Solved

PDC being used in Windows Server 2003 Enviroment

Posted on 2006-10-24
10
231 Views
Last Modified: 2010-04-18
I have inherited a Windows 2003 server enviroment that is still using a PDC.  It is my understanding that in a 2003 enviroment that there is no need to have a PDC.  How can I move away from this so that all of the DC are created equally?  What are the advantages and dis advantages.
0
Comment
Question by:securitythreat
  • 3
  • 2
  • 2
  • +1
10 Comments
 
LVL 39

Expert Comment

by:redseatechnologies
Comment Utility
Hi securitythreat,

In 200x it is that way already - what do you mean "is still using a PDC"?

-red
0
 
LVL 95

Expert Comment

by:Lee W, MVP
Comment Utility
Either you have an NT4 domain with NO 2003 domain controllers OR you have a 2003 domain with no NT4 PDC.  There is simply NO PDC in a 2003 (Active Directory) domain.  You don't "move away" from it.
0
 
LVL 26

Accepted Solution

by:
MidnightOne earned 250 total points
Comment Utility
securitythreat:

In a Windows NT domain, there is a PDC (the only read-write copy of the security database) and BDCs (read-only copies).

In Windows 2000 and later domains, there is no PDC - there is however a PDC Emulator FSMO that performs a lot of the same functions.

If you have a Windows NT PDC -and- a Windows 2003 domain controller on the same domain, there's --going-- to be problems.

With all THAT said, you can still have a Windows NT domain and Windows 2003 servers that aren't domain controllers and there won't be (many) problems.

HTH

MidnightOne
0
 
LVL 1

Author Comment

by:securitythreat
Comment Utility
Then what writes are transferred when the primary server crashed?
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 95

Expert Comment

by:Lee W, MVP
Comment Utility
How do you define primary server?

MidnightOne, in my opinion, incorrectly suggested (intentionally or not) the PDC Emulator is equal to the PDC.  IT is not.  There is NO PDC.  There are 5 FSMO roles that COULD be distributed over 5 servers.  If you did that which would you call the "PDC"?  EVERYTHING is a DC.  And 1-5 DCs hold the FSMO roles.  By default, the first DC to run 2000/2003 (Active Directory) is the system with all 5 FSMO roles.

You MUST have FSMO masters on your domain - so in that respect, you CANNOT have all DCs created equal... and you don't want, nor need, more than 2 DCs per site.
0
 
LVL 26

Expert Comment

by:MidnightOne
Comment Utility
leew:

While the PDC Emulator FSMo isn't equal to a PDC under WinNT, and despites MS's claim to the contrary, I've yet to see a domain function even moderately well when the DC with the PDC Emulator role failed.

*shrugs*

MidnightOne
0
 
LVL 39

Assisted Solution

by:redseatechnologies
redseatechnologies earned 250 total points
Comment Utility
I agree with you MidnightOne,

>>MidnightOne, in my opinion, incorrectly suggested (intentionally or not) the PDC Emulator is equal to the PDC

Where did you suggest that?  I cannot see you say that at all!  What you said, was as follows;

>>In Windows 2000 and later domains, there is no PDC - there is ***however a PDC Emulator FSMO that performs a lot of the same functions***

Which is correct.

Petri agrees with us both...

http://www.petri.co.il/understanding_fsmo_roles_in_ad.htm

-red
0
 
LVL 95

Expert Comment

by:Lee W, MVP
Comment Utility
I never said the PDC emulator wasn't similar.  My feeling was that MidnightOne didn't clarify enough how different the PDC emulator in AD and the PDC in an NT4 domain differed in his original post.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
This video discusses moving either the default database or any database to a new volume.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now