Difference between revisions of "Information Systems:UWDDC4 Domain Controller"

From uniWIKI
Jump to navigation Jump to search
 

Revision as of 10:26, 23 June 2016

This Active Directory domain controller holds none of the FSMO roles for the unipharm.local domain.

This server has an OS of Windows Server 2012R2 and the only server role that is installed is to be a domain controller. No other applications or services are installed and no other programs or services SHOULD be installed on a domain controller. The AD setup is generic as in there is only 1 forest with 1 domain and no sub domains. There is only 1 site configured so replication only occurs with the other DC, which is UWDDC3. The reason why they are labeled as DC3 and DC4 is because we originally started with DC1 and DC2 and we needed all 4 to be up during a hardware refresh. Microsoft does not recommend re-using host names and IP addresses when installing domain controllers.

Due to the OS being Server 2012R2, all of the GPO templates for Windows7 clients and Server 2008R2 clients were included. DarrenF installed the Windows10 GPO templates in early 2016 for testing purposes. When Windows10 clients are deployed, the GPO templates will be applicable.

The OU's in the unipharm.local are organized by department with a couple of exceptions. Buyers have different GPO's assigned to them so buyer's assistants have their own OU and their own GPO's. The GPO's assigned to JohnT and JeremyM are in the Business Intelligence OU because they wanted the same GPO settings. To be more logical, JohnT would be in the Managers OU and Jeremy should be in the IT OU. The design of the OU structure is fine for uniPHARM but might not scale up if the number of staff doubles or triples and there are many more departments doing very different work.

The list of GPO files in AD are properly labeled for what they do. A GPO marked as for printers only handles printers, a GPO for mapped drives only handles mapped drives. There are GPO files with many many settings and they are marked logically so that it is obvious. The GPO files that contain lots of settings are assigned to most of the departmental OU's.

As of 2016, the IT department is not using GPO's to deploy software, only for Windows configuration, printers, mapped drives and URL favourites.