170 likes | 329 Views
Active Directory. Metropolitan State College of Denver Division of Information Technology . Redesign. HOW DID WE GET HERE?. Operating systems supported over the last 13 years. Novell Netware Banyan Vines Windows Server 3.11 Windows Server 4.0 Windows Server 2000 (Active Directory)
E N D
Active Directory Metropolitan State College of Denver Division of Information Technology Redesign
Operating systems supported over the last 13 years • Novell Netware • Banyan Vines • Windows Server 3.11 • Windows Server 4.0 • Windows Server 2000 (Active Directory) • Windows Server 2003 (Active Directory)
REASONS WHY THE PROJECT WAS INITIATED? TO ENHANCE AND SECURE ALL OBJECTS WITHIN ACTIVE DIRECTORY FOR EASE OF MANAGEMENT AND SUPPORT
major issues addressed: • Separate Admin1 and Academic Domain • Students should not be accessing services from Admin1 • Create Internal DNS services • Our current DNS services should remain external • New DNS services will be for internal use only. • Organize OU structure • Role based security
Current Windows Infrastructure • We have a single forest with two domains
WHAT ARE THE ISSUES WITH THE CURRENT DESIGN? • Implicit and mandatory 2-way domain trust • Admin1and academic are members of same forest • All users are considered trusted by the forest model • Students and faculty could access resources (printers, file shares, etc) if left with the default security. • Users from either domain can become members of security groups
PROPOSED DESIGN • Building three new forests of single domains • Administrators and staff will be members of administrative domain • Faculty and students will be members of the student domain • Server based services will be contained in the services domain
What’s Left to do? • Test environment = Completed • Build Production environment = Working on • Test • Create Migration Plan • User/Group migration • Printing • File Sharing • Workstation • SIDS • Citrix • Test • Create schedule for departmental move • Implementation
Thank You