Domian Controller Best Practice

Sam Na 46 Reputation points
2023-04-24T03:30:02.99+00:00

Hi, We have an environment with HUB/Spoke design. several DCs globally connected and replicating. These DCs are onboard vessels connected via satellite. there are times that we lose connection, it could be from a few minutes to a few weeks. What would be the best approach and best practice in our case? RODC would be the best practice? What would be the best replication interval in the above case?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 44,766 Reputation points
    2023-04-24T14:05:44.6566667+00:00

    Hello Thank you for your question and reaching out. I can understand you are having query\issues related to Domain controller best practice. The suggested solution is to install a read-only domain controller (RODC) at places with insufficient physical security. Plan to install the fewest number of regional domain controllers possible to guarantee cost effectiveness. Review "Geographic Locations and Communication Links" first. For each domain that is represented at each hub site, local domain controllers are placed on the local area network. Consider whether regional domain controllers need to be installed at satellite locations once you have installed them in each hub location. The cost of supporting a remote server architecture is reduced by removing unused regional domain controllers from satellite locations. Additionally, make sure that domain controllers in hub and satellite locations are physically secure to prevent unauthorised access. Avoid installing writable domain controllers at hub and satellite sites where you cannot ensure the domain controller's physical security. A person who has physical access to a writable domain controller can attack the system by:

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.