Microsoft details Longhorn ID

Opinion
Mar 29, 20043 mins

* Longhorn ID to sport a Branch Office Domain Controller

I spent a very enjoyable, and enlightening, four days at NetPro’s Directory Experts Conference last week. No, there were no repeats of Trish Gulbransen’s pool exploits (although I’ve yet to uncover who was the big winner in the all-night poker party after the welcome reception). But the usually reliable sources came through once again.

Particularly impressive (to me) was Stuart Kwan, Microsoft product unit manager for Directory Services (Active Directory, Identity Integration Server, etc.) who spent a fair amount of his opening keynote talking about the Longhorn Identity System (called, right now, Longhorn ID). It’s due to arrive with the next version of the Windows Server (which could be the Longhorn release that’s expected in approximately four years, or with an interim version – what some call “shorthorn” – in a couple of years). Bravely, Kwan set out what new things would be included in Longhorn ID, other things that might be included and (here’s the brave part) things that most likely wouldn’t make the cut.

Leading the list of includes is the new Branch Office Domain Controller. According to Kwan, users found installing Domain Controllers (DC) at a branch office to be fraught with problems.

Since security is probably more lax at the branch, a compromised DC could have a major impact on the rest of the forest. Deployment, maintenance and recovery of a DC might require an on-site administrator, which isn’t very likely in these downsizing times. The specter of easier security breaches with no competent on-site staff to deal with them is a major headache to IT.

The solution is a new type of DC, the Branch Office DC, which can limit impact of a compromised DC to just that branch because: its Kerberos tickets are recognized only within that branch; and it’s a read-only DC – there’s no replication back to the hub.

The Branch Office DC will also involve simplified deployment, monitoring and recovery: the deployment effort will be comparable to a domain join rather than to a DCPROMO. It will also offer a “one-button reset” state should any problems occur, which can be handled by typical branch office staff under the direction of IT personnel (by e-mail, phone, poster tacked up in server room, etc.).

The second new feature is more of a service – Microsoft is committing to removing, as much as possible, the need to reboot a DC because of minor (or even some major) changes. Few things bog down the network more than rebooting the servers. Instead, Longhorn ID will allow the equivalent of a “net stop Active Directory” to recycle just the directory service when needed: e.g., to patch DC binary, for offline defrag, to do offline semantic analysis, if you need a database restore, or should you require a domain rename.

Longhorn ID will also include better manageability (more details later) and native support for federated identity (using the WS-Federation standard).

These are all really nice improvements, but I hate waiting another four years before they can be delivered. It sure would be nice if Active Directory releases weren’t so tightly coupled to operating system releases.

Next week we’ll look at what won’t be in Longhorn ID.