* How many Active Directory forests are enough? Last issue I told you about some presentations that I had seen recently that varied widely in the number of Active Directory forests deployed at an enterprise. While the number deployed will certainly vary from organization to organization, still there should be some rules that tend to support either a single forest or dozens.My friend Howard Marks, chief scientist at Networks Are Our Lives recommends that in planning an Active Directory deployment you should first choose one of three models based on your organization’s degree of centralization/de-centralization of control. These are:* Model #1: Strong Central Control – Under this model, all business units share a centralized Directory Services (DS) infrastructure. This is an ideal model for a single forest.* Model #2: Hybrid/Subscription – Here, business units can decide to either opt-in or opt-out of the centralized infrastructure. Multiple forests will be needed: a single centralized one plus a small number of others for the “opting out” organizations. * Model #3: Distributed Infrastructure – In this case, each business unit maintains a separate DS infrastructure. That’s a separate forest for each business unit.While it’s not necessary for Model #3 sites to have one forest for each business unit (or more), the “political” issues – issues of data ownership, server ownership and service ownership lead to the conclusion that there’ll be less acrimony and confrontation should there be many forests with separate administration. Windows 2003 makes the multiple forest scenario somewhat easier to implement and maintain since it supports: cross-forest authentication; cross-forest authorization; Microsoft Group Policy Management Console (MGPMC), for managing all Group Policy-related tasks; and Active Directory/Application Mode (AD/AM) so that individual applications can maintain their own directory structure.So large organizations, with decentralized business units and autonomous offices are prime candidates for multiple forest installations. Remember, though, the setup of the company I mentioned in the last newsletter – whose project started me thinking about forests – large number of users, many offices, very decentralized. Yet, the company’s IT consultant, Sinclair Knight Merz (SKM) chose to go with but a single forest for all of the company’s internal users.SKM may have discovered new methods that will make its design work well. Or else, being new to Windows networking, the company may be unaware of the research that shows that early adopters of Active Directory tended to choose fewer forests than was ideal, and their networks suffered for it.We’ll follow up with SKM later in its project to see how it’s going, but I’d wager it’ll be adding some forests before it’s through. Related content news Dell provides $150M to develop an AI compute cluster for Imbue Helping the startup build an independent system to create foundation models may help solidify Dell’s spot alongside cloud computing giants in the race to power AI. By Elizabeth Montalbano Nov 29, 2023 4 mins Generative AI Machine Learning Artificial Intelligence news DRAM prices slide as the semiconductor industry starts to decline TSMC is reported to be cutting production runs on its mature process nodes as a glut of older chips in the market is putting downward pricing pressure on DDR4. By Sam Reynolds Nov 29, 2023 3 mins Flash Storage Technology Industry news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Cloud Computing opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe