Do any special virus-scanning considerations exist for domain controllers (DCs)?
July 18, 2005
A. Protecting your DCs from viruses is vital. Here are some important guidelines:
Ensure that the antivirus software is certified for the version of Windows you're running.
Use antivirus software that's Active Directory (AD)-aware.
Don't perform actions from a DC that might make it more susceptible to viruses (e.g., surfing the Web).
Avoid using a DC as a file share if load on the machine is a concern; the additional work involved in virus-scanning files on the shares will stress the DC.
Don't place the AD or File Replication Service (FRS) database and log files on a compressed NTFS volume.
Ensure that your virus scanner doesn't scan the following AD database files. (These are the default locations, so you might need to modify the pathnames if you specified nondefault folders during AD creation.) - %windir%tdstds.dit
- %windir%tdstds.pat
- %windir%tdsEDB*.log
- %windir%tdsRes1.log
- %windir%tdsRes2.log
- %windir%tdsTemp.edb
- %windir%tdsEdb.chkEnsure that your virus scanner doesn't scan the following FRS files. (These are the default locations, so you might need to modify the pathnames if you specified nondefault folders during AD creation.)
- %windir%tfrsjettfrs.jdb
- %windir%tfrsjetsysedb.chk
- %windir%tfrsjetlog*.logAlso exclude these SYSVOL areas:
- %windir%sysvolstaging areas
- %windir%sysvolsysvol
About the Author
You May Also Like