Solved

Identifying what domain controllers are not global catalogs

Posted on 2013-12-19
3
348 Views
Last Modified: 2014-01-04
Hi everyone,

Id like to ask you kind People if there is a scripted way to query AD to determine what domain controllers are NOT global catalogs?

Is there also a way to then via script, make those domain controllers found, global catalogs?

Thank you everyone and have a great christmas and newyear.
0
Comment
Question by:Simon336697
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 39730890
You can use the following to find DCs that are not GCs

Get-ADDomainController -Filter {IsGlobalCatalog -eq $false}

for the second I used something from MVP Richard Siddaway's blog, notice I changed the first line.

PLEASE TEST THIS FIRST!!!  I will personally test part 2 in the morning.

http://msmvps.com/blogs/richardsiddaway/archive/2012/03/18/enable-global-catalog.aspx

$dc = Get-ADDomainController -Filter {IsGlobalCatalog -eq $false}         
$contextType = [System.DirectoryServices.ActiveDirectory.DirectoryContextType]::DirectoryServer            
$context = New-Object -TypeName System.DirectoryServices.ActiveDirectory.DirectoryContext -ArgumentList $contextType, $dc            
$gc = [System.DirectoryServices.ActiveDirectory.DomainController]::GetDomainController($context)            
$gc.EnableGlobalCatalog()

Open in new window


Thanks

Mike
0
 
LVL 3

Assisted Solution

by:Aanand Singh Karki
Aanand Singh Karki earned 150 total points
ID: 39731499
Hi Simon,

You can Simply Run NlTest Commands to get the DC and GC Information in your Forest..

http://technet.microsoft.com/en-us/library/cc756476(v=ws.10).aspx

http://technet.microsoft.com/en-us/library/cc731935.aspx


dsquery server -isgc

dsquery server -forest -isgc

or Simply

nltest /dsgetdc:Domain name /GC
0
 
LVL 7

Assisted Solution

by:hirenvmajithiya
hirenvmajithiya earned 100 total points
ID: 39733279
To determine which DC is a global catalog server (Graphical method)


1.Open Active Directory Sites and Services.

2.In the console tree, expand upto Server and then NTDS Settings.

3.Right-click the NTDS Settings object, and then click Properties.

4.On the General tab, if the Global Catalog box is checked, the DC is GC server.

Check this for every DC.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question