samaco Posted September 10, 2022 Posted September 10, 2022 I have a windows server 2016 with a domain .local for a friend in small academy organization. There are roughly 20 users. Recently, he bought a new domain .academy and he wants to migrate the domain of on-site server 2016 from .local to academy. He also wants to change the background picture. He also wants to block USB on domain computers. I prefer to format the server since the number of users are limited and no data on the server. What do you suggest please? I appreciate IT expert recomendation in this matter.
snagrat Posted September 10, 2022 Posted September 10, 2022 What’s the point in changing the domain name?
samaco Posted September 10, 2022 Author Posted September 10, 2022 They changed the name of the school and the emails as well. They want to use the email to login into local computers than mark.local or Douglas.local..... etc
snagrat Posted September 10, 2022 Posted September 10, 2022 No need to change the domain for that. You shouldn’t be login in with anything .local anyway as this should be pre-populated. But if you really wanted to change it then you can change it without rebuilding the domain. There are supported ways to do it. Restricting USB etc can all be done with Group Policy which is a feature of a domain server
samaco Posted September 10, 2022 Author Posted September 10, 2022 Thank you for your swift reply snagrat I know I can restrict the UBS via group policy but the main concern is the domain. How can I make the user login with the new domain please? How to migrate the domain from .local to .academy on the server 2016 please?
snagrat Posted September 10, 2022 Posted September 10, 2022 You can follow this to rename the domain https://www.google.com/amp/s/www.rebeladmin.com/2015/05/step-by-step-guide-to-rename-active-directory-domain-name/amp/ but I still do not think it will help you. Are you wanting users to login with their new email address which you have recently changed?
samaco Posted September 10, 2022 Author Posted September 10, 2022 Yes, I want the user to login with their NEW email address please.
Primus Posted September 10, 2022 Posted September 10, 2022 If you want them to log on with their email address just add it as a UPN suffix and change their accounts so that it uses the new suffix.
samaco Posted September 10, 2022 Author Posted September 10, 2022 I just created a new user on the Azure AD. The new user has the new domain. Also, the account automatically created on the Office 365 portal. But the issuer has the old domain. UPN for the new user is correct and matching the new domain name. How can I change the issuer to the new domain please?
chaplic Posted September 10, 2022 Posted September 10, 2022 Not like that. I’m joining a few dots, but you should create the user in AD with the new UPN and have that project in Azure AD.
mavhc Posted September 11, 2022 Posted September 11, 2022 You can add extra domain names without changing the main domain name
Jcx500 Posted September 11, 2022 Posted September 11, 2022 IMO , if you want / need to change the domain name , just spin up a new vm build a new AD , even better move it to azure ad if that does what you need
samaco Posted September 11, 2022 Author Posted September 11, 2022 (edited) This is the issue with the user that I want to create. It seems there is a sync between the local AD and the one in Azure. How to check if this sync is enabled, and if is useful to have a on-primse AD connect to the Azure one? Edited September 11, 2022 by samaco
Roberto Posted September 11, 2022 Posted September 11, 2022 (edited) This is the issue with the user that I want to create. It seems there is a sync between the local AD and the one in Azure. How to check if this sync is enabled, and if is useful to have a on-primse AD connect to the Azure one? [ATTACH=CONFIG]66384[/ATTACH] Well clearly sync is enabled - or was at some point. You can check this via Azure AD - go to portal.office.com, log in with the same admin account you use for o365 admin, and search for and open Azure AD. In Azure AD, you should see an entry for AD Connect. I can’t remember the exact steps from here and I can’t be bothered to check right now, but it’s fairly easy to find and check the sync health and properties from here. You could also log on to the DCs and see if any of those have AD connect installed - that’s where it typically ends up on small networks. In any case, the message you posted says what it means and means what it says. A sync was set up at some point and in that situation you can only have one source of truth and that is the on-premises AD for hybrid users and objects. Edited September 11, 2022 by Roberto
Davit2005 Posted September 12, 2022 Posted September 12, 2022 (edited) If you really want to go down the AD domain re-naming route I would advise using a subdomain of a public domain you own for internal use. https://social.technet.microsoft.com/wiki/contents/articles/34981.active-directory-best-practices-for-internal-domain-and-network-names.aspx You can add a UPN quite easily and this can normally be completely different from the internal AD name as others have said. Edited September 12, 2022 by Davit2005
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now