Solved

Two domains vs. one = multi-site company

Posted on 2014-01-13
3
325 Views
Last Modified: 2014-01-14
Experienced in basic AD but not too much multi-site work...
Have a client who just purchased a small company in another state.  Client has typical small office AD setup already (less than 30 PCs).  New site only has about 8 machines and no existing server.
Client desires to operate "as one" with equal access to all network resources.

My plan was just to add a new DC to the domain for the new location (with a different subnet) across a VPN (both locations have good internet connections), utilizing GPOs to optimize profile redirection, etc.  Intended to replicate most shares between locations.

An experienced engineer in our company insists that we risk a great deal by sticking with the single domain vs. establishing multiple domains within the forest and using trust relationships.  He feels that losing connection between the sites can cause significant issues for the domain.

My research seems to show this line of thinking is out of date for most situations in a company this size without serious security restrictions - assuming the new site is setup properly with Global Catalogs, solid GPOs, etc.

Opinions?
0
Comment
Question by:mlmslex
3 Comments
 
LVL 10

Accepted Solution

by:
convergint earned 200 total points
Comment Utility
We have over 30 sites in a few countries on one domain, it's not an issue.  The sites have varying connection options (VPN, MPLS, etc).  There are even lots of sites without connectivity to each other as there's no business reason.  We use DFS and another piece of software for file replication.

As long as each DC in each site can replicate to the schema master fairly reliability you won't have any issues.  With the new server 2012, you can have read only domain controllers and limited AD replication for small remote sites to alleviate security issues too.  Now if each site could go offline for months, that would be an issue.

There's no reason you can't use multiple domain and if there are plans in the future for dramatically expanding/splitting the company, then multiple domains could be useful for future proofing.  I would personally not bother with how small of your organization size is.

The other key is planning your subnets well for allow for expansion and remove conflicts.  For example you might find its fine using a 192.168.1.x/24 subnet for HQ but once you get large and have VPNs, etc you might find it limiting.
0
 

Author Comment

by:mlmslex
Comment Utility
Sounds great.  Appreciate the advice.
0
 
LVL 95

Expert Comment

by:Lee W, MVP
Comment Utility
There is a danger if the the sites lose connectivity... FOR 60 DAYS.  If your sites are disconnected for 60 days, I'd be terminating your employment.  Indeed, if the sites lost connectivity for more than a week I'd probably be firing you.

Put simply, you want a SINGLE domain.
0

Featured Post

Google Storage: Standard vs. Nearline vs. Coldline

Google Cloud Storage has a number of classes to choose from. Although there are a lot in common, they vary in price and usage terms. This post explains Google Cloud Storage classes and helps to understand which  one to choose.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
AD health monitoring 2 58
Hibernate on windows 10 18 77
Link Quickbooks point of sale to server 12 78
sql windows 2008 server 24 27
Not many admins are aware that GPOs can be activated and deactivated time-based. Time to change that :)
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now