Re: Upgrading NT4.0 To Windows Server 2003



<SEE INLINE>

--
--------
Hope It Helps!

dw

_______________________________
Don Wilwol
Distributed Application Technologies.
dwilwol(DELETE)@datbusiness.com
http://spaces.msn.com/members/wilwol/
www.datbusieness.com
www.skyphere.com

"Robert" <R_L99@xxxxxxxxxxx> wrote in message
news:4FE52DD0-29DB-41C4-83F7-A9F55AA1903B@xxxxxxxxxxxxxxxx
Hi All,
we are supposed to upgrade existing PDCs from NT4.0 to Win2K3. For some
reason, we have to keep 1 NT BDC in other physical site. Before
implementation, i have some questions and need your help.
1. After the upgrading, there're 3 servers in our environment, Win2k3AD,
NTBDC1, NTBDC2. Is it possible that NT4.0 coexist with Win2k3?
Absolutely

2. I did testing in virtual environment and found
i) when i power off Wink3AD, user cannot logon, even there're backup DC
online, why? authentication? special configuration?
Once an XP machine has authenticated to the AD machine it will always look
to authenticate to AD. Here is why......(found at
http://technet2.microsoft.com/WindowsServer/en/Library/8f492d26-379b-4743-a20a-5c5467108e491033.mspx)
When performing an in-place upgrade of a Windows NT 4.0 domain to Windows
Server 2003, the first domain controller upgraded is the Windows NT 4.0 PDC.
If clients in the domain running Windows 2000, Windows XP, and Windows
Server 2003 select the new Active Directory domain controller for
authentication, the negotiation of the authentication protocol will reveal
that there are now domain controllers in the domain that support the
Kerberos protocol. These clients will then upgrade their secure channel to
exclusively use the Kerberos protocol for authentication requests and will
no longer attempt to authenticate using the NTLM protocol, potentially
causing the new Active Directory domain controller to become overloaded with
authentication requests.

To prevent Windows Server 2003-based domain controllers from being
overloaded with authentication requests, configure each Windows Server
2003-based domain controller to emulate a Windows NT 4.0-based domain
controller during the upgrade process. Configuring a newly upgraded Windows
Server 2003-based domain controller to emulate a Windows NT 4.0-based domain
controller by using the NT4Emulator registry entry shields the new domain
controller from getting too many authentication requests from Active
Directory clients. Shielding the Active Directory domain controller takes
place before the operating system is upgraded to Windows Server 2003 to
prevent clients running Windows 2000, Windows XP, and Windows Server 2003
from ever establishing exclusive communications with a Windows Server
2003-based domain controller.

When upgrading additional Windows NT 4.0-based domain controllers after the
PDC has been configured to emulate a Windows NT 4.0-based domain controller,
you must remember to configure the computer you are upgrading with the
NeutralizeNT4Emulator registry entry. This is so that the additional domain
controller will recognize the upgraded PDC that is emulating a Windows NT
4.0-based domain controller as an Active Directory domain controller. If the
computer is not configured to neutralize emulation, you will not be able to
install Active Directory because the additional domain controller will not
be able to authenticate to an Active Directory domain controller.

For each site in which clients are running Windows 2000, Windows XP, and
Windows Server 2003, ensure that you have enough Windows Server 2003-based
domain controllers deployed in that site before removing Windows NT 4.0
emulation.


ii) logon script cannot export/import between Dcs, cause of the different
path? how to get rid of this problem?
Use lbridge.cmd out of the resource kit to replicate sysvol on 2003 and
netlogon in NT.
http://technet2.microsoft.com/WindowsServer/en/Library/6e81e1f0-7d13-480b-be24-5887f8bfa3cc1033.mspx

iii) if Win2k3AD is crashed, can we promote the existing NTBDC to NTPDC?
I don't know if this is technicaly possible, but the thought of trying it
makes the hair on the back of my nech raise. I'd put another AD domain
controller on the network AND keep a good system state backup. The second
machine could even be a desktop class machine for now.

some detailed i need pay more attention?
Many thanks in advance for your kindness and share.



.



Relevant Pages

  • Re: Migrating Windows 2000 domain to Windows 2003
    ... Other than few hardwar issues..the upgrade went fine. ... you have installed exchange 2003 on Windows ... >>> If Exchange 2000 schema changes have already been installed but you have ... Start Ldp.exe from a domain controller or member computer in the ...
    (microsoft.public.windows.server.migration)
  • Re: New 2003 dc in a 2000 ad domain
    ... Do you have Windows 2000 Service Pack 4 on all the domain controllers and Exchange Servers? ... these aren't support by Windows 2003 servers, and should be upgraded to new version or move them to alternative server. ... You cant install active directory on "Web Server" edition or upgrade ... Move the domain controller from step 1 to unique VLAN that will be isolated from the regular network. ...
    (microsoft.public.windows.server.migration)
  • Re: NT 4.0 to Windows 2003 Active Directory Upgrade
    ... I have tested the NT4Emulator key extensivly in multiple migration/domain ... The purpose of the NT4Emulator key is to prevent domain controller ... windows xp clients or member servers will authenticat againts it causing ... are upgrade ...
    (microsoft.public.windows.server.active_directory)
  • RE: Member Server or Domain Controller
    ... upgrade a Windows NT 4.0-based primary domain controller to a Windows ... Server 2003-based domain controller. ... The first step in the upgrade process is to upgrade the PDC to Windows ...
    (microsoft.public.windows.server.migration)
  • Re: Do I Have To Rejoin WS to Domain If I Rollback to NT Domain After ADS Upgrade
    ... What are the clients' OS'? ... When you upgrade to Windows 2003 domain, ... all the Windows 2000/XP clients may only authenticate with the new Windows ... Server 2003 DC with Kerberos as the authentication protocol. ...
    (microsoft.public.windows.server.migration)

Loading