Best Practices - Active Directory and Domain Controllers for Public / Internet Facing

Hi All,

I am looking for some ideas and steps to put my AD domain for Public / Internet Facing. Appreciate your help in advance.

February 18th, 2015 12:18pm

Hi All,

I am looking for some ideas and steps to put my AD domain for Public / Internet Facing. Appreciate your help in advance.

Free Windows Admin Tool Kit Click here and download it now
February 18th, 2015 12:48pm

It is not a good idea to expose AD domain controller on public network. If you need to support domain clients on Internet, then take a look at Direct Access technology, which provides an automatic and seemless VPN experience to domain clients on Internet. ADFS can be used if you need to provide authentication and authorization  for application access from Internet. For web-applications, ADFS can be used in combination with Application Proxy, which can do an access control check before client's request is forwarded to application server.
February 18th, 2015 1:29pm

Thank you Ahmed & Gleb for your suggestions.

I really do understand the cautions while doing this.

Why I require this, because we have remote user machines, on which I require to apply all policy restrictions which are applied to all domain objects. They have domain ID's. There is no physical connectivity from them with the domain.

Free Windows Admin Tool Kit Click here and download it now
February 18th, 2015 1:41pm

Thank you Ahmed & Gleb for your suggestions.

I really do understand the cautions while doing this.

Why I require this, because we have remote user machines, on which I require to apply all policy restrictions which are applied to all domain objects. They have domain ID's. There is no physical connectivity from them with the dom

February 18th, 2015 2:05pm

if you mean that you will need to apply GPOs on these machines then this is not the way to go. You need to see how to have a site to site VPN or simply use a server on this site and create a n
Free Windows Admin Tool Kit Click here and download it now
February 18th, 2015 2:15pm

It is not a good idea to expose AD domain controller on public network. If you need to support domain clients on Internet, then take a look at Direct Access technology, which provides an automatic and seemless VPN experience to domain clients on Internet. ADFS can be used if you need to provide authentication and authorization  for application access from Internet. For web-applications, ADFS can be used in combination with Application Proxy, which can do an access control check before client's request is forwarded to applicati
February 18th, 2015 2:15pm

Hi All,

I am looking for some ideas and steps to put my AD domain for Public / Internet Facing. Appreciate your help in advance.

If you are asking about best practices then do NOT place AD for public as mentioned before. If you have remote users, they can still accept group policies if they have appropriate infrastructure like VPN available. Otherwise you can start from here:

Free Windows Admin Tool Kit Click here and download it now
February 18th, 2015 4:50pm

if you mean that you will need to apply GPOs on these machines then this is not the way to go. You need to see how to have a site to site VPN or simply use a server on this site and create a n
February 18th, 2015 6:38pm

Thank you guys, allow me to have a look on the articles you posted.
Free Windows Admin Tool Kit Click here and download it now
February 19th, 2015 7:32am

Hi All,

I am looking for some ideas and steps to put my AD domain for Public / Internet Facing. Appreciate your help in advance.

If you are asking about best practices then do NOT place AD for public as mentioned before. If you have remote users, they can still accept group policies if they have appropriate infrastructure like VPN available. Otherwise you can start from here:

February 20th, 2015 7:57am

If you want to expose your AD domains to the Internet just to make them visible, you should consider read-only DCs.

However, if you want to perform AD operations remotely, the best thing probably would be to use third-party web interfaces for AD and put them into a DMZ. 

Free Windows Admin Tool Kit Click here and download it now
February 25th, 2015 3:19am

Thank you for your valuable comments. As of now I am postponing the plan.

Thank you again

February 25th, 2015 6:50am

What service will your public facing AD provides? and to whom?

Free Windows Admin Tool Kit Click here and download it now
February 25th, 2015 6:53am

my intention was to control the workstations located in remote areas in terms of group policy restrictions, but obviously in very secure way after publishing my AD in internet.
February 25th, 2015 7:06am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics