basic question about Actice Directory
 




IT Certification FAQ

 
|
Home
|
Microsoft
|
CISCO
|
CompTIA
|
Exam/Study FAQ
|
Employment FAQ
| Links  | Forums  |
Book Reviews


FAQFAQ  SearchSearch  MemberlistMemberlist  UsergroupsUsergroups  RegisterRegister  ProfileProfile  Log in to check your private messagesPrivate messages  Log inLog in

basic question about Actice Directory

 
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.active_directory
Author Message
Mupfel
Guest





PostPosted: Thu Jan 24, 2008 12:48 pm    Post subject: basic question about Actice Directory Reply with quote

Hi,

i need to know how long a active directory clients needs to be
offline, till it is not more allowed to communicate (authentificate)
with an dc.

is this time period the same between domain controllers too?

Thank you very much for your help

kind regards

Marko Schustek
Back to top
Paul Bergson [MVP-DS]
Guest





PostPosted: Thu Jan 24, 2008 2:16 pm    Post subject: Re: basic question about Actice Directory Reply with quote

There is no time limit that a client can be offline, if it is offline more
than 30 days, when it comes back on it will modify its password but it will
never expire.

DC's on the other hand need to be able to communicate with other dc's with
in the tombstone life time or records fall off and that update is never
replicated to the off line dc.

By default tombstone life time on Windows Server 2003 is 60 days, this was
increased with SP2 and R2 to 180 days (This must be a new install not an
upgrade). You can increase this tweak.

http://support.microsoft.com/kb/924890

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Mupfel" <ms@nic-systemhaus.com> wrote in message
news:98f2d458-089d-4787-bfac-45b7c83fd2eb@i7g2000prf.googlegroups.com...
Quote:
Hi,

i need to know how long a active directory clients needs to be
offline, till it is not more allowed to communicate (authentificate)
with an dc.

is this time period the same between domain controllers too?

Thank you very much for your help

kind regards

Marko Schustek
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.active_directory All times are GMT
Page 1 of 1

 

Copyright © 2002-2006 Web-S-Sense Pty. Ltd. All rights reserved.

Powered by phpBB
Advertising | Policies/Disclaimers | Contact us | Link to us


Featured Sites: Free Antivirus and Antispyware Info | Free PC Support | MCSE Directory