ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SAMIT: Do You Need Two AD Domain Controllers?

    Scheduled Pinned Locked Moved IT Discussion
    samitscott alan milleractive directoryhigh availabilitybest practicesyoutubead dcdomain controller
    72 Posts 14 Posters 11.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @dafyre
      last edited by

      @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

      In an environment with only one AD server, how do you handle DNS if your lone AD server dies?

      Sure, you could drop in Google for the DNS, but that doesn't help you for servers that are inside your network.

      You could spin up a Windows DNS server, but that is still another Windows license. In the SMB, I wouldn't expect many folks to have the skill set to run BIND for DNS.

      BIND, Host files

      dafyreD 1 Reply Last reply Reply Quote 0
      • dafyreD
        dafyre @scottalanmiller
        last edited by dafyre

        @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

        @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

        In an environment with only one AD server, how do you handle DNS if your lone AD server dies?

        Sure, you could drop in Google for the DNS, but that doesn't help you for servers that are inside your network.

        You could spin up a Windows DNS server, but that is still another Windows license. In the SMB, I wouldn't expect many folks to have the skill set to run BIND for DNS.

        BIND, Host files

        See my comment about folks not really having the skill set to run BIND (not in the SMB market anyway).

        Host files could work, but then you have to keep them distributed and updated. Something like Sodium could work if the SMB is aware of it for that purpose, or some kind of automatic scripts to do it... But would somebody at the SMB level of IT actually think about something like that?

        syko24S scottalanmillerS 3 Replies Last reply Reply Quote 1
        • ObsolesceO
          Obsolesce
          last edited by

          In most SMBs, your AD server is the AD, DHCP, DNS, Print, and maybe a file server.

          This whole single AD server can really only make sense if we are just talking about AD.

          Once we start mixing in all infrastructure services, then this is where you take into consideration where Scott says case by case basis... completely depends on your environment and setup.

          Common sense will come in to play.

          JaredBuschJ 1 Reply Last reply Reply Quote 2
          • JaredBuschJ
            JaredBusch @Obsolesce
            last edited by

            @tim_g said in Do You Need Two AD Domain Controllers? SAMIT Video:

            In most SMBs, your AD server is the AD, DHCP, DNS, Print, and maybe a file server.

            This whole single AD server can really only make sense if we are just talking about AD.

            Once we start mixing in all infrastructure services, then this is where you take into consideration where Scott says case by case basis... completely depends on your environment and setup.

            Common sense will come in to play.

            Actually, the adding in of all of those resources does nothing to mean you need another server.

            None of those extra services are natively simple to setup in an HA way.

            The best thing to do is to have the single server virtualized and quick to restore from backup.

            ObsolesceO 1 Reply Last reply Reply Quote 5
            • ObsolesceO
              Obsolesce @JaredBusch
              last edited by

              @jaredbusch said in Do You Need Two AD Domain Controllers? SAMIT Video:

              @tim_g said in Do You Need Two AD Domain Controllers? SAMIT Video:

              In most SMBs, your AD server is the AD, DHCP, DNS, Print, and maybe a file server.

              This whole single AD server can really only make sense if we are just talking about AD.

              Once we start mixing in all infrastructure services, then this is where you take into consideration where Scott says case by case basis... completely depends on your environment and setup.

              Common sense will come in to play.

              Actually, the adding in of all of those resources does nothing to mean you need another server.

              None of those extra services are natively simple to setup in an HA way.

              The best thing to do is to have the single server virtualized and quick to restore from backup.

              Sure... it depends on what is running on the server and it depends on other things like number of locations, distance, number of users, bandwidth, etc.

              My point was to clarify this is all about having a single AD DC, and after that, there are more factors to consider.

              1 Reply Last reply Reply Quote 0
              • syko24S
                syko24 @dafyre
                last edited by

                @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                In an environment with only one AD server, how do you handle DNS if your lone AD server dies?

                Sure, you could drop in Google for the DNS, but that doesn't help you for servers that are inside your network.

                You could spin up a Windows DNS server, but that is still another Windows license. In the SMB, I wouldn't expect many folks to have the skill set to run BIND for DNS.

                BIND, Host files

                See my comment about folks not really having the skill set to run BIND (not in the SMB market anyway).

                Host files could work, but then you have to keep them distributed and updated. Something like Sodium could work if the SMB is aware of it for that purpose, or some kind of automatic scripts to do it... But would somebody at the SMB level of IT actually think about something like that?

