Re: Simple NT4 - 2003 DC question

From: Herb Martin (news_at_LearnQuick.com)
Date: 01/10/05


Date: Mon, 10 Jan 2005 12:20:51 -0600


<jim.mcnamara@gmail.com> wrote in message
news:1105377954.782596.147590@f14g2000cwb.googlegroups.com...
> Hello everyone!
>
> I am in the process of cleaning up another tech's mess, and have to
> replace an old NT4 domain controller with a new server 2003 box. I've
> been looking through google, and that gave me a good education, but I
> wanted to check on a few things that concern me.
>
> The setup:
>
> Very simple. The Current DC is the only server on the network of say 25
> clients. I only looked at the machine for about 3 minutes, so I am not
> sure what roles it is doing in particular, but I know for sure that it
> is the DC, the exchange server, and also a file server for all the
> client machines. I am not sure if the box is also doing DNS or DHCP, it
> could be doing either/both/neither.
>
> Everything I have read about this migration involves one of 2 steps,
> either building the new machine as an NT4 box, getting all the data off
> the old machine, then making the new machine the PDC and then upgrading
> it to server 2003.

Yes, that is the way to upgrade an NT 4 domain when
you MUST use a new machine to do it.

The (new) 'NT4' must be installed as a BDC of the current
domain for the promotion to PDC to work.

> The other possibility is upgrading the old DC to
> server 2003, then bringing the new server into the domain, and
> promoting the new/demoting the old.

IF the NT4 box can tolerate the upgrade (to even Win2000)
however that represents a slightly easier way and does not
involve any new NT BDCs.

Note that the demotion step (of the old/upgraded DC) is
really optional.

> As I don't have copy of NT4, the only choice that gives me is to
> upgrade the current DC to server 2003.

You can likely find a cheap one on eBay if you need
that method.

> As this will be done in a live
> enviornment, I'm nervous that something can/will go wrong and wreck the
> whole job.

Mostly the BIOS of the old DC might not take a copy
of Win2000, or even worse Win2003.

You might bypass many such problems IF you can
get the Standard HAL (the one without PnP or USB
support) loaded but that doesn't always work either.

Suggestion: After making a full backup of the old
machine, upgrade the BIOS to any recommended
(by the MB manufacturer) newer one.

> I have downloaded the admt2.exe file onto the new server,
> and will use that to bring the active directory onto the new machine
> once the old machine is upgraded.

It's not really "bringing the AD" but migrating the
indiviual users.

> From the explaination, it should be
> possible to use that tool to migrate the old active directory from the
> NT4 box to the 2003. Would that be better than upgrading the old box?

I doubt it -- IF you can get the upgrade to work.

(Remember your backups.)

> My plan: (subject to your comments)
> 1) upgrade old box to 2003
> 2) add new machine to the domain
> 3) run dcpromo.exe on the new machine, make it the DC
> (should simultaneously demote the old machine?)

No, it will not. I will (properly) leave TWO DCs -- AD
is multimastered so that is as expected.

Add these steps if you will retire the old box:

    4) Migrate your DNS and make it DYNAMIC on the new DC
    5) Move the "single master roles"(5) (aka: FSMO) using
            NTDSUtil, to the new DC
    6) Make the new DC a GC in AD Sites and Services (do this
        even if you keep the old DC -- and you should probably
        do the DNS as well, only you wouldn't migrate but replicate
        if you were to keep the old DC.
    7) NOW you can run DCPromo on the old DC which is a toggle,
        removing AD if it is installed (and properly updating the AD
        so that the other DC(s) will know of it's removal.

#7 is not optional really, but if you neglect the problems can
be fixed with another set of steps (e.g., you just trash the old
DC.)

> One last question - the old box is running exchange. Is exchange part
> of Active Directory, or will I have to download it from somewhere else?

No, because the newer Exchange that uses AD won't run on NT.

e.g., Not Exchange 5.5 but you should look into issues with Service
Packs etc for supporting Exchange 5.5 on on Win2003 ......

> Thanks,
> Jim
>

-- 
Herb Martin


Relevant Pages

  • Re: NT to W2K3 Migration
    ... How to Upgrade from Windows NT Server 4.0 ... Best Practice Active Directory Design for Managing Windows Networks ... ensure that you have designed a DNS ...
    (microsoft.public.windows.server.active_directory)
  • Re: Connection to a SAMBA Active Directory
    ... Keep in mind that you're trying to setup a NT4 style trust ... if you setup the Exchange as a resource forest model, ... domain and the Exchange server in another domain will work. ... I am able to define a 2 way Realm trust using the Active Directory ...
    (microsoft.public.exchange.connectivity)
  • RE: Single Server Upgrade Exchange Question
    ... The Exchange Migration Wizard can migrate all user mailboxes. ... server and then import them to the destination server. ... Single Server Upgrade Exchange Question ...
    (microsoft.public.windows.server.sbs)
  • Re: Connection to a SAMBA Active Directory
    ... domain and the Exchange server in another domain will work. ... I am able to define a 2 way Realm trust using the Active Directory ... There is a bit of confusing on the SAMBA side. ...
    (microsoft.public.exchange.connectivity)
  • Re: Migration AD from Windows 2000 to 2003
    ... and after move AD from w2000 server to w2003 server. ... Do you want to migrate or upgrade the existent Forest? ... Best Practice Active Directory Design for Managing Windows Networks ...
    (microsoft.public.windows.server.active_directory)