skip to content

IT Help and Support

University Information Services

Guidelines for Windows System Administrators on designing and implementing their Active Directory and related infrastructure.

The Institution Support Service runs an Active Directory for use by all institutions in the University. Information on this is available in the AD domain wiki. This AD can be used by whole or parts of institutions and removes the need for you to run your own AD.

It's possible the first question you should ask is "Do I need Active Directory?". The answer is probably yes if you have 10 or more Windows PCs and Users under your control and you want to effectively centrally administer them. Even for less than 10 users and PCs it may well be worth your while if you want to provide a central data store which you can backup and provide central control over the machines. Many of the terms and concepts discussed here require knowledge of Active Directory as this is not intended to teach you about Active Directory but help you implement it.

Mail for more information or help on existing systems, upgrading a Windows Domain or migrating to a new Domain.

Domain name and design

Within Cambridge the most common Domain naming solution is either for your Domain name to match your current DNS name or be a name directly under the DNS name. It is important to remember that Active Directory names are now DNS names, you will have to implement a DNS which matches your chosen Domain name.

General guidelines

  • Choose a domain name that matches your DNS name possible or choose a domain name that is no more than one below your current DNS name. For example, if your DNS name is CSI.CAM.AC.UK your Active Directory Domain should be CSI or use AD.CSI.CAM.AC.UK.
  • Keep to a single domain wherever possible – there are very few (if any) reasons for one institution to need more than one Active Directory.
  • If part of a large department you should be aware of any other Windows Domains, don't try and take your departments Domain name as your own as it may be an existing Domain name!

Instructions on how to configure your DNS for Active Directory within Cambridge are available on our Windows Server DNS configuration guidelines for Active Directory page.

Active Directory organisational unit structure

Once you have created a Domain you will need to give it some structure. This is done with Organisational Units (OUs).

The actual layout of Active Directory, the Organisational Units (OUs) and where to put users and computers etc. will largely depend on what you will require from group policy. For the users and computers, if they all require the same policies to be applied then a general OU can be created for all of them, although it's often better to separate your users and computers.

General guidelines

  • Keep the depth of OUs as shallow as possible.
  • Should represent structures which won't change.
  • You can restrict access to AD objects to which users have no access if required.
  • Group and Design in a manner that suits your needs. There is no right way to build your structure.

What information should I store in AD?

The question of what information you store will greatly depend on what people want and are prepared to let you store. The more information you put in the more powerful and useful it can become. You can stick to just the minimum required, i.e. login name but you can store so much more, phone numbers location etc. which all your users can search through. Potentially it becomes a very useful searchable store of an organisations information.

Group policy

Group policy and what you can do with it (pretty much anything) may well affect your OU structure.

How Group Policy impacts on your OU design should become obvious depending on your needs, if certain users require certain policies set then adjust their location accordingly, i.e. have your OU structure based on role or requirement rather then physical location, or you can use security groups to apply policies.

General guidelines

  • Keep the number of policies to a minimum as policy processing affects login speed and large numbers of policies can make trouble shooting very difficult.
  • You should as a rule never apply policies on the default domain level as these policies will affect the administrator account.
  • Bear in mind the policy processing order; Local, Site, Domain, OU structure – effects are cumulative, but the last policy processed takes precedence if there is a conflict (unless no over ride is used).
  • Users who require the same settings should have the same policy applied, but they don't need to be in the same OU but it may require additional configuration to prevent users who shouldn't have a particular policy applied who are in the same OU.