{"id":623,"date":"2006-08-10T09:17:00","date_gmt":"2006-08-10T09:17:00","guid":{"rendered":"http:\/\/markwilson.me.uk\/blog\/2006\/08\/delegation-of-active-directory.htm"},"modified":"2007-05-15T09:17:15","modified_gmt":"2007-05-15T08:17:15","slug":"delegation-of-active-directory","status":"publish","type":"post","link":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm","title":{"rendered":"Delegation of Active Directory administration (using Quest ActiveRoles Server)"},"content":{"rendered":"<p><!--115520182056217333-->Recently, I&#8217;ve been working with a client who has an extraordinarily high number of users with domain administrator rights (i.e. those who are members of the Domain Admins group). The problem is historic and they are in the process of moving from Windows NT to Active Directory (AD); whilst AD allows for delegation of control over objects (although best practice dictates that delegation occurs at organisational unit level), under NT the limit for delegation was the domain.<\/p>\n<p>In order to reduce the number of Domain Admins, I&#8217;ve been producing a <a href=\"http:\/\/searchwindowssecurity.techtarget.com\/tip\/1,289483,sid45_gci1134853,00.html?bucket=ETA\">delegation model for AD administration<\/a> that is intended to provide a pragmatic balance between the granular control that AD can provide and the access requirements of each support team, yet still remains realistic from a management perspective. One major issue is that, whilst Microsoft provides several-hundred pages of documentation and a delegation of control wizard, there are no native tools to keep track of the objects over which control has been delegated. Consequently it&#8217;s often necessary to resort to third party tools.<\/p>\n<p>One such tool is <a href=\"http:\/\/www.quest.com\/activeroles_server\/\">ActiveRoles Server<\/a> (ARS) from <a href=\"http:\/\/www.quest.com\/\">Quest Software<\/a>. Quest inherited this technology with their <a href=\"http:\/\/www.quest.com\/news\/show.aspx?ContentId=535\">acquisition of Aelita Software<\/a> (they had previously inherited another product, now known as <a href=\"http:\/\/www.quest.com\/activeroles_direct\/\">ActiveRoles Direct<\/a>, when they <a href=\"http:\/\/www.quest.com\/news\/show.aspx?ContentId=432\">purchased FastLane Technologies<\/a>). Installed onto a Windows server (which should be secured as any domain controller would be), the current incarnation of the product, uses a SQL Server database for configuration data (rather than schema extensions as some previous products did) and publishes itself as a <a href=\"http:\/\/technet2.microsoft.com\/WindowsServer\/en\/Library\/10eafb54-ddde-4741-a71d-162451d2868f1033.mspx\">connection point object<\/a> within AD. The configuration database can be mirrored via SQL replication for redundancy, with one server acting as a publisher and one as a subscriber whilst the connection point model allows for load balancing between the two servers.<\/p>\n<p>In terms of management, ARS can be administered using a Microsoft management console (MMC) snap-in, a browser interface, or using AD services interface (ADSI). By default, ARS will bind to the first AD domain controller that it finds, although this can be overridden in the management toolset.<\/p>\n<p>Despite not extending the AD schema, ARS allows additional attributes to be stored for an object. These attributes are placed within the ARS configuration database and can be used for provisioning (e.g. conditional filtering on attributes) or for storing additional information on a user (e.g. staff ID number). Propagation of directory data to other LDAP directories and <a href=\"https:\/\/www.markwilson.co.uk\/blog\/2005\/04\/managing-identity-with-microsoft.htm\">Microsoft Identity Integration Server<\/a> (MIIS) are supported via <a href=\"http:\/\/www.quest.com\/activeroles_server\/quickconnect.aspx\">Quick Connect for ActiveRoles Server<\/a> and Unix support can be provided using through a support pack for <a href=\"http:\/\/www.quest.com\/vintela_authentication_services\/\">Vintela Authentication Services<\/a>. ARS can also expose attributes that are not normally visible in the standard Active Directory Users and Computers MMC snap-in.<\/p>\n<p>In order to allow for user rights to be elevated as required, user access is proxied via the ARS service account, which should be given the highest level of permissions that will be allowed (e.g. Domain Admins). This means that all access is via ARS, allowing for auditing and reporting of rights use. Quest&#8217;s recommendation is that users are not assigned native rights within Active Directory (beyond the standard read-only permissions given to an authenticated user). In this way, all rights can be managed via ARS (otherwise privileged users could circumvent ARS, avoiding any auditing of their actions); however there is also an option for ARS-delegated rights to be propagated to Active Directory if required.