Sydders01 Posted January 11, 2020 Posted January 11, 2020 Hi All, I hope someone will be able to assist with this- Scenario- *Two domains on a network. Domain 1-curriculum,Domain 2-Admin. *There is a trust between both domains. *There is no intention of building a new network from scratch due to fund constraints.(Would have preferred this option) *Teaching Staffs and Students devices are on the curriculum domain. **Steps to consolidate * Move the File shares and software shares to the Admin domain.Teaching Staffs on the curriculum already have an account on the Admin domain. *No Teaching /Student Devices on the Admin Domain Questions- 1) what should I watch out for? 2)what practical advice do anyone who has done this has for me? 3)I Know from what I have read that the trust on the domains will allow users(and devices ) on the curriculum to access resources on the admin domain is that the case or not? Thanks I will add more questions in due course
Liam Posted January 11, 2020 Posted January 11, 2020 What are the funding constraints.? I'd just rebuild. Probably work out to be easier.
FN-GM Posted January 11, 2020 Posted January 11, 2020 I would merge the 2 domains. I can’t see how this would involve any additional cost.
Sydders01 Posted January 11, 2020 Author Posted January 11, 2020 @ FN-GM that is the plan. Because there is already a trust ,then I intend to move the users gradually,then create device OU. how do you minimize any disruption? when is the best time to take a user out of one domain to the other ? what would be your steps if you are to go through this route? II would merge the 2 domains. I can’t see how this would involve any additional cost.
Liam Posted January 12, 2020 Posted January 12, 2020 Downtime would be inevitable. Do you have capacity to build a system side by side? The half term is the best time but you could od most of it in the background. I'll be doing something similar in the Coming months.
chaplic Posted January 13, 2020 Posted January 13, 2020 I've done dozens it domain consolidations over the years. IT guys love it cos they perceived ending up with a simple, clean environment. Business hates it because it messes stuff up and causes outages and problems, and at the end of it, don't see much visible benefit. Having two domains should cause virtually no impairment to whateever you want to do; people from domain A can login to PCs in domain B (with consideration for GPOs) Some thoughts * Do you really know what is authenticating against your DCs? You can turn up the logging to get some info baout ldap, kerberos type auths. * Often documentation talks about cloning accounts to the other domain and using sidhistory on the new account to access fileshares on the old domain. Whilst this works very well and is slick and easy, it is a confusing mess in years to come. Depending on how clear your permission structure is, I prefer to create equivalent AD groups, populate them with equivalent users from the new domain then permission that up. * Consider Home drives/ personal areas. Perhaps time to move them to onedrive * Is there any delegation of admin of ADs to consider * 'natural wastage' can be helpful - stop adding anything to the domain you want rid of, then get stuff out of it bit by bit.
PotNoodleTech Posted February 13, 2020 Posted February 13, 2020 Zero reason to have a dedicated admin domain any more. Just move all the admin users and PCs onto the curric domain and make sure vlans/ntfs security / share security is tight.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now