Single forest Sec boundary?? advise....!

From: Paul (Paulkrb4_at_hotmail.com)
Date: 10/27/03


Date: Mon, 27 Oct 2003 10:23:17 -0000

Hello,

I have been advising people that should a company require separation in
terms of security that a Forest is the only true boundary. However, Im now
in a situation where a company who requires two of its business to be kept
separate from each other, while maintaining a single global address list and
calendar sharing...

My question is this, In one forest is it possible to secure it in such way
that administrators in one child domain cannot interfere or put at risk
other child domains with in the forest? taking into consideration removal of
enterprise admins from the child domains and in the root domain service
level administrators are trusted across the entire company.

Trusts between forests would not provide a solution in this due to the
security constraints with in the company, Total separation means total
separation. They have tasked me with pointing out what the exact security
risks are, and whether they are manageable through design with in a single
forest.

Any pointers / help on where to look for information or advise would be most
gratefully received.

Many thanks

Paul,



Relevant Pages

  • Re: Active Directory Design
    ... separate forest or a Workgroup envoirenment ... Don't create child domains for this because you can be very sorry, ... domains aren't security boundaries. ... I agree making them stand alone servers in their own workgroup or a separate ...
    (microsoft.public.windows.server.active_directory)
  • Re: Site or Domain
    ... Domain aren't security Boundaries, ... forest, and they are not themselves the ultimate security boundary. ... Each Active Directory domain is authoritative for the ... Domain controller hardware and security facilities Each Windows Server ...
    (microsoft.public.windows.server.active_directory)
  • RE: Active Directory network security
    ... >Subject: RE: Active Directory network security ... >X-Mailer: Microsoft Outlook, Build 10.0.2627 ... In fact the only true security boundary in AD is a forest. ... >Domain Admins must be fully trusted. ...
    (Focus-Microsoft)
  • RE: Active Directory network security
    ... In fact the only true security boundary in AD is a forest. ... Domain Admins must be fully trusted. ... use group policies like crazy. ...
    (Focus-Microsoft)
  • Re: Reasons for Empty (headless root) Root
    ... I am very interested in learning more about how the security is between domain and domain vs forest. ... I quickly and easily compromised a root domain from a child domain for the first time in about May 2000 showing how simple it was and nothing has changed. ... Domains are sort of a replication boundary, the config and schema replicate across all DCs in a forest and also obviously GCs replicate across domain NC boundaries. ...
    (microsoft.public.windows.server.active_directory)