40 Microsoft Domain Name Best Practice Update

This document provides a practitioner s perspective and contains a set of practical techniques to help it executives protect an enterprise active directory environment.
Microsoft domain name best practice. There appear to be varying religious views on the topic. Because the dns names of all the nodes that require name resolution include the internet dns domain name for the organization choose an internet dns domain name that is short and easy to remember. Domain name services dns and name resolution design dns is the core service for active directory and key for all other microsoft products.
2 minutes to read 2. But some organizations buy and reserve those domain names to ensure that no other organization can use the same domain names as public domain. Ad domain vs dns name.
Use a sub domain of the company s already registered internet domain name. The first domain that you deploy in an active directory forest is called the forest root domain. We ve dug into active directory security groups best practices active directory user account best practices and active directory nested groups best practices but there are also a number of tips and tricks for managing active directory as a whole.
Windows server 2016 windows server 2012 r2 windows server 2012. The first is using a generic top level domain. Before we discuss current best practices there are a couple of popular practices that are no longer recommended.
Ad domain names are mainly used within ad operations mostly ldap queries for ad functionality while dns is rather a network level solution for name resolution on ip level to resolve the machines or application names to ip addresses. I agree with microsoft s recommendation. This restriction is a limitation of multivalued non linked attributes in windows server 2003.
In the previous step we purchased our public domains valid top level domain and most of the internet registrars provide the public dns console to manage the domain. This article describes best practices for the configuration of domain name system dns client settings. Your smtp domain name which should be globally resolvable should be different than ad domain names.