Windows 2000 AD and AD/AM
ADAM is best used in the application developement area where programmers donot have to have an AD present in order to test their
applications developed using AD functionalities. ADAM can be installed on any XP workstations. An XP box can host multiple instances
of ADAM. You may look into one of the following solutions:
1. One single AD account with a proper "role" to handle extranet users. Or
2. Create a separate Forest for these users.
#2 is best in term of security but the cost to maintain a separate forest may be your concern.
For your Security: No-No, a thousand No, I would not grant AD access to my internal AD system. How about TRUST ? No, no trust to
external users unless you do know them well.
John
|