:anandkumardeva
Comment Utility
You can have only one Exchange organization in a entire forest. They is no option for separation.

But what I am thinkig here is that you can create address list for each customer and give access only to them. Also you must remove permission on Global address list for all the users except Administrator. This way you can prevent other domain users see whole address list. And this way they think this is their global address list.

Also make sure in the database properties, choose the appropriate offline address book in "Client settings" tab.........

Hope this will help you, let me know how it goes.

~ Anand
0
 

Author Comment

by:DirectImpact
Comment Utility
OK Thanks to give me fast respons

OK in that way, and i ask a question, is there a way to change the domains trust to be unidirectionnal instead of bi-directionnal in the Forest-to-Domain? If not do you think that the best way to reply to my interrogation needs, is to configure the security at the server side(ex Exchange) and maybe force the vew to a particular AD?
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 5

Accepted Solution

by:
anandkumardeva earned 250 total points
Comment Utility
You have to use ADSIEDIT to remove permission. Address list will be stored in,

 CN=All Users,CN=All Address Lists,CN=Address Lists Container,CN=***,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=***,DC=com

Make sure you test this in a test lab and try in production.

~ Anand
0
 

Author Closing Comment

by:DirectImpact
Comment Utility
Missing some links to configure GAL permission
0
 
LVL 5

Expert Comment

by:anandkumardeva
Comment Utility
0
 

Author Comment

by:DirectImpact
Comment Utility
Thank a lot Anand,

This will be great for me, i will introde this setup in my configuration.

Thanks again for your support i appreciate
0
 
LVL 5

Expert Comment

by:anandkumardeva
Comment Utility
You are welcome... Thanks for the points.

~ Anand
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now