Your team has recently been hired to bring the Acme Inc. (herein referred to as
ID: 3855611 • Letter: Y
Question
Your team has recently been hired to bring the Acme Inc. (herein referred to as “The Client”) offices into the current era of computing technology. They currently have no central management or authentication. All files are stored locally on each workstation. Recently, their intern was the victim of laptop theft, who against company policy had copies of confidential information for many of their top customers. The required breach notifications have been sent, but the client wishes to avoid such incidents in the future.
The client currently has two offices; one located in Columbus, Ohio, and the other in Dallas, Texas. The Columbus office has a total of 1029 employees between two buildings on the same campus, connected by underground fiber-optic cabling. The inter-building connectivity operates at 10Gbit speeds. Their main datacenter is also located in Columbus, and is connected to the Internet by two redundant OC-3s.
Dallas is a regional sales hub with far fewer employees (127 at last count). Regional employees visit the office, but are more often traveling and using their workstations remotely. The sales office is connected to the internet by a 15Mbit downstream, 1Mbit upstream asynchronous DSL link. The servers, desktop computers and phone system all share this bandwidth.
The employees operating out of the Dallas office do not typically spend the day in the office. Many employees may not visit the office for days, or even weeks at a time. Corporate policy requires that everyone visit an office in person at least once every 30 days.
You may ask for additional parameters regarding the business to help guide your efforts. You may be given additional information, or given the freedom to make assumptions regarding the nature of the question. Assumptions must be realistic (for example, one should not presume that the client doesn’t care about usability or that funds are unlimited). You must document these additional parameters in your paper
Assignment
Determine the best architecture for the Active Directory infrastructure for the client, keeping the following in Security, convenience and limited bandwidth in mind.
Explanation / Answer
The following points will explain the construct effective Active Directory
1: Keep it simple
Keep the AD as simple as you can.
Active Directory is designed to be flexible, and if offers a lot of many types of objects and components.
If you maintain the AD as a simple network it will improve the efficiency and troubleshooting.
2: Use the appropriate site topology
You may be preferred to use the complex structures whenever necessary.
Bigger networks will almost for all time require multiple Active Directory sites.
The site topology should represent your network topology.
3: Use dedicated domain controllers
For example, take an organization might have a domain controller that also acts as a both file server or as a mail server. Adding additional roles to a domain controller can affect the server's performance, reduce security, and complicate the process of backing up or restoring the server.
4: Have at least two DNS servers
As we know that AD completely depends on the DNS Servers. SO it is better to maintain the two DNS servers. SO it will increase the performance.
5: Avoid putting all your eggs in one basket (virtualization)
However, this redundancy is often circumvented by server virtualization. I often see organizations place all their virtualized domain controllers onto a single virtualization host server. So if that host server fails, all the domain controllers will go down with it. So it is preferred to use virtualization.
6: Don't neglect the FSMO roles (backups)
In the present scenario backup is the more useful. As we know that some IT pros say that you don't have to back up every domain controller on the network because of the way Active Directory information is replicated between domain controllers. So sometime we will face problems. Take the backup of FSMO roles.
7: Plan your domain structure and stick to it
Now a day people are using many computers so we can’t able to predict exactly how Active Directory will grow, but you can at least put some governance in place to dictate the structure that will be used when it does.
8: Have a management plan in place before you start setting up servers
Management of the AD takes place vital role so you are required a good staff to maintain the AD.
9: Place at least one global catalog server in each site
You are preferred to use particular catalog server for each site.
Otherwise, Active Directory clients will have to traverse WAN links to look up information from a global catalog.
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.