Separating the AD domains in mulitenant environments

I'm in a multi-tenant environment.  Some tenants have lived together in a true cloud infrastructure, where resources are grouped together, and separation is applied in the virtualization layer, not the physical layer (i.e. shared physical network infrastructure).  Due to security restrictions more stringent, other tenants have a managed hosting platform with their own equipment for the physical layer (e.g., their own physical switches).  Still other tenants have specialized arrangements tailored to fit a security model to halfway between having totally separate resources and resources pooled completely.  Everything is in a data center.  (Everything is vCenter 5.1 or a later version of SSO is also used in the world)

The question is, when is it appropriate to dedicate a separate AD domain to a tenant?

When I regroup renters with different areas AD in a single AD forest, and when should they have a separate forest?

Hello

It depends on which tenants are in fact. If it is truly multi-tenant your tenants will have their own AD services which will be completely separated. The only ones that will not separate from yours are your authentication and authorization to access their portal. Tenants should never have access to the SSO, they do not need to access the virtual machines. they should not have access to the host either.

Now, if they have their own equipment and control all up and down the stack, then they need a separate domain, I would think while auth does not overlap.

It really depends on who are your tenants and how separated things are now and the policy you are trying to apply. Start here and then choose the best way to do things on this basis.

Best regards
Edward L. Haletky
VMware communities user moderator, VMware vExpert 2009, 2010, 2011,2012,2013,2014

Author of the books ' VMWare ESX and ESXi in the business: Planning Server Virtualization Deployment, Copyright 2011 Pearson Education. ' Of VMware VSphere and Virtual Infrastructure Security: securing the virtual environment ', Copyright 2009 Pearson Education.

Virtualization and Cloud Security Analyst: The Practice of virtualization, LLC - vSphere Upgrade Saga - virtualization security Table round Podcast

Tags: VMware

Similar Questions

  • I used to work with Interbase and Firebird and used databases the keyword "domain". I am now switchig to Oracle as a primary database and would like to find an alternative appropriate "domain" in Oracle, as it appears he does ' t taken in charge the stand

    I used to work with Interbase and Firebird and used databases the keyword "domain".

    I am now switchig to Oracle as a primary database and would like to find a suitable

    Variant of 'area' in Oracle such that it appears he does ' t support the standard SQL syntax.

    for example:

    Create the int2 smallint field;

    create domain id2 int2 default 0 not NULL; / * for the primary key * /.

    create domain rel2 int2 default 0 not NULL; / * foreign key * /.

    I tried a couple of approaches to achieve this "area" is:

    1. create synonym - cannot be used with the basic types;

    2. create the type - type of work, but the implementation is rather clumsy

    and can be costly in terms of performance.

    Is there something else to Oracle that can emulate the feature "domain"?

    Thanks in advence, I got really approciate any help on this.

    Alex.

    Your best approximation is CREATE TYPE, but their is nothing of what is a 100% adjustment.

    For example, if you create a domain with a check constraint you need to implement than separately on each table.

  • When I click on an address, instead of the name of domain appearing in the url field, only the IP address appears. How can I get the real domain to pop?

    When I click on an address, instead of the name of domain appearing in the url field, only the IP address appears. How can I get the real domain to pop?

    Start Firefox in Firefox to solve the issues in Safe Mode to check if one of the extensions or if hardware acceleration is the cause of the problem (switch to the DEFAULT theme: Firefox/tools > Modules > appearance/themes).

    You can attach a screenshot?

    Use a type of compressed as PNG or JPG image to save the screenshot and make sure that you do not exceed the maximum file size (1 MB).

  • Acceleration in the frequency domain

    Hello

    I enclose a vi that I already modified the existing example. I will use this vi to measure pressures (pressure sensor) and acceleration (from an IEPE accelerometer). Each of the two sensors is connected to a housed in a chassis CompactDAQ C Series module connector 4. The pressure sensor measures the pressure of the water flowing in a pipe while the accelerometer will simultaneously measure the vibration of this pipeline caused by the fluctuation of water pressure. In this vi, I am connecting a signal of pressure and acceleration TDMS file and then read the two signals on the cards of distinct waveform. The acceleration signal is written and read in the time domain. I need your help to make change more on this vi to take the acceleration signal and read on a separate table in the field frequency and written also the frequency of the field values in a file of PDM. After this change, the vi is supposed to have three graphics of waveform (pressure, acceleration time-domain and acceleration in the frequency domain and opens two tdms files, one for pressure and acceleration in the time domain and one for acceleration in frequency domain.)

