Multi-tenant AD security concerns
been while since have had architect type of scenario i'm looking more recent guidance...
hosted datacenter environment many clients. management wants complete redesign of domain/forest structure take care of last 5 years of mergers , acquisitions, , customer domains should included. regulated industry isolation of data critical. years mantra "the domain security boundary", has been 1 domain per client (and still current thinking). (architecture team) being told "make 1 large customer domain part of our corp forest" client workstations in untrusted domain using quest (or similar tool) provide sync services.
exchange hosted office365 exchange farm not issue. servers such file/db/app client-specific, not shared. why want create single domain housing of servers?
i looking documentation discusses this. i've read several articles discuss dc placement (mostly irrelevant us) , security permission lockdowns isolate clients per ou. frankly, latter seems recipe disaster. 1 missed acl , you're hosed...
i welcome discussion , ideas. thanks!
charlie
hi,
thanks post.
in opinion, multi-tenancy means customers share infrastructures, applications or databases in order gain price , performance advantages.
below thread discussed same question:
multi tenant
securing active directory multi-tenant environments
please note: since web site not hosted microsoft, link may change without notice. microsoft not guarantee accuracy of information.
best regards,
alvin wang
please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Security
Comments
Post a Comment