?
Solved

Whats the role of Global catalog in user authentication

Posted on 2011-09-12
3
Medium Priority
?
633 Views
Last Modified: 2012-05-12
I had been to an interview and the panel asked me a question
1. Why do you need sites and services?
My Ans: Basically for replication across the sites.

He said there no additional sites or domain. Only one network then whats the role of sites n services?
My ans: i did not answer.

After the interview iasked the answer. He said the global catalog present in sites and services are responsible for user authentication.

I did not ask him how? Can some one please give more details on this please?
0
Comment
Question by:anuboggaram
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 36527591
The roles of sites and services is to help control replication like you said and so that you can control what DC the users at the site use (they use DC based on subnet so if setup correctly the DCs near them)  So the DC in the site will authenticate the user.

As far as the GC that is needed for logon in a mutli-domain enviroment for normal users.

In a single domain it is not a requirment


http://technet.microsoft.com/en-us/library/how-global-catalog-servers-work(WS.10).aspx

Logon Process in a Single-Domain Forest
In a single-domain forest, all domain controllers can service all logon requests, including UPN logons, without requiring a global catalog server. However, only domain controllers that are configured as global catalog servers can respond to LDAP traffic over port 3268.


Thanks

Mike
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 36528025
GC is a separate database from AD and contains a partial, read-only replica of all the directory objects in the entire AD forest. Only Windows servers acting as domain controllers can be configured as GC servers. By default, the first domain controller in a Windows forest is automatically configured to be a GC server.
The GC plays two primary roles on a Windows network:
1. Network logon authentication—In native-mode domains (networks in which all domain controllers have been upgraded to Win2K or later, and the domain‘s functional level has been manually set to the appropriate level), the GC facilitates network logons for ADenabled clients. It does so by providing universal group membership information to the account sending the logon request to a domain controller. This applies not only to regular users but also to every type of object that must authenticate to AD (including computers). In multi-domain networks, at least one domain controller acting as a GC must be available in order for users to log on. Another situation that requires a GC server occurs when a user attempts to log on with a user principal name (UPN) other than the default. If a GC server is not available in these circumstances, users will only be able to logon to the local computer (the one exception is members of the domain administrators group, who do not require a GC server in order to log on to the network).

2. Directory searches and queries—With AD, read requests such as directory searches and queries, by far tend to outweigh write-oriented requests such as directory updates (for example, by an administrator or during replication). The majority of AD-related network traffic is comprised of requests from users, administrators, and applications about objects in the directory. As a result, the GC is essential to the network infrastructure because it allows clients to quickly perform searches across all domains within a forest.
GC Storing information about all AD objects from all domains in a single Forest and universal groups and their associated membership and forwarding Authentication requests to the appropriate Domain when a user principal name is used to logon and validating object references with in a Forest.
GC Port No-3268

Refer this link:
http://technet.microsoft.com/en-us/library/cc728188(WS.10).aspx
http://technet.microsoft.com/en-us/library/how-global-catalog-servers-work(WS.10).aspx
0
 
LVL 21

Expert Comment

by:snusgubben
ID: 36536378
You need a GC in single-domain forest (native mode) for users to be able to logon. There may exist universial groups, and without connectivity to a GC, you can't query Universial Groups. So the authenticating DC will not let you in.

Also if a user logs on with UPN, he can't change his password. If you have Exchange, it depends 100% of the GC.
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses
Course of the Month13 days, 18 hours left to enroll

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question