Number of AD Users increases - what are the concerns?

Currently I have HUB and DR Data centers having writable copies of AD and about 20 remote sites served by RODCs (Read-Only Domain Controllers).
The size of the forest I'm supporting is about to double, as my enterprise will acquire additional remote sites.  Obviously new remote sites will get new RODCs installed. What are the other recommendations?
mezenAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Joseph MoodyBlogger and wearer of all hats.Commented:
Ensure that you have your sites configured correctly in AD and that your subnets are assigned.
mezenAuthor Commented:
Josheph Moody, that goes without saying. Is there a way to size the number of Writable DCs in the HUB?
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

Will SzymkowskiSenior Solution ArchitectCommented:
From personal experience using RODC's are just another server to manage. Unless you are caching your passwords for all users at that site the RODC still needs to query a read/write DC in the same site or another remote site for authentication.

If your remote sites are configured the following configuration then they should not require a DC at that location....
- less than 50 users
- applications that do not require a local DC for faster authentication
- MPLS/DSL line that is 5mbps or greater

So based on the above you could really simplify your network desigen and possibly get rid of your RODC. At that point you would simply associate the Remote Site Subnet with the Active Directory Site you want to authenticate with.

DC's, if properly speced can host thousands of requests. This would include moderate resources.

I never add DC's if they are not required and i think things through before simply added more network devices to my network that may not be needed.


Will.
AmitIT ArchitectCommented:
I agree to Will above. It depends on user and application requirement. Like for Exchange, I prefer to create separate site and separate DC's. So, Exchange won't overload DC's used by users.

LSASS.exe support 50K handles. If it is going above that count then you might need to find out which app or process is using it.
Bryant SchaperCommented:
What size growth are we talking about?  How many AD objects/users do you have now
mezenAuthor Commented:
Bryant Schaper,
We are 4000 + Users now and about to double that number.
Lee W, MVPTechnology and Business Process AdvisorCommented:
So what kind of performance are you getting out of your existing DCs?  Have you checked their load?  How many DCs do you currently have? What is their hardware config?  Are they loaded with 8 GB of RAM and RAID 10 SSDs?  Or are they 1 GB of RAM and running off a mirror of 250GB SATA drives?

With 20 sites and 4000 users you AVERAGE 200 users per site.  Even if your largest site is 5x that, the assumption is that you have one DC per site (at least per site of 50+).  So you double... it doesn't seem like much to me.  ANTIQUATED technology of NT4 PDC/BDCs maxed out at 2000 users per P/BDC - implying your network would need 4 DCs using 20 year old technology... if you have much more than that you're probably fine using newer technology - but the problem is, especially with a network that large, you have do your own homework - determine the overall load CURRENTLY and if you're acquiring another company, perform the same performance tests on them and you can tell what you'll need - but your requirements could be very different from mine even if we had the same size network (in terms of users).

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.