<\/p>\n<p>Some ARS terminology includes:<\/p>\n<ul>\n<li>Access templates: pre-defined role descriptions controlling what a user can\/cannot do. ARS allows further granularity than native AD rights &#8211; for example controlling which attributes a particular user can edit on an object (e.g. allowing for self service of certain directory attributes via a web interface).<\/li>\n<li>Managed units: query-based filters for management of roles (effectively a virtual OU). This avoids issues whereby best practice recommends delegation at OU level but the OU structure is generally designed with group policy in mind.<\/li>\n<li>Policy objects: rules applied to objects as they are created (e.g. when creating a user in a particular OU, add them to certain security groups).<\/li>\n<li>Script modules: bespoke code that allows policy objects to be extended beyond the standard capabilities of AD OUs and group policy (e.g. when creating a user account, e-mail the telephone system administrator and ask them to populate the user&#8217;s telephone number in AD).<\/li>\n<\/ul>\n<p>ARS seems pretty powerful but it does have some limitations:<\/p>\n<ul>\n<li>Firstly, it operates at the domain level, so delegation of forest-level tasks does not seem to be supported.<\/li>\n<li>Secondly ARS is used to provide delegation of control over directory objects &#8211; not the resources protected by the directory itself (e.g. file systems). This means that ARS can be used to control the administration of the groups that allow access to a particular resource; but there is nothing that it can do to prevent a sufficiently-privileged user from bypassing ARS and accessing a resource directly.<\/li>\n<\/ul>\n<p>In reality, this has meant that my client has built part of the delegation model for AD using the Quest tools (the translation of the IT policy and procedures to a provisioning model built around ARS) whilst I have based the administration model for the servers and computers within the domain (as well as forest-wide operations) around Windows groups, with procedural control over the use of privileged and non-privileged accounts.<\/p>\n<p>Although I&#8217;ve been working with Active Directory since Windows NT 5.0 beta 2 (about 8 years now), this is the first time I&#8217;ve really looked at the administration model. It&#8217;s been a difficult process for me &#8211; to do it properly requires business analysis skills as well as (and probably more than) technical knowledge. The following links might be useful to anyone else who is looking at delegating AD administrative control:<\/p>\n<ul>\n<li>Microsoft <a href=\"http:\/\/www.microsoft.com\/technet\/prodtechnol\/windowsserver2003\/technologies\/directory\/activedirectory\/actdid1.mspx\">best practices for delegating Active Directory administration<\/a> (<a href=\"http:\/\/www.microsoft.com\/downloads\/details.aspx?FamilyID=631747a3-79e1-48fa-9730-dae7c0a1d6d3&amp;DisplayLang=en\">white paper<\/a> and the <a href=\"http:\/\/www.microsoft.com\/downloads\/details.aspx?FamilyID=29dbae88-a216-45f9-9739-cb1fb22a0642&amp;DisplayLang=en\">appendices<\/a>).<\/li>\n<li><a href=\"http:\/\/www.microsoft.com\/technet\/security\/topics\/networksecurity\/sec_ad_admin_groups.mspx\">Securing Active Directory administrative groups and accounts<\/a> and <a href=\"http:\/\/www.windowsecurity.com\/articles\/protecting-administrator-account.html\">protecting the Administrator account<\/a>.<\/li>\n<li>Well known security identifiers in Windows operating systems (<a href=\"http:\/\/support.microsoft.com\/?kbid=243330\">Microsoft knowledge base article 243330<\/a>).<\/li>\n<li><a href=\"http:\/\/technet2.microsoft.com\/WindowsServer\/en\/Library\/1631acad-ef34-4f77-9c2e-94a62f8846cf1033.mspx?mfr=true\">Default groups<\/a> in Windows operating systems.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Recently, I&#8217;ve been working with a client who has an extraordinarily high number of users with domain administrator rights (i.e. those who are members of the Domain Admins group). The problem is historic and they are in the process of moving from Windows NT to Active Directory (AD); whilst AD allows for delegation of control &hellip; <a href=\"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Delegation of Active Directory administration (using Quest ActiveRoles Server)<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[],"tags":[102,39],"class_list":["post-623","post","type-post","status-publish","format-standard","hentry","tag-active-directory","tag-useful-software"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Delegation of Active Directory administration (using Quest ActiveRoles Server) - markwilson.it<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Delegation of Active Directory administration (using Quest ActiveRoles Server) - markwilson.it\" \/>\n<meta property=\"og:description\" content=\"Recently, I&#8217;ve been working with a client who has an extraordinarily high number of users with domain administrator rights (i.e. those who are members of the Domain Admins group). The problem is historic and they are in the process of moving from Windows NT to Active Directory (AD); whilst AD allows for delegation of control &hellip; Continue reading Delegation of Active Directory administration (using Quest ActiveRoles Server)\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm\" \/>\n<meta property=\"og:site_name\" content=\"markwilson.it\" \/>\n<meta property=\"article:published_time\" content=\"2006-08-10T09:17:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2007-05-15T08:17:15+00:00\" \/>\n<meta name=\"author\" content=\"Mark Wilson\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@markwilsonit\" \/>\n<meta name=\"twitter:site\" content=\"@markwilsonit\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mark Wilson\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm\"},\"author\":{\"name\":\"Mark Wilson\",\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/#\\\/schema\\\/person\\\/98f61365e7c39d6be942174b8c4de468\"},\"headline\":\"Delegation of Active Directory administration (using Quest ActiveRoles Server)\",\"datePublished\":\"2006-08-10T09:17:00+00:00\",\"dateModified\":\"2007-05-15T08:17:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm\"},\"wordCount\":1013,\"commentCount\":9,\"publisher\":{\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/#\\\/schema\\\/person\\\/98f61365e7c39d6be942174b8c4de468\"},\"keywords\":[\"Microsoft Active Directory\",\"Useful Software\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm\",\"url\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm\",\"name\":\"Delegation of Active Directory administration (using Quest ActiveRoles Server) - markwilson.it\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/#website\"},\"datePublished\":\"2006-08-10T09:17:00+00:00\",\"dateModified\":\"2007-05-15T08:17:15+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/2006\\\/08\\\/delegation-of-active-directory.htm#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Delegation of Active Directory administration (using Quest ActiveRoles Server)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/\",\"name\":\"markwilson.it\",\"description\":\"get-info -class technology | write-output &gt; \\\/dev\\\/web\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/#\\\/schema\\\/person\\\/98f61365e7c39d6be942174b8c4de468\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/#\\\/schema\\\/person\\\/98f61365e7c39d6be942174b8c4de468\",\"name\":\"Mark Wilson\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/i0.wp.com\\\/www.markwilson.co.uk\\\/blog\\\/uploads\\\/image-4.png?fit=800%2C800&ssl=1\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.markwilson.co.uk\\\/blog\\\/uploads\\\/image-4.png?fit=800%2C800&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.markwilson.co.uk\\\/blog\\\/uploads\\\/image-4.png?fit=800%2C800&ssl=1\",\"width\":800,\"height\":800,\"caption\":\"Mark Wilson\"},\"logo\":{\"@id\":\"https:\\\/\\\/i0.wp.com\\\/www.markwilson.co.uk\\\/blog\\\/uploads\\\/image-4.png?fit=800%2C800&ssl=1\"},\"description\":\"A Chartered IT Professional, with recent experience in technology leadership, IT strategy and practice management roles, Mark Wilson is an Enterprise Architect in the Advisory and Management Group at risual. During a career spanning more than two decades, Mark has gained widespread recognition as an expert in his field including both industry and national press exposure. In addition to certifications from Microsoft, VMware, Red Hat, The Open Group and Axelos, Mark held a Microsoft Most Valuable Professional (MVP) award for three years and is now part of the MVP Reconnect programme. Mark is also well-known on social media and maintains an award-winning blog.\",\"sameAs\":[\"http:\\\/\\\/www.markwilson.co.uk\\\/\",\"https:\\\/\\\/www.instagram.com\\\/markwilsonuk\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/markawilson\\\/\",\"https:\\\/\\\/x.com\\\/markwilsonit\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCWHlZCoHRTocdvtrOJ2IL4A\"],\"url\":\"https:\\\/\\\/www.markwilson.co.uk\\\/blog\\\/author\\\/mark-wilson\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Delegation of Active Directory administration (using Quest ActiveRoles Server) - markwilson.it","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm","og_locale":"en_GB","og_type":"article","og_title":"Delegation of Active Directory administration (using Quest ActiveRoles Server) - markwilson.it","og_description":"Recently, I&#8217;ve been working with a client who has an extraordinarily high number of users with domain administrator rights (i.e. those who are