you sync to a physical AD server man. trust me. move the core roles to the VM AD servers and have 2 Virtual and 1 physical or 1 phys and 1 virtual, or best 2 phys and 2 vm that way you have a RTC handling situations.
most people backup during dull times - when everyones offline - you aren't going to tombstone if no changes to the AD are being made. you backup all servers at the same time (veaam for vm's) that way both PHYS and VM backups are time sync'd together - that will give you best chance of survival. imo you want an AD server offsite as well in case you lose everything - it will be alot less trouble if you have one living AD server up all the time - this could be a vpn over comcast business to your home - doesn't have to be fancy but remember some AD traffic can get heavy if you were hosting a ton of exchange domains. just gets costly remember to NEVER run anything else on an AD server - no sql - no exchange - maybe print/light file serving - if you ever demote the server you will roach your exchange/sql as they are unseparable - and the write caching (forced sync) will make it SLOW as a turd. ask me how i know why this is bad
inherited a sql server running sharepoint with AD. now i have to migrate sql and sharepoint to another server because the hardware is aging out.
most people backup during dull times - when everyones offline - you aren't going to tombstone if no changes to the AD are being made. you backup all servers at the same time (veaam for vm's) that way both PHYS and VM backups are time sync'd together - that will give you best chance of survival. imo you want an AD server offsite as well in case you lose everything - it will be alot less trouble if you have one living AD server up all the time - this could be a vpn over comcast business to your home - doesn't have to be fancy but remember some AD traffic can get heavy if you were hosting a ton of exchange domains. just gets costly remember to NEVER run anything else on an AD server - no sql - no exchange - maybe print/light file serving - if you ever demote the server you will roach your exchange/sql as they are unseparable - and the write caching (forced sync) will make it SLOW as a turd. ask me how i know why this is bad
