Authenticating users without local DC

%3CLINGO-SUB%20id%3D%22lingo-sub-2404282%22%20slang%3D%22en-US%22%3EAuthenticating%20users%20without%20local%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2404282%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20All.%20We%20are%20looking%20to%20setup%20a%20few%20smaller%20sites%20with%20no%20DC%20in%20those%20sites.%20My%20question%20is%2C%20to%20point%20those%20users%20in%20those%20smaller%20sites%20to%20authenticate%20to%20a%20DC%20in%20one%20of%20our%20datacenters%20would%20I%20create%20the%20subnet%20for%20each%20of%20the%20smaller%20sites%20and%20associate%20that%20subnet%20with%20the%20datacenter%20site%20where%20the%20DC%20lives%20OR%20would%20I%20create%20a%20new%20site%20for%20for%20each%20of%20the%20smaller%20locations%20and%20create%20a%20site%20link%20to%20the%20datacenter%20site%20where%20the%20DC%20lives%3F%20I%20was%20under%20the%20impression%20that%20creating%20site%20links%20would%20only%20be%20for%20sites%20that%20have%20a%20DC%20and%20facilitate%20replication%20and%20not%20for%20pointing%20users%20to%20a%20DC.%20I%20have%20been%20researching%20this%20and%20am%20confused%20on%20what%20I%20am%20reading.%20Any%20help%20is%20greatly%20appreciated.%3CBR%20%2F%3E%3CBR%20%2F%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2404282%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAD%20Sites%20and%20services.%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2404594%22%20slang%3D%22en-US%22%3ERe%3A%20Authenticating%20users%20without%20local%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2404594%22%20slang%3D%22en-US%22%3E%3CP%3ESome%20general%20info%20here.%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Forphan-topics%2Fws.10%2Fcc755768(v%3Dws.10)%3Fredirectedfrom%3DMSDN%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EBest%20practices%20for%20Active%20Directory%20Sites%20and%20Services%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3ESites%20that%20do%20not%20have%20their%20own%20domain%20controllers%20and%20at%20least%20one%20global%20catalog%20are%20dependent%20on%20other%20sites%20for%20directory%20information%2C%20making%20the%20utilization%20of%20network%20bandwidth%20between%20sites%20less%20efficient.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Fwindows%2Fit-pro%2Fwindows-2000-server%2Fcc978011(v%3Dtechnet.10)%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EDomain%20Controller%20Location%20Process%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2408665%22%20slang%3D%22en-US%22%3ERe%3A%20Authenticating%20users%20without%20local%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2408665%22%20slang%3D%22en-US%22%3EPlease%20create%20a%20site%20and%20associate%20the%20necessary%20subnet%20for%20site-Subnet%20mapping%20and%20followed%20by%20for%20DC-Less%20sites%2C%20please%20update%20the%20DNS%20Site%20LDAP%20priority%20and%20those%20Scopes%20based%20DNS%20option%20to%20target%20the%20data%20center%20for%20proximity%20authentication.%3C%2FLINGO-BODY%3E
Contributor

Hello All. We are looking to setup a few smaller sites with no DC in those sites. My question is, to point those users in those smaller sites to authenticate to a DC in one of our datacenters would I create the subnet for each of the smaller sites and associate that subnet with the datacenter site where the DC lives OR would I create a new site for for each of the smaller locations and create a site link to the datacenter site where the DC lives? I was under the impression that creating site links would only be for sites that have a DC and facilitate replication and not for pointing users to a DC. I have been researching this and am confused on what I am reading. Any help is greatly appreciated.

Thanks!

4 Replies

Some general info here.

Best practices for Active Directory Sites and Services | Microsoft Docs

Sites that do not have their own domain controllers and at least one global catalog are dependent on other sites for directory information, making the utilization of network bandwidth between sites less efficient.

   

Domain Controller Location Process | Microsoft Docs

 

 

Please create a site and associate the necessary subnet for site-Subnet mapping and followed by for DC-Less sites, please update the DNS Site LDAP priority and those Scopes based DNS option to target the data center for proximity authentication.

@Seshadrr Thanks for the response. Are you referring to changing these DNS records under "Sites" in DNS and pointing the records to the DC's in the datacenter?

charlie4872_0-1622651657092.png

 

If you need proximity for the data center, which can be stunned via LDAP priority set to Datacenter DC or your site's clients Ipaddress leased by DHCP, then use the DNS server option as Datacenter get immediate DNS resolution in that way the proximity auth will be nearest.