Active Directory slow for certain users

H

Herb Martin

Hi Herb,

Around 20 groups, which I don't think is excessive. I did discover that
there were some circular lookups going on as some of the groups
referenced each other (for example a UK admin group was a member of a
French admin group and vice versa). Correcting this didn't solve the
problem though unfortunately.

No big deal.

"French admin group". How many domains?

How many GPOs? Where do they originate?

Are you pulling GPOs across domains?
Is there a way to see which groups are member or which other groups
without manually looking?

Probably although not likely some standard tool, but I don't know.
 
X

xmeta4x

There are 11 domains in total now, although there were only 5 when the
problem began! Slow users do not necessarily belong to groups outside
of their parent domain.
GPO is applied on a site basis, so should affect all users equally (or
not at all).

Having exhausted everything I can think of, I've passed the problem
over to our MS whizkid (ok whizoldguy) in the US. If he cracks it I'll
post the fix back here!
 
H

Herb Martin

There are 11 domains in total now, although there were only 5 when the
problem began! Slow users do not necessarily belong to groups outside
of their parent domain.
GPO is applied on a site basis, so should affect all users equally (or
not at all).

The question was really (and not very clear probably) are any of the
GPOs being pulled (especially for slow users) across Domains?
e.g.., users from domain X getting a (site or other) GPO from domain Y?

That is known to be a performance issue.

How large is the stack of GPOs? (GPResult can help)

Are any of the "slow users" supposed to be downloading software
updates? (That can be slow and if it isn't working would re-start
on each logon attemtp....)

If you are authorized, put a Network Monitor (netmon, Etherreal, etc.)
on the line and watch one of them logon....
Having exhausted everything I can think of, I've passed the problem
over to our MS whizkid (ok whizoldguy) in the US. If he cracks it I'll
post the fix back here!

I would seriously consider going back (if you haven't already) and
running DCDiag on (every one of) the DCs.

DNS is again the most likely cause of slowness and DCDiag should
be run periodically anyway.
 
X

xmeta4x

It turned out the cyclical group memberships were the problem. The fix
didn't replicate down for a while, but things are now just as fast as
ever!

Thanks for all your help everyone.

Andy
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top