QuestionQ49

Deploy and manage AD DS

Your network includes an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.

You open a new branch office that contains only client computers.

You need to make sure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.

Solution: You configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO linked to Site1.

Does this fulfill the goal?

Explanation

A site-linked GPO applies to computers within that Active Directory site, so linking this setting to Site1 does not target the new branch-office clients. The Try Next Closest Site setting also selects a fallback site according to site-link cost only when no domain controller is available in the client’s own site; it does not designate Site1 as the clients’ primary authentication site.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!