Solved

Single domain or multiple domain for a school or university???

Posted on 2011-02-14
7
1,183 Views
Last Modified: 2015-06-14
We are a small southern college.  We are in the midst of an Active Directory design.  The question that has been posed to the design team is whether or not we should maintain a single Active Directory domain for all students, faculty and Staff, or should we maintain separate domains...namely, one for students (several thousand) and one for faculty and staff (about a thousand).

Our contention is that a single domain should be fine.  We'd really prefer this as an Exchange system is also being implemented and we'd prefer a single Exchange organization, rather than multiple.  Additionally, we believe students can easily be maintained in a separate OU, and adequate security measures and GPO's can be employed to maintain security.

Personally, it appears to me, that the practice of deploying a separate AD domain in such circumstances is less prevalent than it once was, mainly b/c the feeling is that both security and manageability can be satisfied by deploying a single directory.

I was hoping for feedback.  Especially anyone who is currently or has worked for a college who at one time or another had to do the same thing.  Are there any big minuses from our thoughts on this matter?  Any thing we should keep in mind?

Thank you.
0
Comment
Question by:patriots
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 17

Expert Comment

by:James Haywood
ID: 34891800
I would go with the single domain. The only possible reason you might want separate domains is for DR as if there is an issue with your AD and you have a single domain then the problem will affect pretty much everyone and every machine. Saying that, if you have plenty of redundancy and a decent IT team then you should be able to deal with these problems without much issue.

A good AD layout using thought-out OUs and GPOs will give you huge amounts of control and delegation options. If you have more than one site (like most colleges/Unis) then you can use the AD sites and services rather than child domains.

0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 34891810
You can go either way but if you are managing these three groups from one Admin or Tech suppory group  then I would recommend going with Single domain with multiple OUs this will allow for easier administration.

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_22803733.html
0
 
LVL 5

Expert Comment

by:mickinoz2005
ID: 34891937
as the others say with the level of control you can have with OU's and GPO's it would not make sense to split them.
0
The Ultimate Checklist to Optimize Your Website

Websites are getting bigger and complicated by the day. Video, images, custom fonts are all great for showcasing your product/service. But the price to pay in terms of reduced page load times and ultimately, decreased sales, can lead to some difficult decisions about what to cut.

 
LVL 7

Expert Comment

by:Chris Patterson
ID: 34892003
Having just finished an AD/Exchange migration and redesign for a large college (over 20,000 students plus faculty), we consolidated 3 AD domain and 2 Exchange organizations down to a single AD domain and single Exchange organization.  It just took good planning and organization before hand to lay out the project and complete it.  The administrative overhead from supporting multiple AD domains and Exchange organizations was killing the support staff.  After all was said and done, the simplicity of the "new" centralized infrastructure allowed technicians to start working normal hours and saved dollars spent on overtime and supporting too many disparate systems.
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 250 total points
ID: 34892010

Multiple domains within a forest do not provide any security advantage, because the security boundary is the edge of the forest, not the edge of the domain.

Implementing multiple domains is something which is only recommended if you have a very large subset of users with specific requirements, or if you have thousands of users who work for lots of different companies which need a degree of separability, maybe in DNS namespaces or management boundaries for the various IT teams. In your deployment, a single domain is the best configuration you'll opt for. Everything is secured using GPO and separate OUs for each category of user. It's also less costly, because you could potentially have twice the redundancy on a single domain as you could on two domains (since the redundant hardware/software needed for two could all participate in one).

FWIW, my work is at a school environment with a 2500 user network, and we run a single domain. I wouldn't go for anything else, because the TCO in adding hardware, software, training and the interoperability of the two just cannot be justified. As I mentioned above, unless you have a real reason to split the domains off (which you are struggling to identify -- which is good) then sticking with a single domain is the best option you can go for.

-Matt
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 34894526
I agree a single domain has its benifits.

So, maybe we should be providing alternatives and a different form of security. Have you considered a single domain split via VLANS?

ADMIN VLAN, User VLAN, Wireless VLAN, STAFF VLAN, etc...

VLANS allow you to control what ports are accessible by other VLANS if configured right.

You can always count on students hacking into the system.
0
 

Expert Comment

by:garryshape
ID: 40829078
Can I ask what is more difficult about managing two different domains? Say 1 forest and multiple child-domains?
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question