Domain Controllers (Production - Non-Production Test environment)

Ahmed Essam 140 Reputation points
2025-02-10T09:34:35.22+00:00

Hello Microsoft Community,

I’m seeking some recommendations regarding the configuration of Domain Controllers for our production and non-production test environments.

Currently, both our production and non-production (test) environments are within the same forest. As our environment grows and the need for separation between production and non-production increases, we are evaluating our options for re-structuring this setup. Specifically, we would like to understand the best approach for isolating the non-production environment while still allowing for appropriate access between the two environments if needed.

Here are the options we are considering:

Creating a New Forest for Non-Production – We are considering creating a completely separate forest for non-production and establishing a forest trust between the production and non-production environments. Is this recommended, and are there any best practices for implementing forest trusts in this context?

Creating a New Tree or Child Domain in the Current Forest – Alternatively, we could create a new tree or child domain under the current forest. This would potentially provide easier management but might not offer as much isolation as a separate forest. What are the trade-offs here in terms of security, management, and scalability?

We would greatly appreciate any insights or recommendations from others who have dealt with similar scenarios or have expertise in managing domain environments with both production and non-production systems.

Thank you in advance for your help!

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,899 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Thameur-BOURBITA 35,681 Reputation points
    2025-02-25T22:42:41.17+00:00

    Hi @Ahmed Essam

    The test environment should be completely separate from production, in order to avoid impacting production during testing.

    What I recommend is to install a new forest on a network completely separate from production and not to configure a trust relationship between the two environments.


    Please don't forget to accept helpful answer



Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.