From the Field: AD Sites and Services

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿฐ๐Ÿฎ.๐Ÿต%ย of infrastructures Iโ€™ve assessed ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐—ฝ๐—ฟ๐—ผ๐—ฝ๐—ฒ๐—ฟ๐—น๐˜† ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฆ๐—ถ๐˜๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€

๐—œ ๐—ผ๐—ณ๐˜๐—ฒ๐—ป ๐˜€๐—ฒ๐—ฒ ๐˜๐˜„๐—ผ ๐—ฐ๐—ฎ๐˜€๐—ฒ๐˜€:

โ–ช๏ธ admins configure it โ€œhow they feel,โ€ or

โ–ช๏ธ they donโ€™t configure it at all.

Both are wrong.

If you have multiple sites (DCs in multiple physical locations), ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด๐˜‚๐—ฟ๐—ฒ ๐—”๐—— ๐—ฆ๐—ถ๐˜๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ ๐˜๐—ผ ๐—บ๐—ถ๐—ฟ๐—ฟ๐—ผ๐—ฟ those locations.

๐—ช๐—ต๐˜†:

โœ… It helps you set replication properly across locations.

โœ… Devices can contact the nearest DCโ€”but only if you also define Subnets and tie them to a site.

๐—ž๐—ฒ๐—ฒ๐—ฝ ๐—ถ๐˜ ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐—ฒ:

โ–ช๏ธ In most cases, leave the replication topology at defaultโ€”the KCC will create and adapt the topology once sites are defined. Manual connection links can get complicated.

โ–ช๏ธ Set intersite replication to Change Notification System (AD Configuration partition).

โ–ช๏ธ Create sites to match physical locations, move DCs accordingly, and map subnets to sites.

 

Nothing more. ๐—ช๐—ต๐—ฎ๐˜โ€™๐˜€ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฎ๐—ฝ๐—ฝ๐—ฟ๐—ผ๐—ฎ๐—ฐ๐—ต ๐—ณ๐—ผ๐—ฟ ๐˜๐—ต๐—ถ๐˜€?