Jump to content

Recommended Posts

Posted
The danger with migrating away but keeping the domain and servers is that you bring across legacy practices that had no place in 1998 nevermind 2018. Don’t be afraid of a hard break to get rid of things like crappy file permission practices and the mixing of applications and user data.

 

I agree with just about everything you’ve said but I don’t think anyone is advocating keeping the domain AND all of its servers in place. You can get rid of all the RM manure but still keep the existing domain in place if you wish.

Posted
If you're moving from one domain to another and you're syncing with Azure AD Connect, you will need to turn off sync on the old domain. You'll need to wait for this to finish, that might take up to three days. Once that has done, the Office 365 users will be "converted" to in-cloud users. You'll then have to de-populate the ImmutableID from the Office 365 users as if you don't, when you try to sync the new domain it will come up with an error saying that these users are already synced from another domain.

 

I had fun with this when we stopped using Captia Openhive to manage our Office 365 and moved management in-house.

You could also configure the existing AADDync in the CC4 network to use ms-ds-consistencyguid (which is a fairly automatic process), export this value and put it into your new domain, before hooking up AADSync in the new domain and everything will match. You won't need to clear the immutable ID in O365.

 

If you haven't already made this change, the immutable ID is the objectguid, which can't be transported between domains.

  • Thanks 1
Posted
would anyone mind sharing the process they followed for this in more detail ?

 

When we moved our two schools away we didn’t flatten AD and we have never had problems. We even had a power shell script to strip all the RM policies and software from clients as we had a hand full of admin machines with extra software and setup that needed keeping. We only ended up using this on a few desktops in the end and I must say we did rebuild them very soon after.

Posted

Went thru a similar project back in 2009.

 

We built a new DC without installing the RM stuff.

 

We then found that policies changed in Group Policy Management were been changed back after 5mins. This was linked to a user account that RM setup had installed.

 

For a number of other reasons we had to rebuild the last remaining DC that had RM installed.

 

We never had to rebuild the domain. This was back in the time of Live@EDU but we had on-site exchange for Staff.

  • 2 weeks later...
Posted

Looks like I have inherited an RM network that I am keen to remove for a Vanilla network - I have never worked with an RM system before so I am feeling a bit like a rookie with the idea of having to move it (limited network/server experience).

If anyone could help me out with where/how I should even begin planning this, I would be eternally grateful.

Posted

First of all, if you were thinking of doing this over the summer, I would suggest that it's too late to start planning for it now. I would stick with CC4 the next year and plan to do the work over summer 2019.

 

But fundamentally, it's not that complex:

 

You will need to decide whether to keep the existing domain or build a new one. As already discussed, either is viable.

You will need to decide which features of CC4 you need to keep and what you're going to use to replace them.

You will need to budget for replacement software, you won't be able to do everything CC4 does with Windows alone.

You will need to decide which server and client OS you're going to use when you migrate (I would highly recommend not using anything less than Server2016/W10 if you're sticking with Windows)

You will need to plan how you're going to migrate user data from CC4 to the vanilla systems.

You will need to design the server infrastructure for the new network.

You will need to design the domain and OU structure for the new network.

You will need to design group policies etc on the new network.

  • Thanks 2
Posted

I agree with that timetable - Summer 2019 is do-able.

 

Ultimately there is a lot of studying/planning ahead of me, all whilst learning this new role...

Posted
I can't even rename the domain because it hosted an Exchange instance once upon a time.

Our domain is still the old school name because of that. However, we do still have Exchange (now 2016) on premises.

Posted (edited)

Hi Janx1975

We have converted a few schools now with RM CC4 installed, in the case of schools with exchange we have left the domain as is and converted around the RM trash and finally decommissioned all the RM servers over a period of 6 months, we also tidied up all the redundant groups etc while we were on and others we started from scratch. If you want any support or model GPOs etc just PM me and we can help, we also have a few neat ways of doing package management that doesn’t need any expensive Microsoft magic or the use of messy GPO installs, we have even managed to keep The staff that used RM tutor happy.

Just to note I work for a school in staffs that support lots of other schools I’m not a company touting for business.

Edited by dbu
Missed something out
Posted

Hi i'd be interested in the "package management " and "GPO's", we are looking at moving away for 444 this summer :)

 

 

Hi Janx1975

We have converted a few schools now with RM CC4 installed, in the case of schools with exchange we have left the domain as is and converted around the RM trash and finally decommissioned all the RM servers over a period of 6 months, we also tidied up all the redundant groups etc while we were on and others we started from scratch. If you want any support or model GPOs etc just PM me and we can help, we also have a few neat ways of doing package management that doesn’t need any expensive Microsoft magic or the use of messy GPO installs, we have even managed to keep The staff that used RM tutor happy.

Just to note I work for a school in staffs that support lots of other schools I’m not a company touting for business.

