Jump to content

Migrating to new network - head mashed - calming influence needed!


Recommended Posts

Posted

In the middle of drawning up plans to start a fresh for September. Looking at changing domain name as current domains uses xxx.local.

 

New domain will be xxx.internal (tick)

Looked at server deployment - happy with that. (tick)

Looking at creating new GPOs as there are some issues with existing GPOs (tick)

 

I've gone through this in my head so many times that I am now second guessing myself with things and need a calming reassurance from people who have done this before.

 

SIMS & Solus 3

--------------

SIMS.net - should be a case of remove from old domain and add to new domain and checking permissions (Server Name and IP Address will not be changing)

Solus 3 (should work as all work station are being rebuilt with a fresh install of Solus and Sims) - first time Ive use Solus 3 so not 100% sure this is correct.

 

 

Exchange 2010 - Office 365

---------------------------

Will be migrating to Office 365 - and removing the on premise exchnage server.

Currently username and password are sync'd to allow Office 365 Logons - not tested any mail migrations yet.. will need to seek advise on this as never done it before and not sure on the best approach.

 

 

User Accounts

-------------

Looking to purchase Salamander to create username and Office 365 email accounts from SIMS using the existing Username format - Once created, work would be restored (should be as simple that shouldnt it?)

 

 

 

So...... after reading this - am I over thinking things? Have I missed anything? Am I being a complete idiot?

 

ARRRRGGGHHHH - need more coffee!!

Posted
I moved us away from CC4 last summer I underestimated the time needed to build and test software packages you may not have this issue if your sticking with the same software distribution method.
Posted
I moved us away from CC4 last summer I underestimated the time needed to build and test software packages you may not have this issue if your sticking with the same software distribution method.

 

Agreed. We moved away from CC3 this time back in 2010 and there were still important things that hadn't been done yet when the students started in September. Admittedly at the time we were totally windows xp and the move included a total move to win7, so stuff like old printers not having win 7 compatible drivers, etc.

Posted
Shared areas? I'm guessing you'll have areas for staff to share documents with each other and with students - make sure you know who has what rights to where.
  • Thanks 1
Posted

Ermmm, not wanting to cause issues with your current fragile state but are you sure you want to go to .internal? If you are starting again it is probably best to go with a subdomain of an external domain you own. This is to ensure you can get SSL certificates ok as they will not issue certificates to a domain you do not control anymore.

 

I am doing a similar exercise this summer so you are not alone. Other things on my mind are:

 

AV - We are using SCEP so shouldn't have too much of a 'mare

Software Distribution - We are using SCCM & hoping to be able to migrate our current server across. Otherwise it will be a matter of exporting/copying across MSIs and the like.

Printers - These always seem to cause fun!

File servers - If you are going to a virtual infrastructure don't forget you could split it up more than you would with a physical server, so maybe staff, student and shares all separate.

Random services - check for any odd services or installs you may have forgotten about. Things like door security, LEA scripts that upload data, Library software.

DHCP/DNS - now might be a good time to check your current DHCP & DNS for any devices you may have forgotten about that will hog an IP you are trying to assign to something else

 

Don't count it as overthinking, think of it as using the 6Ps. Map everything, document everything as you go. You may think you don't have time but it will help if you suddenly start second guessing yourself mid way, or you find your self with an issue and need to check what you did. There is a wiki that works from a single file that may be useful as you will be able to easily transfer it without having to set up any infrastructure, or a Goggle Docs page or a One Note document.

 

Good luck!!

  • Thanks 1
Posted
Current recommendation is that your internal domain name should be the same as your external email domain (I.e xxx.xxx.sch.uk) to get the smoothest integration with office365.
Posted

My advice, plan plan and more planning. Write it down, do a day by day plan of what you are going to do, in what order and when. Make sure to include time for testing and time for troubleshooting. Be realistic with this. Get your new domain up and running as early as you possibly can and create a trust with your existing domain, this make's file migrations etc. a whole lot easier.

Make sure you have installation files/product keys for everything you want to keep on your new domain, especially if you are doing a new workstation build to go with it. Pay attention to those odd machines which have custom software installed on them and make sure you know what it is, where it comes from and how it works before you get to 'D-Day'

Pay attention to services which may authenticate against your AD, do you use RADIUS for your wireless for example?

Document AS YOU GO. Don't think "I'll do it later" as later never comes, and suddenly you find your documentation ends up on sticky notes all over the place and little txt files saved in obscure places. You can produce a surprisingly large amount of the documentation before you deploy. Use Robocopy for your file migration, it's old but oh so reliable and make sure you get it to log the data. Ensure you have a last known good backup from your old network before you do any data migration. Talk often with your head and share your plans with them so they are fully aware of what you are doing and the scope of the work, that way if there are problems they are 'in the loop' so to speak. If you are changing Office versions as part of the upgrade, try and get it installed on at least some workstations prior to the main upgrade so staff get a chance to experience it. Ensure key software is going to run on new versions of the operating system. Make sure you know those obscure bits of information you only need once, like does your LEA have a time server you can sync your new domain from, what are their DNS forwarders etc.

 

Your exchange migration is something you can do easily by federating your existing exchange server with Office 365, you then just move the mailboxes into Office 365 in the same way as you move mailboxes between databases on a local server. Be warned it takes AGES to copy large mailboxes so migrating a large exchange server into Office 365 can take weeks. If you can, get a hybrid setup up and running before you move totally over - if you get this right you can move peoples mailboxes into Office 365 way in advance of the migration and they will never actually know as your existing exchange server works as a proxy for it when fully federated I believe. This way you can do them in small batches spread over many months and it makes your life a whole lot easier. Make sure you know who holds your domain registration so you can get the MX records changed etc.

