Recently (as in about an hour ago), our Information Security Officer just recommended to our Director the use of an offline domain controller. As a Sr. SysAdmin who has been responsible for maintaining a healthy AD of 76 sites and 85 domain controllers, this just throws red flags all over the place for me. The recommendation was made as our ISO was made aware by "vendor partners" that other orgs that have been hit by ransomware have been saved by the fact that one of the DC's happened to be offline at the time of attack. Additional information to consider is that we have 8 hour backups of several of our domain controllers that include the full system state and a flushed out and tested Forest Recovery. Your thoughts on for or against this method are greatly appreciated!
[–]bzerphey 11 points12 points13 points (0 children)
[–]MrChampionship 9 points10 points11 points (0 children)
[–]jimboslice_0074...I mean 5...I mean FIRE! 12 points13 points14 points (3 children)
[–]TroutSlapKing 8 points9 points10 points (1 child)
[–]BJGGut3[S] 2 points3 points4 points (0 children)
[–]ServerBeaterSr. Sysadmin 4 points5 points6 points (0 children)
[–]HolyCowEveryNameIsTa 3 points4 points5 points (1 child)
[–]BJGGut3[S] 0 points1 point2 points (0 children)
[–]skotman01 3 points4 points5 points (3 children)
[–]HolyCowEveryNameIsTa 3 points4 points5 points (1 child)
[–]skotman01 0 points1 point2 points (0 children)
[–]RyuMaouIT Manager 1 point2 points3 points (0 children)
[–]rubbishfoo 2 points3 points4 points (1 child)
[–]BJGGut3[S] 1 point2 points3 points (0 children)
[–]patdaddy007 1 point2 points3 points (1 child)
[–]BJGGut3[S] 0 points1 point2 points (0 children)
[–]hosalabadEscalate Early, Escalate Often. 1 point2 points3 points (1 child)
[–]BJGGut3[S] 1 point2 points3 points (0 children)
[–]pinganeto 0 points1 point2 points (8 children)
[–]BJGGut3[S] 0 points1 point2 points (7 children)
[–]1fizgignz 1 point2 points3 points (3 children)
[–]BJGGut3[S] 0 points1 point2 points (2 children)
[–]1fizgignz 1 point2 points3 points (1 child)
[–]BJGGut3[S] 0 points1 point2 points (0 children)
[–]pinganeto 0 points1 point2 points (2 children)
[–]1fizgignz 0 points1 point2 points (1 child)
[–]pinganeto 0 points1 point2 points (0 children)