AD FSMO and remote DC GPO creation


just question ad fsmo , gpo. have 2 dc's fsmo roles in main office. remote offices have dc's gc on them. if have wan problem, able create gpo remote office users ? gpo work remote users if link gpo ou ? or each time create gpo need have connection dc's fsmo roles ? windows 2008r2

if edit group policy in domain changes stored in ad , sysvol , replicated out other dcs in domain.

editing or creation of group policy objects (gpo) done gpo copy found in pdc emulator's sysvol share, unless configured not administrator 

so pdc emultaor plays important role.  can display current server gpmc working against through view - options - general, check middle check box

computers/users in physical site in use subnets have configured in sites , services dclocator , authenticate against local domain controller local them.  assuming domain controller has copy of gpo , replication has occurred shouldn't have problem applying gpo.

the article below 2003 still read. i've pasted of below , linked article well.

group policy replication

in domain contains more 1 domain controller, group policy information takes time propagate, or replicate, 1 domain controller another. low bandwidth network connections between domain controllers slow replication. group policy infrastructure has mechanisms manage these issues.

each gpo stored partly in sysvol on domain controller , partly in active directory. gpmc , group policy object editor present , manage gpo single unit. example, when set permissions on gpo in gpmc, gpmc setting permissions on objects in both active directory , sysvol. not recommended manipulate these separate objects independently outside of gpmc , group policy object editor. shown in following figure, important understand these 2 separate components of gpo rely on different replication mechanisms. file system portion replicated through frs, independently of replication handled active directory. sysvol subfolder (%systemroot%\sysvol\sysvol) shared , replicated. sysvol designed allow multiple domain’s sysvols replicated in same tree — each domain’s sysvol contained under subfolder of sysvol share. current domain, copy of domain’s sysvol subtree stored directly under %systemroot%\sysvol\domain folder.



if answered question, remember “mark answer”.

if found post helpful, please “vote helpful”.

postings provided “as is” no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS