Jump to content

Recommended Posts

Posted

Greetings all.

 

Due to on going issues with a legacy Active Directory Domain that has been historically poorly maintained, we're seriously weighing up the advantages of starting afresh with a new Domain. With the current issues being experienced, we already have a requirement to rebuild every PC in school. We're also scheduled to install new PC's in the majority of classrooms. Given the PC work we'll be undertaking, migrating PC's to a new domain, via the rebuild, wouldn't be too much of an issue.

 

The plan is between now and summer, we'd create a brand new Domain, DNS, GPO's etc, using another of our sites config as a reference.

 

During the summer, we'd look to migrate data to a new file server and add some of the existing app servers to the new domain.

 

The question is, does anyone have any experience of setting up and migrating to a new domain (we wont be using ADMT)? We use Frog, Papercut, Smoothwall, SIMS and all the usual extractors like Groupcall and Wonde etc. Did you migrate these servers or start them afresh and migrate data?

 

Thanks in advance for any suggestions or feedback.

Posted

What sort of issues is it you're getting? even if you're going to do a full wipe with GPOs etc you might not need to do a full domain clear etc

 

Steve

Posted
To name a few : We have GPO's nested upon GPOs's, that configure things that are then over written with other GPO's. We have no override and block inheritance everywhere that have been used to get things working. Slow logons. IP address ranges incorrectly setup. Profiles that hard reference a server that no longer exists. Offline files that won't turn off and data is being written everywhere. Software that doesn't work if a particular server is turned off. Appdata local/roaming duplication issues. AD Sync errors.
Posted

None of that is really needing a full rebuild though.

 

If you're going to re-do all your GPOs for a new domain you could just delete them all on the server and import the new ones anyway. That solves all the overwrites and inheritance etc.

Profiles etc can be scripted to change all users at once.

Offline files etc are GPO based again and will wipe when pcs rebuilt.

Software that's linked to a server will still need that server anyway, and if you reconfigure it to a new address it'll work on pc rebuilds etc.

 

Just seems like you're causing a lot of extra changes that might not be required if you can fix them, but obviously it's down to you guys at the end of it :p You can easily setup a new test user with GPOs and test it before summer to see if it really requires a rebuild or not, and if not will find it a lot easier :p

 

Steve

  • Thanks 1
Posted

Crete a replica OU structure in your existing domain and spend some time working out what policies are required and linking them into this structure. Then gradually migrate users\computers over

For the hardcoded profile paths....going forwards you are problably going to need to tackle this with DFS. A script can be run across AD to change paths easy enough

Slow logons - Possibly caused by the incorrect GPO config

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...