Manage DC with multiple rolesĭomain Controllers with multiple roles installed are difficult to manage. Installing additional services on your DC increases the attack surface, makes it difficult to manage and can lead to performance issues. It is recommended to avoid this if you can. It is common for small organizations to install additional roles and 3rd party software on their domain controllers. Your domain controller should be a domain controller/DNS and that is it. The general recommendation is to not run any additional roles on your domain controller other than DNS. Use IP conflict detection only when it is needed.Subnetting and benefits of network segmentation.Avoid static IP assignments and use DHCP reservations.Don’t put DHCP on Your Domain Controller.