jmak Posted March 29, 2018 Posted March 29, 2018 Current situation: All clients and users part of schoolname.local domain. (Server 2012R2) Desired end state: All clients and users part of schoolname.internal domain with Azure AD Connect joining them to schoolname.com O365 domain (Server 2016) My plan was to re-image all machines and join to the new domain and then set up Azure AD Connect to replicate/synchronise. However the new server installation has been delayed. Obviously the Easter Break is by far the most convenient time to re-image. Any thoughts from the collective on how straight forward/ unwise it would be to re-image and join to the old domain and then migrate when the new domain is ready? Data migration shouldn't be impacted - I'll leave the teacher machines until migration. I've read about adding a second domain to the forest and then demoting the existing DC when I'm ready. I've also seen that Manage Engine have a free tool. So I've established it's possible - just not sure whether it's a good idea... Thanks
azureusnation Posted March 31, 2018 Posted March 31, 2018 First just to let you know best practice for a domain name is . a domain that you own. .local and .internal could eventually be registered as a TLD (top level domain). Any way, just use ADMT to migrate your machines over, it is stupidly simple and if you still have users in your old domain just set a group policy setting on your new domain that points the new domain computers to use users from the old domain: https://support.microsoft.com/en-us/help/2908796/using-gpos-to-change-default-logon-domain-name-in-the-logon-screen And also this one to allow group policies to go cross forest: https://social.technet.microsoft.com/Forums/en-US/ac99a522-7a50-48fc-8784-1f8b44a614c8/can-group-policy-apply-onto-other-forest-users-in-my-domain-?forum=winserverDS Then you can relax and just migrate your users over really easily. Once you have them in the new domain with their sid history, remove the two GP's ive said and then they will use the new domain to logon with and as you have the sid history they will still be able to access the files and folders that they used to before the domain migration. Any questions hit me up, I'm migrating 1600 users at the moment so I know what its like. Thanks Ash 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now