Do I really need domain controllers at every remote office?

0
17
Asked By TechWiz99 On

I manage a company with 12 locations, including a main office and several remote sites. Each of the remote locations currently has its own domain controller, but we are using Active Directory sync to connect to Azure AD. Given that the remote sites have site-to-site VPN connectivity back to the main office and colocation center, I'm questioning whether it's necessary to maintain domain controllers at every single remote location. Most of these remote sites have 5-10 users. Would it be reasonable to remove the domain controllers from these smaller sites, or is there something I'm missing?

5 Answers

Answered By NetGuru42 On

I’d say ditch the DCs and reinvest those funds into a more reliable failover ISP instead. It could potentially improve your overall network performance!

Answered By FutureProofIT On

You can definitely remove those local DCs if you ensure good connectivity to the DCs in your colo. Just keep in mind your plans for DHCP and DNS. If it’s all running smoothly, then you should be fine. However, a larger number of clients or increased latency might make an onsite DNS necessary.

Answered By OfflineOrBust On

Think about what would happen if the internet goes down. It’s easy to assume that nobody can work without internet access, but having a local DC can allow some work to continue offline. You might really want to weigh the difference in functionality between sites with and without a DC during an outage. If users are completely locked out of their systems without a DC, that’s a significant risk. Just documenting the implications of losing internet access could save you some headaches later.

Answered By TechYoda88 On

Having just one domain controller is risky. If you only have one DC and there’s an outage, you could be in serious trouble. It's better to have redundancy and make sure you’re configured correctly so that users can always connect to a DC, wherever they are.

Answered By CloudyDayDreamer On

For small teams of 5-10 people with a solid site-to-site VPN to your main office and colo, keeping local DCs seems unnecessary. You'd just be complicating things with added security risks and potential failure points if someone misconfigures something. Just make sure your VPN is reliable. If it goes down, users might struggle to log in, as they’d be relying on cached credentials. So, definitely consider testing your network reliability before making the switch.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.