    I tried many ways all failed because I'm not very familiar with the measurements of vibrations.

    I thank in advance.

    Hello

    It is important that you should decide if the frequency data you are interested in are constants based on time, or if you need to know how the data of frequency changes over time.

    For constant frequency over time, take a look at the Fast Fourier Transform: http://www.ni.com/white-paper/4541/en/

    If you need to know how the frequency display, take a look at the analysis of the frequency of the common time: http://www.ni.com/white-paper/3548/en/

  • Remove 1 of the 3 domain controllers in a Windows environment

    I have a Windows domain that has Windows 2003 and 2008 R2 servers to support workstations, SharePoint and exchange among other things. There are 3 domain controllers. The first domain controller created on window 2003 server. Later, more 2 domain controllers were added on Windows 2008 R2. During the promotion of each of the servers in DC, each of them were activated as DNS and Global catalog servers. In addition, both 2008 DHCP configuration on them were servers and one Server 2008 R2 is configured as primary and the second as the secondary. The 2003 is just a DC member. I made main hold all 5 FSMO roles and replication works as well on both servers.
    I now have to demote the first Windows Server 2003, and then it must be taken out of the area. But whenever I have to run DCPromo to demote the server he kept a message that no other DC cannot be contacted, and when I try to disable the NIC in Server 2003, replication will stop automatically on the two 2008 R2.

    Any help please.
    Thanks in advance.

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • I keep getting "the trust relationship between this workstation and the primary domain failed" error windows 2008R2

    Hi all

    I appreciate your help. And I hope that this issue has been addressed previously, although I couldn't find any solution there.

    I manage a domain windows 2008 with 3 domain controllers. Recently my workstations continue to fall out of the field. I get "the trust relationship between this workstation and the primary domain failed" to many workstations.

    I know how to fix properly, use netdom.exe. But the mistakes keep coming back. I don't know where to look for the source of this error. A possible problem might be the time in any field is out of sync. But all my workstations synchronize with the domain controller with the primary domain controller role and seems to work correctly.

    Are there other sources, that I need to check? This is getting frustrating.

    Thank you much for the help.

    Sincerely,

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • How to migrate users existing AD to the new domain in Server 2003r2

    I need to migrate users from the old domain to the new domain please help in this matter.

    Windows Server gurus all them lying around in the TechNet forums, here, we are dealing with the problems of user security.

    http://social.technet.Microsoft.com/forums/en-us/categories

  • Group Policy infrastructure failed due to the error below. The specified domain does not exist or could not be contacted.

    using several Windows 2003 domain in an attempt to push the msi using Group Policy is following on xp sp3 machine error

    Group Policy infrastructure failed due to the error below.
    The specified domain does not exist or could not be contacted.

    Note: Due to the GP Core failure, no other component processes Group Policy policy.  Consequently, status information for the other components are not available.

    Hello

    Your question of Windows is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please post your question in the Technet Windows Forums. Here is the link:
    http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

  • Explain to me how a multi-level security strategy can be deployed domain LAN-to-WAN and the LAN domain to the domain of the workstation with the use of internal firewalls.

    Explain to me how a multi-level security strategy can be deployed domain LAN-to-WAN and the LAN domain to the domain of the workstation with the use of internal firewalls.

    Hello

    Your Windows XP question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please ask your question in the following forum.
    http://social.technet.Microsoft.com/forums/en-us/itproxpsp/threads

  • The network domain name

    I have two PCs (both with Windows XP SP3) and an HP printer that are networked and cables Ethernet and a 2Wire gateway.  Now I want to install Debian GNU/Linux 5.0.6 on one of the computers and do a dual-boot machine.  The other PC will stay only with Windows XP.

    During the installation of Debian, I am asked to provide the name of the network domain.  He tells me that I have a name, but to be sure to use the same domain name on all computers.

