www.mvatcybernet.com
SUPPORTED ACTIVE DIRECTORY
TOPOLOGIES BY LYNC 2013
LYNC SERVER 2013Lync Server 2013 supports the same Active Directory Domain Services topologies as Microsoft Lync Server 2010 and Microsoft Office
Communications Server 2007 R2. The following topologies are supported:
SINGLE FOREST WITH SINGLE DOMAIN
SINGLE FOREST WITH A SINGLE TREE AND MULTIPLE DOMAINS
SINGLE FOREST WITH MULTIPLE TREES AND DISJOINTNAMESPACES
MULTIPLE FORESTS IN A CENTRAL FOREST TOPOLOGY
MULTIPLE FORESTS IN A RESOURCE FOREST TOPOLOGY
The following figure identifies the icons used in the illustrations in this section.
SINGLE FOREST, SINGLE DOMAIN
The simplest Active Directory Topology supported by Lync Server, a Single
www.mvatcybernet.com
The following figure illustrates a Lync Server deployment in a Single Domain Active Directory Topology.
SINGLE FOREST, MULTIPLE DOMAINS
Another Active Directory Topology supported by Lync Server is a Single Forest that consists of a Root Domain and one or more Child Domains. In this type of Active Directory Topology, the Domain where you create Users can be different from the Domain where you deploy Lync Server. However, if you deploy a Front End Pool, you must deploy all the Front End Servers in the Pool within a Single Domain.
Lync Server Support for Windows Universal Administrator
Groups enables Cross-Domain Administration.
The following figure illustrates a deployment in a Single Forest with Multiple Domains. In this figure, a user icon shows the Domain where
the User Account is Homed, and the arrow points to the Domain where the
Lync Server Pool resides. User Accounts include the following:
USER ACCOUNTS WITHIN THE SAME DOMAIN AS THE LYNCSERVER POOL
USER ACCOUNTS IN A DIFFERENT DOMAIN FROM THE LYNCSERVER POOL
USER ACCOUNTS IN A CHILD DOMAIN OF THE DOMAIN WITH THEwww.mvatcybernet.com
SINGLE FOREST, MULTIPLE TREES
A Multiple-Tree Forest Topology consists of Two or More Domains that
define Independent Tree Structures and Separate Active Directory
Namespaces.
The following figure illustrates a Single Forest with Multiple Trees. In this figure, a user icon shows the Domain where the User Account is Homed, a solid line points to a Lync Server Pool that resides in the same or a
different Domain, and a dashed line points to Lync Server Pool that resides in a different Tree. User Accounts include the following:
USER ACCOUNTS WITHIN THE SAME DOMAIN AS THE LYNCwww.mvatcybernet.com
USER ACCOUNTS IN A DIFFERENT DOMAIN FROM (BUT THE SAMETREE AS) THE LYNC SERVER POOL
USER ACCOUNTS IN A DIFFERENT TREE FROM THE LYNC SERVERPOOL
MULTIPLE FORESTS, CENTRAL FOREST
Lync Server supports Multiple Forests that are configured in a Central Forest Topology. Central Forest Topology use Contact Objects in the Central Forest to represent Users in the other Forests.
The Central Forest also Hosts User Accounts for any Users in this Forest. A Directory Synchronization Product, such
as Microsoft Identity Integration Server
www.mvatcybernet.com
or M icrosoft Identity Lifecycle M anager (ILM) 2007 F eature Pack 1 (FP1), manages the life cycle of user accounts within the organization:
When a New User Account is created in one of the Forests or a User Account is Deleted from a Forest, the Directory Synchronization
Product Synchronizes the Corresponding Contact in the Central Forest.
A CENTRAL FOREST HAS THE FOLLOWING ADVANTAGES:
SERVERS RUNNING LYNC SERVER ARE CENTRALIZED WITHIN A SINGLE FOREST.
USERS CAN SEARCH FOR AND COMMUNICATE WITH OTHER USERS IN ANY FOREST.
USERS CAN VIEW PRESENCE OF OTHER USERS IN ANY FOREST.
THE DIRECTORY SYNCHRONIZATION PRODUCT AUTOMATES THE ADDITION AND DELETION OF CONTACT OBJECTS IN THE CENTRAL FOREST AS USER ACCOUNTS ARE CREATED OR REMOVED.
The following figure illustrates a central Forest Topology.
In this figure, there are Two-Way Trust Relationships between
the Domain that hosts Lync Server, which is in the Central Forest, and each User-Only Domain, which is in a Separate Forest. The Schema in
www.mvatcybernet.com
MULTIPLE FORESTS, RESOURCE FOREST
In a Resource Forest Topology, one Forest is dedicated to running Server Applications, such as Microsoft Exchange Server and Lync Server. The Resource Forest hosts the Server Applications and a synchronized representation of the Active User Object, but it does not contain logon-enabled user accounts. The resource Forest Acts as a Shared Services Environment for the other Forests where User Objects Reside.
The User Forests have a Forest-Level Trust Relationship with the Resource Forest.
When you deploy Lync Server in this type of Topology, you create one Disabled User Object in the Resource Forest for every User Account in the User Forests.
If Microsoft Exchange is already deployed in the Resource Forest, the Disabled User Accounts might already exist.
A Directory Synchronization Product, such as Microsoft Identity Integration Server
www.mvatcybernet.com
or Microsoft Identity Lifecycle M anager (ILM) 2007 F eature Pack 1 (FP1), manages the life cycle of user accounts within the organization:
When a New User Account is created in one of the User Forests or a User Account is Deleted from a Forest, the Directory Synchronization Product Synchronizes the corresponding User Representation in the Resource Forest.
This Topology can be used to Provide a Shared
Infrastructure for Services in Organizations that Manage Multiple Forestsor to separate the Administration of Active Directory Objects from
other Administration. Companies that need to isolate Active Directory Administration for Security reasons often choose this Topology.
This Topology provides the benefit of limiting the need to extend the Active Directory Schema to a Single Forest (that is, the Resource Forest).
The following diagram illustrates a Resource Forest Topology.