Re: 2003 AD upgrade and consolidation

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi Herb,

I want to have one root in a single tree.

The plan is to have one server as the forest root in a new AD domain e.g.
abc.local. Then I would have a second server as a new tree root in an
existing AD forest e.g. abc.com. For each subisdary, I would place a server
to act as their new DC and join this server as a child domian e.g.
sub1.abc.com, sub2.abc.com.

The forest root and tree root are seperated in case the client accquires
further subsidaries. A trust relationship will be set up between the forest
root and the new subsidary at the beginning. When the new subsidary can
comply with the company's policies, it will be made a child domain as the
other subsidaries.

Right now each subsidary has their own seperate AD forest. The plan involves
creating domains which are different from the domain names currently being
used. New DC's will have to be built and a migration done from the existing
domain to the new one.

Glad to hear that ADMT can transfer computer accounts. So after I build
domain controllers for the new forest root, tree root and child domains, I
can used ADMT to transfer the user settings and computer accounts, etc. Then
used the File Transfer Wizard to migrate the files. This will keep the
permissions in the new domain?

Once the ADMT transfers the servers account, the server apps should continue
to work. They are already running on Windows 2003 servers and have no
dependency on the domain name.

Welcome your comments,
Ken



"Herb Martin" wrote:

"Ken Manohar" <KenManohar@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1C0D025E-8431-4C15-8ADB-4F6DAB464D2C@xxxxxxxxxxxxxxxx
Hi Good Day,

A client would like to utilized the centralized management provided by
Active Directory.

They have a number of subsidaries, each with their own AD forest. A
mixture
of Windows 2000 and Windows 2003.

The client would like to create one Forest Root and one Tree Root. Then
have
the subsidaries as child domains to this tree root.

Do you mean "one each" or one Root in a single tree?

Additional Trees are ONLY about having different DNS suffixes.

Any ideas on the best way to do this migration? The method I have so far
is
to:
1) Build all the 2003 servers (Forest root and tree root on different
servers)

What is the point of the "Forest root" if there is going to be
another tree root? (It may make sense but hearing the idea
would help us to help you.)

2) Promote to domain controller

Promote what? Once you have the domains you have
at least some DCs. Nothing wrong with more of course.

3) Use ADMT to transfer user settings

And users, passwords, computers, groups, OUs ...

4) Use the file transfer wizard to transfer files/shares and permissions

Watch our for User Profiles which may not get included by
default.

5) Manually unjoin and join each workstation to the new domain

The ADMT can be used to actually create the computer
accounts.

The client does not use Exchange. Their applications are compatible with
Windows 2003.

Watch out for duplicate names, especially if these
are large domains (the odds of a clash increase.)

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


Thanks in advance,

Regards,
Ken



.



Relevant Pages

  • Re: 2008 migration issue
    ... In my test lab I have an empty forest root with 1 dc and a domain tree ... after the promotion I install DNS and make them a DNS Server. ... If so, in each domain in a multi-domain forest, the DC holding the IM FSMO can't be a GC. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Flattening a Forrest
    ... The current forrest root uses a fqdn of.ent. ... tree that will use.com. ... Also having the the forest root will allow me to keep a DC/GC at our NOC for ... so you have 17 child domains and one forest root domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Moving forest root server
    ... Ensure the other Forest Root Domain Controller remains online and are configured for being a GC, DNS also as you suggested move all FSMO roles off the DC you are going to transfer to another location. ... Forgot to mention that we're currently running a Windows 2000 Server ...
    (microsoft.public.windows.server.active_directory)
  • Re: Will zone transfer erase existing records?
    ... Define two "regular" domain controllers. ... I don't know what a root server would have to do with the question you ... You cannot change a forest root, if you remove the forest root DC, it will ...
    (microsoft.public.windows.server.dns)
  • Re: Part 1 (of 3): What are major aspects of evolutionary theory?
    ... >>4) by assuming monophyly of two divisions of the tree ... >>each of these is a clade and that the root lies between them. ... which is commonly rooted by outgroup. ...
    (talk.origins)