Active Directory must be supported by multiple domain controllers where the Risk Management Framework categorization for Availability is moderate or high.

From Active Directory Domain Security Technical Implementation Guide (STIG)

Part of Directory Service Availability

Associated with: CCI-000366

SV-30996r3_rule Active Directory must be supported by multiple domain controllers where the Risk Management Framework categorization for Availability is moderate or high.

Vulnerability discussion

In Active Directory (AD) architecture, multiple domain controllers provide availability through redundancy. If an AD domain or servers within it have an Availability categorization of medium or high and the domain is supported by only a single domain controller, an outage of that machine can prevent users from accessing resources on servers in that domain and in other AD domains.

Check content

Determine the Availability categorization information for the domain. If the Availability categorization of the domain is low, this is NA. If the Availability categorization of the domain is moderate or high, verify the domain is supported by more than one domain controller. Start "Active Directory Users and Computers" (Available from various menus or run "dsa.msc"). Expand the left pane item that matches the domain being reviewed. Select the Domain Controllers Organizational Unit (OU) in the left pane. If there is only one domain controller in the OU, this is a finding.

Fix text

Implement multiple domain controllers in domains with an Availability categorization of moderate or high.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer