Monday, October 22, 2007

The beastly AD

The network that I work on is currently have some replication problems in its Active Directory. I'm not talking about the built in windows replication, but instead a custom replication that we make between two different forests where there happens to be nu trust established. We know the problem is linked back to the fact that the amount of data is too much for the synchronization process, and in result the replication crashes are application which triggers the process. We also know that this is caused by the fact that we are not paging or replication request, but while our developers on working on fixing it I have had to find a work around. My work around involves running a scheduled task which goes through all of our accounts (about 1000), and changes their permissions, allowing for a small number (150 users) of them to be viewable during a replication. Then I cycle through which users are viewable between each replication cycle. It may seem like a ugly process, but I am all words if you have anything better in mind.