ADAM instead of setting up domain in the 'perimeter' ? Sharepoint+AD

ADAM instead of setting up domain in the 'perimeter' ? Sharepoint+AD

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
ADAM instead of setting up domain in the 'perimeter' ? Sharepoint+AD Marlon Brown 10-12-2005
Posted by Marlon Brown on October 12, 2005, 11:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
We are currently planning to setup an AD forest in the perimeter network to
accomodate a number of front/back end Sharepoint servers and DC's, etc. The
idea is that if extranet users need to access Sharepoint from the extranet,
they could authenticate using accounts existing in such "Domain-Perimeter"
and avoid coming "inside" my organization for future access. Such
"Domain-Perimeter" would be setup in a separate Forest with an one-way trust
relationship to my corporate domain.

I just thought more about it:
How about instead of setting up an entire domain infrastructure to
accomodate such security need of account isolation, I just setup an AD/AM
structure in a Sharepoint servers "inside" my organization. That way I could
accomplish the same goal of providing external users with "isolated"
accounts from my corporate domain and I could make the whole implementation
much easier.

Let me know your thoughts and whether that would work.



Posted by Marlon Brown on October 12, 2005, 1:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The AD guys tell me the 'trust like' capabilities for repositories such as
ADAM would be released at later date.

> We are currently planning to setup an AD forest in the perimeter network
> to accomodate a number of front/back end Sharepoint servers and DC's, etc.
> The idea is that if extranet users need to access Sharepoint from the
> extranet, they could authenticate using accounts existing in such
> "Domain-Perimeter" and avoid coming "inside" my organization for future
> access. Such "Domain-Perimeter" would be setup in a separate Forest with
> an one-way trust relationship to my corporate domain.
>
> I just thought more about it:
> How about instead of setting up an entire domain infrastructure to
> accomodate such security need of account isolation, I just setup an AD/AM
> structure in a Sharepoint servers "inside" my organization. That way I
> could accomplish the same goal of providing external users with "isolated"
> accounts from my corporate domain and I could make the whole
> implementation much easier.
>
> Let me know your thoughts and whether that would work.
>



Posted by Roger Abell [MVP] on October 13, 2005, 10:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yes, and yes.
The "traditional" way, as you outlined with the AD trust, has since the
intoduction of Adam had an alternative, and, depending on the resource
access needs this Adam alternative can also be combined with a more
restrictively used AD trust so the protocol transitioning out of Adam
can also allow "gated" access to those resource using Windows principals.
The other yes is that you definitely should evaluate what ADFS v1 in
the R2 release cycle will bring as added alternatives.

> We are currently planning to setup an AD forest in the perimeter network
> to accomodate a number of front/back end Sharepoint servers and DC's, etc.
> The idea is that if extranet users need to access Sharepoint from the
> extranet, they could authenticate using accounts existing in such
> "Domain-Perimeter" and avoid coming "inside" my organization for future
> access. Such "Domain-Perimeter" would be setup in a separate Forest with
> an one-way trust relationship to my corporate domain.
>
> I just thought more about it:
> How about instead of setting up an entire domain infrastructure to
> accomodate such security need of account isolation, I just setup an AD/AM
> structure in a Sharepoint servers "inside" my organization. That way I
> could accomplish the same goal of providing external users with "isolated"
> accounts from my corporate domain and I could make the whole
> implementation much easier.
>
> Let me know your thoughts and whether that would work.
>



Similar ThreadsPosted
Perimeter domain:using corporate Anti-virus repository or let servers go to Internet November 29, 2005, 6:14 pm
Security Setting on Domain Controllers November 3, 2008, 3:56 pm
Computer in a Workgroup Access in a Domain Setting June 21, 2005, 11:55 am
Your opinion on segmentation (perimeter network) October 4, 2005, 12:56 pm
Gurus: server on perimeter vs. corporate advice August 15, 2005, 11:36 pm
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
Standby setting December 30, 2005, 3:36 pm
Security Setting May 12, 2007, 2:07 am
Giving access to a share folder in domain A to users in Domain B May 17, 2007, 2:22 pm
CAs: Enterprise root on parent domain, subordinate on child domain March 20, 2008, 10:28 am

The site map in XML format XML site map

Contact Us | Privacy Policy