Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


DHCP lease Assigning with AD

Posted on 2015-02-17
Medium Priority
Last Modified: 2015-02-17

I was wondering what happens with a DHCP Server assigning leases if there are no links to Domain Controllers available

Can anyone send me links to TechNet or any relevant articles

Question by:nico-
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1

Expert Comment

by:Jelle Dedoyard
ID: 40613986
I do not know what you mean by this but a dhcp server is on its own. It does not have any links to AD. It can however auto register dns items for name resolution but that has nothing to do with AD and you have configure this option so it is not mandatory.

Author Comment

ID: 40614059
If the DHCP server cannot contact an AD Server (WAN link down). Considering it has to be authorised by AD.
Links please as i need something to refer to

Expert Comment

by:Jelle Dedoyard
ID: 40614085
DHCP is not authorised by AD. It works at a different level. AD has nothing to do with it unless you use some very specific software that i do not know about. It only distributes IP addresses and might register the name of the computer in the DNS server if you specified that.

Link about what a dhcp server is and what it does:
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.


Author Comment

ID: 40614132
But you do DHCP authorise in AD :-

I wondered what happens in the background for authentication is the DC connectivity is broken

Expert Comment

by:Jelle Dedoyard
ID: 40614171
right I'm going to shut up now... you are absolutely right. I never had this issue because I have always used a dhcp server on a DC or non windows dhcp (like watchguard, cisco etc).

My bad... sorry.
LVL 37

Expert Comment

ID: 40614353
If DHCP server is already authorized, it will lease out IP addresses no matter DC is present or not

However if its not authorized with AD, probably it cannot lease IP no matter DC is online or offline
(Not applicable to DHCP server in workgroup)

Now wrt client logon, assuming if DC is offline, client will get IP lease from DHCP and if this computer and user has previously logged on, he will continue to logon with cached credentials

For new users and computers, they won't logon as DC is unavailable however they will get DHCP lease

because once authorized, DC offline \ online status won't stop DHCP from leasing out IP addresses

To prove this:
Consider branch with remote DC and with onsite DHCP and link got down, DHCP still leasing IP

Author Comment

ID: 40614411
Thanks Mahesh

I was thinking along the line of SCCM client builds taking a DHCP address whilst using F12/PXE boot.

So basically the build can go ahead, but nothing else.  As you say, cached logons would work (if not set otherwise by GPO for security) but new users etc could not logon as no DC to authenticate against
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40614804
Also, if a machine gets a lease and DHCP is not available the lease will continue to function on that machine until it is released locally.

LVL 37

Accepted Solution

Mahesh earned 1500 total points
ID: 40614914
You are right.
Yes cached logons will always work unless restricted by GPO
Also users who are trying to logon 1st time and if at that time DC is not available they also won't logon because they don't have cached credentials on workstation.

Author Comment

ID: 40615460
Thanks for your help Mahesh

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question