Operations Masters/ High kerberos authentications
hi guys
we have couple of domains in our forest - domain.com forest root, have emea.domain.com, usa.domain.com, apac.domain.com etc. each domain has 6 dc's.
in usa domain, notice 3 domain-specific operations masters (pdc, rid, infrastructure master) held on 1 dc (dc3.usa.domain.com). wise? ad experts on here recommend each role has different dc- and, if so, why? or perhaps better have them on 1 dc?
one of reasons ask our 3rd party monitoring tool reporting dc3.usa.domain.com has high levels of requested kerberos authentications , trying figure out why.
the usa domain has several domain trusts other external domains....would these authenticate against pdc?
thanks..
see here fsmo placement:
http://support.microsoft.com/kb/223346/en-us
you have take care of infrastructure master role in multi domain environment.
see also:
http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/03/08/37975.aspx
best regards meinolf weber disclaimer: posting provided "as is" no warranties, , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment