Solved

Domain functional levels...

Posted on 2004-08-05
7
418 Views
Last Modified: 2010-07-27
Right now I am running a Windows 2003 network in "Windows Server 2003 interim mode".  I have have 2 w2003 DC, 2 NT4 DC and no w2k DC.  I have about 100 clients.  I want to switch to "WIndows Server 2003" domain functional level.  I know that NT 4 DC are not supported in this senerio.  I need to keep the NT 4 DC up until  I can move the apps that reside on them over to different servers.  I don't care if the NT 4 DC aren't able to authenticate users or perform and DC functions in the new domain functonal level.  I was just wondering if there are adverse effects in keeping 2 NT 4 DC in this new domain functional level.  The 2 W2003 DC servers should easily handle all the DC roles in my network.  Must I purge all the NT 4 DC before continuing?
0
Comment
Question by:alocke2940
7 Comments
 
LVL 16

Expert Comment

by:JamesDS
ID: 11729416
alocke2940

If you raise the Domain functional level then the NT4 DCs will nolonger be able to replicate the AD database and will not receive updates - IE they will effectively cease to be DCs.

Yes, you should purge NT4 DCs before upgrading

Cheers

JamesDS
0
 
LVL 51

Expert Comment

by:Netman66
ID: 11729522
Also, if you require authentication to access shares and applications, they will fail too.

0
 
LVL 83

Accepted Solution

by:
oBdA earned 125 total points
ID: 11730029
Basically, it would be better to move the applications to another machine before raising the level. If you're in a hurry, or can't move it for whatever reason, you could try to simply depromote your NT4 BDCs to member servers.
Read the instructions carefully (especially the part about what happens with the NTFS permissions), though, and make sure you have a working backup of the machines.
UPromote
http://utools.com/UPromote.asp
0
 

Author Comment

by:alocke2940
ID: 11730081
You can depromote and NT 4 server from a DC to member server?  How do you do that?
0
 
LVL 83

Expert Comment

by:oBdA
ID: 11730252
Well, with the Upromote tool from the link?
We've just run this successfully on a couple of NT4 BDCs in a W2k3 domain that were still serving as print servers and had no problems. Whether it works for you depends on your setup. (And the air humidity, your stepsister's horoscope, and whatever else influences computers ...)
Major caveat: When/if you depromote a DC that way, it will be removed from the domain first and become a stand-alone server. During this, the NTFS permissions at least on the system drive will have to be reset as well, due to the SID changing; so if you've developed some elaborate permission construction on your system drive, you might have to reconstruct it. You can leave the permissions on the other drive(s) if you plan to rejoin the domain.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now