• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1581
  • Last Modified:

Benefits of multiple domains in a forest

Apart from security boundaries (e.g. for Domain Admins), are the benefits of having multiple domains in a forest?

Any benefits in terms of replication (AD and DNS etc)?

And - even for the Domain Admin bit, is this really a benefit?
0
kam_uk
Asked:
kam_uk
  • 2
2 Solutions
 
KenMcFCommented:
The domain is not a security boundry, it is the forest. Domain Admins in the child domains are able to elevate their permissions in the forest.

Depending on what FFL and DDL you are running one benifit is password policies. Starting with 2008 you could create fine granied password policies but before that it was one password polciy per domain without 3rd party apps.

DNS is another one. You could create domain partitions so they will not replicate to all Domain contorllers in the forest.
0
 
kam_ukAuthor Commented:
Thanks KenMCF

So lets say I have emea.kam.com, apac.kam.com and us.kam.com

Are you saying that a DA from EMEA can make themself a DA of APAC?

"DNS is another one. You could create domain partitions so they will not replicate to all Domain contorllers in the forest."

- Could you expand on this?
0
 
KenMcFCommented:
Yes, there are ways that DA ina  child domain can elevate their permissions like that.


Here is a link that explains DNS application partitions.

http://technet.microsoft.com/en-us/library/cc778236(WS.10).aspx
0
 
Mike KlineCommented:
As Ken said they can make themselves an EA  or DA in another domain (they have to know what they are doing).  There was also a good thread on the TechNet forums about this

http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/3f8d0e88-7f26-40f9-b3d2-ca4215b63aea

If you see my post there; I "borrowed" a quote from Laura I still like her line "The oops boundary"

Thanks

Mike
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now