Backup Approach
System State Backup
Backup Tool
Windows Server Backup (WBADMIN.EXE)
Operating System
Windows Server 2012 R2
Backup Frequency
Daily
Domain Controllers to Backup
At least Two DCs per Domain, one of those should be FSMO role holder
Backup Method
Through Scheduled Task (1 Full > 14 Incremental > 1 Full > 14 Incremental )
Where to Store the Backup
In a non-system disk, mounted as a local disk. Not in network share.
Backup Versioning
Versioning will be managed automatically by the backup tool.
Disk Space Management
Will be managed automatically by the backup tool.
Service Account
NT AUTHORITY\SYSTEM
Area
Design Considerations & Best Practices
Forest & Domain Layout
1) In a single forest multi-domain model, typically the root domain should act as the Resource Domain, which hosts critical infrastructure like CA servers, Exchange, Lync, ADFS etc.
2) Forest Root Domain typically hosts some Group Policies which are applied / enforced to all the child domains.
3) Forest Root Domain should not host users and groups, unless Enterprise Admins and Certificate Admins.
4) Domain Controllers of Forest Root Domain should be spread across multiple regions.
5) For large enterprises which are spread globally, the domains should ideally be based on regions.
6) For High Availability (HA) purpose, each region should host Domain Controllers of other regions.
7) User, Group, GPO, Computer objects in a region would be stored within the Domain partition of child domains, which are region specific.
AD Site Layout
Global Catalog Placement
1) Please ensure that each site must have at least one Global Catalog (GC). 2) You can also make all your DCs act as a GC. 3) Replicate additional attributes to GCs, if required.
OU Management
AD Group Management
DC Deployment & Management
AD Replication
Time Synchronization
AD Backup
Forest Trust Considerations
Group Policy Management
DNS Considerations
Sr no
Activity
Suggested Frequency
Method
1
Monitor AD Replication Summary Report for the entire Forest.
Daily twice
Use this script
2
Monitor AD Replication Full Report, for all NTDS Partitions.
Daily once
3
Monitor DC Diagnostic Report
Weekly once
4
Monitor Domain Controller Health
Real Time monitoring
Free Disk Space, Automatic Services, OS patch consistency, Antivirus policy, Event Logs.
5
Check accuracy of PDC Emulator and other Domain Controllers of Forest Root Domain system clock.
Once in every fortnight
Check PDC emulator time and other DC time with some reliable clock. You can use www.timeanddate.com
6
Check Time Skew Report for all Domain Controllers within a Domain
7
Monitor AD Backup Success / Failure Report
Refer this article
8
Ensure there is no stale record in AD Database
Monthly once
There should not be any stale Domain Controller present in AD Database. This includes: 1) AD Sites and Services 2) Replication Report 3) Domain Controllers OU 4) Domain Controllers Group