Hi @Narayan Das Kohli ,
Welcome to the Microsoft Q&A platform!
Microsoft generally does not recommend using a domain controller (DC) as a database availability group (DAG) witness server. Here are the reasons and recommended architectures:
Why not use a DC as a DAG witness server?
- The witness server should be a minimal role server to reduce the attack surface. DCs have broader roles and run more services, which increases risk.
- The additional load on the DC affects its primary function, which can affect the overall performance of the network.
- Combining roles makes troubleshooting more complex and time-consuming.
Recommended architecture for a witness server :
- Ideally, the witness server should be a dedicated server that does not perform any other roles. This minimizes security risks and simplifies management.
- If possible, place the witness server in a third site. This helps ensure that the witness server is available even if one of the primary sites fails.
- Make sure the witness server is configured with the necessary permissions and belongs to the same Active Directory domain as the DAG members.
For detailed guidance on setting up a DAG and preferred architecture, you can refer to Microsoft's Exchange 2019 preferred architecture.
Please feel free to contact me for any updates. And if this helps, don't forget to mark it as an answer.
Best,
Jake Zhang