Global Domain

One domain

New Forrest with a Single domain or per regions domains

Pros

Already connected to the Azure cloud

Schema is compatible with Exchange on prems or Hybrid

nothing to do in U.S side (Simplification)

Cons

click to edit

New regional domains in existing forrest

Open Questions to

Technical stuff

TBD

ADRAP is required (health state of AD)

Cost of a Migration of Euorpean and Asian Domain might be a problem

Is One Domain hosted in the U.S GDPR compliant or APAC compliant ?

Clean up should be done in AD ES

Do we consider AD contains personnal Datas (EU rules) ?

What about datas stored in Change Auditor (stored in the U.S afterward) ? IP adress identification by Samaccount

What does the law require today?


Today, the EU definition of “personal data” is set out in the Data Protection Directive 95/46/EC. It defines personal data as “any information relating to an identified or identifiable natural person” (Art. 2(a)), and specifically acknowledges that this includes both ‘direct’ and ‘indirect’ identification (for example, you know me by name – that’s direct identification; you describe me as “the Fieldfisher privacy lawyer working in Silicon Valley” – that’s indirect identification)Link Title

click to edit

Does people in Europe need to have admin rights on top level domain ? Is it planned to share responsabilities

What is the DNS Infoblox that should be use ? EMEA already contains a zone forward to ES.AD.ADP.COM (no scynchronizaton of Zones) Zone forward is not compatible with AD

response time for applying GPO Script and so on (Depending of DC spread into the world)

Risk of Black out ?

Account should be impersonnate (making easy GDPR rules)

define a Rasci Matrix including each regions

Synchronization of objects between regions has rules (Time zone and lags). Number of objects

Pros

Keep a regional governance

Solved problems without impacting other regions (on call duty). Upgrade and updates (security patch)

GDPR compliant in EU (expectation)

Cons

business hours presence

Cloud service and hybrid mode ready

Cost of a Migration of Euorpean and Asian Domain might be a problem

respect the split for non EU reisdent administrators

Can people outside EU from different regions could have admin rights or potential rights on EU ressources ?

What informations are stored in the cloud Sync in U.S tenant

it appears that

Should verify to each EU stakeholders and get authoriaztions from

Worker councils

Local HR departement

Legal

How works DR process ?

Strategy shown buy Indian is to use IAAS in AWS why not using Azure ? regions coverage is better.

Respect technical prerequisite for exchange on prems or Hybrid

Don't like the name "ES", "D" should be better

ready to go to office 365

Other GETS Teams

We believe an upgrade to Windows 16 have to be the target

Schema update ?

click to edit