Skip the navigation
)

Longhorn Server Revealed: Active Directory Enhancements

By Jonathan Hassell
January 8, 2007 12:00 PM ET

Computerworld - Longhorn Server, due to be released later this year, is a major revision of Microsoft Corp.'s flagship server operating system. In this article, I’ll take a look at the most significant enhancements to Active Directory in Longhorn Server and how they will impact your business.

Read-Only Domain Controllers

Think back to the days of Windows NT 4.0, where there was one king of the hill, the primary domain controller (PDC), and then any number of subservient princes below that king on the same hill -- the backup domain controllers, or BDCs. It was easy to see the flow of information: Changes were made to the master copy of the domain security information on the PDC, and from there it flowed outward, unidirectionally, to the BDCs.

When Active Directory came around, however, this distinction was eliminated, and in practice a domain controller (DC) was equal to any other domain controller, without any designation of primary, backup, and so on. (Well, in actuality, some DCs are a little more equal than others when you factor operations master roles into the equation, but that’s not relevant to this discussion.)

While this new design increases the fault-tolerance and distributed-deployment capabilities of the operating system, it can be a problem if a domain controller anywhere on the network pushes corrupt or otherwise incorrect data to other DCs. How would you prevent that?

This is a problem particularly in branch-office scenarios. Since the designated administrator in a branch office needs domain administrator credentials to administer the DC in his office; this actually gives him the right to administer any DC, not just the one he’s responsible for looking after. It’s not the best security situation.

While this equality of domain controllers is still the case in Longhorn Server’s Active Directory implementation, there is now the concept of a read-only domain controller. A read-only domain controller (RODC) is just that. It receives information replicated to it from full domain controllers, but it doesn’t permit any changes to be made to its own copy of the directory database, and thus no information can be replicated back to the full DCs in the domain of which it’s a member.

This is a great win for branch offices whose companies are large enough to have a comprehensive Active Directory structure. Now you don’t have to deploy a full-blown domain controller to your remote locations -- you can simply place a RODC there.

The benefits are significant and include:

  • You reduce the risk of someone attacking a branch office location and sending poisoned data throughout the entire Active Directory database.
  • The RODC caches only the credentials of local users, not those of other Active Directory domain accounts, which reduces the possibility that accounts can be cracked from a stolen branch office domain controller.
  • The RODC never caches administrator credentials, so the keys to the kingdom are more fully protected.
  • The Kerberos authentication tickets issued by the RODC will be valid only for systems within its scope, so it can’t issue falsified tokens to get nefarious users onto the full network.
  • The RODC is a Server Core-designated role, which means there’s hardly any need for administration locally. No graphical user interface also means a smaller attack surface. (See my Longhorn Server Beta 2 article on this site for more details.)



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Data Center White Papers
Finding the right cloud solutions for your organization
HP is driving the evolution of what we call the Instant-On Enterprise. It is an enterprise that embeds technology into everything it does...
Converged Infrastructure for Dummies
As you know, everything is mobile, connected, interactive, and immediate. This is exactly why organizations need a highly agile IT infrastructure in order...
Measuring the Business Value of CI in the Data Center
One of the key strategies that IT teams are pursuing to reduce capital costs while boosting asset utilization and employee productivity is the...
Seven Priorities for Integrated Network Management - How HP Intelligent Management Center Delivers an Enterprise-class Solution
This white paper describes the major requirements for network management solutions to help the organizations become more profitable, efficient and reliable.

Intel and the...
Building Cloud-Optimized Data Center Networks white paper
Enterprises are turning to the Cloud to improve business agility, reduce expenses and accelerate business innovation. Cloud computing redefines the way IT assets...
All Data Center White Papers
Data Center Webcasts
Redefine Expectations in the Data Center
Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
Oracle Database Appliance Best Practices
Business users increasingly demand 24x7 availability of their data while IT departments face the challenge of ensuring maximum availability while operating with limited...
Unlock the Value of Cloud Computing with Workload Automation
Learn how to get the most from your cloud investment in our on-demand webinar from BMC and InformationWeek. You'll hear how integrating the...
Introduction to Virtualization
Have you been thinking about what it would take to start using virtualization? Or do you know the basics and want to find...
Best Practices to Optimize Your Data Center at Every Layer of the Stack
Date: May 31, 2012
Time: 1 PM EST

Organizations are reaping the benefits of simplifying IT, lowering costs and dramatically improving transactional throughput by deploying...
All Data Center Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs