Engineering Topology
摘要
Active Directory presents us with a wide selection of topology choices – forests that trust each other (or not) and domains that make them up, geographical distribution to sites with site links following the physical layout of the corporate WAN (sometimes they don’t, leading to less-than-optimal function of the directory environment and interesting troubleshooting sessions), custom DNS and application partitions with their own replication scopes, read-only domain controllers thrown into the mix, and thousands of individual settings that govern the replication and site coverage behavior of our AD organization. Topology is the one area of the entire engineering effort that probably has the smallest security implications, apart from the fact that the forest and not the domain is the true security boundary in AD. Yet topology is important – for the overall resilience and manageability of our identity infrastructure, and good manageability tends to go hand in hand with good security. It is also important in case of recovery from a catastrophic failure, be it due to a cyber incident or to more mundane causes.