Jump to content

Renaming a domain, in the era of cloud connected systems


Recommended Posts

Posted

So, there's a possibility that I will need to rename our domain soon - to a completely different FQDN.

 

I understand in the past, when it was just your active directory domain it was a bit of a faff, but doable but these days, with Azure Ad being linked to it, and Google etc... What are the implications?

Posted

There shouldn't be any implications for Google itself. Your primary domain will stay the same most likely - its very difficult to move it - so you'll need to keep the domain name active and owned, but you can add new domains till the cows come home.

You will need to move your users domains Google wise, but you should be able to do this using GAM, and also alias their old addresses to their new ones.

Posted
There shouldn't be any implications for Google itself. Your primary domain will stay the same most likely - its very difficult to move it - so you'll need to keep the domain name active and owned, but you can add new domains till the cows come home.

You will need to move your users domains Google wise, but you should be able to do this using GAM, and also alias their old addresses to their new ones.

What do you mean the primary domain will stay the same? In Google or in AD? If in AD, this can't happen - we would want this to be a new domain name.

Posted

It's possible to change the display name for a domain (on the logon screen), instead of changing the FQDN, so for example -

 

Computer Config > Policies > Admin Templates > System > Logon - Assign a default domain for logon - Enabled

 

In here specify Test (for example), then restart a workstation.

 

The user then logs in using [email protected] - whatever their user reads in AD if you've specified custom/additional domains to your real FQDN.

 

If you're part of a larger Academy Trust, this can be unique per school/per GPO/per OU if you understand what I mean?

 

Test.png

Posted

I renamed my home AD domain about a year ago to a subdomain of a public domain I own but different domain to my O365 email using the Microsoft ADMT tool.

 

Created 2 new domain controllers, created conditional forwarders in DNS, created a 2 way trust between the domains. Then started the task of copying GPOs and migrating AD groups, computers/servers and users over to the new domain. If all goes well there is no visible impact to users, I did have some issues with one Laptop as the ADMT requires access to the admin share of the computers in order to do the profile stuff etc. AAD connect was simply a matter of going through the wizard from memory. The only other thing I had to do was remove WDS feature on my server running MDT (copying the boot images beforehand) then adding the feature back in. I also made a DNS forward lookup zone so I could keep the DNS names of my ESXi servers.

 

I don't run any SQL or Exchange at home so cannot comment on that side. Many guides tell you to install the ADMT tool on the new domain controller but I just installed on VM on my local PC in VirtualBox in the old domain then it all got destroyed when I got rid of the old domain. Quite painless apart from the admin share issues on client PCs.

 

I did keep my O365 email domain the same though.

Posted
What do you mean the primary domain will stay the same? In Google or in AD? If in AD, this can't happen - we would want this to be a new domain name.

 

DNS plays a big role if you rename the FQDN, this is what @paulkerton means, so you'll still need a DNS Zone of your existing FQDN thereafter, but end users obviously won't know this.

Posted
DNS plays a big role if you rename the FQDN, this is what @paulkerton means, so you'll still need a DNS Zone of your existing FQDN thereafter, but end users obviously won't know this.

Why? If the domain is using the new FQDN? What would still be using the old one?

Posted

The award for understatement of the year goes to localzuk for 'a bit of a faff'

 

So this piqued my interest, so I had a look around (as you probably have already) and came to this: https://docs.microsoft.com/en-us/answers/questions/77503/internal-domain-rename.html which summarises all the other links that I came across about the matter.

 

 

 

A quick look around suggest Exchange and Hybrid are both blockers for the renaming of the internal domain. Have you seen documentation suggesting otherwise?

 

A migration might be a better option? or perhaps changing the upn suffix and updating the domain in Azure AD/365 if you are allowed to keep the old domain in the background?

Posted
What do you mean the primary domain will stay the same? In Google or in AD? If in AD, this can't happen - we would want this to be a new domain name.

 

Within Google. You would need to keep the ownership of your FQDN for Google, as changing your primary domain isn't a simple process.

For example in Google we still have our primary domain as school.county.sch.uk but we now run school1.co.uk and school2.co.uk out of Google without any issue.

 

AD wise, you can change it as Google > AD sync relies on the domain on the email address rather than the FQDN in AD, if you're using Google's sync tool that is.

Posted
A quick look around suggest Exchange and Hybrid are both blockers for the renaming of the internal domain. Have you seen documentation suggesting otherwise?

 

We don't use Exchange. By Hybrid, do you mean Hybrid AD join or Hybrid Exchange setup?

Posted

I'm outside my experience here, so take with a pinch of salt, but I read it in context to mean hybrid exchange.

 

To be honest if removing all traces of the current domain name was the desired outcome, given the apparent lack of blogs written by MVPs or articles on docs.microsoft.com on the topic, I might consider paying for a day's consultancy to develop feasibility study for the project.

Posted (edited)

We run a Google domain with directory sync against our AD and also use onsite Exchange. When it was first setup we didn't really care about GMail, so we just left that turned off. After a couple of years the school wanted to provide the students with mail. GSuite supports using multiple domains and the users we sync over are using a different domain from the internal. I don't know what renaming the underlying AD domain would do though.

 

There has to be a path to utilizing multiple AD domains with Google and Azure. Standing up your new domain with a trust relationship to the old and slowly migrating over would be the safest thing to do if it is an option.

Edited by Duke5A
Posted

Renaming the google domain is easy enough, licences on your account can be a blocker though - When i did this a fair few years ago google shuffled stuff around for us and made it happen.

 

We dont have any ad connections though

Posted
I cannot talk about Google, but don't rename AD/ Azure AD. Add your new domain to Azure AD and create additional UPN suffixes in AD then change your people over to it.
Posted
Personally I would just build a new domain and transfer users over time. I did that years ago when I merged 2 domains and it worked very well.

Not so easy when your domain is spread across 8 sites though? Plus, there's the issue of licensing, and the issue still of Azure Ad.

  • Thanks 1
Posted

What is the OS on your DC? if your 2016 and above its not that much of a faff. Rendom and gpfixup commands add your new domain name to your Azure AD tenant and set it as primary.

 

There are a few steps that I may have missed but I reckon that about covers it....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...