    I configured the domestic network (using Windows XP), a long time ago and I honestly don't remember not so and what name I gave to the network.  I'm not much of an expert with these things, would someone please tell me how can I find my network name in Windows XP?  Of course, I would like to use the same name when installing Debian.

    I went at the start-> my network places, but then I don't know where is the name of the network on this screen...

    Thank you.

    Probably, you don't have a domain name because you really do not have a domain.  You have a working group name, yet if Debian will recognize that and use it sometimes as a 'domain name' I don't know.

    To find your workgroup name (which is probably "Workgroup" or "MSHome") make a right click my computer and choose Properties. On the "Computer name" tab, you should see the name of indicated working group.

    -B-
    http://www.officeforlawyers.com | http://www.OneNote-tips.com
    Author: Guide to counsel for Microsoft Outlook

  • Disabling a Windows Firewall which is on the same domain of the remote computers.

    Hello world

    I have a Windows Firewall client machine is activated, preventing me from rattling of the machine or by connecting remotely. The user logged on to this computer doesn't have permissions to disable the firewall. How would turn off the firewall on the computer on my side?

    The machine runs Windows XP and is on the same domain as my pc.

    Thank you

    I think I found the solution:

    First, you must obtain the correct name of the service, apparently the display name of the service is not the actual service name.

    SC getkeyname "Windows Firewall"

    This gave me the correct name for the service, "mpssvc.

    I then ran the new commandment:

    SC \\computername stop mpssvc

    This service order.

  • The specified domain does not exist or could not be contacted.

    Last night I completely disconnected my laptop. This morning when I turned on the machine, she does everything as planned. When I reached the screen that requires a password to connect to Windows, the following error message came after I saw that my password and press ENTER.

    The specified domain does not exist or could not be contacted.

    I use Windows Vista Ultimate and the laptop connected to a wireless router.

    I tried to restart and stop several times. It did not work. I did a Diagnostic Windows memory check and it went well. Also, I restarted Windows in Safe Mode and some other modes and received the same exact error message.

    Thanks in advance for your answers!

    Dan

    Hello
     
    1. don't you make changes before the show?
    2. is the laptop connected to a domain or have you tried to connect to a domain?
    3. you have to any other user account on the laptop?
     
    If you have any other user account on the laptop, try logging in there and see if the problem still occurs. If you are able to connect, sever the computer from the domain. Try the following steps to separate the field.
    1. right click on computer from the start menu, click Properties, click Advanced system settings, the computer name, change, select workgroup and workgroup name type.  Click Ok. You will need the necessary permissions to perform this task.

    If the computer is not connected to a domain and you have not made any changes recently. Try to restore the system using Vista DVD.
    To run the restore of the system using Vista DVD, try the following steps.
    1. start in Vista installation DVD.
    2. choose your language settings, and click Next.
    3. click on repair your computer.
    4. choose your operating system and click Next. This should bring up the System Recovery Options.
    5. click on system restore.
    6. follow the instructions in the wizard to complete the task.
    7. once the system restore is complete, start the computer as usual and try to connect.
     
    For more information on the Windows recovery environment options, see this link:
    http://Windows.Microsoft.com/en-us/Windows-Vista/what-are-the-system-recovery-options-in-Windows-Vista
     
    Try the steps and post back with the results, so that we can help you further.
     
    Kind regards
    Syed
    Answers from Microsoft supports the engineer.
  • I want to switch to a different service provider, but keep the same domain name

    original title: domain name

    I want to switch to a different service provider, but keep the same domain name.

    If you are referring to your own personal domain as "MyName at mydomain.com" email then you should be able to change the host very well.

    You need to change the e-mail servers in the DNS.
    You should be able to get support and complete itinerary on the mail, Web hosting.

  • "The specified domain does not exist or could not be contacted" then tried to connect to Windows

    Original title: could not open a session after computer F8\Repair selection

    Running Vista Home Prem

    Dell Inspiron 1501

    No Cd MFG.

    I have recently been struck by application pretty nasty virus/malware and want to do a factory restore. The problem I have is that when I select the option to repair through F8 at startup I get to the logon screen and all it shows is 'another user' in the way witness name of user/pass fields.

    I tried every possible user and the user/pass combo I could find and think. Every time I have enter a value in these fields and try to connect, I get the message "the specified domain does not exist or could not be contacted", if I try to log in without putting information in the field I get a msg of windows security saying that I have a user/pass to open a session.

