Making Active Directory changes atomic

Posted by Matt Simmons on Server Fault See other posts from Server Fault or by Matt Simmons
Published on 2009-08-12T15:08:26Z Indexed on 2010/04/06 16:23 UTC
Read the original article Hit count: 299

I've got a Windows 2003 Active Directory infrastructure, and there are times (such as when terminating an employee) that I want instantaneous propagation across both of my AD servers. Currently, I make the change in both places, which I suspect is unhealthy, but it's the only way I know to make sure that the account is disabled to every machine.

Is there a better way? Do I have to wait for the normal propagation time for convergence, or is there a way to "force" it?

© Server Fault or respective owner

Related posts about active-directory

Related posts about propagation