Re: Universal Group Membership Caching
- From: "Austin Osuide" <austin@xxxxxxxxxxx>
- Date: Thu, 25 Oct 2007 21:51:30 +0100
I'm afraid Jorge you got it wrong there.
Once you flip the DFL switch to 1, the KDC when authenticating a client really doesn't have visibility of the number of domains etc. that's why it looks for a GC to create the users Security Token. If it doesn't find one, it barfs. A failsafe measure.
That's why to cover that base, the first DC in a single domain forest is a GC!
Also, docs here: http://support.microsoft.com/kb/216970
Regards,
Austin
"Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx> wrote in message news:%230TTsS0FIHA.4228@xxxxxxxxxxxxxxxxxxxxxxx
HiA GC will still need to be contacted for logon to succeed (Native mode assumed).
This isn't totally true.
Actually this is only true for Forests with multiple domains, but there are other situations where it doesn't apply, for example: in a single domain environment it doesn't apply.
--
===================================
I hope that the information above helps you.
Have a Nice day.
Jorge Silva
MCSE, MVP Directory Services
===================================
"Austin Osuide" <austin@xxxxxxxxxxx> wrote in message news:eWFCbeyFIHA.4712@xxxxxxxxxxxxxxxxxxxxxxxHi RC,
Universal Group Membership Caching is a function of the DCs in the site you've enabled it on. If you have no DCs in the site, it will have no effect if the users logon to DCs in other sites that do not have UGMC enabled and have no local GCs. A GC will still need to be contacted for logon to succeed (Native mode assumed).
Regards,
Austin
"RC" <RichChristy@xxxxxxxxx> wrote in message news:1193330500.425707.138770@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxIf you create a site, assign the appropriate subnets, but it doesn't
have a DC associated with the site and enable UGMC (universal group
membership caching) does UGMC still effectively do what it is designed
to do?
I would assume not unless you have a DC in that site right?
Thanks in advance.
.
- Follow-Ups:
- Re: Universal Group Membership Caching
- From: Dean Wells \(MVP\)
- Re: Universal Group Membership Caching
- From: Jorge Silva
- Re: Universal Group Membership Caching
- References:
- Universal Group Membership Caching
- From: RC
- Re: Universal Group Membership Caching
- From: Austin Osuide
- Re: Universal Group Membership Caching
- From: Jorge Silva
- Universal Group Membership Caching
- Prev by Date: Re: Old network drive letter keeps reappearing
- Next by Date: Active Directory FSMO, GC and Exchange Proper Setup
- Previous by thread: Re: Universal Group Membership Caching
- Next by thread: Re: Universal Group Membership Caching
- Index(es):
Relevant Pages
|
Loading