    I looked in all possible aspects of user accnts, changed the need to open a session, deleted all passes, gave full control to all parts of windows and I still get the same screen.

    I need to know if there is a way around this or if the virus has changed the aperture setting of session for the repair operation? Also, if someone could tell me what measures the system and what files it loads when you browse the F8 repair op.

    Anything you could tell me would greatly

    Thank you

    Running Vista Home Prem

    Dell Inspiron 1501

    No Cd MFG.

    I have recently been struck by application pretty nasty virus/malware and want to do a factory restore. The problem I have is that when I select the option to repair through F8 at startup I get to the logon screen and all it shows is 'another user' in the way witness name of user/pass fields.

    I tried every possible user and the user/pass combo I could find and think. Every time I have enter a value in these fields and try to connect, I get the message "the specified domain does not exist or could not be contacted", if I try to log in without putting information in the field I get a msg of windows security saying that I have a user/pass to open a session.

    I looked in all possible aspects of user accnts, changed the need to open a session, deleted all passes, gave full control to all parts of windows and I still get the same screen.

    I need to know if there is a way around this or if the virus has changed the aperture setting of session for the repair operation? Also, if someone could tell me what measures the system and what files it loads when you browse the F8 repair op.

    Anything you could tell me would greatly

    Thank you

    Hey

    link below has the dell way they do a reinstall of recovery

    http://support.Dell.com/support/topics/global.aspx/support/KCS/document?c=us&l=en&s=Gen&docid=DSN_336966&isLegacy=true

    If you continue to have problems with it contact dell

    There is also a support link for dell at this link of recovery

    It's their recovery process

    Walter, the time zone traveller

  • Computer disconnects error the specified domain does not exist or could not be contacted

    Original title: Vista connection problem

    Using Vista, I can not connect. It does give me an option of safe mode. When you start in normal mode, it just runs and runs but does not charge. When I use the repair option which brings me to a login screen, but not my normal connection, he says any other user. Any user or password that I use, I get the following message: "the specified domain either does not exist or could not be contacted.

    Hello

    ·         You will remember to do recent changes on the computer before this problem?

    ·         Your computer is on the network?

    ·         What is the exact message that you get in what concerns the "other user"?

    I suggest you follow the steps below:

    Method 1:

    Restart the computer in safe mode controls the State of the question. Let us know the results. Follow the steps from the link to the following article to find out how to start the computer in safe mode:

    http://Windows.Microsoft.com/en-us/Windows-Vista/start-your-computer-in-safe-mode

    Method 2:

    If the problem occurred recently then I would suggest allows you to perform a system restore from winre mode at a time where everything worked well. Follow the steps in the link:

    http://Windows.Microsoft.com/en-us/Windows-Vista/what-are-the-system-recovery-options-in-Windows-Vista

Maybe you are looking for

  • photos not appearing is not on the iMac over the clouds

    I bought a new iMac and decided to give iCloud and Photos a good try. I have over 21 k images (from the Photos on my iMac). My iMac is my main computer so I put it where the original is uploaded on it. I also have a macbook pro and two iPhones. When

  • P1102w: Air Print

    Hello I'm new to this forum and please forgive me if I break some rules, but I'm in a hurry... I just get my new LaserJet Pro P1102w printer, and it is AMAZING! But I have some problems with the connection to AirPrint (iPhone 5 / 8.1.2 software) I kn

  • Satellite L650-S5096 - error when installing recovery

    My brother ordered me this laptop online from Best Buy for my Christmas present in Dec.2010. After I opened and he started upward, I did then the system backup disc as it was told to do. I showed that I needed to 4 discs for back to the top after the

  • Error: Access violation at 0x7C80A00 (tried to read from 0x0017A000), program ended

    When starting a pc game, that I had downloaded from Big Fish, I received the error message "above.  When I contacted McAfee, told me that the problem was with my Microsoft Windows.  Help!

  • get the error message "status.msi".

    After insalling windows XP Pro SP3 yesterday, everything was fine. Today, I turn on the computer and get this continuous message "status.msi" missing. I have accumulated my brain trying to find the file with no luck. Done a repair and still a problem