On Wed, Aug 12, 2009 at 5:17 PM, Tom Miller<[email protected]> wrote:
> I'd love to be able to add these PCs to our domain so I could enforce our
> various GPOs at these locations.  Has anyone done this?

  Active Directory's LDAP and Kerberos components will work just fine.

  GPOs depend on file sharing, so the "slow link" setting is likely to
kick in and disable GPO processing.  Same goes for scripts.

  SMB (Windows file sharing) sucks mud when put on anything that
doesn't have LAN-like latency, so overriding the default "slow link"
setting may not be a good idea.

  A read-only domain controller at the remote site will fix this, but
that may be outside your budget.  Even if you have an "old" PC to run
the server, you still need the Windows Server license.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to