Advanced AD DS Infrastructure Management
Advanced AD DS Infrastructure Management
Advanced AD DS Infrastructure Management
Advanced AD DS infrastructure
management
Module Overview
• Child domain:
• Is a child of a parent domain
• Shares the same namespace with the parent domain
• Tree domain:
• Creates a new domain tree and a new namespace
• Are commonly used in merger and acquisition scenarios
Demonstration: Installing a domain controller in a new
domain in an existing forest
Fabrikam.net Adatum.com
Interforest migration
Department IT
CN=April
distinguishedName Reagan,OU=IT,DC=fabrikam,DC=net
givenName April
name April Reagan
Fabrikam.net
S-1-5-21-322346712-1256085132-
objectSID 1900709958-1375
Department IT
CN=April
distinguishedName Reagan,OU=IT,DC=fabrikam,DC=net
givenName April
Adatum.com name April Reagan
S-1-5-21-433467823-2367196243-
objectSID NEW 2011810069-2486
SID-History S-1-5-21-322346712-1256085132-
1900709958-1375
Considerations for implementing complex AD DS
environments
• DNS considerations:
• Centralized versus decentralized
• Verify the DNS client configuration and name resolution
• Optimize DNS name resolution:
• Conditional forwarders and stub zones
• DNS name devolution and DNS suffix search order
• Deploy a GlobalNames zone
• Use Active Directory-integrated zones
• Extending AD DS to Azure
• UPN considerations:
• UPN suffixes
• Global catalog
• Federated authentication scenarios
Lesson 3: Configuring AD DS trusts
P/C P/C
P/C
P/C Contoso
(Windows NT 4.0 domain)
S E
Separate forest
adatum.com fabrikam.com
3
2
Shortcut trust
1 4
CL1 D
EU.adatum.com ESP.fabrikam.com
Client computer CL1 requests access to a file on file server D
How trusts work between forests
Tailspintoys.com Wideworldimporters.com
Logon Information
Virtual machines: 20742B-LON-DC1
20742B-TOR-DC1
20742B-LON-SVR2
20742B-TREY-DC1
User name: Adatum\Administrator
Password: Pa55w.rd
Review Question
• Common Issues and Troubleshooting Tips