Multi-child domain vs multi-child domain with new tree

Posted on 2010-11-12
Last Modified: 2012-05-10
I start a Windows 2008 R2  Datacenter with a corporated AD Forest that will host many customer Domain.
 Each domain will need to be entirely independant for the others, meaning that all accounts, security, Exchange, Terminal server, AD etc...must not be view or available to the other domains.
Important, these domain must be linked to the corporated Forest because they will be monitor by SCCM that will be installed on the Root Domain.
For now i have 2 child domain(not with new tree) and it goes well ,but the trouble is that Exchange 2010 see all the AD account of the other domain and  this is bad.
There is no way to remove transitive replication on the root domain.
 So my question is, "What is the best way to configure the security of my actual setup or what is the best way to restart my entire Forest considering that many independant Domain will be install in the corporate Forest in the futur?"
Question by:DirectImpact
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4

Author Comment

ID: 34120392
Thanks a lot
LVL 57

Expert Comment

by:Mike Kline
ID: 34121077
When you say security has to be independent that is not possible with domains in the same forest.  The forest is the security boundary.   Joe Richards has a great quick blog on it

So in terms of configuring security if you want t true security boudnary you have to have them in separate forests.



Expert Comment

ID: 34121316
You can have only one Exchange organization in a entire forest. They is no option for separation.

But what I am thinkig here is that you can create address list for each customer and give access only to them. Also you must remove permission on Global address list for all the users except Administrator. This way you can prevent other domain users see whole address list. And this way they think this is their global address list.

Also make sure in the database properties, choose the appropriate offline address book in "Client settings" tab.........

Hope this will help you, let me know how it goes.

~ Anand
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users


Author Comment

ID: 34121371
OK Thanks to give me fast respons

OK in that way, and i ask a question, is there a way to change the domains trust to be unidirectionnal instead of bi-directionnal in the Forest-to-Domain? If not do you think that the best way to reply to my interrogation needs, is to configure the security at the server side(ex Exchange) and maybe force the vew to a particular AD?

Accepted Solution

anandkumardeva earned 250 total points
ID: 34121428
You have to use ADSIEDIT to remove permission. Address list will be stored in,

 CN=All Users,CN=All Address Lists,CN=Address Lists Container,CN=***,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=***,DC=com

Make sure you test this in a test lab and try in production.

~ Anand

Author Closing Comment

ID: 34158507
Missing some links to configure GAL permission

Expert Comment

ID: 34161928

Author Comment

ID: 34163882
Thank a lot Anand,

This will be great for me, i will introde this setup in my configuration.

Thanks again for your support i appreciate

Expert Comment

ID: 34170099
You are welcome... Thanks for the points.

~ Anand

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to:…
Suggested Courses

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question