Forest root _msdcs zone & replication/transfer
What is the present-day advice in regards to replication/transfer of the
_msdcs domain for the forest root? Replicate it only to the DNS servers in
the forest root, or all DNS servers in the forest? I'm having a heck of a
time keeping our own _msdcs forest root zone correct on our 130'ish domain
controllers. It seems like gc _ldap and the GUID CNAME records mysteriously
disappear now and then for some DCs. Secure-only dynamic updates are
enabled.
|