Textbook Active Directory setup for remote sites

AD Newbie sorry :-(

I am ready to deploy 12 servers to my remote locations. Can someone give me the textbook setup for AD for these locations. Currently I have 1 domain setup test.local and have all users in that domain in the users folder. What do I need to do to the remote servers so that they replicate only the users for that facility? I am also running exchange under that domain. Can create an OU for each facility and place those users for that facility in the correct OU and replicate only that OU to the remote server?
ccosnerAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

buddholeCommented:
Microsoft etxt: http://technet.microsoft.com/en-us/library/cc787284.aspx
There are several options designing your ad and sites. Easiest way is to have one domain with several sites configured. All DC's replicate their AD databases, including users with each other. The sites must be connected to a main site with a VPN or other connection.
If you're doing 12 sites and you're an AD newbie be careful ! It's important to read much more about this issue to design a correct AD and site topology. Maybe hiring a consultant with practica experience is an option ? You cannot learn the ins and outs of AD design in on EE thread.
0
Joseph DalyCommented:
I think you may be off a little bit. By default AD will replicate the entire contents of your main DC to all of the remote sites. It must do this in order to function properly. That is what the DCPROMO does it makes each new DC a replica of the original DC.

Once you have  your 12 new DC's configured you would configure which site points to which DC in active directory sites and services. This way users will authenticate to the closest DC to their site and fail over to a remote DC in the event of a failure of their site DC.

You can create different OU's for the users at the different sites but this is more for ease of management, delegation of duties, and group policy settings than AD replication.

I hope this helps a little bit. Anything else just ask.
0
Joseph DalyCommented:
I agree with BUDDHOLE active directory is defintely not something that can be learned over an EE post
0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

ccosnerAuthor Commented:
xxdcmast-

I was just thinking that I could replicate a small amount of the domain to cut down on the data being transfered over a slow link. Is this not correct?

0
buddholeCommented:
That is not possible, you replicate all or nothing. If you want to limit the amount of replication data you have to create child domains.
0
buddholeCommented:
You might consider using smtp site links, more about setting up links is found here: http://codeidol.com/active-directory/actdir/Configuring-Sites-and-Managing-Replication/Lesson3.Configuring-Intersite-Replication/
 
0
Joseph DalyCommented:
If the amount of data being transferred is really an issue for you I would reccomend doing the DCPROMO in your main office and then shipping the servers. Once the initial replication is complete there is much less data to keep it up to date.

And as BUDDHOLE mentioned replication is an all or nothing deal. One other thing to note is that you should ensure that every one of your 12 sites can communicate with each other. Active directory does not like it when it can not talk to all the domain controllers. If you do not have links enabled between all the sites you will get alot of error and warning messages in your event viewer about repication.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.