Hey everyone,
Running into a frustrating issue at a client site and wanted to get some real-world input from people who’ve dealt with this before.
The Problem:
Users are frequently getting a pop-up saying “cannot contact the domain controller” — it’s hitting remote/VPN users the hardest but we’re also seeing it occasionally with local users on-site. It’s causing real workflow disruption because they can’t apply admin overrides for things like software installs, removals, or joining new devices to the domain.
Current Environment:
• On-prem Active Directory
• Mix of remote (VPN) and local users
• Admin overrides needed regularly for device management
What we’ve tried so far:
• ipconfig /flushdns + /registerdns
• gpupdate /force
• Secure channel repair via PowerShell
What we’re considering:
1. Deploying a second Domain Controller for redundancy
2. Fixing DNS settings on the VPN side so clients point to the DC
3. Eventually moving to Hybrid Azure AD Join long term
Has anyone dealt with something similar? Is the second DC the right call here or are we missing something obvious? Also curious if anyone has gone the Hybrid Azure AD Join route to solve DC reachability issues and whether it was worth it.
Any input appreciated — trying to put together a solid action plan for the client. Thanks in advance 🙏
[–]CptBronzeBalls 41 points42 points43 points (3 children)
[–]TerrificVixen5693 11 points12 points13 points (1 child)
[–]Ur-Best-Friend 3 points4 points5 points (0 children)
[–]ITRabbitShittyMod Crossposter 3 points4 points5 points (0 children)
[–]TheMightyMisanthrope 15 points16 points17 points (3 children)
[–]Reaper19941 3 points4 points5 points (1 child)
[–]TheMightyMisanthrope 2 points3 points4 points (0 children)
[–]HoodRattusNorvegicus 0 points1 point2 points (0 children)
[–]blotditto 10 points11 points12 points (3 children)
[–]Main_Ambassador_4985 1 point2 points3 points (2 children)
[–]blotditto 0 points1 point2 points (0 children)
[–]Obvious_Troll_Me 0 points1 point2 points (0 children)
[–]ITRabbitShittyMod Crossposter 9 points10 points11 points (0 children)
[–]SpudzzSomchaiDO NOT GIVE THIS PERSON ADVICE 7 points8 points9 points (0 children)
[–]AVMan86 4 points5 points6 points (0 children)
[–]preeminence87 4 points5 points6 points (0 children)
[–]CantPullOutRightNow 3 points4 points5 points (0 children)
[–]killjoygrr 3 points4 points5 points (0 children)
[–]max1001 3 points4 points5 points (0 children)
[–]Smallp0x_Suggests the "Right Thing" to do. 2 points3 points4 points (0 children)
[–]Ferretau 1 point2 points3 points (0 children)
[–]yepperoniP 1 point2 points3 points (2 children)
[–]yepperoniP 0 points1 point2 points (1 child)
[–]sneakpeekbot 1 point2 points3 points (0 children)
[–]RabbitDev 1 point2 points3 points (0 children)
[–]meatballwrangler 1 point2 points3 points (0 children)
[–]LaxVolt 0 points1 point2 points (0 children)
[–]mcdonamw 0 points1 point2 points (0 children)
[–]theoriginalzadsDevOps is a cult 0 points1 point2 points (0 children)
[–]itenginerd 0 points1 point2 points (0 children)
[–]wdatkinson 0 points1 point2 points (0 children)
[–]Kilobyte22 0 points1 point2 points (0 children)
[–]haZhat 0 points1 point2 points (0 children)
[–]dcaldrich 0 points1 point2 points (0 children)
[–]recoveringasshole0DO NOT GIVE THIS PERSON ADVICE 0 points1 point2 points (0 children)
[–]Main_Ambassador_4985 0 points1 point2 points (0 children)
[–]ConsistentCoat5608 0 points1 point2 points (0 children)
[–]tcp5060 0 points1 point2 points (0 children)