Adding a Domain, child or someghing....



So we have a few servers that have local users on them and after upgrading the servers here and there we lose the Local Users and have to re-create them on the new server. All of the Servers are Member servers in an AD Domain.

The local users are there only because we have given Extranet Access to some services and we do not want our customers to have the potential to access something in our AD Domain.

Is there a way to use our Existing DCs to create another domain or child or something that would allow central administration of the users with out giving them access to resources in our AD Domain?

Of the of the users have set up servers here with access to them via 'Authenticated User' So we do not want the Extranet Users to have access to these resources, or else we'd jsut add them to a new OU.

What is my best bet here? Do I need to add another AD Domain and another DC to support the domain and have a Trust? I really dont want to have to add more servers.

Thank you,
Scott<-

.



Relevant Pages

  • Re: AD Integrated zone deleted, cant recreate secondary zones
    ... users are just logging in to the member servers as ... > local users and accessing what they need through mapped drives. ... make sure all zones for the domain are deleted ...
    (microsoft.public.win2000.dns)
  • Re: NDR but delivered?
    ... >I currently have 3 main sites with different local domain names and one ... >Keep getting these NDRs for local users and external users in same mail ... I am forwarding through smarthosts. ... In a normal configuration your three servers would mesh mail between ...
    (microsoft.public.exchange2000.admin)
  • RE: computer management on W2k3
    ... I would use Terminal services from an xp desktop to access your servers and then use the server's own management console for management. ... > to manage my Windows 2003 member servers. ... I get access denied on event viewer local users ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Domain upgrade
    ... SAM (Local Users ad Groups) are not effected when you change domain ... No email replies please - reply in the newsgroup ... > - want to migrate all servers from NT4 domain to a new ... > - All but the PDC/BDC are Windows 2000 already. ...
    (microsoft.public.win2000.active_directory)
  • Re: Exchange 2003 only on localhost
    ... i am using exchange server 2003. ... >I want to know that how can i enable exchange 2003 for local users. ... If the servers and users are all on the same network then you could do ...
    (microsoft.public.exchange.admin)