Home › Deploying domain controllers › Step 6

Best practices for virtualising domain controllers

Step 6 of 6 in Deploying domain controllers · video 3:22

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Virtual domain controllers bring hardware independence, better use of resources and easier scaling, but they need some care so that AD DS is not put at risk. The lesson lists the main practices. Run at least two virtual DCs per domain on different hosts, and spread them across hardware, storage, networks and, ideally, data centres or regions. Make sure hosts and guests belong to the same time infrastructure and keep the same time. Choose a hypervisor that supports the virtual machine generation identifier and run Windows Server 2012 or later guests, so that the virtualisation safeguards and cloning work. Where those safeguards are missing, prevent checkpoints entirely, for example with a pass-through disk; even with safeguards, avoid them. Treat virtualisation administrators as being as trusted as domain admins. The lesson ends with cloning guidance: start no more than 10 clones at once, move clones to branch sites during off-peak hours, and plan a naming scheme that allows for clone names.

Good to know: common Microsoft guidance for Hyper-V is to stop domain controller guests taking their time from the host (partly disable the Time synchronization integration service) so that they follow the domain time hierarchy.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What is the minimum number of virtual domain controllers per domain the lesson recommends, and where should they run?

At least two, on different virtualisation hosts, so that the failure of one host cannot take out every domain controller in the domain.

2. What does the lesson advise about time on the hypervisor host and its domain controller guests?

All of them should take part in the same time service infrastructure, and host and guest clocks must not differ, because AD DS relies on accurate time, for example for Kerberos authentication.

3. What should you do about checkpoints on a virtual DC whose host or guest does not support the virtualisation safeguards?

Make checkpoints impossible, for example by giving the DC a pass-through disk instead of a virtual hard disk, because rolling a DC back to an old checkpoint without safeguards can damage directory replication.

4. You need 30 new domain controllers from clones. Why should you not start them all at once?

The file replication used for SYSVOL allows only 10 replication connections at the same time, so clones should be started in batches of 10 at most.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← Cloning virtual domain controllersPath complete - back to Deploying domain controllers →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.