Min AD Requirements

J

Joe Bushee

I'm setting up our DR site, and want to test some
restores, using a seperate hub to create a mini domain to
do some application testing.

I'm testing one application server which is a DC and our
Exchange server which is a Global Catalog server and also
a DC, but not our DC01 (currently holding the 5 FSMO
roles).

If I just seize the 5 FSMO roles on the DR DC, will there
be enough AD there for the mini-domain to function?

Thanx
Joe
 
P

Paul Bergson

You will need dns as well. Run dcdiag in verbose mode to check if things
are working well and watch your rid fsmo role to make sure it has a new rid
pool assigned. You

Make sure the two domains can't talk to one another and don't EVER connect
the tow together once you seize the roles.
 
J

Joe Bushee

Thanx, and sorry if I appear dense, but some further
clarification please.

We have DNS functioning, and the servers can talk to each
other, but no logon scripts are running etc.

Can you give me a bit more info on DCDIAG and checking the
RID pool please?

Thanx again
Joe
 
P

Paul Bergson

Disregard step number they are from my DR plan.



14. This DC needs to be the File Replication Service Master (Q316790)

· Stop the File Replication service on the DC

· Start Registry Editor (Regedt32.exe)

· Locate and then click the BurFlags value under the following key in
the registry:

¨
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtFrs\Parameters\Backup
/Restore\Process at Startup

· On the Edit menu, click DWORD, click Hex, type D4, and then click
OK

· Quit Registry Editor

· Restart the File Replication Service



14. This DC needs to be a Global Catalog Server

· Click Start, point to Programs, click Administrative Tools, and
then click Active Directory Sites and Services

· Double-click Sites to expand it, expand Servers, and then select
the DC

· Double-click the DC to expand the server contents

· Below the server, an NTDS Settings object is displayed. Right-click
the object, and then click Properties

· On the General tab, you can observe a global catalog check box,
which should be selected, by default

¨ If the global catalog check box is not checked, then check it



17. Ensure that the DC has registered the proper computer role

· Enter net accounts at a dos prompt

¨ The computer role should say "primary"



27. Do an analysis of the AD within the Enterprise

· If exists delete c:\dcdiag.log

· Using dcdiag.exe

¨ "C:\program files\support tools\dcdiag" /e /c /v /f:c:\dcdiag.log

§ This program can take several minutes to complete

§ The log file is stored in c:\dcdiag.log

§ Review the log file for errors

v Any previous Replication errors in the Replication Event Log will
appear in this log




Rid pool is where object creation sid assignment values are kept. DCDIAG
which I have defined above will check to see if it works. If you see any
failed messages then examine what exactly isn't working and if you have to
fix it.




--

Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.
 
J

Joe Bushee

Thanx Paul. Will attempt Tuesday.

Joe
-----Original Message-----
Disregard step number they are from my DR plan.



14. This DC needs to be the File Replication Service Master (Q316790)

· Stop the File Replication service on the DC

· Start Registry Editor (Regedt32.exe)

· Locate and then click the BurFlags value under the following key in
the registry:

¨
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtFrs \Parameters\Backup
/Restore\Process at Startup

· On the Edit menu, click DWORD, click Hex, type D4, and then click
OK

· Quit Registry Editor

· Restart the File Replication Service



14. This DC needs to be a Global Catalog Server

· Click Start, point to Programs, click Administrative Tools, and
then click Active Directory Sites and Services

· Double-click Sites to expand it, expand Servers, and then select
the DC

· Double-click the DC to expand the server contents

· Below the server, an NTDS Settings object is displayed. Right-click
the object, and then click Properties

· On the General tab, you can observe a global catalog check box,
which should be selected, by default

¨ If the global catalog check box is not checked, then check it



17. Ensure that the DC has registered the proper computer role

· Enter net accounts at a dos prompt

¨ The computer role should say "primary"



27. Do an analysis of the AD within the Enterprise

· If exists delete c:\dcdiag.log

· Using dcdiag.exe

¨ "C:\program files\support
tools\dcdiag" /e /c /v /f:c:\dcdiag.log
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top