members of the Domain Admins group). The problem is historic and they are in the process of moving from Windows NT to Active Directory (AD); whilst AD allows for delegation of control &hellip; Continue reading Delegation of Active Directory administration (using Quest ActiveRoles Server)","og_url":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm","og_site_name":"markwilson.it","article_published_time":"2006-08-10T09:17:00+00:00","article_modified_time":"2007-05-15T08:17:15+00:00","author":"Mark Wilson","twitter_card":"summary_large_image","twitter_creator":"@markwilsonit","twitter_site":"@markwilsonit","twitter_misc":{"Written by":"Mark Wilson","Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm#article","isPartOf":{"@id":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm"},"author":{"name":"Mark Wilson","@id":"https:\/\/www.markwilson.co.uk\/blog\/#\/schema\/person\/98f61365e7c39d6be942174b8c4de468"},"headline":"Delegation of Active Directory administration (using Quest ActiveRoles Server)","datePublished":"2006-08-10T09:17:00+00:00","dateModified":"2007-05-15T08:17:15+00:00","mainEntityOfPage":{"@id":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm"},"wordCount":1013,"commentCount":9,"publisher":{"@id":"https:\/\/www.markwilson.co.uk\/blog\/#\/schema\/person\/98f61365e7c39d6be942174b8c4de468"},"keywords":["Microsoft Active Directory","Useful Software"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm","url":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm","name":"Delegation of Active Directory administration (using Quest ActiveRoles Server) - markwilson.it","isPartOf":{"@id":"https:\/\/www.markwilson.co.uk\/blog\/#website"},"datePublished":"2006-08-10T09:17:00+00:00","dateModified":"2007-05-15T08:17:15+00:00","breadcrumb":{"@id":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.markwilson.co.uk\/blog\/2006\/08\/delegation-of-active-directory.htm#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.markwilson.co.uk\/blog"},{"@type":"ListItem","position":2,"name":"Delegation of Active Directory administration (using Quest ActiveRoles Server)"}]},{"@type":"WebSite","@id":"https:\/\/www.markwilson.co.uk\/blog\/#website","url":"https:\/\/www.markwilson.co.uk\/blog\/","name":"markwilson.it","description":"get-info -class technology | write-output &gt; \/dev\/web","publisher":{"@id":"https:\/\/www.markwilson.co.uk\/blog\/#\/schema\/person\/98f61365e7c39d6be942174b8c4de468"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.markwilson.co.uk\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":["Person","Organization"],"@id":"https:\/\/www.markwilson.co.uk\/blog\/#\/schema\/person\/98f61365e7c39d6be942174b8c4de468","name":"Mark Wilson","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/i0.wp.com\/www.markwilson.co.uk\/blog\/uploads\/image-4.png?fit=800%2C800&ssl=1","url":"https:\/\/i0.wp.com\/www.markwilson.co.uk\/blog\/uploads\/image-4.png?fit=800%2C800&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.markwilson.co.uk\/blog\/uploads\/image-4.png?fit=800%2C800&ssl=1","width":800,"height":800,"caption":"Mark Wilson"},"logo":{"@id":"https:\/\/i0.wp.com\/www.markwilson.co.uk\/blog\/uploads\/image-4.png?fit=800%2C800&ssl=1"},"description":"A Chartered IT Professional, with recent experience in technology leadership, IT strategy and practice management roles, Mark Wilson is an Enterprise Architect in the Advisory and Management Group at risual. During a career spanning more than two decades, Mark has gained widespread recognition as an expert in his field including both industry and national press exposure. In addition to certifications from Microsoft, VMware, Red Hat, The Open Group and Axelos, Mark held a Microsoft Most Valuable Professional (MVP) award for three years and is now part of the MVP Reconnect programme. Mark is also well-known on social media and maintains an award-winning blog.","sameAs":["http:\/\/www.markwilson.co.uk\/","https:\/\/www.instagram.com\/markwilsonuk\/","https:\/\/www.linkedin.com\/in\/markawilson\/","https:\/\/x.com\/markwilsonit","https:\/\/www.youtube.com\/channel\/UCWHlZCoHRTocdvtrOJ2IL4A"],"url":"https:\/\/www.markwilson.co.uk\/blog\/author\/mark-wilson"}]}},"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":897,"url":"https:\/\/www.markwilson.co.uk\/blog\/2007\/09\/installing-microsoft-dynamics-crm-without-domain-administrator-rights.htm","url_meta":{"origin":623,"position":0},"title":"Installing Microsoft Dynamics CRM without domain administrator rights","author":"Mark Wilson","date":"Tuesday 11 September 2007","format":false,"excerpt":"I recently inherited the task of designing the infrastructure for a Microsoft Dynamics CRM 3.0 implementation. After being briefed by the consultancy partner that we are using for the application customisation and reading Microsoft's implementation guide I was fairly comfortable with the basic