• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 446
  • Last Modified:

multi tenant active directory design

Dear Experts.

I am currently at a Managed IT Services Company.
Currently they have a totally separated AD/Network for each customer and internal environments (UAT, DEV, Prod).
This makes it VERY hard to manage as you have to RDP on to that server to get on to another server.
Same for the different internal environments, to me UAT testing is irrelevant as the ADs are so out of date with the production, you cant take in to account the way AD is on the testing.

We may have a chance to greenfields the whole thing. What would be the best way to architecture it.
Single domain forest with child domains.
Single AD with each managed company having its own OU
Different domains with trust relationships setup
Different domains with trust for the company's, then internal one domain with subdomains for the different environments with one way AD replication. that way Dev people cant affect GPOs for prod

To me a picture is worth a thousand words. So any input with diagrams would be great
0
jackoltd
Asked:
jackoltd
  • 2
  • 2
3 Solutions
 
theruckCommented:
if the AD is for your apps just for authentication purposes then i would go for Single AD with each managed company having its own OU but that depends on the customers environments as well. if there are big customizations to customers AD you need to count in with your apps then you need a similar and separated AD for that customer.
trusts between domains would create administrative overhead and child domains would make your future AD operations more difficult
0
 
jackoltdAuthor Commented:
The only apps we use that really require AD is Sharepoint, XenApp/XenDesktop and Exchange.
With regards to Exchange, they are all separated, would it be better to have one exchange environment in conjuntion with a single domain
0
 
theruckCommented:
"they are all separated" - who?
regarding the exchange you have not mentioned any needs and concerns yet
0
 
jackoltdAuthor Commented:
Doesnt matter now, they have decided to keep it all separated
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now