Decommissioning old domain controller in several remote sites

I have some remote offices old domain controller box that I need to decommission.

Each office sites got their own aD domain controller with global catalog and has each dedicated AD site.

I'm going to build two AD domain  controllers / global catalog in the data centre in its own AD site.

So is there any steps or consideration that I need to do before and after decommissioning the old domain controllers in each office sites ?

Do I have to delete or eliminate the AD site in each office location ?
LVL 9
Senior IT System EngineerIT ProfessionalAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Senior IT System EngineerIT ProfessionalAuthor Commented:
If anyone also know what is the best practice of building AD sites for multiple office branch location that'd be greatly appreciated to share it here. Thanks.
0
Seth SimmonsSr. Systems AdministratorCommented:
are you removing the AD sites entirely and consolidating?
is the site itself going away (office closing) or just domain controllers?
0
Senior IT System EngineerIT ProfessionalAuthor Commented:
I'm consolidating the domain controllers so instead of the small remote branch office and hotels has its own domain controller, they can use the two domain controllers in the data centre.

This is for 170 sites for multiple different hotel and apartment within one continent in Asia.

The link to the data centre is MPLS link.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

Senior IT System EngineerIT ProfessionalAuthor Commented:
So if no AD domain controller exist in one site physically do I still must keep the AD site or I can safely delete it ?
0
Seth SimmonsSr. Systems AdministratorCommented:
a couple things...
1) no domain controller means that there could be latency with logons because of reaching out over the wan to talk to another server
2) if you delete the site, that will make things worse because a domain controller will take over a site if there isn't one in place there so without the site makes things more complicated.  also, without a subnet for that site, other domain controllers will constantly throw warnings about clients talking to it from subnets that don't exist

better off leaving the sites there with the appropriate subnets
clients will still find a domain controller
0
Senior IT System EngineerIT ProfessionalAuthor Commented:
Seth,

Assuming that the 10 MBps WAN link is always on with no bottleneck issue, can I just demote the domain controllers in each AD sites and then leave the AD sites as you suggested?

because my problem at the moment is that there are too many domain controllers to be managed in each sites. Therefore the only domain controllers will be in the main Data Center only not on each sites.
0
Seth SimmonsSr. Systems AdministratorCommented:
if you remove the domain controllers in other sites, then the sites will be taken over by the existing domain controllers since none exist in the others

for example, if you have sites in japan - say tokyo, nagoya, osaka and you remove the domain controllers in nagoya and osaka but leave the AD sites, the domain controller(s) in tokyo (or a DC in another site) would take network requests for systems in the nagoya and osaka sites that don't have their own domain controller

the problem comes in when the connection breaks
some parts of asia that i've been in don't have reliable connectivity at all but others have excellent reliability and speed
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Senior IT System EngineerIT ProfessionalAuthor Commented:
Thanks
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.