Link to home
Start Free TrialLog in
Avatar of lehan
lehan

asked on

Moving Active Directory accounts to a new server

Hi all,

I am planning on building a new Windows 2000 Server and I want to move all user accounts (including computer accounts) from my existing 2000 server to the new one.
Any idea on how to do this simply?

Thanks
lehan
ASKER CERTIFIED SOLUTION
Avatar of rhinoceros
rhinoceros

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
That pretty much answers it.  If you are trying to replace the server with the one you have and need to keep the name of the old server, though, the other option would be to image the drives using Symantec Ghost Enterprise or some other imaging software(difficult, but possible with RAID drives due to the sheer volume of info) and then reinstall the operating system again and it will pick up all the old info from the registry and NTDS and SYSVOL directories.  This is much more hazardous than rhinoceros's suggestion.  I don't recommend it unless you're in a hole and really need to do a "replace" of the old server...as you might waste a lot of time if the upgrade of the image doesn't work.

Of course, you WOULD have your old server around and would always be able to go back to it.

Good Luck!
Avatar of lehan
lehan

ASKER

Actually I will be taking the old server out of the domain. I am basically changing the old server due to its hardware age.

Its not really important to keep the old server name as long as changing it does not affect account logins and/or permissions.

So correct me if I am wrong:
I install W2k server on the new system (using a new comouter name)
Have it join the domain as an ADC
Then follow the 4 steps that "rhinoceros" mentioned above
Then prey to god that users can still login and everything is intact :)

I am sure that its easier said than done!
Thank you both for great answers so far.

will be rewarding the points as soon as I get little more feedback.

lehan
Yes, it's true.

But you should give more enough time for two servers replcation before demote. Like as DNS replication, AD (Directory service / File service ) replication, license replication (each 24hrs) etc.

I think a few days time as well. (make sure 100% transferred between them), & remind the Event log for  any mistake / error will come out during this waiting period.

One more, look for two servers' "Active Directory Users and Computers", "Active Directory Sites and Services" (replcation link will appear & Global catalog setting), "DNS server" for double check before demote.

I hope it can help.