Solved

AD Design for SME with Oversea Branch

Posted on 2013-11-10
3
17 Views
Last Modified: 2015-06-23
Dear expert,

Our company is a SME with global presence. The HQ is in Singapore, with branch in Taiwan, China, Malaysia, Europe and US. However, the distribution of staffs in these place is uneven. Singapore, Taiwan and China account for 90% of the total headcount, whereas Malaysia, Europe and US only account for about 10%.

For security purpose, our company intended to implement AD. Since I am quite new to AD, I am currently stuck on a few questions waiting for your clarification:
My current design is creating one forest and many domain controller, with each domain controller corresponds to one branch. however, some branch such like the ones in malaysia and europe have only a few staffs. So should I still create one dedicated domain controller for such branch?
We intend to set up AD server only in Singapore but not other place, will this design cause latency to oversea users? In what situation should I set up AD server in other branches as well? Which approach is recommendable to our company?
Is VPN necessary for oversea staffs to use AD service(e.g. authentication) and exchange service in HQ?
Thank you in advance.
0
Comment
Question by:chkueh
3 Comments
 
LVL 6

Accepted Solution

by:
iradatsiddiqui earned 500 total points
ID: 39638164
You need to have site to site VPN across locations and needs to have Additional domain controller at each site.........even you can use Desktops (Not high end servers) to install ADC in the branches with low staff or users.........
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40845790
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have been working as System Administrators since 2003. I recently started working as a FreeLancer and was amazed to find out that very few people are taking full advantage of their Windows Server Machines. Microsoft Windows Server comes with so…
Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question