                Apart from tickets can Sodium do anything else at this point? Or did you mean once the functions are added?

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @dafyre
                  last edited by

                  @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                  @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                  @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                  In an environment with only one AD server, how do you handle DNS if your lone AD server dies?

                  Sure, you could drop in Google for the DNS, but that doesn't help you for servers that are inside your network.

                  You could spin up a Windows DNS server, but that is still another Windows license. In the SMB, I wouldn't expect many folks to have the skill set to run BIND for DNS.

                  BIND, Host files

                  See my comment about folks not really having the skill set to run BIND (not in the SMB market anyway).

                  Host files could work, but then you have to keep them distributed and updated. Something like Sodium could work if the SMB is aware of it for that purpose, or some kind of automatic scripts to do it... But would somebody at the SMB level of IT actually think about something like that?

                  I don't accept the "SMB hires bad people and therefore should do a bad job" argument. It makes no logical sense. Why would anyone hire someone that can't do the job, why would they keep them if they hired them by accident, and why would someone in that position be excused to not attempt to do a good job? Why does the SMB so often get used as an excuse to not need basic business or IT competence?

                  There is no logic that connects "people often do things badly" with "people shouldn't be told how to do things well."

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @syko24
                    last edited by

                    @syko24 said in Do You Need Two AD Domain Controllers? SAMIT Video:

                    @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                    @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                    @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                    In an environment with only one AD server, how do you handle DNS if your lone AD server dies?

                    Sure, you could drop in Google for the DNS, but that doesn't help you for servers that are inside your network.

                    You could spin up a Windows DNS server, but that is still another Windows license. In the SMB, I wouldn't expect many folks to have the skill set to run BIND for DNS.

                    BIND, Host files

                    See my comment about folks not really having the skill set to run BIND (not in the SMB market anyway).

                    Host files could work, but then you have to keep them distributed and updated. Something like Sodium could work if the SMB is aware of it for that purpose, or some kind of automatic scripts to do it... But would somebody at the SMB level of IT actually think about something like that?

                    Apart from tickets can Sodium do anything else at this point? Or did you mean once the functions are added?

                    Functions need to be added, but that one will be soon. Hosts management is very simple.

                    syko24S 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @dafyre
                      last edited by

                      @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                      But would somebody at the SMB level of IT actually think about something like that?

                      This is like asking if we should bother telling people how to brake safely on snow or ice since most people will just panic and slam the brakes, anyway.

                      dafyreD 1 Reply Last reply Reply Quote 0
                      • syko24S
                        syko24 @scottalanmiller
                        last edited by

                        @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                        @syko24 said in Do You Need Two AD Domain Controllers? SAMIT Video:

                        @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                        @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                        @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                        In an environment with only one AD server, how do you handle DNS if your lone AD server dies?

                        Sure, you could drop in Google for the DNS, but that doesn't help you for servers that are inside your network.

                        You could spin up a Windows DNS server, but that is still another Windows license. In the SMB, I wouldn't expect many folks to have the skill set to run BIND for DNS.

                        BIND, Host files

                        See my comment about folks not really having the skill set to run BIND (not in the SMB market anyway).

                        Host files could work, but then you have to keep them distributed and updated. Something like Sodium could work if the SMB is aware of it for that purpose, or some kind of automatic scripts to do it... But would somebody at the SMB level of IT actually think about something like that?

                        Apart from tickets can Sodium do anything else at this point? Or did you mean once the functions are added?

                        Functions need to be added, but that one will be soon. Hosts management is very simple.

                        Cool looking forward to the updates. I just thought maybe I missed something.

                        1 Reply Last reply Reply Quote 0
                        • dafyreD
                          dafyre @scottalanmiller
                          last edited by

                          @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                          @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                          But would somebody at the SMB level of IT actually think about something like that?

                          This is like asking if we should bother telling people how to brake safely on snow or ice since most people will just panic and slam the brakes, anyway.

                          That's kinda my point. Somebody could think about BIND after AD has already spread its guts all over the virtual walls, lol.

                          I think for most, the best bet is as @JaredBusch mentioned if you have a single AD controller, just virtualize it so you can restore from snapshots or backups and be done with it.

