Information Technology Policy: Active Directory Architecture
Information Technology Policy: Active Directory Architecture
Information Technology Policy: Active Directory Architecture
1. Purpose
The purpose of this Information Technology Policy (ITP) is to establish policy
regarding the Commonwealth's Microsoft Active Directory infrastructure.
2. Scope
This Information Technology Policy (ITP) applies to all departments, boards,
commissions and councils under the Governor’s jurisdiction. Agencies not under
the Governor’s jurisdiction are strongly encouraged to follow this ITP.
3. Policy
The commonwealth's Office of Administration/Office for Information Technology
(OA/OIT) provides Active Directory services for agencies under the governor's
jurisdiction. This ITP addresses the Active Directory infrastructure that has been
established for agency use within this environment.
• The CWOPA forest is to be used for internal resources such as, but not
limited to, employee security principles (user accounts), security and
distribution groups, workstations, servers, Exchange servers, and all objects
or services required to support the commonwealth's standard desktop
environment. Only intranet accounts will be granted access to this forest and
ITP-APP030 – Active Directory Architecture
• All agencies under the governor's jurisdiction are to maintain their intranet
user accounts (security principles and distribution groups) and resources
(Windows workstations, Windows servers, printers, and other related
peripherals) as members of the CWOPA (PA.LCL) forest. This design is known
as the Consolidated Forest Architecture; and is illustrated in Figure 1 below.
Page 2 of 5
ITP-APP030 – Active Directory Architecture
• In addition to the CWOPA and APPS Forests which OA/OIT maintains for the
Consolidated Forest Architecture, agencies may have an agency-specific
resource forest. The purpose of the resource forest is to contain all agency
resources (Windows workstations, Windows servers, printers, and other
related peripherals) and to isolate them from management or access by the
CWOPA enterprise administrators, reducing potential security breaches.
(See Figure 2.)
• All agencies with a resource forest are to maintain their intranet user
accounts (security principles and distribution groups) in the CWOPA (PA.LCL)
forest.
Page 3 of 5
ITP-APP030 – Active Directory Architecture
In the event an agency chooses to seek an exemption, for reasons such as the
need to comply with requirements for a federally mandated system, a request
for waiver may be submitted via the ITP-BUS004 – IT Waiver Review Process.
Requests are to be entered into the COPPAR Tool located at coppar.oa.pa.gov/.
Agency CIO approval is required.
OA/OIT will review the request and schedule discussions with agency
representatives to further understand the request and work collaboratively with
the requesting agency to determine the best architecture for the Commonwealth
that meets all necessary requirements.
Waiver Approval:
If a waiver request has been approved, the agency will ensure the following:
• The agency resource forest is to follow the technical specifications set forth
for the CWOPA forest and adhere to all enterprise standards.
• The agency resource forest is to be subject to the specifications set forth for
the commonwealth's identity management infrastructure. This includes the
provisioning and maintenance of user accounts as well as the maintenance of
authorizations assigned to those accounts.
Page 4 of 5
ITP-APP030 – Active Directory Architecture
6. Authority
• Executive Order 2011-05, Enterprise Information Technology Governance
Page 5 of 5