Peer-Root Domain Model Win2k3

  • Thread starter Thread starter Stubby
  • Start date Start date
In the brief scan of that page I saw quite a few incorrect assumptions. I would
be wary of the document.

I have never heard the term peer-root before this post. It simply looks to be a
multi-tree forest with one tree that is entirely the forest root domain.

This method to isolate the schema group or any method to isolate the schema
group is pretty silly.

The forest is security boundary, not the domain, not the tree.

The goal should be to try and stick to a single domain if possible, if not, try
to use a minimal number of domains. If you need true security boundaries, this
means multiple forests. Multiple forest deployments are actually gaining
popularity especially in larger orgs with Exchange and different admins running
Exchange and AD so you can have separation of responsibilities, etc.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top