Windows Server Rollout - Multiple Sites 2008R2


Before i hit the "go" button i would like to confirm the suitability of my planned server rollout and welcome any suggestions or corrections the same.

Firstly, Network resides over 6 sites - 1 site Head Office, the other 5 are Branch Offices.  All sites linked to Head Office by good speed VPN's (Cisco ASA's).

Head Office to have Main AD Server and an Additional AD Server with one Domain.
Branch Offices to be setup as Additional AD Servers on the same Domain as Head Office.
All Servers act as GC Server, run DHCP for their local subnet's and handle DNS to which forwards to Head Office AD.
All Servers have local shares, printers active. Some branch servers will have DFS setup between each other.

Questions :

So, the local users authenticate to their own local AD server and travellers will authenticate against the server in which they are visiting?

Home shares will still availible as no trusts are required with all servers being on the same domain?

When a user and/or machine is added to Head Office it is replicated to all other AD servers?

DNS is updated and replicated to all servers when a DNS change is made?

GPO's that are created on the Head Office Server are replicated to all other AD servers?

Of course file sharing and subsequent permissions are still handled at each server as is DHCP.

Is there anything unforseen that i may of missed?

Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mohammed KhawajaManager - Infrastructure:  Information TechnologyCommented:
Within AD you set your AD sites where each site will include one or more DCs.  This is what dictates to which site the user authenticates to.  Each site will be bound one or more IP subnets (i.e. site1 subnet is /24 then you make this part of site1 and ensure there is a DC on /24 network.

Home shares will be available without any issues but remember that traveling users will be access the shares over the network.
When a user and/or machine is added to Head Office it is replicated to all other AD servers?

Ensure your DNS is AD integrated and this way each DC will be a DNS server.  Instead of forwarding DNS queries for sites on the Internet to the head office, I recommend you enable root-hints and each DNS server will use local Internet connection for DNS queries (less data between sites).

GPOs are replicated between all sites regardless of which site or DC they were created on as this is part of AD Data.  GPOs are stored in SYSVOL on each DC which is replicated across all DCs.

One thing to remember though is that default replication could take up to 90 minutes (this does not include security related items such as account lockout, account deletion, password expiration, etc.).  If this is not acceptable and most administration is done at the head-office then you could change the replication time between head-office and each site.
tmaster100Author Commented:
Thanks for your comments, very much appreciated.
tmaster100Author Commented:
Great. So what happens if i join a workstation to the non-head office server, will it replicate to all the others aswell? I assume it will but best to check.
Mohammed KhawajaManager - Infrastructure:  Information TechnologyCommented:
It will.  Rule of thumb is that everything in AD will be synchronized across all sites.  Adding a computer is an AD object and it will be replicated to all sites.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.