Re: Multi domain administration



for me and others, without knowing the reasons behind the choices it is hard
to say you should do this or you should do that...
however... for a small environment as yours (2 DCs) I would be very
interested to hear "why two domains?". Not trying to offend someone here, it
is not the first time such a decision has been made because someone does not
fully understand the concept of AD.
In your case I THINK it would be OK to have ONE domain with 2 DCs instead of
having two domains with one DC each! So what can you do about it... is your
Q...
Well...(very very very high level steps)
* migrate the contents (users, groups, computers,data, etc.) of the child
domain to the parent domain
* demote the DC in the child domain to a stand alone server (don't forget
the setting that the DC is the last DC in the domain)
* promote the stand alone server into the parent domain

If you are going to follow these steps....make sure that both DCs:
* host DNS
* host WINS
* are GCs
* all clients and servers point to both DCs for DNS and WINS
in that case you will have redundancy within your env if one of the boxes
dies

if you don't have backups for those DCs, MAKE FULL BACKUPS NOW! (after
changing the config of course and keep doing that on a regular basis)

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Nick" <Nick@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:379445C3-9AE8-4555-A953-1873CB2F2C56@xxxxxxxxxxxxxxxx
Hi again

We have two domain with one DC in each. It was originally made that way.
I'm
still not sure why. Anyway i'm stuck with this config.

Do you thinck it would be possible to put both in the same domain without
loosing data, accounts, config.

As i can see, i will not be able to manage both domain without having an
account in each and reloging each time from my workstation.

"Jorge de Almeida Pinto [MVP]" wrote:

We have two domain controller.

a.x.local and b.x.local

looks like you are talking about DCs

I can manage domain a.x.local from domain b.x.local and opposite
with
the
administrator account.

looks like you are talking about DOMAINS


remember that a domain can have multiple DCs

do you have 2 domains with each domain only having one DC?
if yes.... make sure you ALWAYS have AT LEAST 2 DCs for each domain!

explain why you have two domains if that is the case?!
--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Nick" <Nick@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4ED093E3-AEC0-4A6E-92F0-CDCF896B7446@xxxxxxxxxxxxxxxx
Hi Jorge

What do you mean?

"Jorge de Almeida Pinto [MVP]" wrote:

are you talking about DOMAINS or DOMAIN CONTROLLERS?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Nick Bergeron" <NickBergeron@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:85D044C6-2431-4B65-95DB-BA63273E021D@xxxxxxxxxxxxxxxx
Hi everyone

Here is the deal.

We have two domain controller.

a.x.local and b.x.local

My personnal account is created in a.x.local with domain admins
privilege.
Whe i log into b.x.local with the administrator account, it won't
let
me
add
my account in the domain admins group.

I can browse AD of the a.x.local domain from b.x.local, i see my
account
but
when i select it, it's being refused.

I can manage domain a.x.local from domain b.x.local and opposite
with
the
administrator account.

What am i missing ?

Thanks everyone








.



Relevant Pages

  • Re: Branch Office DC Best Practice
    ... letting ordinary users/admins logon to DCs, ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... he has control of the other DCs ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory Upgrade
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... LVR is only available at FFL w2k3! ... (for DCs and GCs) ...
    (microsoft.public.windows.server.active_directory)
  • Re: 12293 Event Log error with SAM Database (Duplicate Account Del
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... them aparently grabbed the same SID as an account that has existed ... event log for additional duplicates. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Taskpad Delegation
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... account it works dandy, so somewhere there is a permissions problem. ...
    (microsoft.public.windows.server.active_directory)
  • Re: strange AD behavior need help!
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... if yo only have 1 AD domain make all DCs a GC! ... add a user it said something about uniqueness. ...
    (microsoft.public.win2000.active_directory)