Global Domain
One domain
New Forrest with a Single domain or per regions domains
Pros
Already connected to the Azure cloud
Schema is compatible with Exchange on prems or Hybrid
nothing to do in U.S side (Simplification)
Cons
click to edit
New regional domains in existing forrest
Open Questions to
Technical stuff
TBD
ADRAP is required (health state of AD)
Cost of a Migration of Euorpean and Asian Domain might be a problem
Is One Domain hosted in the U.S GDPR compliant or APAC compliant ?
Clean up should be done in AD ES
Do we consider AD contains personnal Datas (EU rules) ?
What about datas stored in Change Auditor (stored in the U.S afterward) ? IP adress identification by Samaccount
What does the law require today?
Today, the EU definition of “personal data” is set out in the Data Protection Directive 95/46/EC. It defines personal data as “any information relating to an identified or identifiable natural person” (Art. 2(a)), and specifically acknowledges that this includes both ‘direct’ and ‘indirect’ identification (for example, you know me by name – that’s direct identification; you describe me as “the Fieldfisher privacy lawyer working in Silicon Valley” – that’s indirect identification)Link Title
click to edit
Does people in Europe need to have admin rights on top level domain ? Is it planned to share responsabilities
What is the DNS Infoblox that should be use ? EMEA already contains a zone forward to ES.AD.ADP.COM (no scynchronizaton of Zones) Zone forward is not compatible with AD
response time for applying GPO Script and so on (Depending of DC spread into the world)
Risk of Black out ?
Account should be impersonnate (making easy GDPR rules)
define a Rasci Matrix including each regions
Synchronization of objects between regions has rules (Time zone and lags). Number of objects
Pros
Keep a regional governance
Solved problems without impacting other regions (on call duty). Upgrade and updates (security patch)
GDPR compliant in EU (expectation)
Cons
business hours presence
Cloud service and hybrid mode ready
Cost of a Migration of Euorpean and Asian Domain might be a problem
respect the split for non EU reisdent administrators
Can people outside EU from different regions could have admin rights or potential rights on EU ressources ?
What informations are stored in the cloud Sync in U.S tenant
it appears that
Should verify to each EU stakeholders and get authoriaztions from
Worker councils
Local HR departement
Legal
How works DR process ?
Strategy shown buy Indian is to use IAAS in AWS why not using Azure ? regions coverage is better.
Respect technical prerequisite for exchange on prems or Hybrid
Don't like the name "ES", "D" should be better
ready to go to office 365
Other GETS Teams
We believe an upgrade to Windows 16 have to be the target
Schema update ?
click to edit