Re: Second domain

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Each domain has its own Password Policy, so creating a new domain in the existing forest will allow you to use a different Password Policy for the given users.

In Windows Server 2008, you can leverage fine-grained password policies, which allow you to create multiple password and account lockout policies in a domain. However, this requires a domain functional level of Windows Server 2008, which means 1) all of your existing domain controllers mush have Windows Server 2008 installed and 2) you cannot add any domain controllers in future that have an operating system version that is lower than Windows Server 2008.

There are third-party solutions that allow you to create multiple password policies within a single domain. Do a search for "Active Directory password filters" and you should find a fair number of them.
--

JPolicelli, MVP - Directory Services

http://www.policelli.com
http://policelli.com/blog

This posting is provided AS IS with no warranties and confers no rights. Always plan and test.

----

"Phillip Windell" <philwindell@xxxxxxxxxxx> wrote in message news:ewIHrn9fJHA.5408@xxxxxxxxxxxxxxxxxxxxxxx
"Joe Brown" <JoeBrown@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:C693BBC1-30E4-48A1-A645-17923041AF25@xxxxxxxxxxxxxxxx
I may need to setup a 2nd domain to move a group of users to in order to have
a separte password policy for those users. Is there documentation for doing
this that someone can point me to? I searched some on the MS site but didn't
see what I was looking for. This is a 2003 Server environment. I know how
to promo the DC and create the domain, but can I just drag and drop users
from one domain to the new one?

I'm not sure but you might be able to create a Child Domain then have a different Policy within it,...and it would still be in the same Forest. But if that won't work I guess you will have to create a New Forest and a New Domain.

But in either case the "Objects" have to be migrated from one place to the other. This is done with the Active Directory Migration Tool (ADMT). It should already be on your DC or on the Install CD,...but you can just download the latest version from MS's site and that would probably be better. You can download the documentation for it as well,...and then be sure to study it. This isn't something you want to take a chance on doing wrong the first time.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


.



Relevant Pages

  • Re: 2000 to 2003
    ... |I think you plan is OK as promoting a Windows Server 2003 DC and extending ... |the forest schema are separate steps. ... ||> We must run the Adprep commands to update the schema in the existing ... ||> information about using Adprep see Active Directory Help. ...
    (microsoft.public.windows.server.migration)
  • Re: Forest Setup Question
    ... Deployment Kit, which you can purchase in hard copy form at Amazon (or ... Designing the Active Directory Logical Structure ... Enabling Advanced Windows Server 2003 Active Directory Features ... Deploying the Windows Server 2003 Forest Root Domain ...
    (microsoft.public.windows.server.general)
  • Re: Forest Setup Question
    ... Deployment Kit, which you can purchase in hard copy form at Amazon (or ... Designing the Active Directory Logical Structure ... Enabling Advanced Windows Server 2003 Active Directory Features ... Deploying the Windows Server 2003 Forest Root Domain ...
    (microsoft.public.exchange.misc)
  • Windows Server 2008 and adprep /forestprep
    ... I have a Windows Server 2003 R2 DC running a private forest. ... It asks me to run "Active Directory Domain ... first prepare the forest using "adprep /forestprep". ...
    (microsoft.public.windows.server.setup)
  • Need some input for 70-294
    ... Exercise 2-1: Planning for an Active Directory Installation ... Margie's Travel has decided to install a Windows Server 2003 network. ... Create a pen and paper drawing of how you would design this forest ...
    (microsoft.public.windows.server.active_directory)