Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / Exchange Server / Design / July 2006

Tip: Looking for answers? Try searching our database.

Exchange user authentication

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Marcus Bentley - 13 Jul 2006 14:28 GMT
I have been asked to look putting a mail server in a central site for use by
outlook clients on a couple of sites.

The AD has a root domain and 3 child domains. The child domains hold the end
user accounts

This is all on server 2003 SP1 and Exchange 2003 SP2.

I wanted to have a DC on the same physical site as the Exchange box so that
when a user tries to logon to their mailbox the authentication will not
require a lookup on a remote DC over the WAN. What I didn't want was to have
a DC for all 3 child domains on the site with Exchange as it would cost more
money than I would want to spend.
Will Global Catalog allow me to use a single DC with exchange with this plan

The Exchange server is installed in the root domain
The DC local to the Exchange server is a DC in the root domain
This local DC is a Catalog server for all 3 child domains.

If I do this will Exchange simply authenticate credentials for mailbox
access from the local GC for the users domain, or will it still go accross
the WAN to an actual DC for the user domain?

Thanks for any help.
Al Mulnick - 15 Jul 2006 18:22 GMT
Authentication requires a DC.
You can read more about the multi-forest and multi-domain authentication
options here:

www.microsoft.com/exchange/library

In this case, you're pretty much stuck with either WAN traffic or DC
creation.  If cost is a factor and you expect the numbers to be fairly low,
you might want to have a look at what R2 and server virtualization can do
for you and the licensing around that. Might dovetail nicely into a
backup/recovery plan as well. :)

Al

>I have been asked to look putting a mail server in a central site for use
>by
[quoted text clipped - 26 lines]
>
> Thanks for any help.
jamestechman@gmail.com - 16 Jul 2006 19:36 GMT
This is really not a yes or no answer. Your Exchange server will use
any global catalog for purpose of authenticating Outlook clients.
However, Exchange will refer GC's that are local to the Exchange's site
for authentication although this is configurable through the desktop
running Outlook in the registry. Therefore, when an Outlook client
tries to authenticate, Exchange will refer him to the GC that's within
it's local site. The second portion is Exchange's role with GC's.
Exchange queries information within GC's through a process called
DSACCESS for obtaining information such as name resolution in GAL,
quotas, routing updates, locating user's HOME server etc. Your Exchange
server by default will use a GC in it's local site. Because GC's have
readable access to all objects in every domain, it can serve DSACCESS
requests to objects in different domains for getting any of those
attributes listed above without having to query the GC in it's
corresponding domain. So in the end GCs can server most requests that
are required by Exchange, but I would prob expect to see some WAN
communcations.

James Chong
MCSE + Messaging, MCTS
msexchangetips.blogspot.com

> I have been asked to look putting a mail server in a central site for use by
> outlook clients on a couple of sites.
[quoted text clipped - 20 lines]
>
> Thanks for any help.
Marcus Bentley - 19 Jul 2006 14:46 GMT
Thanks, I'm pretty clear now.

> This is really not a yes or no answer. Your Exchange server will use
> any global catalog for purpose of authenticating Outlook clients.
[quoted text clipped - 42 lines]
> >
> > Thanks for any help.
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2009 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.