Link to home
Start Free TrialLog in
Avatar of IT Guy
IT GuyFlag for United States of America

asked on

Best to deploy Direct Access within its own virtual server or can it be installed on server currently running other roles (such as AD)

Is it best to deploy Microsoft Direct Access within its own virtual Server 2016 virtual server or can it be installed on a server that is currently running other Windows roles (such as Active Directory) or on a Hyper-V base server?
Avatar of yo_bee
yo_bee
Flag of United States of America image

Never a good practice to run anything else on Domain Controller accept DNS and DHCP (IMO).  The more access to your Domain Controller the more points of the system being compromised and if it is compromised or something goes wrong with the additional roles that may mean downtime that you cannot afford.

If you can setup a separate server to run this DA role I would do that.
And Never a good idea to run DirectAccess with anything else on a server. DirectAccess needs certain Firewall rules running to function correctly and that can interfere with other options. Your best bet is to run DirectAccess on a its own server and I also recommend you setup a separate Network Location Server  in your network.
Avatar of IT Guy

ASKER

Please provide me with step-by-step instructions on how to how to setup & configure a Network Location Server for Direct Access here.
ASKER CERTIFIED SOLUTION
Avatar of Jeff Glover
Jeff Glover
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial