Solved

AD Queries

Posted on 2014-09-24
4
93 Views
Last Modified: 2014-09-24
What is the recommended size (no. of users) for a site to install local AD server
What is the functions of AD server
What is the pros in having local AD server installed
What is the cons in having local AD server installed
What is the recovery process in event of AD server hard disk crash, etc.
If AD server is down, what is the failover/backup arrangement
0
Comment
Question by:sureshkumarit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 58

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 250 total points
ID: 40341056
EE is a great resource for help when you get stuck, but it cannot and should not replace IT training, books, and traditional learning. I encourage you to buy and read this book to answer your questions on active directory:

https://www.microsoft.com/learning/en-us/book.aspx?id=13349
0
 

Author Comment

by:sureshkumarit
ID: 40341163
Can you give some basic idea, where I can start as I need some guidence
0
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40341180
You asked some incredibly broad questions, so the book I linked to really is a good place to start.
0
 
LVL 17

Accepted Solution

by:
Learnctx earned 250 total points
ID: 40341251
Yes very broad questions. You're basically after for an entire infrastructure design so no one can give you a complete answer though if you need a consultant I'm sure there are plenty who could be available for hire :)

Read the following free bits of info and look at books if you want easier reading as Cliff suggested.

http://technet.microsoft.com/en-us/library/dd448614.aspx
http://technet.microsoft.com/en-us/library/cc770946%28v=ws.10%29.aspx

I can give some basic answers below to get you on your way but really you need to read, read, read :)

What is the recommended size (no. of users) for a site to install local AD server
You have to take many things into consideration.

Network topology. Network bandwidth between sites. Redundant/backup links or single point of failure? How many users will there be? Will your domain controllers be used just domain controllers or will they be running other services? The list goes on. Microsoft have guide lines available around this. Refer to TechNet but there is no right answer and your specific situation will vary to someone else.

What is the functions of AD server?
I'm going to assume you're talking about Domain Controllers (DC's) specifically (putting aside other stuff like CA's, ADFS, etc). They provide authentication services (logon, etc), identity (users, groups, printers, computers, etc), access (ACL's) and management (GPO's) and more. Domain controllers host the AD databases and replicate changes between each other. Simple answer, if you want to know more you will need to start reading some TechNet articles or books.

What is the pros in having local AD server installed.
Faster local access to AD services. Less traffic going across links. Redundancy. This will depend on your specific situation though. If you have high speed redundant links from a site to a hub site you might not want to put a domain controller there.

What is the cons in having local AD server installed
Depends on the link at the site but really cost, making sure that the server is physically secure and patching can be a problem if the server is on a slow link as well. This will all depend on your specific situation.

What is the recovery process in event of AD server hard disk crash, etc.
Turn the box off if its on. Perform a metadata cleanup to remove the server from AD (though I'm always told in 2008 R2/2012 AD is smart enough to do this itself if you delete the DC object from AD...I still prefer a metadata cleanup). Warranty the drives. Rebuild the server and promote as a DC again.

If AD server is down, what is the failover/backup arrangement
AD handles this itself. KCC (knowledge consistency checker -- read about AD replication, topology and bridgeheads if you don't know) will fix up replication. Clients will hit the next closest domain controller available if there is not another DC in that site.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question