AFP548

Active Directory Schema upate versus “Magic Triangle”

Hi All, I know this has probably been asked a million times (and I have endeavoured to read everything I can about this) but I am still not sure what the best course of action is. I administer an Active Directory environment at a school and up until now we have been a pure Microsoft/AD shop (with about 500 PCs). Starting next year we are implementing (for the first time) a 1:1 laptop program for all staff and students and we have chosen Apple Macs as the platform. There will be approximately 1000 Macs. I have read everything that I have been able to get my hands on but I am still unsure about a clear direction between going with an OD server and a "Magic Triangle" versus extending our AD schema. I have no issue with extending our AD schema, nor do I have any issue with adding an OD server - so from my point of view I wouldn't choose one method or the other based on wanting to minimise server numbers or because of a reluctance to extend the AD schema. I want to pick the best method from a technical and supportability point of view. I have done as much reading as I can and come up with the following list of reasons to choose one over the other. Please correct me if you disagree! Reasons to extend AD schema: 1. Single directory 2. Less complicated 3. Cheaper as no OD server required (but as I stated above, this is not an issue for us) Reasons to add OD server: 1. Potentially more supportable (??) - I am not even sure this is true, but I imagine that from an Apple point of view it may be easier to get support from Apple if I can demonstrate an issue between a Mac OS X client and an OD server, rather than trying to get support for an AD issue. I also assume that as Apple releases new patches and versions that they test the integration between OS X Client and OD quite extensively - which they may not do with AD. 2. Unknown future changes (??) - This is another one I am not sure about, but let me try and explain what I mean. I am thinking that in the future as Mac OS X 10.7, 10.8, 10.9 etc are released that Apple could add features to OD and OS X which may require an OD server in a similar way that the Microsoft client and AD are very tightly integrated. It's possible Apple will add completely new features which rely on OD and we find ourselves having to add an OD server anyway. If this was the case, we would wish we had used OD in the first place. 3. Support for Computer Groups (AD integration only supports Computer Lists) 4. Microsoft will release their own patches which go on our domain controllers and new server OSes in the future which will upgrade AD. The fact that our MCX configuration lives in AD may add complication when it comes to upgrading to these newer versions. 5. No AD schema update required (but as I stated above, this is not an issue for us) I am not even sure that some of these are relevant. The OD list seems longer but they are less "solid" reasons and mostly based on "what ifs". Using AD is obviously quite compelling as 1 directory service has to be better than 2! :) Does Apple have an official "recommended position" on which method is better to use? I know that their White Papers and Online Seminars show how to do both but maybe they have a preferred method. What do AFP forum users recommend? Any advice appreciated! Cheers, David
Exit mobile version