Solved

How many DC's needed for my domain.

Posted on 2008-06-13
8
184 Views
Last Modified: 2010-05-18
I've started with a company who has about 60 users, and are setup with two domains in their forrest (Parent and Child).  They run 5 DC's total 2 in the parent and 3 in the child.  I'm hoping to lessen the amount of servers they use here however I'm being told that it is essential to the stability of the network that we reamain using 5 dc's according to my predecessor.   What I believe he may have been reffering to was in regards to the FSMO roles and not having the infastructure master on the same dc as a global catalog server which wouldn't be the case.  Are their any other reasons why this would be?  If more info is needed please let me know.

Thanks,
0
Comment
Question by:rkroger
  • 3
  • 2
8 Comments
 
LVL 58

Expert Comment

by:tigermatt
ID: 21780622
If they've got so few users, then there is no gain by separating any resources into their own child domain. I would first start by transitioning from the child domain back to the parent domain, then completely removing the child domain from the network. That will give you 1 single Active Directory domain to play with - much better for a small 60 user environment. I've worked on domains of 2000+ users where they only have one Active Directory domain - the use of subdomains is really only good in very large corporate environments with thousands of users and computers.

In a single-domain environment, you can place all the FSMO roles on the same server as the Global Catalog role. Even in a multiple domain environment, you would only need a second server to move the Infrastructure role to - I guess the third in the parent domain is simply so you can have two Global Catalogs for resilience but still have somewhere to run the Infrastructure Master Operations role from. If you rid yourself of the child domain though, I would say two DCs would probably be enough for that amount of users. 5 DCs in that environment, while it adds lots of resilience, it's probably too much maintenance for you particularly looking at the size of the network. They could easily be put to use as Exchange, SQL servers or file and print servers, without running the DC roles and therefore much more effectively.

I've got clients with 800 user networks who only have 2 - 3 DCs -- it's a good idea for any more than a few users to have more than one DC for resilience, but five for 60 users is overkill.
0
 

Author Comment

by:rkroger
ID: 21780711
Thanks for the quick response.

Totally agree with you, I've already made mention that  the current setup is overkill and want to move to a single domain enviroment.  Unfortunately it's not in their plans for this year.  I thought I could lighten my load a bit by reducing it to four servers but they are convinced their is a need for 5.  The only thing I could really find was that you can't have your GC and Infastructure on the same dc.  Also I should mention we use a data center and 2 of the dc's of the child domain sit over here in our office.  Could that have anything to do with needing the 5 dc's?

(Sorry I'm new to multiple domain infastructure)
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 125 total points
ID: 21780815
I think there are 5 DCs for the following reasons:

a) You cannot place the Infrastructure Master FSMO operations role on the same server as a Global Catalog server, when there is more than one domain (it's fine in a single-domain environment);
b) It is nice to have resilience.

As a result, the parent domain has 3 DCs - 2 of them probably act as Global Catalog servers, giving resilience. There must therefore be another non-GC DC which is acting as the Infrastructure Master role holder. The child domain then again has 2 DCs for resilience.

I've no idea why they've used a child domain for the office and made it a child of the domain on DCs in the data centre. The correct way to do it would be to just add another site into Active Directory Sites and Services on the parent domain, configure the IP subnet correctly, and then perhaps bring up a DC in the office which is just an additional domain controller for the *parent* domain. There's no need to use a child domain for a branch office - that's just complicating matters beyond what is necessary!

If you still want total resilience and they aren't going to migrate away from the parent/child domain environment, then I think looking at this 5 DCs are going to be required. I guess one of the DCs in the parent domain which is acting as a Global Catalog is unnecessary - but demoting it would only leave one Global Catalog server in that domain.

Once you migrate away from the child domain scenario you should get away with 2 DCs, though. As you can see, this is just one of the many reasons why child domains are not feasible for small businesses and small networks - they just require too many servers to function correctly.

-tigermatt
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 95

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 125 total points
ID: 21781250
Multiple domains makes little sense for most offices.

As for multiple Domain Controllers, I recommend TWO DCs per site.  Any more is excessive.  If the predecessor says you need 5, then ask him WHY?  What's his logic?  Maybe there's something we're not aware of that is unique to your environment.  
0
 

Author Comment

by:rkroger
ID: 21781405
Maybe it doesn't matter but it's only 2 dc's in the parent and 3 in the child.  See I thought that if in the child domain i had on dc1 RID and PDC and have it be a Global Catalog.  On dc2 have it be the Infastructure Master and then eliminate the 3rd DC.  I understand some resiliance will be lost but we wouldn't loose functionality on our network.
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 21781438
Yes that would certainly work. Don't forget the other roles you need though - they are the PDCe, RID Naming Master, Infrastructure Master, Schema Master and Domain Naming master. It's just the Infrastructure master role which shouldn't be on a GC - other than that it's really up to you. You could in theory have one DC acting as a GC in the child, then have all the FSMO roles on the other DC which isn't a GC. Alternatively, you could have all 4 FSMO roles on the GC DC and just the infrastructure master on the non-GC DC.

Both of these would work.
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
why user can't see mapped share folder 8 42
Barracuda Backup Server 5 28
Event ID: 2005 / Source: Microsoft-Windows-PerfNet 4 68
Connecting two servers 30 75
I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now