Domain Design for Security Worksheet

profilesapper55
week2_ia_domain_structure_design.docx

RUNNING HEAD: DOMAIN STRUCTURE DESIGN

DOMAIN STRUCTURE DESIGN

Domain Structure Design

Todd Whitlock

POS 421

December 14th, 2014

Robert Singer

Domain Structure Design

Active directory domain structure is the structural representation of an organizational active directory in terms of showcasing how its forest, containers and objects are organized and how they function within the whole concept of the AD DS (active directory domain services).

Great care and attention to detail should be taken when designing a domain structure so as to ensure that the derived design showcases scalability, security, and efficiency, in both user and resource infrastructure utilization. Some of the best practices put in mind during domain design include proper planning, be it for growth, maintenance, risk management, understanding requirements and generally following accepted standards. The benefits reaped from best practices include:

· Simplified management of large windows networks containing numerous objects

· A compact domain structure resulting in reduced cost of administration

· Reduced consumption of network bandwidth

· Low total cost of ownership

· Easy resource sharing

· Easy delegation of resources as needed.

· Optimum performance in searching

A well-designed domain structure will also ensure that there is efficient integration of important features like desktop lockdown, group policies, software distribution and also effective administration of groups, users, servers and workstations.

In the design of this organizational domain structure the above mentioned best practices and considerations were put in place so as to ensure that interrelationship, resource sharing, management and even communication in the organization remains as efficient as possible.

STRUCTURAL DESIGN

For a company such as this one with a centralized IT/IS administration and within the same city, it is preferred to use a single forest that will host all the other domain and or organizational units containing site objects in the active directory domain services(AD DS). Doing so will promote a clear understanding and will enforce what this four core terms (forest, domain, organizational units and site objects) in our design really mean.

A forest is the uppermost functional level in the active directory domain service, this is usually the first domain in the forest and it acts like the topmost container that houses all the other domain containers in the active directory. The name of this domain is usually the name of the forest, e.g. corporate.intl the other entire domain will exhibit this name throughout their domain names, to conclude on forest they generally act as a security boundary for information contained in the AD instance.

Secondly we have the domain that can be defined as a collection of defined objects that are managed as a unit and have a shared common database directory, same security policies and a trust relationship with other domains.

Lastly organizational units can be defined as container objects that facilitate arrangement of other objects like people, computers and devices in the organization in a manner that both facilitate and support administrative purposes.

As stated above our design was to comprise a single forest from which all the other objects were to arise from. We have three domains where each domain has its own domain controller to facilitate authentication, identification, and replication, also manage trust relationship among the three domains in the forest.

The domain controllers recommended for implementation use Kerberos version 5 which was used for authentication purposes in the AD DS. In the organization domain structure, shortcut relationships are used to facilitate interaction since we only needed communication between the different domains within the same forest.

Most or almost all the shortcut relationships used were one-way transitive trust in that two domain would communicate but only in one direction so as to facilitate the domain holding the executives department will be able to communicate to gain access to the other domains without them gaining access to it.

Generally in this design, the domain belonging to the executives has a trust path (a collection of trust relationships that must be followed by authentication request between communicating domains) that were fully two-way transitive up to the forest root. From there the paths became one directional only in that authentication control between the remaining domains was downward and not upward.

Now after establishing appropriate trust relationship among domains organizational units were created in each of the respective organizational departments, the organizational units contained the various grouped objects that were in use by the particular departments.

The organizational units are enforced in a transitive two way trust relationships among the objects so as to ensure that members in the different objects have full access to each other as long as they fall within the same organizational unit in the same domain.

The Figure below displays overall domain structure:

CONCLUSION

At the end of this design the 100 organizational employees, computers and other organizational devices like printers, scanners and servers in the three locations will be well spread across the organizational network infrastructure with each employee having appropriate privileges to be able to perform his/her tasks as outlined and without anyone being able to get access to what he/she is not supposed to access. This quality and effective domain structure design will provide efficiency, scalability, security and capacity for appropriate manageability as required.

References

Liu C. and Albitz P.(2006). DNS and BIND(5th Ed). O'Reilly Media, Sebastopol, CA

Morimoto, R., Noel, M., Droubi, O., Mistry, R., & Amaris, C. (2010). Windows Server 2008 R2 unleashed. Indianapolis, IN: Sams.

Microsoft, Technet Library (2013). Accessing resources across domains. Retrieved from http://technet.microsoft.com/en-us/library/cc787646%28v=ws.10%29.aspx

Microsoft, Technet Library (September 29, 2013). ADMT Guide: Migrating and Restructuring Active Directory Domains. Retrieved from http://technet.microsoft.com/en-us/library/cc974332(v=ws.10).aspx

Microsoft, Technet Library (February 29, 2012). IP Address Management (IPAM) Overview, Retrieved from http://technet.microsoft.com/en-us/library/hh831353.aspx

Mir M. (June 12, 2011). Accessing Resources Across Forest and Achieve Single Sign ON (Part1) [Web blog post]. Retrieved from http://blogs.technet.com/b/mir/archive/2011/06/12/accessing-resources-across-forest-and-achieve-single-sign-on-part1.aspx