Jump to content

Recommended Posts

Posted

Hi All,

 

I'm fairly new to the systems used within education but i'm quickly picking things up!

 

I work at a trust where the trust hub is on a school site. The hub has its own AD set up and the school has its own. I need to merge these two domains to be one. Does anyone have an easy-ish process on how to do this?

 

Id also be extremely grateful of any useful tips and tricks with Active directory.

 

Many Thanks

Dan

Posted

Hi Dan,

 

I'd generally start by getting a trust relationship setup between the two domains, with a bit of messing around then users should be able to login to the other site's domain.

 

From there you can look at using ADMT to move the users, have to say it isn't the easiest looking process.

 

I'd probably start by spinning up a couple of new domains and having a play away from the live environment.

  • Thanks 1
Posted (edited)

I've migrated my small network at home to a different Domain and if everything works OK users won't notice but I'd say out of 10 servers/workstations 1 windows 10 and one server 2008 had to manually muck around as ADMT could not get access to the C drive.

 

Basic steps I performed were:

Setup conditional forwarders on DNS servers in each domain

Set up a 2 way trust

Set up a domain joined server/workstation to run ADMT (should not need to be installed on a DC, and certainly would not want to install it on a new DC)

Use ADMT to migrate workstations, groups and users

 

You will also need to export group policies too from old domain and import to new one

 

I did not have to deal with SQL or Exchange in my setup and only had one user on Office 365 which I cannot remember how I dealt with.

Edited by Davit2005
Posted
This is potentially a complex project. You need to consider all the services that tie into AD. An example would be Office 365, Raduis, and other software and systems.
  • Thanks 1
Posted (edited)
Too add if you are creating a new AD domain/forest I'd go for creating a subdomain for the public domain you already own i.e. internalad.someschool.sch.uk . Edited by Davit2005
Posted

The devil is in the detail, and that recent post by MS and highlighted by @HPlum78 shows there is a lot more detail to worry about since 2012.

 

What is the business case for the migration? I wonder if an alternative solution might be a better fit?

 

The alternative I would consider would be to go hybrid into a overarching tenant and then pivot the old domain to Intune/365 only. This would avoid the need to migrate all the ancillary services up to the central Trust AD, which is itself legacy at this point.

 

You still have to do all the work, but you end up with a modern solution, rather than one based on the 1999 design documents.

 

(FWIW I'm still heavily AD centric because the business case for pushing to 100% cloud, for us, is not compelling enough; integrating another site would definitely change this balance)

  • Thanks 1
Posted

As above it depends a lot on how much is feeding into and hanging off your AD and the number of users + devices.

 

I'd probably start with a trust relationship to allow logins between the schools.

 

Then look at reviewing / documenting the structure, file + printer shares, group policy, account provisioning process etc. Having a clear idea of how want your overall domain to look when you are done is worth having written down. Once you have this, you can create checklists to make sure things don't get forgotten.

 

When we did this a few years ago, we ended up making a new trust domain, setting up automated account creation with LGFL + other scripts, and then re-created the Group Policy and shares, share permissions, security groups etc, taking the opportunity to get rid of stale stuff. It took a while, but it was worth it to clean everything up and get things automated. The last thing we did was moving the PCs over (We might have done 1 site at a time). An advantage of doing a new domain is that you can test and develop without getting in the way of anyone, then you have 1 switch over say a holiday.

 

It would be worth talking to your LA and or someone like Salamander to see if automation is the way forward at least for the accounts.

 

Were we to do this again, I'd start looking at things like Azure or Google's windows support. I think hosting your domain in the cloud in some way is the way forward.

Posted
My personal opinion is to simply ditch your current AD structure and migrate onto the trusts HUB, unless the hub means that you need to have your own parent domain. In which case i'd ask the person managing the trust HUB to create you a new subdomain and then do a CSV extract of your users and groups off your old domain and recreate them on the new system. If the trusts hub has different naming conventions, maybe now is the time to say to staff and students that this summer we're converting to the main academy's trust. We will adopt the following changes and these are the benefits (e.g. different site learning). Don't create extra hassle or work for yourself trying to interconnect an old system to a new one, just see if you can modernise your system into the trusts.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...