[Last Call] Learn how to a build a cloud-first strategyRegister Now


Benefits of multiple AD sites

Posted on 2011-05-09
Medium Priority
Last Modified: 2012-05-11
We are thinking of building two datacentres, both in the same city, but at opposite ends.

We're currently running Windows 2008 AD.

Could someone tell me the benefits of seperating the two datacentres into seperate AD sites, or just keeping them as one? I can't see what we gain by having two AD sites, one per centre?
Question by:Joe_Budden
LVL 57

Accepted Solution

Mike Kline earned 668 total points
ID: 35724453
The two main benefits of sites are

1.  Control Authentication - Users use a local DC in their site for Auth
2.  Control Replication - intersite replication

More info here  http://technet.microsoft.com/en-us/library/cc782048(WS.10).aspx

There are also site aware apps (SMS/SCCM for example)

If both data centers are connected by high speed links then you may get away with having only one site.


LVL 43

Assisted Solution

by:Adam Brown
Adam Brown earned 668 total points
ID: 35724613
Having a single site will cause computer to authenticate more or less randomly (with some constraints)  to any Domain Controller on your network. If you have two physical locations this can cause a lot of traffic to cross your WAN link between sites. This will result in a significant amount of bandwidth being used up by regular domain traffic. As Mike stated in fewer words, setting up a site for each location will allow you to decrease this burden by having all computers at one site use DCs in the site they are assigned to. When this is done properly, the amount of bandwidth required for Active Directory between sites is quite low, as only replication traffic needs to go between sites to make sure that all the Domain Controllers are up to date and have the same information. If you have a slow link, it makes a lot of sense to have separate sites for each location.

Expert Comment

ID: 35724851

I agree with mkline71 and acbrown2010

Localizing access to resoures is very important because active directory is sharing the WAN connection with other traffice. The last thing you want to do is increase WAN utilization due to login and Global Catalog traffic.  It is also important from an application standpoint. Certain applications such as Microsoft Exchange rely on the global catalog for directory look ups so having a local GC server is highly reccommended for optimal performance.  
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

LVL 24

Assisted Solution

Awinish earned 664 total points
ID: 35725993
Protection when something wrong goes to complete datacenter so other will be available to server you & help you to bring the business to normality due to power failure or anything like that.


Author Comment

ID: 35739594
Thanks all for the great replies!

As regards MS Exchange -  you say that it needs GC's for it to function. Do you know how Exchange (or any application really) finds out the closest GC's to it? What's the actual process?
LVL 43

Expert Comment

by:Adam Brown
ID: 35740354
The Global Catalog servers are listed in DNS under the _msdcs zone (which controls SRV records for the Domain). If all the DNS servers that clients are configured with fail, or if all the global catalogs fail, there is no way for clients and servers to know where Domain information is served. The SRV records for Global Catalogs are separated by site in DNS as well, and sites are determined by the subnet range assigned to the site. So a Computer will look up DNS for the appropriate site information and attempt to contact a Global Catalog in its site. If none is found, it will go through other sites based on link cost to find a Global Catalog.

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Suggested Courses

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question