Link to home
Start Free TrialLog in
Avatar of DP230
DP230Flag for United Kingdom of Great Britain and Northern Ireland

asked on

pros and cons of using Domain Controller and Additional DC

Dear Experts, what are the pros and cons of using DC and ADC?
in test environment, sometimes we got problem with replication.
Avatar of Lee W, MVP
Lee W, MVP
Flag of United States of America image

First, what's an ADC?  There is no "ADC" in Active Directory if you're using proper terminology.  All DCs are just that - DCs - Domain Controllers.  There are 5 Flexible Single Master Operation roles (FSMO roles) and the first DC in a given domain has them all by default... but they can be split up amongst other DCs (though may not be depending on the environment).  You also have Global Catalogs, which the first DC is by default.

If you have experienced, knowledgeable people on staff or managing Active Directory for you (outsourced), then a second DC is a near necessity in my opinion.  If you DON'T know AD and you DON'T have experienced AD people managing your domain, then you LIKELY should only have ONE DC and make sure it's backed up fully and regularly.  Failing to understand how to properly restore a domain controller in a failure can cause catastrophic corruption in your domain.
ASKER CERTIFIED SOLUTION
Avatar of J0rtIT
J0rtIT
Flag of Venezuela, Bolivarian Republic of image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Microsoft best practices dictates at least to domain controllers per AD site.
Not having backups is a far more serious problem then not having a second DC.  I've seen people cause major problems with multiple DCs when they don't understand AD and they try to restore.  I maintain, ONE DC ONLY if you're not fully versed in Active Directory.  If you ARE experienced, THEN you want two DCs
Avatar of DP230

ASKER

Hi, our DC is used both for authenticating domain users and Exchange mail users, we intent to install a second DC in an other site, using MPLS VPN then 2 DCs will serve round 1000 domain users. We are using Veeam to backup the first DC (which is VM)

@ Jose: "Check replication should be a daily task": What are the procedures to check this? Do you have any reference link?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
As previously mentioned,it should be two DCs per-site. Each one references the other in the TCP/IP properties for the DNS server, as well as itself.
The replication results can be viewed in event viewer as well as in Active Directory Replication Status tool.
You should avoid referencing the other DNS server if it's in another site.
For the kind of questions you have posted, I'd recommend that you get some training.

here's a web page to get training for free.

https://mva.microsoft.com/
If you are tech savvy and have an aptitude to learn, then doing these things are easy, If you have no idea, it would be cheaper and wiser to hire a pro
Avatar of DP230

ASKER

many thanks!