0

I have 3 DC's, with the original as GC. When I configured the new DC for Exchange, i made it a GC as well. best Practices suggest it not be a GC. How negatively can this impact my server? I know it's usually best to heed their advice, Im just curious as i now have a good config, and afraid to change anything...

Seth
  • 334
  • 2
  • 9
  • 21

1 Answers1

2

Best practice is to always separate your Domain Controllers from ALL other applications. I would suggest demoting the DC that you have Exchange installed on and making the additional two DC GL servers as well.

If your on different subnets and the Exchange is on the only DC for that network, I would propose creating a new DC. If its a small network it doesn't need to be super powerful, if your on 2008/R2 you can even look at doing an RDOC (Remote Domain Controller) with a minimal install.

st3v3o
  • 470
  • 1
  • 3
  • 9
  • Would you say there are any negative impacts of demoting it now that I just got Exchange configured? I must say however, 2008 has more GP options to handle 7. I thought when I updated the schema 2003 would get these new policies? Maybe doesn't work that way? – Seth Feb 25 '11 at 18:49
  • I'm not 100% on the possibility of there being negative impacts, though you shouldn't have any issue. 2008 AD does offer a MUCH greater extension of GPOs that you can apply, that were specially designed to work with Windows 7 and newer – st3v3o Feb 25 '11 at 20:38