AD DS Redesign Project

Posted on 2014-08-26
Last Modified: 2014-12-07
Hey everyone,

Need a bit of help regarding this project thats been thrown on me today :S

Basically our company was bought out by another, I setup a 2way forest trust between the companies ADDS but they now want me to look at redesigning the whole ADDS and migrate both forest to the new one.

Reasons being:-

Company A's AD OU/GPO structure is all types of messed up.. Really haven't seen anything like in my life and I die a little on the inside when I have do anything in it.
Also the DNS Namespace is a split-DNS config, which the powers the be want rectified (based off a security audit they had) and it also doesn't represent the business name anymore,

Company B is configured with an '.internal' DNS Namespace and based on the fact that the whole company will be migrating to the Office 365 project I'm also working on and the fact that my ADDS is full of dead DC metadata that wasn't cleanup up.
Also, with the changes in SSL certificates in regards to the TLD I think I'm going to have a hard time in replacing the SAN SSL certificate in 12mths time when it expires and I'm not sure what it will involve to fix.

Therefore based on all that it's been decided that its time for a fresh design for the our ADDS.

Based on the business requirements, I can't really think of any reason that we need to use a single forest/multi domain design. We are expanding globally, however everything will be administer by me and all the infrastructure is located at one place.
Hence, I believe that going a single forest / single domain will be the best course of the redesign. I will then look to create separate AD sites for each of global offices and set them up with a DC/GC at each branch office.
And the security/configuration requirements will be constructed using OU's in a 'Mixed Hybrid' design

I have a fairly good understanding of the OU and GPO design that I plan to use, but I still have a few question regarding the DNS namespace design and requirements for the Office 365 and other DNS design.

I've purchased the  '' which we have registered and the DNS delegation is controlled by the company that we use for all the other domains we administer (which I can edit/administer)

Now to to avoid the TLD issues again and taking in consideration the Office 365 project, should I therefore create the new root forest/domain name as '' or can I use ''. Please note that we don't have any dns entries configured for this domain.

Thanks for all you help..
Question by:QuazzieM
    1 Comment
    LVL 11

    Accepted Solution

    Only because you don't see the need for splitbrain dns, use

    There's new tools to help with AD and Office 365

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Join & Write a Comment

    Suggested Solutions

    Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
    NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
    With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now