Solved

URGENT: Active Directory separation scenario's

Posted on 2015-01-19
5
164 Views
Last Modified: 2015-05-11
Hello,

Our company is joining another one and one part of the company will not join. Therefore they ask me to present some scenario to seperate from our forest the company that will not follow us in the join adventure.

To keep it simple i need to present  AD seperation with pro and cons.
Is there anyone that can help me with documentation ?
How to manage the seperation technically (different steps to achieve the goal ???
i believe ADMT will be involved but don't really know how to use it...... :-(
May be creaye a new forest and migrate is the best solution???
But i need to present different scenarios to the management before wednesday :-(
We have PKI, exchange hosted by MS in the cloud, Share point and SSO, GPOs

Thanks for your help...

Regards,
0
Comment
Question by:AMATERASOU
5 Comments
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 40559160
How big is your environment?

How quickly does this need to be done?

I have never done this. ;-)

The best, cleanest option that I can think of is to migrate the parts of the company that is joining the other company into their existing forest. This probably involves a temporary forest trust, and then use ADMT to migrate. This leaves the new joined company with a clean forest, and then your existing forest would just need to delete everything that has been migrated and keep on operating with whatever is left.

An option I don't really like is to migrate the part of the company that will be left behind into a new forest, and then establish a forest trust between your current forest and the forest of the other company. You should still eventually migrate everything from your current forest into their infrastructure.

A final option that I can think of, which is pretty quick and dirty is to take some domain controllers and use them to partition your existing forest and domain(s) into a split-brain where you basically partition the network and disconnect the domain controllers from each other, do a meta data cleanup to remove the domain controllers that are now in the other forest. This is similar to cloning your AD environment for testing purposes. It sounds like you have some integration between your private AD environment and the public Internet, and that would require some work to get separated out.

Sounds like a good project to bring in some consultants.
0
 
LVL 77

Expert Comment

by:arnold
ID: 40559303
Kevin, quite an analysis.

Have not gone through this either.

The combination of the multiple options outlined depending as Kevin pointed on the size of each group and your timeframe. Deals with locally managed resources/infrastructure.
Presumably the shift of those who would not be remaining needs to be shifted out first before the join into the new.


The external/cloud exchange/sharepoint, is it tied into your DCs?
The external hosted separation, domain stays with which side?
........

Are there any regulatory issues that need to be managed/handled in the transition?
0
 

Author Comment

by:AMATERASOU
ID: 40559389
Hello,
The external/cloud exchange/sharepoint, is it tied into your DCs?
Yes

My priority is the AD seperation i need to split AD with part of our company who will not follow us in the jointure
0
 
LVL 77

Expert Comment

by:arnold
ID: 40559908
Timeframe?

can  the current internal domain be kept by the remaining group?
Who keeps the external domain.

Those deal with where the priority should be.
But presumably, the trust between current and the other can not be established so long as those who remain have access.


You would likely need to use the first option Kevin included while at the same time handling the 365 separation and DC tie in. To separate
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 40560489
The part of company which do not follow joint venture, how big it is?
How many users do you have there?

If you want to separate them, that's not very big issue
U can create brand new AD forest and use ADMT to migrate users from old domain to new domain
However what about email infra?
Which email infra you wanted to use, the previous one OR you will be leveraging new O365 domain and email address?

If you are shaming same SMTP name space but still you wanted separate directory partitions, better you could create tree root domain in same forest and then do intra forest user migration
This will allow you to use same O365 domain as previous one

ADMT can migrate intra forest \ inter forest:
Download ADMT guide from below location
http://www.microsoft.com/en-us/download/details.aspx?id=19188
0

Featured Post

Can’t get the mobile email signature right?

Not having any luck when trying to create an email signature for mobile devices? Does the formatting keep messing up? Make sure you have great email signatures on all devices by using Exclaimer Cloud - Signatures for Office 365.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I don't know if many of you have made the great mistake of using the Cisco Thin Client model with the management software VXC. If you have then you are probably more then familiar with the incredibly clunky interface, the numerous work arounds, and …
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now