Re: AD - users and computers in child domain
- From: "Fyodor Yemelyanenko" <fyodor_e@xxxxxxx>
- Date: Wed, 7 Sep 2005 09:41:49 +1100
Yes, you are right. I know, that IM cannot be GC. But as written in article
you reccomend me
(http://support.microsoft.com/?id=197132#XSLTH3159121123120121120120) "If
all the domain controllers in a domain also host the global catalog, all the
domain controllers have the current data, and it is not important which
domain controller holds the infrastructure master role." This is my case.
All DCs in the forest are GCs.
"Ace Fekay [MVP]"
<PleaseSubstituteMyActualFirstName&LastNameHere@xxxxxxxxxxx>
ÓÏÏÂÝÉÌ/ÓÏÏÂÝÉÌÁ × ÎÏ×ÏÓÔÑÈ ÓÌÅÄÕÀÝÅÅ:
news:u$uwpEqsFHA.3640@xxxxxxxxxxxxxxxxxxxxxxx
> In news:Om9WFUosFHA.3908@xxxxxxxxxxxxxxxxxxxx,
> Fyodor Yemelyanenko <fyodor_e@xxxxxxx> made this post, which I then
> commented about below:
>> About domains and roles.
>> Two DCs in the root domain have roles as follows
>> DC1 - Infrastructure, RID, Schema and Domain Naming roles
>> DC2 - PDC
>>
>> DC in the child domain has Infrastructure, RID and PDC FSMO roles
>>
>> All DCs are global catalog therefore as far as I know location of
>> Infrastructure role don't play any role.
>>
>> My problem is mostly like that I don't use some command line switch
>> or don't select some option in ADUC...
>
> AD101: If there are multiple domains in a forest, the GCs CANNOT be an IM
> (Infrastructure Master), otherwise the IM will NOT ferret references for
> objects in other domains, hence thwarting it's job. The GC has references
> to specific limited types of objects, but not global or domain local
> groups, etc, that are in other domains. But if the IM sees that stuff in
> the GC, it will satisfy itself (in layman's terms!) that it already knows
> what's out there, not knowing it's incorrect.
>
> What the IM does:
> http://support.microsoft.com/?id=197132#XSLTH3159121123120121120120
>
> On DC1, uncheck the "This is a GC" box. Let replication happen and check
> it out. Likewise with all other domains, since each domain has an IM.
>
> Let us know if that helped.
>
> Ace
>
>
.
- Follow-Ups:
- Re: AD - users and computers in child domain
- From: Ace Fekay [MVP]
- Re: AD - users and computers in child domain
- From: Ulf B. Simon-Weidner [MVP]
- Re: AD - users and computers in child domain
- References:
- AD - users and computers in child domain
- From: Fyodor Yemelyanenko
- Re: AD - users and computers in child domain
- From: Ace Fekay [MVP]
- Re: AD - users and computers in child domain
- From: Fyodor Yemelyanenko
- Re: AD - users and computers in child domain
- From: Ace Fekay [MVP]
- Re: AD - users and computers in child domain
- From: Fyodor Yemelyanenko
- Re: AD - users and computers in child domain
- From: Ace Fekay [MVP]
- AD - users and computers in child domain
- Prev by Date: Where are passwords stored in AD?
- Next by Date: Re: Where are passwords stored in AD?
- Previous by thread: Re: AD - users and computers in child domain
- Next by thread: Re: AD - users and computers in child domain
- Index(es):
Relevant Pages
|