Jump to content

Recommended Posts

Posted

We are a MAT with lots of different schools, all FQDN in different formats, some have references to names of schools that have since changed.

 

We've been asked to look into changing all of these so they have similar naming conventions and remove references to school names that are no longer in use. We are also considering the possibility of other schools joining our domain and us wanting to change their domain to one that matches our format if required.

 

So my question, how easy is it to change a domain name? My previous experience is that you would probably have to rebuild the whole network, is it still such a daunting task or are there easy ways to do it now? Have any other MAT's done this and is it q requirement if you take on a new school?

 

Any advice would be appreciated.

 

Thanks

Posted

Do you “need” to change the format? As in as you linking schools AD directly, or was this more in reference to emails/usernames which could be changed without changing domain name

 

Even on a normal pc it’s in the first part of the FQDN that shows up when logging in etc

 

Steve

Posted

When we became a MAT, we initially had Trust relationships between domains, but then decided to rebuild the entire thing from scratch, with the new Trust name. Much simpler to do than trying to rename and fiddle around with a bunch of school systems.

 

It also allowed us to properly centralise services, and eliminate servers from all but 1 of our schools.

Posted
You change the log onto Name quite easily in ADSI editor. Although the fqdn will stay the same you can change how usernames are displayed.
Posted (edited)

Many different ways. I did it at home by building new DCs, creating a conditional forward in DNS, creating a trust between the 2 domains then started migrating Servers and Desktops and user accounts/groups across using ADMT installed on a member server in the old domain. The benefit being that you can do over a few weeks/months. One PC I had issue with migrating over to the new domain, some sort of permission issue on the c$ share but 1 out of about 5 desktops only had that issue, jus ended up rebuilding.

 

If it all goes well users will not notice a difference. Have to move GPOs over too and not forgetting DHCP and any specific DNS.

 

I did not have exchange running or any SQL servers but I did have AAD Sync and WDS. WDS I had to save the images as backup and then uninstall and re-install the service. I think I had to re-install AAD sync too. Only one user though, me.

Edited by Davit2005
Posted

Assuming we mean active directory, dont do it. You can't do it if youve got exchange and it's a whole pile of work for no business benefit.

 

Just add additional UPN suffixes and change users UPN to that. Cosmetic change that's desired with low risk and effort

Posted

I'd be more inclined to rebuild on a new forest, especially if the AD domains you acquire are a bit rubbish/neglected/WTF.

 

That's one of my many summer jobs. It'll be annoying, but it'll remove needless complexity and make maintenance and troubleshooting much easier.

Posted
Create a new domain from fresh, put trusts in if you really need to but with the overall plan to migrate to new domain unless you already have 1 domain you want to migrate to is how I would and have done it in the past before in business.
Posted

Thanks everyone for the feedback.

 

We currently have trust relationships between all the sites.

 

The main reason we have been asked to change is for branding reasons, we've been asked to remove anything that references the old school names.

 

I've explained the best approach is to rebuild the whole AD and that this is a big job with some risks attached and that we will need to take time to plan it and implement with as little impact to users as possibly. They were hoping we could do it this summer with a few clicks of button. :D

 

Luckily no Exchange so that is one thing I don't have to worry about!

Posted

I am reminded of a time I was working for a major name housebuilder, maybe 14k users. I just came in after they had done a new AD and was telling one of the directorates IT directors how great this new windows thing was that I would be doing. His response was absolute fury over the impact to the business of the AD change for no obvious benefit, despite being told up front how it was great and the best approach. And he was right.

 

Assuming your AD is not trivial, do not do this. You have articulated it isn't easy which is good, but it will be harder than you expect. If the current AD is messy a new one will get messy too unless you change practises and nothing in AD is unfixable and much less risk to tidy up.

 

And a teacher that cant get something working that used to work on a Monday morning will not care that a directory name they cant really even see refers to something old.

 

Add UPNs, tell everyone to login with "email address", job done and a few clicks.

Posted

There's a GPO for this -

 

Computer Config > Policies > Admin Templates > System > Logon - Assign a default domain for logon Enter the required name in the field.

 

All users thereafter will need to logon using [email protected]

 

Entering jbloggs as before will no longer work.

 

This is the cleanest/quickest way, however from experience I've had resistance from some users, despite requiring to enter the above in O365 for example (don't ask).

Posted

I recall this being an issue like 20 years ago, so I'm surprised microsoft have not fixed it. Then again, I'm not sure these old style AD domains have much future.

When I joined the school it had just had it's name changed to one of these newfangled community technology colleges (the CTC's with 'specialisms' introduced by labour). There was pressure for us to change the name from X-college to the new CTC. We resisted the change because it didn't really affect anyone. 15 years later the CTC's get scrapped and the school changes it's name back. Finally the domain name matches :)

  • Thanks 1
Posted
There's a GPO for this -

 

Computer Config > Policies > Admin Templates > System > Logon - Assign a default domain for logon Enter the required name in the field.

 

All users thereafter will need to logon using [email protected]

 

Entering jbloggs as before will no longer work.

 

This is the cleanest/quickest way, however from experience I've had resistance from some users, despite requiring to enter the above in O365 for example (don't ask).

 

This is the way , we name companies ad.corp.com and then change the pre logon in adsi edit to the company name

Posted
The big issue with renaming domains is not the domain itself, but anything that is linked to it. E.g. if you run Config Manager, or onsite Exchange. Or any other tools that won't take kindly to the rename.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...