The primary reason is to provide authentication services in the event of a WAN failure.
JorgeM
Senior Poster
3,998 posts since Dec 2011
Reputation Points: 294
Solved Threads: 543
Skill Endorsements: 115
CimmerianX brings up some good points. Just to add though in the event of a WAN failure, if there are Universal groups established in the domain communication between client and a GC (Global Catalog DC) is required for authentication to be successful. In a single first, single domain model with at least one DC (with GC enabled) located at each site mitigates these types of issues. For organizations with many sites.. implementing robust, redundant WAN links can further mitigate the need to deploy DCs at each site.
JorgeM
Senior Poster
3,998 posts since Dec 2011
Reputation Points: 294
Solved Threads: 543
Skill Endorsements: 115