Solved

Windows 2003 Migration

Posted on 2004-08-18
4
132 Views
Last Modified: 2010-04-19
All, I am about to migrate my domain from NT4 to W2K3...

Could someone please clarify this point for me..

We have 100 desktops, 17 servers and 50 remote workers with laptops

My question is about the remote users; I can migrate the desktops using the computer migration tool which is fine, however its going to take a while (about a month) to get all the remote users in so I can migrate the laptops. To this end, will I need to keep the 17 windows based servers on the *old* domain until I get all latops migrated? I assume I will also have to keep the remote users logging into the *old* domain until I have migrated the laptops; I also assume that I can get them to log onto the *new* domain when I have migrated the laptops (obv I wil be cutting across the SID History)

Your urgent thoughts would be most appreciated

Thanks  
0
Comment
Question by:credmood
  • 2
  • 2
4 Comments
 
LVL 6

Expert Comment

by:youre1m
ID: 11828370
Yes you need to run your 2 environments in parallel, but not necessarily all 17 servers depending on what they are doing and what the Remote workers use on each server. You can set up a trust between the old and new domain and have them log in with new domain accounts but I would recommend keeping it clean and migrating as you have planned already. That way as you mention you get to carry the SID history accross.

We just completed a similar exercise, we transferred DHCP, DNS to the new environment and worked our way through everyone in teams as shared data can cause an issue if you have some users of it on the old and some on the new, so we set up a trust to enable new domain users to acces shared data on the old domain. Then once everyone that used that data had been migrated we moved the data to the 2003 domain until we were eventually clear on the old. Then we shut down but didn;t remove any old servers for 1 month, so that we had a rollback plan in the event of failure. Obviously you will be relying on new servers though, if your hoping to use the old kit for the new domain then you might have to take more of a "big bang" approach.
0
 

Author Comment

by:credmood
ID: 11838742
thanks for this, I have decided to stick with a *clean* migration and get all the remore users to use their *old* accounts until we get them into the office to do the computer migration..waht ill do is disable all the target accounts for remote users (untill their laptops are done) and disable all internal peoples source accounts..this way everyone is defo using the correct accounts....until i get everyone done and close the old domain.

Also, the problem I have is that the two serves I have targeted as being the DC's (I do have a tempdc that im going to build the new domain on) are file servers as well. However these will need to be on the new domain in oredr for me use as DC's. This involves me having to A) leave all existing permissions and create new ones for the new domain or B) migrating the server (which will change the permissions) and redo the old domain permissions. (I am going to have a trust set up). I think I will choose B this seems to be the better option...

Any thoughts on this

Thanks for your help

0
 
LVL 6

Accepted Solution

by:
youre1m earned 500 total points
ID: 11839095
We had new servers so didn't have this problem. We also used new group names so used robocopy to move the data and applied the permissions manually. Depends on the size of your operation  but we used it as a housekeeping exercise rather than simply recreating what we had before, as it didn't seem to quite fit what we were trying to achieve.

I'm a big fan of doing stuff as important as this as clean as possible, and with only 150 users your data probably isn't that complex a structure that it will take too long.
0
 

Author Comment

by:credmood
ID: 11839187
so your saying that what Im suggesting should be fine?
Your rigjht about the groups, however i went through them and they seem to more or less match what we're trying to do so I thought for ease I would just migrate them as well as the users...keeps everything *clean* as you rightly point out.

Cheers youre1m, its always good to get some feedback, just last minute panics that ive thought of everything thats all...:o)
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have never ceased to be amazed how many problems you can encounter on a fresh install of a Windows operating system.  This is certainly case in point& Unable to complete ANY MSI installation.  This means Windows Updates are failing and I can't …
Learn about cloud computing and its benefits for small business owners.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now