                          scottalanmillerS 1 Reply Last reply Reply Quote 2
                          • scottalanmillerS
                            scottalanmiller @dafyre
                            last edited by

                            @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                            @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                            @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                            But would somebody at the SMB level of IT actually think about something like that?

                            This is like asking if we should bother telling people how to brake safely on snow or ice since most people will just panic and slam the brakes, anyway.

                            That's kinda my point. Somebody could think about BIND after AD has already spread its guts all over the virtual walls, lol.

                            But, how is that a point? What relevance does that have? Why would "some people might not have taken advice" affect "when we give advice?"

                            dafyreD 1 Reply Last reply Reply Quote 0
                            • dafyreD
                              dafyre @scottalanmiller
                              last edited by

                              @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                              @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                              @scottalanmiller said in Do You Need Two AD Domain Controllers? SAMIT Video:

                              @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                              But would somebody at the SMB level of IT actually think about something like that?

                              This is like asking if we should bother telling people how to brake safely on snow or ice since most people will just panic and slam the brakes, anyway.

                              That's kinda my point. Somebody could think about BIND after AD has already spread its guts all over the virtual walls, lol.

                              But, how is that a point? What relevance does that have? Why would "some people might not have taken advice" affect "when we give advice?"

                              Until my brain remembers where I was going with that, I'll have to say: You got me there.

                              We don't give advice just to give advice. We give advice in the hopes that we'll help somebody avoid a painful experience down the road.

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @dafyre
                                last edited by

                                @dafyre said in Do You Need Two AD Domain Controllers? SAMIT Video:

                                We don't give advice just to give advice. We give advice in the hopes that we'll help somebody avoid a painful experience down the road.

                                Right, which is why we say you don't need two domain controllers. Just because people might not take the advice doesn't mean that we should avoid giving it or give intentionally bad advice.

                                1 Reply Last reply Reply Quote 0
                                • jmooreJ
                                  jmoore
                                  last edited by

                                  Good points here. Every environment is unique. I could be wrong but i think some people try to use "best practices" reasoning because they do not know how to go about figuring out if something like this makes sense or not. its the "easy" button for them.

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @jmoore
                                    last edited by

                                    @jmoore said in Do You Need Two AD Domain Controllers? SAMIT Video:

                                    Good points here. Every environment is unique. I could be wrong but i think some people try to use "best practices" reasoning because they do not know how to go about figuring out if something like this makes sense or not. its the "easy" button for them.

                                    Right, when really best practices is always "determining what is right for your environment" and "hiring people competent enough to make good decisions."

                                    1 Reply Last reply Reply Quote 1
                                    • bigbearB
                                      bigbear
                                      last edited by

                                      If you think about small biz server 2000 - with ISA server, AD, Exchange, File shares all on the same box, directly connnected to your LAN and your internet connection, you really have to perceive MS best practices we're designed for very large companies. SMB was an after thought once it was identified as a growth market.

                                      Lotus had a server product called Foundations that I thought was kick ass before the cloud arrived. You got Domino server, file services and the Domino App/Database servers.

                                      scottalanmillerS 1 Reply Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller @bigbear
                                        last edited by

                                        @bigbear said in Do You Need Two AD Domain Controllers? SAMIT Video:

                                        If you think about small biz server 2000 - with ISA server, AD, Exchange, File shares all on the same box, directly connnected to your LAN and your internet connection, you really have to perceive MS best practices we're designed for very large companies.

                                        That, by definition, means it isn't a best practice. A true best practice is not affected by size of company.

                                        1 Reply Last reply Reply Quote 1
                                        • S
                                          StorageNinja Vendor
                                          last edited by StorageNinja

                                          There are other windows functions tied to AD (Print Servers, GPO's, authentication if users are domain users).
                                          Are we at the point of using MDM systems for management, and external identity and SSO for authentication?

                                          bigbearB scottalanmillerS 2 Replies Last reply Reply Quote -1
                                          • bigbearB
                                            bigbear @StorageNinja
                                            last edited by

                                            @storageninja said in Do You Need Two AD Domain Controllers? SAMIT Video:

                                            There are other windows functions tied to AD (Print Servers, GPO's, authentication if users are domain users).
                                            Are we at the point of using MDM systems for management, and external identity and SSO for authentication?

                                            Honestly I cant believe we arent at the point where everyones cell phone doubles as a desktop CPU and all business apps arent pushed through app streaming.

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 3 / 4
                                            • First post
                                              Last post