domain change in a school

M

Mathieu

Hi,

From you, specialist in domain structure, I ask some advise about domain
structure and AD in a school.
When I installed the first servers in the school, in NT4, I installed 2
domains.
The first domain for the pupils and theaching purposes, named DOM-L. For
safety reasons, I installed a second domain named DOM-A for administration
purposes. Teachers and pupils could not access DOM-A. There where two
domaincontrollers for the domains. One for each domain.
A third NT4-server is installed as a proxy-server, used by the two domains
to access internet (ADSL-fixed IP).

Two years ago I upgraded the teachers and pupils domain, called DOM-L to
Windows2000 server. All the clients now are minimum Windows2000. I installed
AD whit OU for each group of pupils. I installed policys, first to heavy,
later more flexible with more possibility's so they could change
desktopsettings etc.

Now, I want to upgrade the second NT4 domain, DOM-A to Windows2000 or
Windows2003. So the administration wil be upgradet.

I first wanted to keep the structure with 2 domains. But reading about
W2k3server, I maybe can add the users to the AD as an OU in the first Win2K
domain and secure the maps from the domain with usergroups. Also AD
restricts users to theiu own maps.
The administration members get the rights on Administration maps
(schooladministration, not server administrator).

Is it safe to work with one domain.
I also want to remove the proxy-server while the ADSL is fast enough to serv
the internet pages.

Then I have one free server, wich can hold the replication for AD, and the
second free server can hold a firewall.

Please, your advise

Thanks,

Mathieu
 
R

Robert Moir

Mathieu said:
Hi,

From you, specialist in domain structure, I ask some advise about
domain structure and AD in a school.
When I installed the first servers in the school, in NT4, I installed
2 domains.
The first domain for the pupils and theaching purposes, named DOM-L.
For safety reasons, I installed a second domain named DOM-A for
administration purposes. Teachers and pupils could not access DOM-A.
There where two domaincontrollers for the domains. One for each
domain. A third NT4-server is installed as a proxy-server, used by
the two domains to access internet (ADSL-fixed IP).

Two years ago I upgraded the teachers and pupils domain, called DOM-L
to Windows2000 server. All the clients now are minimum Windows2000. I
installed AD whit OU for each group of pupils. I installed policys,
first to heavy, later more flexible with more possibility's so they
could change desktopsettings etc.

Now, I want to upgrade the second NT4 domain, DOM-A to Windows2000 or
Windows2003. So the administration wil be upgradet.

I first wanted to keep the structure with 2 domains. But reading about
W2k3server, I maybe can add the users to the AD as an OU in the first
Win2K domain and secure the maps from the domain with usergroups.
Also AD restricts users to theiu own maps.
The administration members get the rights on Administration maps
(schooladministration, not server administrator).

Is it safe to work with one domain.
I also want to remove the proxy-server while the ADSL is fast enough
to serv the internet pages.

Then I have one free server, wich can hold the replication for AD,
and the second free server can hold a firewall.

I've migrated a college network from a NT4 domain model with 5 domains (ugh)
to a Windows 2000 AD model with one domain for all users and another for
various servers that required different security settings and from a
security point of view its working just fine...

http://www.robertmoir.co.uk/win/Upgradingaschoolorcollege-3.html
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top