Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Two domains vs. one = multi-site company

Posted on 2014-01-13
3
Medium Priority
?
341 Views
Last Modified: 2014-01-14
Experienced in basic AD but not too much multi-site work...
Have a client who just purchased a small company in another state.  Client has typical small office AD setup already (less than 30 PCs).  New site only has about 8 machines and no existing server.
Client desires to operate "as one" with equal access to all network resources.

My plan was just to add a new DC to the domain for the new location (with a different subnet) across a VPN (both locations have good internet connections), utilizing GPOs to optimize profile redirection, etc.  Intended to replicate most shares between locations.

An experienced engineer in our company insists that we risk a great deal by sticking with the single domain vs. establishing multiple domains within the forest and using trust relationships.  He feels that losing connection between the sites can cause significant issues for the domain.

My research seems to show this line of thinking is out of date for most situations in a company this size without serious security restrictions - assuming the new site is setup properly with Global Catalogs, solid GPOs, etc.

Opinions?
0
Comment
Question by:mlmslex
3 Comments
 
LVL 10

Accepted Solution

by:
convergint earned 800 total points
ID: 39778097
We have over 30 sites in a few countries on one domain, it's not an issue.  The sites have varying connection options (VPN, MPLS, etc).  There are even lots of sites without connectivity to each other as there's no business reason.  We use DFS and another piece of software for file replication.

As long as each DC in each site can replicate to the schema master fairly reliability you won't have any issues.  With the new server 2012, you can have read only domain controllers and limited AD replication for small remote sites to alleviate security issues too.  Now if each site could go offline for months, that would be an issue.

There's no reason you can't use multiple domain and if there are plans in the future for dramatically expanding/splitting the company, then multiple domains could be useful for future proofing.  I would personally not bother with how small of your organization size is.

The other key is planning your subnets well for allow for expansion and remove conflicts.  For example you might find its fine using a 192.168.1.x/24 subnet for HQ but once you get large and have VPNs, etc you might find it limiting.
0
 

Author Comment

by:mlmslex
ID: 39778244
Sounds great.  Appreciate the advice.
0
 
LVL 96

Expert Comment

by:Lee W, MVP
ID: 39778589
There is a danger if the the sites lose connectivity... FOR 60 DAYS.  If your sites are disconnected for 60 days, I'd be terminating your employment.  Indeed, if the sites lost connectivity for more than a week I'd probably be firing you.

Put simply, you want a SINGLE domain.
0

Featured Post

Ready for your healthcare security check-up?

In the past few years, healthcare organizations have become a prime target for advanced attacks. Does your organization have what it needs to defend itself? Schedule your healthcare security check-up today and download our free Healthcare Security Resource Kit today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Web hosting control panels were first developed to make it faster and easier for most users to set up and operate websites. The graphical user interface (GUI) allows users to perform tasks by pointing and clicking rather than typing highly specific…
While Plesk offers many potential benefits to website administrators, including compatibility with Windows Server and other leading technologies, the company has also been working to differentiate it from other control panels for content management…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Suggested Courses

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question