Solved

W2K3 domain controller offline temporarily

Posted on 2008-06-15
3
3,540 Views
Last Modified: 2010-05-19
I am jointly responsible for administering and managing a Windows 2003 Active Directory environment, comprsing around 200 servers, around 20 of which are domain controllers. 3 domains exist within the forest, 2 child domains and one root domain.  

One of the domain controllers needs to be powered off for around a week and management do not want to dcpromo the box, for various reasons.  I have been asked to investigate how long a domain controller can theoretically be powered off for before problems could oocur.  I am well aware of the tombstone lifetime and also have a fairly good understanding of the replication process.  However, what else could affect this scenario?  Could the machine be powered off for a month for example?  I appreciate that replication could hammer the machine once powered back on but I just need a few more bits of info.  By the way, no FSMO roles exist on this domain controller.

Thanks in advance.
0
Comment
Question by:gkeane
3 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 21789601
I think that 30 days is max, since after that the AD data will not be accepted via replication , so that is your max.


I hope this helps !
0
 

Author Comment

by:gkeane
ID: 21789623
I wasn't aware of that limit, cheers.  What is the process/mechanism that controls this?  Is it the KCC?
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 125 total points
ID: 21791224
There is a limit to the length of time a Domain Controller to be offline. I always thought it was 30 days as well, but it looks like, according to http://support.microsoft.com/kb/198793/, that in Windows Server 2003, this limit has been increased to 180 days.

This limit is all related to the garbage collection process in Active Directory.

You might want to review http://technet2.microsoft.com/windowsserver/en/library/ab0ad0e9-2f7a-417c-a312-676c0fc9cd771033.mspx?mfr=true which details a checklist of things to do before you take a DC offline for a long period of time.

-tigermatt
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question