ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    domain controller in the cloud for small office?

    IT Discussion
    17
    120
    9.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Mike DavisM
      Mike Davis
      last edited by

      Does anyone have any small offices where you're running a domain controller in the cloud? I have a small office of 8 computers that is separating from the main network as the company splits. They have HIPAA concerns, so I would like to be able to centrally manage passwords (and their expiration) and stuff like that. I don't think it makes sense to put a physical server onsite for that.

      Any recommendations?

      NashBrydgesN 1 Reply Last reply Reply Quote 0
      • gjacobseG
        gjacobse
        last edited by

        That small of an office,. do you really need a DC - you should still be able to have HIPAA security without it.

        Mike DavisM 1 Reply Last reply Reply Quote 1
        • Mike DavisM
          Mike Davis @gjacobse
          last edited by

          @gjacobse said in domain controller in the cloud for small office?:

          HIPAA security without it.

          How do you create a password change policy that gets enforced without a domain controller?

          scottalanmillerS Reid CooperR larsen161L 3 Replies Last reply Reply Quote 1
          • scottalanmillerS
            scottalanmiller
            last edited by

            NTG did this until we decided AD wasn't useful.

            1 Reply Last reply Reply Quote 0
            • travisdh1T
              travisdh1
              last edited by

              If they feel they must have the functionality available, why not use Azure Domain Services https://azure.microsoft.com/en-us/services/active-directory-ds/ (Or whatever it happens to be called at the moment, I can't keep track.)

              Mike DavisM 1 Reply Last reply Reply Quote 1
              • scottalanmillerS
                scottalanmiller @Mike Davis
                last edited by

                @mike-davis said in domain controller in the cloud for small office?:

                @gjacobse said in domain controller in the cloud for small office?:

                HIPAA security without it.

                How do you create a password change policy that gets enforced without a domain controller?

                GPO, Salt, JumpCloud, AzureAD, etc.

                You are below even Microsoft's long stated minimum use case threshold.

                gjacobseG Mike DavisM 2 Replies Last reply Reply Quote 4
                • C
                  castellanosjc
                  last edited by

                  You can do such a thing through VPN tunnels, I have one massive Domain Controller and through VPN i provide those group policies to them. Allowing small business to get the benefit without having the expense. Also what concerns are they having about HIPPA ? Encryption can be done on each station and if you are providing a network share, I believe Ike V2 is HIPPA compliant and encrypting the server also provides that compliance.

                  1 Reply Last reply Reply Quote 0
                  • Mike DavisM
                    Mike Davis @travisdh1
                    last edited by

                    @travisdh1 said in domain controller in the cloud for small office?:

                    If they feel they must have the functionality available, why not use Azure Domain Services https://azure.microsoft.com/en-us/services/active-directory-ds/ (Or whatever it happens to be called at the moment, I can't keep track.)

                    That looks like what I'm looking for, but it looks like $111.60/month. Seems like I could spin up a vultr windows server for $27/month.
                    0_1508348621311_AzureAD.png

                    1 Reply Last reply Reply Quote 0
                    • gjacobseG
                      gjacobse @scottalanmiller
                      last edited by

                      @scottalanmiller said in domain controller in the cloud for small office?:

                      @mike-davis said in domain controller in the cloud for small office?:

                      @gjacobse said in domain controller in the cloud for small office?:

                      HIPAA security without it.

                      How do you create a password change policy that gets enforced without a domain controller?

                      GPO, Salt, JumpCloud, AzureAD, etc.

                      You are below even Microsoft's long stated minimum use case threshold.

                      I can see the 'issue' with GPO.. you have to update the GPO per machine (Right?) whereas using a DC, you set the GPO once...

                      I do think that with eight PCs,.. maybe look at the other options..

                      Mike DavisM scottalanmillerS 3 Replies Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403
                        last edited by

                        In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

                        scottalanmillerS 1 Reply Last reply Reply Quote 1
                        • Mike DavisM
                          Mike Davis @gjacobse
                          last edited by

                          @gjacobse said in domain controller in the cloud for small office?:

                          I can see the 'issue' with GPO.. you have to update the GPO per machine (Right?) whereas using a DC, you set the GPO once...
                          I do think that with eight PCs,.. maybe look at the other options..

