Active Directory must be supported by multiple domain controllers where the Risk Management Framework categorization for Availability is moderate or high.
An XCCDF Rule
Description
<VulnDiscussion>In Active Directory (AD) architecture, multiple domain controllers provide availability through redundancy. If an AD domain or servers within it have an Availability categorization of medium or high and the domain is supported by only a single domain controller, an outage of that machine can prevent users from accessing resources on servers in that domain and in other AD domains.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-243500r959010_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Implement multiple domain controllers in domains with an Availability categorization of moderate or high.