Mutiple Customers inside Active Directory without the ability for them to see eachother


hiyas,

we're working on active directory design struggle.

the goal have multiple customers sharing standard windows server platform (like file server, printing, exchange, etc.).
normally, inside active directory isn't hard accomplish logically seperating company company b placing objects in seperate organizational units.
maintaining security boundary on per service base done on service (e.g. on file server we're planning use access based enumeration)

we're dealing following design objectives:

1) make sure company unable see company b inside active directory in way.  objective kind of challenge since authenticated users have 'read' rights throughout entire ad forest.

2) architecture should higly flexible. should able move services , shared resource domain see fit.

3) architecture should accomplished minimal of changes on active directory permissions or schema. updating searchflags attribute each class in active directory schema isn't option.

these objectives made seperate domains , seperate forest for: company a, company b , resources.
if i'm not mistaken normal 'trust' scenario give same problem using seperate ou's each customer: read rights throughout domains.

next thing did @ active directory federation services 2.0. in basic, need maintain single sign on users while using seperate domains in seperate forests. bad works http(s) published resources. services offer customers not compliant federation services , therefore can not use adfs.

so, long story short: know of solution or (third party) products can use maintain security boundary on customer , customer b, while using shared resources (file server, print server, exchange) , providing single sign on ?


in advance,

ruben van gogh

 

if "security boundary" mean abilityt to prevent viewing content of specific container in ad, typically accomplished leveraging dsheuristics attribute/listobjects permissions - more @ http://msdn.microsoft.com/en-us/library/ms675746(vs.85).aspx

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...