                          Wouldn't that mean logging on to each machine and creating a local policy to force them to change passwords and then the user would have to do the same thing on the share from the computer acting as the server.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • Mike DavisM
                            Mike Davis @gjacobse
                            last edited by

                            @gjacobse said in domain controller in the cloud for small office?:

                            I can see the 'issue' with GPO.. you have to update the GPO per machine (Right?) whereas using a DC, you set the GPO once...

                            yes.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @gjacobse
                              last edited by

                              @gjacobse said in domain controller in the cloud for small office?:

                              @scottalanmiller said in domain controller in the cloud for small office?:

                              @mike-davis said in domain controller in the cloud for small office?:

                              @gjacobse said in domain controller in the cloud for small office?:

                              HIPAA security without it.

                              How do you create a password change policy that gets enforced without a domain controller?

                              GPO, Salt, JumpCloud, AzureAD, etc.

                              You are below even Microsoft's long stated minimum use case threshold.

                              I can see the 'issue' with GPO.. you have to update the GPO per machine (Right?) whereas using a DC, you set the GPO once...

                              I do think that with eight PCs,.. maybe look at the other options..

                              DC has to do it per machine, just the same.

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @DustinB3403
                                last edited by

                                @dustinb3403 said in domain controller in the cloud for small office?:

                                In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

                                Tie in? Samba does GPO exactly like any other AD does.

                                DustinB3403D 1 Reply Last reply Reply Quote 3
                                • scottalanmillerS
                                  scottalanmiller @Mike Davis
                                  last edited by

                                  @mike-davis said in domain controller in the cloud for small office?:

                                  @gjacobse said in domain controller in the cloud for small office?:

                                  I can see the 'issue' with GPO.. you have to update the GPO per machine (Right?) whereas using a DC, you set the GPO once...
                                  I do think that with eight PCs,.. maybe look at the other options..

                                  Wouldn't that mean logging on to each machine and creating a local policy to force them to change passwords and then the user would have to do the same thing on the share from the computer acting as the server.

                                  That's how AD does it, if AD's system isn't enough, then AD isn't the answer.

                                  1 Reply Last reply Reply Quote 1
                                  • scottalanmillerS
                                    scottalanmiller @Mike Davis
                                    last edited by

                                    @mike-davis said in domain controller in the cloud for small office?:

                                    @gjacobse said in domain controller in the cloud for small office?:

                                    I can see the 'issue' with GPO.. you have to update the GPO per machine (Right?) whereas using a DC, you set the GPO once...

                                    yes.

                                    No, DC is just handling the centralization for you. You can do this with a script, with Jump, with Salt, etc.

                                    1 Reply Last reply Reply Quote 1
                                    • DustinB3403D
                                      DustinB3403 @scottalanmiller
                                      last edited by

                                      @scottalanmiller said in domain controller in the cloud for small office?:

                                      @dustinb3403 said in domain controller in the cloud for small office?:

                                      In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

                                      Tie in? Samba does GPO exactly like any other AD does.

                                      So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

                                      scottalanmillerS PenguinWranglerP 3 Replies Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @DustinB3403
                                        last edited by

                                        @dustinb3403 said in domain controller in the cloud for small office?:

                                        @scottalanmiller said in domain controller in the cloud for small office?:

                                        @dustinb3403 said in domain controller in the cloud for small office?:

                                        In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

                                        Tie in? Samba does GPO exactly like any other AD does.

                                        So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

                                        Nothing I said should lead you to ask that question. I think you are not clear on what GPO is.

                                        DustinB3403D 1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          GPO is handled identically on Samba as it is on MS AD. That alone should answer all questions. Any editor that works with MS AD with work with Samba, no editor can tell the difference, as they are identical.

                                          1 Reply Last reply Reply Quote 1
                                          • scottalanmillerS
                                            scottalanmiller @DustinB3403
                                            last edited by

                                            @dustinb3403 said in domain controller in the cloud for small office?:

                                            @scottalanmiller said in domain controller in the cloud for small office?:

                                            @dustinb3403 said in domain controller in the cloud for small office?:

                                            In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

                                            Tie in? Samba does GPO exactly like any other AD does.

                                            So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

                                            Why would you want this? He has Windows machines to manage, so why avoid the Windows desktop tools in a scenario that only works when you have Windows desktops?

                                            Mike DavisM 1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 1 / 6
                                            • First post
                                              Last post