Jump to content

Recommended Posts

Posted

I have a windows server 2016 with a domain .local for a friend in small academy organization. There are roughly 20 users.

Recently, he bought a new domain .academy and he wants to migrate the domain of on-site server 2016 from .local to academy. He also wants to change the background picture. He also wants to block USB on domain computers.

 

I prefer to format the server since the number of users are limited and no data on the server. What do you suggest please?

 

 

I appreciate IT expert recomendation in this matter.

Posted

They changed the name of the school and the emails as well.

They want to use the email to login into local computers than mark.local or Douglas.local..... etc

Posted

No need to change the domain for that. You shouldn’t be login in with anything .local anyway as this should be pre-populated.

 

But if you really wanted to change it then you can change it without rebuilding the domain. There are supported ways to do it.

 

Restricting USB etc can all be done with Group Policy which is a feature of a domain server

Posted

Thank you for your swift reply snagrat

I know I can restrict the UBS via group policy but the main concern is the domain.

How can I make the user login with the new domain please?

How to migrate the domain from .local to .academy on the server 2016 please?

Posted

I just created a new user on the Azure AD. The new user has the new domain. Also, the account automatically created on the Office 365 portal. But the issuer has the old domain.

UPN for the new user is correct and matching the new domain name.

How can I change the issuer to the new domain please?

chrome_5A2CSoR1HM.png

Posted
IMO , if you want / need to change the domain name , just spin up a new vm build a new AD , even better move it to azure ad if that does what you need
Posted (edited)

This is the issue with the user that I want to create. It seems there is a sync between the local AD and the one in Azure.

How to check if this sync is enabled, and if is useful to have a on-primse AD connect to the Azure one?

AD.png

4fnk4CxrdmXfYAAAAASUVORK5CYII=

Edited by samaco
Posted (edited)
This is the issue with the user that I want to create. It seems there is a sync between the local AD and the one in Azure.

How to check if this sync is enabled, and if is useful to have a on-primse AD connect to the Azure one?

[ATTACH=CONFIG]66384[/ATTACH]

4fnk4CxrdmXfYAAAAASUVORK5CYII=

 

Well clearly sync is enabled - or was at some point.

 

You can check this via Azure AD - go to portal.office.com, log in with the same admin account you use for o365 admin, and search for and open Azure AD. In Azure AD, you should see an entry for AD Connect. I can’t remember the exact steps from here and I can’t be bothered to check right now, but it’s fairly easy to find and check the sync health and properties from here.

 

You could also log on to the DCs and see if any of those have AD connect installed - that’s where it typically ends up on small networks.

 

In any case, the message you posted says what it means and means what it says. A sync was set up at some point and in that situation you can only have one source of truth and that is the on-premises AD for hybrid users and objects.

Edited by Roberto
Posted (edited)

If you really want to go down the AD domain re-naming route I would advise using a subdomain of a public domain you own for internal use.

https://social.technet.microsoft.com/wiki/contents/articles/34981.active-directory-best-practices-for-internal-domain-and-network-names.aspx

 

You can add a UPN quite easily and this can normally be completely different from the internal AD name as others have said.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...