C
Chauncy Desmond
Hi All,
Planning AD...I've read the MS branch office planning guides...still on the
fence about placing a DC at each site. We have roughly 10-15 sites around
the globe. For ease of administration and cost, we are using a single domain
model and sites over VPN-based WAN.
I would like to have a DC at each site, but we do not have a full time IT
staff member at just about all of the branch offices. I am worried about the
security of the DC's at these offices, so i am thinking about not putting a
DC at all at most sites and just having users authenticate over WAN.
However, when the WAN link dies, users can not access local network
resources (without using 'local' user accounts, which someone will have to
administer/sync with domain user accounts.)
So back to a DC at each site...if we back up the domain controller to tape,
wont ALL of our AD info be on the tape waiting to be cracked by who knows
what?
Sorry if I seem paranoid...maybe its because i am![Wink ;) ;)](/styles/default/custom/smilies/wink.gif)
Just wondering what others might be doing for AD on a low budget and no IT
staff at branch offices. Any advice is greatly appreciated...
Planning AD...I've read the MS branch office planning guides...still on the
fence about placing a DC at each site. We have roughly 10-15 sites around
the globe. For ease of administration and cost, we are using a single domain
model and sites over VPN-based WAN.
I would like to have a DC at each site, but we do not have a full time IT
staff member at just about all of the branch offices. I am worried about the
security of the DC's at these offices, so i am thinking about not putting a
DC at all at most sites and just having users authenticate over WAN.
However, when the WAN link dies, users can not access local network
resources (without using 'local' user accounts, which someone will have to
administer/sync with domain user accounts.)
So back to a DC at each site...if we back up the domain controller to tape,
wont ALL of our AD info be on the tape waiting to be cracked by who knows
what?
Sorry if I seem paranoid...maybe its because i am
![Wink ;) ;)](/styles/default/custom/smilies/wink.gif)
Just wondering what others might be doing for AD on a low budget and no IT
staff at branch offices. Any advice is greatly appreciated...