September 2012
Intermediate to advanced
1680 pages
88h 3m
English
The schema is the most critical component of AD DS and should, therefore, be protected and guarded closely. Unauthorized access to the schema master domain controller for a forest can cause some serious problems and is probably the best way to corrupt the entire directory. Needless to say, segregation of the keys to the schema from the user base is a wise option to consider. From this concept was born the empty-root domain model, shown in Figure 5.11.
Figure 5.11. Empty-root domain model with an unpopulated forest root.
In short, the peer-root domain model makes use of an unpopulated forest root domain ...
Read now
Unlock full access