Domain Trust between Production and Development


we have 2 domains:

1) ourcompany.com (windows server 2003 active directory. used in-house email, development, etc.)

2) ourcompany-production.com (windows server 2003 active directory. contains database , web servers exposed our clients , customers)

there lot of management tasks because there no trusts established between domains , creates lot of work our staff. purposed idea of creating trust between company domain , production domain. however, colleagues said idea had been brought before discouraged because security risk.

i don't feel great security risk. theory if attacked in house or in production it's still attack , should have been prevented. while colleagues argued seperation of trust helps mitigate severity (or spread) of attack.

i love expert oppinions on matter? should we? shoudn't we? etc. etc.

also, looking move server 2008 well. having trust established prior migration create lot of work upgrades, or not really?

thank input. cheers!

hi,

 

thank post here.

 

your domain structure (separate forest/domain difference purpose) typical adds domain structure when want isolate user accounts/resources (security) between internal domain (production) , external partners. think answer question whether trust or not should come exact environment , business policies.

 

1. kind of trust create? bidirectional trust horrible because enables cross forest resource accessing. if partner (external members) has user account in ourcompany-production.com, able authenticate production domain , access resources not configured (anonymous, group or guest account).

 

2. infrastructure of infrastructure, internal directory service should not take risk may expose date/objects external. may check mof (microsoft operations framework) recommended security guideline while processing on infrastructure modification.

 

microsoft has alternative solutions such adfs (active directory federation services) , fim (forefront identity manager) cross realm authentication. may search microsoft site more information them. if have more questions, glad here.

 

 

 

 



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file