Jump to content

Recommended Posts

Posted

Good Afternoon All,

 

So bit of a weird one here, recently changed jobs and taken over a school that's seems to have been run by a bunch of cowboys for many years, and it's a complete state, weird permissions bodges put in place all over AD/GPO, loads of 2008 servers with huge security issues, servers in-place upgraded multiple times with no cleanups in place, no proper documentation, 6+ long daisy chained switches etc etc and all! So certainly an interesting project to get stuck into

 

Now one of my first things I need to get sorted is getting a clean state of AD to begin the healing process, but with thousands of random groups/users who haven't been used in ages, and the previously mentioned permission bodges etc, I'm seriously considering it might be safer all over to just rebuild the domain, considering there's no documentation as to what each of these bodges relates to, and by "fixing" one it's likely to cause problems down the line

 

Now with so many servers that needs rebuilds etc, while I'd normally just go down the route of taking it offline over summer and bringing it all over to the new domain I really don't think that's going to be a choice here time wise

 

Thinking of going down the route of side-by-side domains forested/trusted (obviously going to have to use another domain name for this), and then slowly migrating things over as I go, rebuilding a server at a time etc and fixing all the issues

 

Now my concern is that using a cross domain/forest account would mess with the GPOs that are applying to said users depending where they logged on (Either the new/working side that might not play nicely with the bodges on the other side, or the bodged users logging in to a new server again with issues due to GPOs etc).

 

Is there any way while all the users/pcs etc are trusted, that you fully block crossing GPOs, and forcing them to use the "correct" domain settings during their access to those services?

 

(As a side note, the other thought was a fully AD default back to basic reset via Powershell, but obviously that could nuke some important bits if they are needed and hidden away!)

 

Steve

Posted
Back up AD and run the PowerShell, still think that you will be doing a side by side but you will be in a known position (sort of). Good luck seems like you have your work cut out in the coming months.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...