Moving clients to an Active Directory environment: The benefits

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Organisational units improve scalability
Another way that Active Directory improves scalability in large organisations is through the use of organisational units (OUs). An OU is basically a collection of users and computers. The idea is that if you have a large domain, you can organise the domain into OUs. For example, suppose that your client's company used one large domain that spanned the entire corporation. Normally, this would mean that the administrative team would be responsible for managing the entire domain and all of the objects within it. Now imagine that your client's company has a really large finance department and that the finance department's secretary is good with computers. You could create an OU named FINANCE and move all of the user accounts and computer objects for the finance department into this OU. After doing so, you could delegate the authority to reset passwords for this OU to the finance secretary. When someone in finance needed a password reset, they wouldn't have to contact the help desk; they could just ask the secretary. This would give the department faster turnaround on password resets and free the help desk from some of the administrative burden. When you delegate authority to an OU, the person that you're delegating control to only has the permissions that you allow and only for that OU. Therefore, the secretary in finance wouldn't be able to reset passwords for the rest of the company. The secretary also would not be able to perform any other administrative tasks within the OU, unless, of course, you delegated additional permissions. If you like the idea of delegating authority, you'll be happy to know that you can also delegate authority to create, delete, or manage user accounts or groups within the OU. Multimaster replication and sites
Another cool benefit of an Active Directory environment is the concept of sites and multimaster replication. In Windows NT, when you make a change to the SAM, the change is applied directly to the PDC and is later replicated to each BDC. In an Active Directory multimaster replication environment, each domain controller contains a copy of Active Directory, not just the information for a single domain. Therefore, when a change is made to Active Directory, the change is applied to whatever domain controller is the closest, and is then replicated to the remaining domain controllers. This prevents a designated PDC from being overburdened. You can really see the benefits of multimaster replication when you consider how sites work. Sites are a logical Active Directory structure completely independent from domains. The idea is that if part of a domain is connected by a slow link, you may designate each side of the link as a separate site. Each site has its own domain controller. Therefore, when someone within a site needs to make an Active Directory update, the updates are applied to the domain controller within the site. The changes are collected and then replicated to the domain controller on the other side of the site link at preset intervals. This domain controller is known as a bridgehead server. It's the bridgehead server's job to intercept the updates and replicate them to the remaining domain controllers. Sites can be a little complicated to understand, but the basic idea is that they greatly decrease the amount of traffic that must flow across your slow or high-cost network links.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

26 minutes ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

56 minutes ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

3 hours ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

4 hours ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

4 hours ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

21 hours ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

21 hours ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

23 hours ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

23 hours ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

24 hours ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

1 day ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

1 day ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

1 day ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

1 day ago by Mispam on Windows 8 start-up speed forces USB boot workaround
apexwm

I've also seen that Mac OS X for Intel machines is supposed to run in VirtualBox, which would also be a nice solution. I've never tried it though.

1 day ago by apexwm on xTreme Triple Booting: Linux, Mac & Windows
dave heasman

What I wonder is why when companies are caught bang to rights in not providing contracted services, people bend over to smear the customers? Surely...

1 day ago by dave heasman on Virgin throttles broadband for high-speed customers
pjc158

Strange statement from HP regarding Mike Lynch and not capable of scaling a company. Autonomy was a $7bn purchase which started as a small company...

1 day ago by pjc158 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
lojolondon

Or - possibly, they will destroy business by ensuring people do not invest where there is no return. Another socialist idea, well beyond it's...

1 day ago by lojolondon on Open Data Institute will act as biz incubator
J.A. Watson

Good stuff Jake, very interesting. Thanks. jw

1 day ago by J.A. Watson on xTreme Triple Booting: Linux, Mac & Windows
openhgs

"the cost of a second LCD screen is about the same as one day of an office worker's time, so this should soon be recouped in extra productivity."...

1 day ago by openhgs on Windows 8 could speed multi-monitor uptake