USGS Active Directory Bureauwide Architecture
Cost &
Resulting Benefit Analysis
Each USGS office is isolated from most of the rest of the Bureau. Remember the first time you visited one of your key discipline field offices? Your laptop wasn’t set up to work on that office’s local network setup. You couldn’t print to local printers, couldn’t access the USGS internal Web sites, you couldn’t get access to the file servers back at your home office where you keep you spreadsheets and other documents that your home office staff share. By asking a lot of questions, you found out that if you could schedule your host offices’ helpdesk staff to reconfigure your laptop, and add you to their list of local users, then you at least could use their printers and access the USGS Web sites.
We don’t know what we own without doing manual “data calls”. Twice in the past year all of the USGS offices have been asked to take an inventory of software licenses we own so that we could get credit for what we already bought, so we could take advantage of enterprise bulk licensing discounts. It took two or more employee months collectively each time to either do a local “data call” using email (which added to hours spent getting the answer, since now everyone had to check their computer and email their response for someone to summarize) or worse yet, a helpdesk staff member visiting each desktop in the Bureau to see what was loaded on each machine. Even with all this extra work, the potential savings in licensing costs through “credits” made it seem like a good investment of time, but it could have been automated.
Once the enterprise licenses are bought at volume savings that sometimes are as great as 50%, the USGS is then always faced with how the new software is going to be deployed. So far, we’ve duplicated CD’s and mailed them to 100 offices with instructions for “trickle-down” distribution to small offices, or we’ve emailed instructions to all 400+ USGS offices on how they can buy their own discs, and in some cases distributed instructions on how to install and configure new software… hoping that by informing about 25% of USGS offices, we’ll have ensured that at least those locations will be installed consistently with all the necessary security protection in place. This is a slow “hit and miss” approach that requires a lot of redundant work at each office nationwide.
Computer viruses seem to “come out of no-where” anymore with a regularity that is about the only one thing we can be sure of with regard to viruses. The USGS has purchased a bureauwide anti-virus software solution for employees to install on servers and desktops, but the software is only as good as how frequently it is updated at the desktop with protection against new viruses. Right now, each user is expected to routinely load anti-virus updates from USGS Web sites where the updates are posted. Less than 10% of USGS desktops load these anti-virus protection files weekly, while new viruses make the rounds several times a week looking for desktops such as ours which haven’t got the most recent anti-virus protection in place.
These are just a few examples of how the USGS has been managing its desktop and server hardware and software manually without exploiting common automation tool technology. Technology that enables organizations to do these same time consuming jobs faster, consistently everywhere in the Bureau, and with greater efficiencies and savings in staff hours than most of us have resigned ourselves to expect in an increasingly complex world of desktops and servers.
This proposal for a USGS Active Directory Architecture is for how to do exactly that; automate tedious processes, ensure our desktops and servers are protected, and provide the most up-to-date versions of software and “patches” to all offices, no matter what discipline or size they may be. All this while saving staff time, and giving our regional and local system administrators tools they can use to ensure a USGS that works together as a single bureau, rather than a collection of independent computer networks disconnected from one another.
Bureauwide, senior computer system administrators envision an IT infrastructure that facilitates the exchange of ideas and earth science data between USGS disciplines, government agencies, and the public. There is a shared commitment to a highly reliable enterprise computing environment that enables access to information and computer resources in a collaborative manner that is effective, efficient, and secure.
The USGS Windows2000 Investigation Team (WIT) was commissioned by the Information Council in 1999 to determine the viability of Windows 2000 becoming a critical component of the USGS infrastructure to achieve an integrated USGS computing infrastructure. After conducting testing and prototyping, the WIT presented their findings at the June 2000 ITEM2000 USGS IT meeting. The WIT recommended that Windows2000 be pursued as a solution that meets the USGS’s needs for a shared computing environment. Following the recommendation of the WIT, a bureau Lighthouse Project was initiated in a no-cost partnership with Compaq and Microsoft to create an operational prototype to test and validate the Microsoft® Active Directory®, Dynamic DNS, Enhanced Security, and many other features that offered solutions towards a shared USGS infrastructure.
The Lighthouse Project completed a 5-month prototype and delivered its recommendations to the senior information managers and the Geographic Information Officer on May 18, 2001. Their recommendation was that the USGS should proceed with implementation of a shared architecture built based on a “placeholder” model, where there is an empty “root” to form a DOI structure that allows for possible future growth (other DOI bureaus, etc.), and a main USGS domain linked to it where all USGS information would be located with local domains termed “Organizational Unit (OU)” which would be under the control of the current USGS local system administrators.
As the bureau continues its transformation into an integrated science agency, the need for an easier and more efficient way to manage and secure our computer infrastructure as a collaborative environment becomes critical. Currently, there are over 600 servers running Windows NT4 and Windows 2000 Server/Advanced Server in the USGS. There are also about 13,000 desktops/laptops running Win9x, NT4, and Windows 2000 Professional. A large number of these Windows NT/2000 systems are either in stand-alone mode or are members of isolated NT-based domains that do not recognize or interconnect with other USGS windows domains.
Another major problem with the current USGS Windows NT environment is that each domain or site is uniquely configured and managed to satisfy only local needs. The insular qualities of each environment deters data sharing and impedes consistent reliability, efficient resource management, and effective security. Within the current environment, sharing of resources between projects or sites, synchronizing user accounts, or sharing of information between NT environments anywhere in the Bureau is virtually impossible. Additionally, the distinctness of each NT environment makes interoperability with other Bureau systems difficult or, in some cases, unachievable.
