80 Microsoft Ad Domain Name Best Practices New

The ad domain name is not the same as the dns name but they are linked.
Microsoft ad domain name best practices. 17 minutes to read. Best practices for securing active directory. Active directory tips and best practices checklist.
Securing domain admins groups in active directory. Microsoft it has developed detailed best practices for account configuration physical security operating systems versions and configurations patch management and configuration management on secure administrative hosts. Documenting the forest root domain name.
Although you should use internal non resolvable domain names for active directory. But some organizations buy and reserve those domain names to ensure that no other organization can use the same domain names as public domain. For example you will not be able to synchronize your domain with windows azure active directory unless you own the domain name that you are trying to synchronize.
Generic tlds like local lan corp etc are now being sold by icann so the domain you re using internally today company local could potentially become another company s. Before we discuss current best practices there are a couple of popular practices that are no longer recommended. Ad domain names are mainly used within ad operations mostly ldap queries for ad functionality while dns is rather a network level solution for name resolution on ip level to resolve the machines or application names to ip addresses.
Naming conventions in active directory for computers domains sites and ous. The reason is it is causing split brain dns by nature as well as if you would like your organization website to be accessible by the domain name only it won t because it will resolve to the ad unless you append the www. The first is using a generic top level domain.
For more information about designing a dns infrastructure to support ad ds see creating a dns infrastructure design. Organization s experience which is accountable for protecting the assets of microsoft it and other microsoft business divisions in addition to advising a selected number of microsoft global 500 customers. It is important for the active directory dns owner to work with the dns owner for the organization to obtain ownership of the name that will be used for the active directory namespace.