Creating the forest structure
Once the forest mode has been decided on, the next step is to create the forest structure. In order to do that, we need to decide whether we are going to achieve autonomy or isolation.
Autonomy
Autonomy gives you independent control over resources. An Active Directory environment that is focused on autonomy will help administrators manage the resources independently, but there will be more privileged administrators who can manage the resources and privileges of other administrators.
There are two types of autonomy:
- Service autonomy: This will provide privileges to an individual or a group of administrators to control the service level of AD DS fully or partially. For example, it will allow administrators to add or remove domain controllers, modify the Active Directory schema, and modify DNS without the forest owner.
- Data autonomy: This will provide privileges to an individual or a group of administrators to control data stored...