The goal of the 2000 Windows Investigation Team (WIT) and
the follow-on 2001 Lighthouse Project was to investigate existing technologies
that could be integrated into the existing USGS infrastructure to break down
the barriers of communication between sites, disciplines, and
geographies. A unified USGS Windows
2000 Active Directory design will establish an enterprise infrastructure that
all disciplines may use for new Windows 2000 environments. Existing isolated environments based on
earlier versions of Windows NT may be migrated to the new structure at any
time. Moving user accounts, data, and
servers into an enterprise Active Directory infrastructure will ease data
sharing, improve reliability, simplify resource management, and tighten
security.
The foundation for Microsoft’s future technologies is Windows 2000. Existing and future Windows-based IT solutions will require the presence of a Windows 2000 infrastructure to operate. If a bureauwide implementation of Windows 2000 Active Directory does not occur, the existing “stovepipe” NT environments will go ahead and upgrade to Windows 2000 regardless, remaining distinct environments with no ability for improved interoperability. Implementing Active Directory will also provide interoperability, not only for PC desktops, but also for non-Windows clients such as Unix and Mac OS. As the bureau reorganization takes place security is a major concern; the time to change and improve our current NT environment is now. The Lighthouse Team identified this as an urgent need and stated it in their vision statement.
A number of important benefits will be realized as a result of having Active Directory (AD) implemented in the USGS, including:
Costs
Estimating costs for building and operating a shared USGS computing infrastructure is relatively straightforward. The Lighthouse Team developed a 5-year estimate for implementation and operations that includes hardware, software licenses, and staffing, plus a 10% “cushion factor” for rising costs of services. These costs were based on assigning USGS staff to carry out the entire deployment and long-term operations through FY06. Below is a table that summarizes these costs, and estimates for contracting out the day-to-day operations. All FY 2001 costs (except salaries) have already been covered by the Accessible Data Transfer monies assigned to the USGS through Title VIII.
|
|
Microsoft
2000 Active Directory |
|
|
|||
|
Cost Summary |
||||||
|
|
|
|
|
|
|
|
|
|
FY 2001 |
FY 2002 |
FY2003 |
FY2004 |
FY2005 |
FY2006 |
|
|
Operational Prototype/ Startup |
Operations Years |
||||
|
|
|
|
|
|
|
|
|
Equipment
(Tier 0 & 1 DC) |
230,000 |
50,000 |
50,000 |
25,000 |
25,000 |
230,000 |
|
Equipment
(Tier 2 DC)* |
0 |
400,000 |
0 |
0 |
0 |
0 |
|
Windows
2000 CALs |
114,000 |
0 |
0 |
0 |
75,000 |
75,000 |
|
AD
Support Tools |
120,000 |
13,000 |
13,000 |
13,000 |
13,000 |
13,000 |
|
Supplies
and Materials |
6,000 |
4,000 |
4,000 |
4,000 |
4,000 |
4,000 |
|
Travel |
20,000 |
25,000 |
25,000 |
25,000 |
25,000 |
25,000 |
|
Training
(Bureau Level) |
30,000 |
25,000 |
25,000 |
10,000 |
10,000 |
10,000 |
|
Training
(Site Level) |
|
30,000 |
30,000 |
30,000 |
30,000 |
30,000 |
|
Consulting
Services |
40,000 |
75,000 |
70,000 |
70,000 |
70,000 |
70,000 |
|
|
|
|
|
|
|
|
|
Sub
Totals for Non-Staff Costs |
560,000 |
622,000 |
217,000 |
177,000 |
252,000 |
457,000 |
|
|
|
|
|
|
|
|
|
USGS
Staff Salaries |
150,000 |
500,000 |
500,000 |
500,000 |
500,000 |
500,000 |
|
(assumes no contracting out) |
|
|
|
|
|
|
|
Totals |
710,000 |
1,122,000 |
717,000 |
677,000 |
752,000 |
957,000 |
|
|
|
|
|
|
|
|
Estimated cost to contract out
|
300,000 |
500,000 |
500,000 |
500,000 |
500,000 |
500,000 |
|
In lieu of USGS staff support |
|
|
|
|
||
|
|
|
|
|
|
||
|
*Cost if we
provide USGS field offices with servers
for their node that provides failover for
neighboring offices. |
|
|
Projected
Costs for Five-Years: |
$4,225,000 |
||
|
|
|
|
10%
Cushion |
|
425,500 |
|
|
|
|
|
Projected
Costs for Five-Years: |
4,647,500 |
||
Based on the results of the prototype and this evaluation of the related costs and benefits, it is recommended that the USGS proceed with implementation of a shared architecture built with a single USGS Active Directory domain versus remaining with the status quo where each USGS location will continue to build isolated domains. Although there are costs related to the implementation, these are felt to be well within reason when gauged against the opportunity costs and lost productivity resulting from implementing and managing redundant isolated local systems. Implementation of the USGS shared Active Directory-based architecture would result in the elimination of duplication of effort and saved staff hours.
For further information and detailed results of the prototype, the Lighthouse Project final report can be found online at: http://www.usgs.gov:8888/usgs-teams/IC/IIP/lighthouse_report.doc