Use of Restricted Groups

R

Ryan Sanders

I am looking to use Restricted Groups on several domain security groups.
I would like to create a domain level GPO that contains explicit
membership to several highly sensitive security groups. I have read in
the documentation on this and it says it is not advise on Domain
Controllers.

What I can not find is why not. This works great in my lab.

Other considerations?

Thanks!
 
J

Joe Richards [MVP]

And of course a single DC is a bad thing. It means on any kind of
failure you are doing a full domain restore. This isn't something you
generally want to have to do. Even if the second DC is a very small
underpowered machine it is better than nothing because it can reduce
your complete and utter downtime from hours/days to nothing and just
running in a reduced capacity. Plus you don't have to restore, you can
just rebuild and repromote your main DC which is much preferred to a
recovery.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top