Active Directory Administration Cookbook
上QQ阅读APP看书,第一时间看更新

Intending to do the right thing

The first few items on the list of preparations is to have the right ideas for promoting domain controllers throughout their life cycles:

  • Intend to create at least two domain controllers per Active Directory domain: This way, both servers can be advertised to networking clients as LDAP servers and DNS servers. Then, when you have to reboot one of at least two servers, these clients wouldn't be hindered. Also, restoring a domain controller while another domain controller is still available allows for scenarios such as non-authoritative restores, domain controller cloning, and domain controller re-promotion.
  • Intend to implement role separation: By all means, do not misuse a domain controller as an Exchange Server or SQL Server, unless it's a Windows Small Business Server. The DNS Server, DHCP Server, and NPS server roles are gray areas here, which should be addressed with common sense: if it means a domain controller will be harder to restore, manage, or decommission, separate the roles.