AD Domain Scope - TechRepublic
General discussion
August 16, 2001 at 08:05 AM
tomh

AD Domain Scope

by tomh . Updated 24 years, 10 months ago

I?m having a hard time with this particular issue:

My understanding is that if you have a four domain tree (one parent of mobilian.com (dedicated forest root) and three children pdx, san, isr), each of the four domains keeps a copy of the wholeAD for it?s respective domain, and a global catalog for a subset of the AD?s in the other domains. In addition, the root domain, while being the parent of pdx, san, and isr, only has a full AD of itself (mobilian.com) and not of it?s children, while it does have a gc of a subset of it?s children.

What this means is that if our root domain becomes unavailable, the only features that are unavailable on the entire tree are those that are affected by the lack of a schema master (which is responsible for changes to the AD schema) and a domain naming master (which is responsible for the addition or removal of domains in the forest). Which means our entire network keeps functioning, but we can no longer authenticate in mobilan.com, add or remove domains, or modify the active directory schema.

Is this perception correct? If not can you show me some documentation somewhere that says that the parent domain has the full AD of it?s children?

This discussion is locked

All Comments