Choosing between a new domain or forest
In organizations, sometimes, an expansion or business change requires changes in Active Directory too. In Active Directory terms, the change might require creating a new Active Directory domain or a new Active Directory forest. In this recipe, we'll look at the reasoning between these two choices, taking the entire life cycle of Active Directory into consideration.
Why would you have a new domain?
A new Active Directory domain – as either a subdomain of an existing domain or a new domain tree in an existing forest – provides a boundary.
The boundary of domains in Active Directory relates to the following:
- DNS name: An additional domain tree offers the possibility to add a DNS domain name to the organization to, for instance, correctly label a new business venture. An alternative might be to add an additional UPN suffix.
- Domain DNS zones replication: Throughout an Active Directory forest, all domain controllers...