Steve21 Posted August 29, 2020 Posted August 29, 2020 Good Afternoon All, So bit of a weird one here, recently changed jobs and taken over a school that's seems to have been run by a bunch of cowboys for many years, and it's a complete state, weird permissions bodges put in place all over AD/GPO, loads of 2008 servers with huge security issues, servers in-place upgraded multiple times with no cleanups in place, no proper documentation, 6+ long daisy chained switches etc etc and all! So certainly an interesting project to get stuck into Now one of my first things I need to get sorted is getting a clean state of AD to begin the healing process, but with thousands of random groups/users who haven't been used in ages, and the previously mentioned permission bodges etc, I'm seriously considering it might be safer all over to just rebuild the domain, considering there's no documentation as to what each of these bodges relates to, and by "fixing" one it's likely to cause problems down the line Now with so many servers that needs rebuilds etc, while I'd normally just go down the route of taking it offline over summer and bringing it all over to the new domain I really don't think that's going to be a choice here time wise Thinking of going down the route of side-by-side domains forested/trusted (obviously going to have to use another domain name for this), and then slowly migrating things over as I go, rebuilding a server at a time etc and fixing all the issues Now my concern is that using a cross domain/forest account would mess with the GPOs that are applying to said users depending where they logged on (Either the new/working side that might not play nicely with the bodges on the other side, or the bodged users logging in to a new server again with issues due to GPOs etc). Is there any way while all the users/pcs etc are trusted, that you fully block crossing GPOs, and forcing them to use the "correct" domain settings during their access to those services? (As a side note, the other thought was a fully AD default back to basic reset via Powershell, but obviously that could nuke some important bits if they are needed and hidden away!) Steve
HPlum78 Posted August 29, 2020 Posted August 29, 2020 Back up AD and run the PowerShell, still think that you will be doing a side by side but you will be in a known position (sort of). Good luck seems like you have your work cut out in the coming months.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now