Should i virtualize domain controllers




















VMware fully supports virtualizing Domain Controller as long as you follow their recommended practices. You could ask yourself if Microsoft still tests Domain Controller functionality and updates on physical hardware.

You can run Domain Controllers on machines with loathsome specifications. When running Domain Controllers as Server Core installations, the requirements drop even further. This makes them ideal candidates to virtualize. The distributed nature of the Active Directory database also adds to the virtualization-friendliness of Active Directory. Just add small-sized VMs to the virtualization platform and Active Directory is again ready to go.

All Domain Controllers are created equal but some Domain Controllers, like the aforementioned PDC emulator and replication offers a multi-master model. This makes Active Directory resilient; with the majority of Domain Controllers decimated during a disaster, it can still function. This proclivity stems from the complexity of timekeeping in virtual machines, deviation from current build processes or standards, the ability to keep an AD Flexible Single Master Operations FSMO role physical, privilege escalation, and fear of a stolen.

The release of Windows Server and Windows Server and its virtualization-safe features and support for rapid domain controller deployment alleviates many of the legitimate concerns that administrators have about virtualizing AD DS. Active Directory is the cornerstone to every environment — when Active Directory comes to a halt, everything connected does too. Since many domain controller virtual machines may be running on a single VMware ESXI host, eliminating single points of failure and providing a high-availability solution will ensure rapid recovery.

VMware provides solutions for automatically restarting virtual machines. Using configuration options, you can prioritize the restart or isolation status for individual virtual machines. VMware also allows you to specify a priority for restarting virtual machines. For example, it is important for domain controllers functioning as global catalog servers to be online before your Exchange Server environment initializes. It is always a best practice to set your domain controller virtual machines as high-priority servers.

Popular Topics in Virtualization. Spiceworks Help Desk. The help desk software for IT. Track users' IT needs, easily, and with only the features you need. Learn More ». Pure Capsaicin. Virtualization expert.

Ghost Chili. Robert This person is a verified professional. Verify your account to enable IT peers to see that you are a professional. There are at least two schools of thought on this topic, and many different opinions. Personally, I like to keep a physical server as a domain controller. Edit: looks like others were beating me to the punch while I was typing. Ethan This person is a verified professional. CPHastings This person is a verified professional.

Thai Pepper. Matthew May 3, at UTC. The host should have either a local admin account or at least cached domain admin credentials. In my environment, I just connect to the host local, logon as a local admin and then start the VM's if needed. Even with a domain-joined host I keep a local account for this exact reason just in case.

That being said it's never a terrible idea to keep at least one physical DC in the mix. This topic has been locked by an administrator and is no longer open for commenting.

Read these next For more information about this scenario, see Avoid creating single points of failure. These DCs on separate platforms should be kept online and be network-accessible in DNS and in all required ports and protocols to the clustered hosts.

In some cases, the only DCs that can service authentication requests during cluster startup are on a clustered host computer that's being restarted. In this situation, authentication requests fail, and you must manually recover the cluster. Do not assume that this situation applies to Hyper-V only. Third-party virtualization solutions can also use Active Directory as a configuration store or for authentication during certain steps of VM startup or configuration changes.

For more information, see Support policy for Microsoft software that runs on non-Microsoft hardware virtualization software. Feedback will be sent to Microsoft: By pressing the submit button, your feedback will be used to improve Microsoft products and services. Privacy policy.

Skip to main content. This browser is no longer supported. Download Microsoft Edge More info. Contents Exit focus mode. Applies to: Windows Server , Windows Server , Windows Server R2 Original KB number: Summary A virtual hosting environment lets you run multiple guest operating systems on a single host computer at the same time.

Host software virtualizes the following resources: CPU Memory Disk Network Local devices By virtualizing these resources on a physical computer, host software lets you use fewer computers to deploy operating systems for testing and development, and in production roles.

VMware family of virtualization products. Novell family of virtualization products. Citrix family of virtualization products. For more information about the current status of system robustness and security for virtualized DCs, see the following article: Virtualizing Domain Controllers using Hyper-V.



0コメント

  • 1000 / 1000