 

Also, don't be afraid to ask questions on here if you get stuck!

 

Above all else, plan.

  • Thanks 1
Posted
Ermmm, not wanting to cause issues with your current fragile state but are you sure you want to go to .internal? If you are starting again it is probably best to go with a subdomain of an external domain you own. This is to ensure you can get SSL certificates ok as they will not issue certificates to a domain you do not control anymore.

 

I can see the sense in that, especially when looking at SSL Certs and Office 365 integration. As I'm still on the pen and paper stage it can be changed.

 

I am doing a similar exercise this summer so you are not alone. Other things on my mind are:

 

AV - We are using SCEP so shouldn't have too much of a 'mare

Software Distribution - We are using SCCM & hoping to be able to migrate our current server across. Otherwise it will be a matter of exporting/copying across MSIs and the like.

Printers - These always seem to cause fun!

File servers - If you are going to a virtual infrastructure don't forget you could split it up more than you would with a physical server, so maybe staff, student and shares all separate.

Random services - check for any odd services or installs you may have forgotten about. Things like door security, LEA scripts that upload data, Library software.

DHCP/DNS - now might be a good time to check your current DHCP & DNS for any devices you may have forgotten about that will hog an IP you are trying to assign to something else

 

AV - currently have Avira installed - but the school purchased Kaspersky before I arrived so I will be starting fresh.

Software Distribution - Going on a SCCM Course in a couple of weeks. Hoping I can import my existing MSIs

Printers - My technician doesnt know this yet but that will be his thing - check details, download drivers etc

File Servers - yes will be VMs and already posted on here about server roles - will be running roles on seperate VMs. I have a sevrer setup with several installations of Server 2012R2 ready to be turned on and assigned roles etc.

Random Services - I havent come across any yet! - But there is still time!

 

Feb half term - doing a full audit of the workstations to make sure we have all the software to hand when redeploying new images.

 

 

 

Shared areas? I'm guessing you'll have areas for staff to share documents with each other and with students - make sure you know who has what rights to where.

 

Already started those conversations with staff, I am not taking the current setup as gospel.

 

 

My advice, plan plan and more planning. Write it down, do a day by day plan of what you are going to do, in what order and when. Make sure to include time for testing and time for troubleshooting. Be realistic with this. Get your new domain up and running as early as you possibly can and create a trust with your existing domain, this make's file migrations etc. a whole lot easier.

 

Didnt think about creating a trust! - excellent idea, will be adding that to the planning sheet.

 

 

Make sure you have installation files/product keys for everything you want to keep on your new domain, especially if you are doing a new workstation build to go with it. Pay attention to those odd machines which have custom software installed on them and make sure you know what it is, where it comes from and how it works before you get to 'D-Day'

Pay attention to services which may authenticate against your AD, do you use RADIUS for your wireless for example?

Document AS YOU GO. Don't think "I'll do it later" as later never comes, and suddenly you find your documentation ends up on sticky notes all over the place and little txt files saved in obscure places. You can produce a surprisingly large amount of the documentation before you deploy. Use Robocopy for your file migration, it's old but oh so reliable and make sure you get it to log the data. Ensure you have a last known good backup from your old network before you do any data migration. Talk often with your head and share your plans with them so they are fully aware of what you are doing and the scope of the work, that way if there are problems they are 'in the loop' so to speak. If you are changing Office versions as part of the upgrade, try and get it installed on at least some workstations prior to the main upgrade so staff get a chance to experience it. Ensure key software is going to run on new versions of the operating system. Make sure you know those obscure bits of information you only need once, like does your LEA have a time server you can sync your new domain from, what are their DNS forwarders etc.

 

A lot of the services will be redone from scratch - eg. Meraki Wireless will be reconfigured to use RADIUS so it talks to Smoothwall nicely.

 

The current servers VMs will be powered down and exported to a seperate Server so they can be started if any issues (or that is the current plan)

 

I have a weekly meeting with the head of IT to keep him in the loop and he reports back to the head.

 

Not looking to change workstation OS or Office version - so all good on that side of things.

 

 

 

Your exchange migration is something you can do easily by federating your existing exchange server with Office 365, you then just move the mailboxes into Office 365 in the same way as you move mailboxes between databases on a local server. Be warned it takes AGES to copy large mailboxes so migrating a large exchange server into Office 365 can take weeks. If you can, get a hybrid setup up and running before you move totally over - if you get this right you can move peoples mailboxes into Office 365 way in advance of the migration and they will never actually know as your existing exchange server works as a proxy for it when fully federated I believe. This way you can do them in small batches spread over many months and it makes your life a whole lot easier. Make sure you know who holds your domain registration so you can get the MX records changed etc.

 

I was thinking about a Hybrid solution. I have approx 1500 mailboxes to move over so Im thinking this will take some time. Current thinking is start looking at configuring a hybrid config and start moving in a couple of weeks. - Any adivce, crib sheets welcome :D

 

MX Records - I have access to change along with DNS records.

 

Also, don't be afraid to ask questions on here if you get stuck!

 

Oh dont worry I will be asking plenty of questions! Why struggle when there are people who have been through this before.

  • 2 weeks later...
Posted

Ok, so new domain name will be internal.schooldomain.uk

 

Netbios name.... Internal

 

Am i best leaving this as is or could I change this?

 

What have other people done?

 

Cheers

  • 3 weeks later...
Posted (edited)
Don't underestimate time for your DNS changes requests and requests for SSLs.... Two weeks is our counties SLA time so we are stuck waiting for the final organisation DNS verification to finish our hybrid setup. If we were waiting in the summer then 2 weeks would be a long wait!!! Edited by burgemaster

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...