ZDNet UK


Skip to Main Content

  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Office applications Toolkit

Moving clients to an Active Directory environment: The benefits

Brien M Posey

Published: 17 Jul 2003 13:27 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Now that Microsoft has had the official launch ceremony for Windows Server 2003, Windows NT's days are numbered. Since Microsoft will soon be discontinuing support for Windows NT, now is a good time to suggest to clients that they take a look at Windows 2000 or 2003 Server.

The biggest difference between these two server operating systems and Windows NT is the addition of Active Directory. Although there is a bit of a learning curve associated with implementing an Active Directory environment, the benefits of doing so far outweigh the negatives.

A better representation of the network
Centralisation sums up my primary reason for implementing Active Directory. The Active Directory structure makes it possible for you to achieve truly centralised management of users, regardless of how big your client's network has become. If you've worked with Windows NT before, you know that in Windows NT a domain is a completely independent entity. While it's possible to create a trust relationship between domains that exist on a common network, the domains are never truly integrated with each other because there is no higher authority that manages the domains.

Seeing through the forest
The situation is different with Active Directory. Whereas the domain level was the highest level of abstraction in Windows NT, the highest level of abstraction in Windows 2000 and 2003 Server is the forest, which is basically a collection of domains. Microsoft chose to call this unit a forest because you can place domains into the forest, and you can place entire trees of domains into it. A domain tree consists of a parent, child, grandchildren, and great grandchildren domains. You can have as many layers of subdomains within a domain tree as is necessary to achieve the desired organisational structure.

The Active Directory domain structure is handy to have whether your client's network is big or small. As you may recall, in Windows NT, each domain had its own Administrator account and its own Domain Admin group that was responsible for managing that domain. In Windows 2000 and 2003 Server, the domain Administrator account and the Domain Admin group still exist and can be used the same way that you were used to using them in Windows NT. There is also an Enterprise Admin group. Members of this group can manage any object within the entire Active Directory, regardless of what domain it exists within.

Managing trust relationships
The first time that someone tried explaining the concept of parent and child domains, forests, and trees to me, my head was spinning. All I could think about was that managing trust relationships for an organisation that made use of all of these structures must be a real chore. However, managing trust relationships in Windows 2000 and 2003 Server is much easier than in Windows NT because there are essentially no trusts to manage. Within a forest, every domain trusts every other domain automatically. The only time you'd really have to worry about managing trust relationships would be if you had a relationship between domains residing within different forests. The only time that you would likely have to set up an interforest relationship would be if you needed to set up a trust relationship with a domain in another company's network.

These enhanced management capabilities make Windows 2000 and 2003 Server more scalable than Windows NT. This is especially true for larger organisations. Windows NT has a limit of about 40,000 objects within a domain. Windows 2000 Server expands this limit to over 10 million objects. I have not yet seen the object limit figures for Windows 2003 Server, but I'm sure that it's possible to have over 10 million objects.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
82 out of 188 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Featured Talkback

In association with Intel
Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Discussions

lumension lumension

What do I need to consider in managing...

Wednesday 19 November 2008, 8:11 AM

1 comment
lumension lumension

Great to have the patches but which of...

Wednesday 19 November 2008, 7:57 AM

1 comment
lumension lumension

Eliminate Malware by Controlling Appli...

Wednesday 19 November 2008, 7:45 AM

1 comment
jingletruck jingletruck

Dont be Evil

Tuesday 18 November 2008, 10:00 PM

1 comment

Vista Upgrade Blog

Wireless Networking - Linksys WRT350N...

Ok, this is driving me crazy. Why does this not work? I have a Linksys WRT350N Wireless-N router, and a laptop with an Intel 4965AGN Wireless Network Interface. When I am running... More

5 comments

Software Jihad part 2

I guess the point of my previous post (read rant if you want) was that Microsoft makes a lot of noise of "protecting" their IP but in reality they are only paying lip-service to it... More

3 comments

Software Jihad

I've been reading an article/blog over at CNN talking about the Chinese lawyer that has filed suit on Microsoft for putting black desktop backgrounds every hour on pirated copies of... More

2 comments