How do I determine total number of Active Directory Forests in an enterprise

%3CLINGO-SUB%20id%3D%22lingo-sub-1680256%22%20slang%3D%22en-US%22%3EHow%20do%20I%20determine%20total%20number%20of%20Active%20Directory%20Forests%20in%20an%20enterprise%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1680256%22%20slang%3D%22en-US%22%3E%3CP%3EI%20heard%20that%20theoretically%20we%20could%20port%20scan%20global%20network%20for%20TCP%203268%20i.e%20identifying%20all%20Global%20Catalog%20Domain%20Controllers(DCs).%20So%20my%20questions%20are%3A%3C%2FP%3E%3COL%3E%3CLI%3E%3CP%3EHow%20identifying%20Global%20Catalog%20servers%20is%20correlated%20with%20total%20number%20of%20Active%20Directory%20Forests%20in%20an%20enterprise%3F%20How%20do%20I%20tell%20total%20number%20of%20forests%20by%20identifying%20all%20Global%20Catalog%20servers%3F%20Please%20elaborate%20this%20method.%3C%2FP%3E%3C%2FLI%3E%3CLI%3E%3CP%3EIs%20there%20any%20alternative%2Fautomated%2Fpractical%20way%20to%20answer%20this%20question%20without%20checking%20network%20documentation%20and%20AD%20design%20documents%20or%20interviewing%3F%3C%2FP%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%3CSPAN%3EKindly%20answer%20with%20explanation%20specific%20to%20above%20mentioned%20questions.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1680256%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1680689%22%20slang%3D%22en-US%22%3ERe%3A%20How%20do%20I%20determine%20total%20number%20of%20Active%20Directory%20Forests%20in%20an%20enterprise%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1680689%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F653925%22%20target%3D%22_blank%22%3E%40G-ONE%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20something%20like%20the%20below%20script%20be%20of%20help%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fgallery.technet.microsoft.com%2Fscriptcenter%2FForest-and-Domain-6060a979%23content%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgallery.technet.microsoft.com%2Fscriptcenter%2FForest-and-Domain-6060a979%23content%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1683238%22%20slang%3D%22en-US%22%3ERe%3A%20How%20do%20I%20determine%20total%20number%20of%20Active%20Directory%20Forests%20in%20an%20enterprise%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1683238%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F383653%22%20target%3D%22_blank%22%3E%40HidMov%3C%2FA%3E%26nbsp%3BIn%20my%20question%2C%20I%20am%20not%20asking%20about%26nbsp%3Bto%20determine%20functional%20level%20of%20the%20Active%20Directory%20forest%20and%20all%20domains%20in%20the%20forest.%20OR%20FSMO%20role%20holders%2C%20all%20sites%2C%20and%20and%20all%20Global%20Catalog%20servers%20in%20the%20forest.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20understand%20my%20original%20question%20clearly%20and%20then%20answer%20specifically.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I heard that theoretically we could port scan global network for TCP 3268 i.e identifying all Global Catalog Domain Controllers(DCs). So my questions are:

  1. How identifying Global Catalog servers is correlated with total number of Active Directory Forests in an enterprise? How do I tell total number of forests by identifying all Global Catalog servers? Please elaborate this method.

  2. Is there any alternative/automated/practical way to answer this question without checking network documentation and AD design documents or interviewing?

Kindly answer with explanation specific to above mentioned questions.

3 Replies
Highlighted
Highlighted

@HidMov In my question, I am not asking about to determine functional level of the Active Directory forest and all domains in the forest. OR FSMO role holders, all sites, and and all Global Catalog servers in the forest.

 

Please understand my original question clearly and then answer specifically.

Highlighted

@G-ONE Apologies - I would have thought that determining discrete forests through an automated script would help. Best of luck with it.