principles but I was also alarmed that\u2026","rel":"","context":"In \"Microsoft Active Directory\"","block_context":{"text":"Microsoft Active Directory","link":"https:\/\/www.markwilson.co.uk\/blog\/tag\/active-directory"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1206,"url":"https:\/\/www.markwilson.co.uk\/blog\/2008\/09\/active-directory-design-considerations-part-3-organizational-units.htm","url_meta":{"origin":623,"position":1},"title":"Active Directory design considerations: part 3 (organizational units)","author":"Mark Wilson","date":"Wednesday 17 September 2008","format":false,"excerpt":"In the previous post in this series of posts about design considerations for Microsoft Active Directory (AD), based around the MCS Talks: Enterprise Architecture series of webcasts, I looked at forest and domain design. This post continues with a look at organizational unit (OU) structure. The OU structure is not\u2026","rel":"","context":"In \"Microsoft Active Directory\"","block_context":{"text":"Microsoft Active Directory","link":"https:\/\/www.markwilson.co.uk\/blog\/tag\/active-directory"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":862,"url":"https:\/\/www.markwilson.co.uk\/blog\/2007\/07\/windows-server-2008-read-only-domain-controllers.htm","url_meta":{"origin":623,"position":2},"title":"Windows Server 2008 read only domain controllers","author":"Mark Wilson","date":"Monday 30 July 2007","format":false,"excerpt":"This is the last post I'm intending to write based on the content from the recent Windows Server UK User Group meeting - this time inspired by Scotty Mc Leod's presentation on read only domain controllers (RODCs), a new feature in Windows Server 2008. In my post from a few\u2026","rel":"","context":"In \"Microsoft Active Directory\"","block_context":{"text":"Microsoft Active Directory","link":"https:\/\/www.markwilson.co.uk\/blog\/tag\/active-directory"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1203,"url":"https:\/\/www.markwilson.co.uk\/blog\/2008\/09\/active-directory-design-considerations-part-1-introduction.htm","url_meta":{"origin":623,"position":3},"title":"Active Directory design considerations: part 1 (introduction)","author":"Mark Wilson","date":"Tuesday 16 September 2008","format":false,"excerpt":"A few weeks back, I wrote a series of posts on the architectural considerations for designing a predominantly-Microsoft IT infrastructure, based on the MCS Talks: Enterprise Infrastructure series (Introduction, Remote offices, Controlling network access, Virtualisation, Security, High availability and data centre consolidation). Session 2 of the MCS Talks series looked\u2026","rel":"","context":"In \"Microsoft Active Directory\"","block_context":{"text":"Microsoft Active Directory","link":"https:\/\/www.markwilson.co.uk\/blog\/tag\/active-directory"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":966,"url":"https:\/\/www.markwilson.co.uk\/blog\/2007\/12\/migrating-passwords-with-the-active-directory-migration-tool.htm","url_meta":{"origin":623,"position":4},"title":"Migrating passwords with the Active Directory Migration Tool","author":"Mark Wilson","date":"Friday 21 December 2007","format":false,"excerpt":"I've spent most of this month working with a customer who is consolidating various Active Directory forests into a single domain. We didn't use any third party tools - just the standard Microsoft utilities, i.e. Active Directory Migration Tool (ADMT) v3 and Exchange Migration Wizard (one of the Exchange Server\u2026","rel":"","context":"In \"Microsoft Active Directory\"","block_context":{"text":"Microsoft Active Directory","link":"https:\/\/www.markwilson.co.uk\/blog\/tag\/active-directory"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":566,"url":"https:\/\/www.markwilson.co.uk\/blog\/2004\/04\/migrating-from-exchange-server-55-to.htm","url_meta":{"origin":623,"position":5},"title":"Migrating from Exchange Server 5.5 to Exchange Server 2003","author":"Mark Wilson","date":"Wednesday 7 April 2004","format":false,"excerpt":"With Microsoft Exchange Server 2003, Microsoft have made Exchange installation simpler - the Exchange Server deployment tools and documentation (ExDeploy) lead an administrator through the entire Exchange Server installation or upgrade process and it is recommended that Exchange Server 2003 Setup is run using ExDeploy. Specific tools and utilities can\u2026","rel":"","context":"In \"Microsoft Exchange\"","block_context":{"text":"Microsoft Exchange","link":"https:\/\/www.markwilson.co.uk\/blog\/tag\/exchange"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/posts\/623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=623"}],"version-history":[{"count":0,"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/posts\/623\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.markwilson.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}