authentication between member computers (in remote site) when no domain controller available
i need input on how organise access file share if domain controller computers unavailable...
i have large network many small sites (over 100 separate locations), each having 2-6 computers. need these computers domain enable many remote management, asset management , software deployment tasks. have been testing first few sites, running major trouble if domain controller unavailable reason.
in each site, 1 of computers is a "main computer" hosts few shares , databases other computers in site. main computer desktop, no server grade hardware in sites. when domain controller available (= wan functional), there no problems. computers can talk each other happily. however, if connection domain controller cut, authentication between member computers fails, , site rendered useless computers lose access "main computer" shares. this unacceptable, need find solution or workaround.
all computers in question windows xp sp3, latest patches, on desktop hardware.
i can't spare domain controllers in each location, because of license, hardware , management costs (again, on 100 locations). hope can tell me alternative/fallback authentication methods or workarounds.
any insight appreciated!
without remote dcs, may need failback local accounts created on these system. not the best solution, work without additional cost.
for instance, if these failures expected occur infrequently, can have "backup" account can defined locally on each computer @ site. during situation when network down, users can use account access resources on each of local comptuers in site. can have gpo in place routinely change password prevent users bypassing requirement of using local "backup" account when network operational.
visit: anitkb.com, knowledge base.
Windows Server > Directory Services
Comments
Post a Comment