Solved

Slow replication between Domain Controllers and Client PCs - Windows 2003 Active Directory.

Posted on 2007-03-22
3
415 Views
Last Modified: 2013-04-03
I have a two part question regarding expected performance on a Windows 2003 Active Directory domain.  I'll first provide some background info:  We have a large domain; about 5000 users (Win XP, 2000, some Mac OS X).  Two domain controllers set to the default replication interval (15 mins, I think) between each other. Both DC's are Win2003 R2.  Our entire site spans across multiple buildings in the same city connected by gigabit Ethernet.

My first question is pretty simple: Do we have enough DCs (2) for the current size of our user objects (5000)?  What is the "industry standard" ratio for DCs to users?

My second question is a little more complex:  For some reason we are experiencing latency during replication between client PCs and the DC.  That is, when we update a new Group Policy (for instance, elevating a local User account to a local Admin account via GPO), that change can take a good 5 to 10 minutes to go into affect.  Most of the times, we need the user to log off and back on multiple times before they receive the new policy.  We've even tried to have the user manually force a GPUPDATE and do a DNS flush, but it still takes a good while for the new policy to take hold.  This also occurs during Drive Mappings using a GPO login script.  

I'm not sure how many DCs I should have on a network of this size.  And I'm also unsure if Admins out there are "tweaking" the replication settings so that GPOs are applied almost instantaneously between DCs and client computers.

Thanks for your tips and help on this!!
0
Comment
Question by:esckeyrwm
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 70

Accepted Solution

by:
KCTS earned 75 total points
ID: 18771805
Client Group policy is refreshed every 90mins by default GPUPDATE /force can be used to force a refresh of group policy but you need to consider that even when this occurs some policy settings, like those relating to a logon, cannot be applied until the next logon. In the same way a few policies, because of their nature cannot take effect until the next startup.
0
 

Author Comment

by:esckeyrwm
ID: 18772106
Hmm, interesting.... is there a way to change the refresh interval from 90mins to something shorter, like 15mins?  If so, what would be the ramifications in doing so?  Do you think 2 DCs are enogh to handle the load of 5000 users?
0
 
LVL 2

Assisted Solution

by:gabrielaz
gabrielaz earned 50 total points
ID: 18772983
yes yo ucan set the policy refresh rate via group policy iis located under  computer settings ---windows setting-administrative tiemplates---system--group policy-group policy refresh
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are many software programs on offer that will claim to magically speed up your computer. The best advice I can give you is to avoid them like the plague, because they will often cause far more problems than they solve. Try some of these "do it…
This article helps those who get the 0xc004d307 error when trying to rearm (reset the license) Office 2013 in a Virtual Desktop Infrastructure (VDI) and/or those trying to prep the master image for Microsoft Key Management (KMS) activation. (i.e.- C…
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question