  • Thanks 1
  • 2 weeks later...
Posted
RM offer a cc4 removal service.. Leaving you with a vanilla domain. Personally, I'd be looking closely at that... And yes it costs money. Don't underestimate time setting up a new network... Assume you are going win10 S win7 finishes next year...
  • Thanks 1
Posted

I'm currently in a RM to Vanilla migration. Existing Network RM CC4, Windows Server 2008 R2.

I've added a new vanilla Server 2016 DC to the domain, created Windows 10 Policies and clean installed windows 10 on a PC and linked policies in GPO.

All OU's are still as before but new policies are security filtered only for windows 10 PCs.

Plan is once all clients are on Windows 10, to then did-assemble the 'establishments' OU and break this separate into separate computer and user OU's and re-link policies.

Seems to work fine with creating windows 10 profiles, no issues so far.

 

This means a simple migration, Windows 7 RM pcs can continue with existing policies etc, and then any new windows 10 pcs will use the new GPOs and settings.

  • Thanks 2
Posted

Would you happen to have a step-by-step guide or something similar that I could take a gander at?

Ultimately I would be trying to set up a guide myself and show common pitfalls and areas to focus on during the process.

 

SLT has given me the green light to go ahead, but they want it planned before the head approves. They are cautious about removing RM specifically for the support they give (Network manager turnover has been quite high here over the last 2 years and I can see why!)

 

Using RM to remove their network would have some poetic justice, has anyone used this offereing from them? If anyone from RM is reading - do you have any case studies?

Posted
For package management I would use PDQ full version as using the free version to supplement SCCM has been really good. SCCM was in place when I arrived but if I was looking for light weight I would use MDT for imaging and PDQ for software deployment.
  • Thanks 1
Posted
Having never managed a CC4 domain I'm not able to compare, but I will say that once SCCM is installed it's actually more straightforward to use than you might think.
Posted

For something scalable, free and very customisable we use WPKG. We use it to in conjunction with DFS to manage packages across 3 sites and tons of different hardware and operating systems.

Oh and did I say it was free.

Posted

janx1975 - it’s quite hard to give you a step by step plan as each school is different but a few ideas ...

 

Decide how you are going to deploy images and ensure they are generic so that you don’t have to maintain more than one.

 

Decide on your package management method so that you can start building and testing packages for all existing software, this also helps with making sure you don’t bake out of date software into the image.

 

Ensure you survey staff (we use a basic google form) to get their opinions on what is currently good and what they would like to make things better (people are happier with change if they think they had a say in it) plus you may find out things people still use that you weren’t aware of.

 

Do an inventory of equipment and collect together all of your drivers and make a plan for hardware that isn’t up to it.

 

Consider your policies carefully as you don’t want hundreds of them each with a single setting in. We have 4 , Global, staff, students , restricted.

 

The same goes for security groups, consider them as this will help with things like shared area permissions.

 

If you are going to sync with office 365 consider your domain name carefully and read MS guidelines as this does cause fun and games.

 

Download all the really useful tools from wisesoft that will help when exporting users from your old system and reimporting them into the new one.

 

There is lots lots more but I can’t type anymore on my iPhone :)

 

Hope some of that helps.

  • Thanks 1
  • 9 months later...
Posted
currently doing a cc4 migration to vanilla. going easy as pie so far. just set up some vanilla servers as additional AD servers and created windows 10 policies. gradually over the weeks reimaging clients onto windows 10. pull in all the drives policies etc. no issues so far. just had to install the rm password sync took so it can sync password changes but that's all. once all clients are on Windows 10, shares dhcp etc will all be moved over and rm DCs decommissioned.
  • Thanks 1
Posted
Our migration took place over the Summer last year and very much like @ITGURU we found it went very smoothly. We built our new servers, and built new groups within AD that were seperate to anything to do with RM. We built new images using WDS and created task flows and built group policies to manage clients. During the summer we promoted one server to DC and migrated DNS and DHCP roles over and demoted one of the RM servers, then repeated the processed with the second. It all went very smoothly, we re-imaged all our clients fresh. For us we rebuilt all our servers so there was no remanence of anything RM. We then cleared the section of AD that RM populates and ever since things have never been better!
  • Thanks 1
Posted
Our migration took place over the Summer last year and very much like @ITGURU we found it went very smoothly. We built our new servers, and built new groups within AD that were seperate to anything to do with RM. We built new images using WDS and created task flows and built group policies to manage clients. During the summer we promoted one server to DC and migrated DNS and DHCP roles over and demoted one of the RM servers, then repeated the processed with the second. It all went very smoothly, we re-imaged all our clients fresh. For us we rebuilt all our servers so there was no remanence of anything RM. We then cleared the section of AD that RM populates and ever since things have never been better!

 

Basically what we done but we killed the process/task on the server making the changes but had already built a server without the RM stuff. Niether of us knew RM (IT Manager or me), had no support and school was not willing to pay for any (long complicated story) so it had to go and it did.

  • 1 year later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...