Jump to content

Recommended Posts

Posted

Hi everyone,

 

Hope you all are doing good, I have been tasked to do the following :

 

Migrate our current child domain to root domain, remove child domain completely, a few questions I have are as follows :

 

We have 2 x 2008R2 DCs, both of which also acts as file server (Yes - I have inherrited this just recently:-) )

 

Goal :

 

To Migrate and consolidate our Child Domain by Migrating Users, Groups, OUs, to ROOT Domain in Same Forest.

To Have our FileServers on the Current Hardware and Remove DC's off it

 

I am thinking that I would have to do the following :

 

a) Get a New Server Hardware, Install 2K8R2, DCPROMO to the ROOT Domain (Connected via VPN to ROOT Site)

b) Install ADMT with SQL Express on Newly Created DC

c) Start Migrating Users, Groups, Computer accounts, OUs to the parent / root domain in same forest

 

How would I demote the 2 x dcs while ensuring there file-structure and permissions are in-tact on the same hardware or do I have to purchase fileserver hardware too for migration ?

 

Will be grateful if someone could provide a step by step as to how to go about this migration.

 

Thanks so much !!

Regards

Rihatum

Posted
I demoted a DC to file-server here, pretty straightforward. Just DCPROMO. They'll carry on as normal otherwise. Bear in mind that you could use a VM to help as an intermediary machine here, moving roles to it temporarily if needed. If you're purchasing a new server for a DC, remember that's a very light role on hardware - virtualising may give you much better returns (though a bare metal DC can be nice to have).
Posted
We have 2 x 2008R2 DCs, both of which also acts as file server

 

This isn't as crazy as it sounds. It's quite common practice in Junior or Infant schools. In a Secondary school or College, you would expect many more servers for various tasks.

 

You method looks OK to me. That's probably how I would go about it.

 

I'm a bit confused about why you're wanting to demote 2 x 2008 DCs. Surely you want a DC at each site, so if your link goes down, everything continues as normal until the link is restored.

Posted
This isn't as crazy as it sounds. It's quite common practice in Junior or Infant schools. In a Secondary school or College, you would expect many more servers for various tasks.

 

You method looks OK to me. That's probably how I would go about it.

 

I'm a bit confused about why you're wanting to demote 2 x 2008 DCs. Surely you want a DC at each site, so if your link goes down, everything continues as normal until the link is restored.

 

More to the point - set up Sites and Services properly and you can stop clients trying to authenticate across the link. Unless I'm misunderstanding the infrastructure.

  • 1 month later...
Posted

Hi All,

 

Thank you for your valuable input, I have been able to do a test-lab (just once).

 

Replicated the existing scenario and it all went well...BUT :-) I have a few more questions :

 

a) During our Migration test via ADMT (ADMT installed on the target Domain DC), we had to create a USER on Target DOMAIN (Existing PARENT DOMAIN) and make that a LOCAL ADMIN of CLIENT workstations in order for client computers to migrate as well.

 

Can you advise us of as to how we can populate this Target Domain User to be a LOCAL ADMIN on ALL our COMPUTERS, SERVERS when we move computer accounts from OLD CHILD DOMAIN to PARENT DOMAIN ?

 

I did a test of populating a DOMAIN USER as a LOCAL ADMIN on some client workstations via GPO, but I noticed that it removed every other local-admin on that specific computer, which we cannot afford as we have some high-ups who are (they want to be) local admins of there computers :-) (Yes I know) :-)

 

So, I am looking for a safe way to populate this TARGET Domain User as a Local Admin user on all client computers / servers so that ADMT goes fine.

 

I am going to document the steps I did in my next reply / or update my original question so that you experts can have a look.

 

thanks !

this site is great !

Posted
Can you advise us of as to how we can populate this Target Domain User to be a LOCAL ADMIN on ALL our COMPUTERS, SERVERS when we move computer accounts from OLD CHILD DOMAIN to PARENT DOMAIN ?

 

The only way is via GPO, or you can do it manually via MMC per computer. If you want to cheat, adding Domain Users as local admins DOMAIN\Domain Users via GPO should do the trick.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...