Jump to content

Recommended Posts

Posted

Hi All,

 

I hope someone will be able to assist with this-

 

Scenario-

 

*Two domains on a network. Domain 1-curriculum,Domain 2-Admin.

*There is a trust between both domains.

*There is no intention of building a new network from scratch due to fund constraints.(Would have preferred this option)

*Teaching Staffs and Students devices are on the curriculum domain.

 

**Steps to consolidate

 

* Move the File shares and software shares to the Admin domain.Teaching Staffs on the curriculum already have an account on the Admin domain.

*No Teaching /Student Devices on the Admin Domain

 

Questions-

1) what should I watch out for?

2)what practical advice do anyone who has done this has for me?

3)I Know from what I have read that the trust on the domains will allow users(and devices ) on the curriculum to access resources on the admin domain is that the case or not?

 

Thanks I will add more questions in due course

Posted

@ FN-GM that is the plan. Because there is already a trust ,then I intend to move the users gradually,then create device OU. how do you minimize any disruption? when is the best time to take a user out of one domain to the other ? what would be your steps if you are to go through this route?

 

I

I would merge the 2 domains. I can’t see how this would involve any additional cost.
Posted

Downtime would be inevitable. Do you have capacity to build a system side by side?

The half term is the best time but you could od most of it in the background. I'll be doing something similar in the Coming months.

Posted

I've done dozens it domain consolidations over the years. IT guys love it cos they perceived ending up with a simple, clean environment. Business hates it because it messes stuff up and causes outages and problems, and at the end of it, don't see much visible benefit.

 

Having two domains should cause virtually no impairment to whateever you want to do; people from domain A can login to PCs in domain B (with consideration for GPOs)

 

Some thoughts

 

* Do you really know what is authenticating against your DCs? You can turn up the logging to get some info baout ldap, kerberos type auths.

 

* Often documentation talks about cloning accounts to the other domain and using sidhistory on the new account to access fileshares on the old domain. Whilst this works very well and is slick and easy, it is a confusing mess in years to come. Depending on how clear your permission structure is, I prefer to create equivalent AD groups, populate them with equivalent users from the new domain then permission that up.

 

* Consider Home drives/ personal areas. Perhaps time to move them to onedrive

 

* Is there any delegation of admin of ADs to consider

 

* 'natural wastage' can be helpful - stop adding anything to the domain you want rid of, then get stuff out of it bit by bit.

  • 5 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...