Active Directory structure and security
When the IT admin creates a new session host, they have the option to connect to Active Directory (AD). It is recommended that not everyone has access to these objects, so it’s a good idea to have a good structure in place. This structure includes the following:
- Separated Organizational Unit (OU)
- Separated GPO for each environment
- Dedicated service account to domain join
Let’s discuss these next.
Separated OU
It’s important to limit the access to the session hosts AD objects to apply zero trust on these objects. Because of this, the IT admin can create separate OUs for each environment. This way, somebody with access to the development (dev
) hosts doesn’t have access to the production (prd
) hosts.
In the following example, the IT admin has created a structure to organize prd
and dev
:
Figure 10.70 – AD structure