I have 3 DC's, with the original as GC. When I configured the new DC for Exchange, i made it a GC as well. best Practices suggest it not be a GC. How negatively can this impact my server? I know it's usually best to heed their advice, Im just curious as i now have a good config, and afraid to change anything...
Asked
Active
Viewed 296 times
0
-
What best practice are you referring to? – joeqwerty Feb 24 '11 at 16:54
-
Best Practice Analyer – Seth Feb 24 '11 at 17:05
-
What is it reporting, specifically? – joeqwerty Feb 24 '11 at 17:17
-
What I said above, it suggests the Exchange server not be a Global Catalog – Seth Feb 24 '11 at 18:22
-
OK, I misunderstood. I didn't realize you had Exchange installed on a DC. Why did you install it on a DC? – joeqwerty Feb 24 '11 at 18:28
-
It was my impression it would increase lookup performance is all – Seth Feb 24 '11 at 18:34
-
It's really not considered best practice to install Exchange on a DC except in the case of SBS. – joeqwerty Feb 24 '11 at 19:06
1 Answers
2
Best practice is to always separate your Domain Controllers from ALL other applications. I would suggest demoting the DC that you have Exchange installed on and making the additional two DC GL servers as well.
If your on different subnets and the Exchange is on the only DC for that network, I would propose creating a new DC. If its a small network it doesn't need to be super powerful, if your on 2008/R2 you can even look at doing an RDOC (Remote Domain Controller) with a minimal install.

st3v3o
- 470
- 1
- 3
- 9
-
Would you say there are any negative impacts of demoting it now that I just got Exchange configured? I must say however, 2008 has more GP options to handle 7. I thought when I updated the schema 2003 would get these new policies? Maybe doesn't work that way? – Seth Feb 25 '11 at 18:49
-
I'm not 100% on the possibility of there being negative impacts, though you shouldn't have any issue. 2008 AD does offer a MUCH greater extension of GPOs that you can apply, that were specially designed to work with Windows 7 and newer – st3v3o Feb 25 '11 at 20:38