QuestionQ50

Deploy and manage AD DS

Your network includes an Active Directory Domain Services (AD DS) forest. The forest contains three Active Directory sites named Site1, Site2, and Site3. Each site contains two domain controllers. The sites are connected by using DEFAULTIPSITELINK.

You open a new branch office that contains only client computers.

You need to make sure that the client computers in the new office are primarily authenticated by the domain controllers in Site1.

Solution: Create an organizational unit (OU) containing the client computers in the new branch office. Configure the Try Next Closest Site Group Policy Object (GPO) setting in a GPO linked to the new OU.

Does this accomplish the goal?

Explanation

The Try Next Closest Site policy makes DC Locator try a domain controller in the next closest Active Directory site, determined from site topology and site-link costs, when it cannot locate one in the client’s own site. It does not select or prioritize a named site such as Site1. Ensuring Site1 is used would require appropriate site/subnet and site-link topology configuration so that Site1 is the applicable closest site.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!