Solved

How many DC's needed for my domain.

Posted on 2008-06-13
8
187 Views
Last Modified: 2010-05-18
I've started with a company who has about 60 users, and are setup with two domains in their forrest (Parent and Child).  They run 5 DC's total 2 in the parent and 3 in the child.  I'm hoping to lessen the amount of servers they use here however I'm being told that it is essential to the stability of the network that we reamain using 5 dc's according to my predecessor.   What I believe he may have been reffering to was in regards to the FSMO roles and not having the infastructure master on the same dc as a global catalog server which wouldn't be the case.  Are their any other reasons why this would be?  If more info is needed please let me know.

Thanks,
0
Comment
Question by:rkroger
  • 3
  • 2
8 Comments
 
LVL 58

Expert Comment

by:tigermatt
ID: 21780622
If they've got so few users, then there is no gain by separating any resources into their own child domain. I would first start by transitioning from the child domain back to the parent domain, then completely removing the child domain from the network. That will give you 1 single Active Directory domain to play with - much better for a small 60 user environment. I've worked on domains of 2000+ users where they only have one Active Directory domain - the use of subdomains is really only good in very large corporate environments with thousands of users and computers.

In a single-domain environment, you can place all the FSMO roles on the same server as the Global Catalog role. Even in a multiple domain environment, you would only need a second server to move the Infrastructure role to - I guess the third in the parent domain is simply so you can have two Global Catalogs for resilience but still have somewhere to run the Infrastructure Master Operations role from. If you rid yourself of the child domain though, I would say two DCs would probably be enough for that amount of users. 5 DCs in that environment, while it adds lots of resilience, it's probably too much maintenance for you particularly looking at the size of the network. They could easily be put to use as Exchange, SQL servers or file and print servers, without running the DC roles and therefore much more effectively.

I've got clients with 800 user networks who only have 2 - 3 DCs -- it's a good idea for any more than a few users to have more than one DC for resilience, but five for 60 users is overkill.
0
 

Author Comment

by:rkroger
ID: 21780711
Thanks for the quick response.

Totally agree with you, I've already made mention that  the current setup is overkill and want to move to a single domain enviroment.  Unfortunately it's not in their plans for this year.  I thought I could lighten my load a bit by reducing it to four servers but they are convinced their is a need for 5.  The only thing I could really find was that you can't have your GC and Infastructure on the same dc.  Also I should mention we use a data center and 2 of the dc's of the child domain sit over here in our office.  Could that have anything to do with needing the 5 dc's?

(Sorry I'm new to multiple domain infastructure)
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 125 total points
ID: 21780815
I think there are 5 DCs for the following reasons:

a) You cannot place the Infrastructure Master FSMO operations role on the same server as a Global Catalog server, when there is more than one domain (it's fine in a single-domain environment);
b) It is nice to have resilience.

As a result, the parent domain has 3 DCs - 2 of them probably act as Global Catalog servers, giving resilience. There must therefore be another non-GC DC which is acting as the Infrastructure Master role holder. The child domain then again has 2 DCs for resilience.

I've no idea why they've used a child domain for the office and made it a child of the domain on DCs in the data centre. The correct way to do it would be to just add another site into Active Directory Sites and Services on the parent domain, configure the IP subnet correctly, and then perhaps bring up a DC in the office which is just an additional domain controller for the *parent* domain. There's no need to use a child domain for a branch office - that's just complicating matters beyond what is necessary!

If you still want total resilience and they aren't going to migrate away from the parent/child domain environment, then I think looking at this 5 DCs are going to be required. I guess one of the DCs in the parent domain which is acting as a Global Catalog is unnecessary - but demoting it would only leave one Global Catalog server in that domain.

Once you migrate away from the child domain scenario you should get away with 2 DCs, though. As you can see, this is just one of the many reasons why child domains are not feasible for small businesses and small networks - they just require too many servers to function correctly.

-tigermatt
0
Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

 
LVL 95

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 125 total points
ID: 21781250
Multiple domains makes little sense for most offices.

As for multiple Domain Controllers, I recommend TWO DCs per site.  Any more is excessive.  If the predecessor says you need 5, then ask him WHY?  What's his logic?  Maybe there's something we're not aware of that is unique to your environment.  
0
 

Author Comment

by:rkroger
ID: 21781405
Maybe it doesn't matter but it's only 2 dc's in the parent and 3 in the child.  See I thought that if in the child domain i had on dc1 RID and PDC and have it be a Global Catalog.  On dc2 have it be the Infastructure Master and then eliminate the 3rd DC.  I understand some resiliance will be lost but we wouldn't loose functionality on our network.
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 21781438
Yes that would certainly work. Don't forget the other roles you need though - they are the PDCe, RID Naming Master, Infrastructure Master, Schema Master and Domain Naming master. It's just the Infrastructure master role which shouldn't be on a GC - other than that it's really up to you. You could in theory have one DC acting as a GC in the child, then have all the FSMO roles on the other DC which isn't a GC. Alternatively, you could have all 4 FSMO roles on the GC DC and just the infrastructure master on the non-GC DC.

Both of these would work.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
RAID Card RS3WC080 Will Not Start Code 10 5 58
Server 2016 installation on Dell r720 12 66
DNS/WINS in a domain 10 39
Recomended server racks 3 17
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
More or less everybody in the IT market understands the basics of Networking, however when we start talking about Storage Networks, things get a bit dizzier, and this is where I would like to help.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question