AD FSMO and remote DC GPO creation
just question ad fsmo , gpo. have 2 dc's fsmo roles in main office. remote offices have dc's gc on them. if have wan problem, able create gpo remote office users ? gpo work remote users if link gpo ou ? or each time create gpo need have connection dc's fsmo roles ? windows 2008r2
if edit group policy in domain changes stored in ad , sysvol , replicated out other dcs in domain.
editing or creation of group policy objects (gpo) done gpo copy found in pdc emulator's sysvol share, unless configured not administrator
so pdc emultaor plays important role. can display current server gpmc working against through view - options - general, check middle check box
computers/users in physical site in use subnets have configured in sites , services dclocator , authenticate against local domain controller local them. assuming domain controller has copy of gpo , replication has occurred shouldn't have problem applying gpo.
the article below 2003 still read. i've pasted of below , linked article well.
group policy replication
in domain contains more 1 domain controller, group policy information takes time propagate, or replicate, 1 domain controller another. low bandwidth network connections between domain controllers slow replication. group policy infrastructure has mechanisms manage these issues.
each gpo stored partly in sysvol on domain controller , partly in active directory. gpmc , group policy object editor present , manage gpo single unit. example, when set permissions on gpo in gpmc, gpmc setting permissions on objects in both active directory , sysvol. not recommended manipulate these separate objects independently outside of gpmc , group policy object editor. shown in following figure, important understand these 2 separate components of gpo rely on different replication mechanisms. file system portion replicated through frs, independently of replication handled active directory. sysvol subfolder (%systemroot%\sysvol\sysvol) shared , replicated. sysvol designed allow multiple domain’s sysvols replicated in same tree — each domain’s sysvol contained under subfolder of sysvol share. current domain, copy of domain’s sysvol subtree stored directly under %systemroot%\sysvol\domain folder.
if answered question, remember “mark answer”.
if found post helpful, please “vote helpful”.
postings provided “as is” no warranties, , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment