We have a smallish web farm of < 5 Windows 2008 servers. Some do data, most do IIS hosting. Is it a good/bad idea to set up a domain controller and put all in the same "production" domain?
We want to avoid a world where we have to sync multiple admin passwords between the boxes (or share admin credentials among the team).
Presumably, the DC would be just another VM, so hardware cost doesn't enter into the discussion.
Clarifying: the DC would presumably be a standalone "ProdServers" domain all connected on a private network. The office domain would be 100% separate. So most admins would have credentials for the main office, plus a second set for the production domain.