Quote:
Originally Posted by CanuckBB
There is nothing wrong with BES on a DC. It's Exchange that can be a nightmare on a DC.
|
IMO (and in the opinion of MS' best practices) a DC should be a DC only, not a DC and anything else. No IIS, no BES, and definitely no Exchange or other heavy-weight applications. I realize that some smaller/non-technical shops have the Small Business edition of Windows that puts everything and a DC on one system, but that is really about as far from ideal as you can get.
One of the big reasons for this is the lack of true local groups on a DC. If you have something that requires its service account to be a local admin, and you put it on a DC, now it's a domain admin. If you have a user who you want to give admin rights to the server, they are a domain admin too.