Go Premium for a chance to win a PS4. Enter to Win


Bringing in a new SBS 2003 into existing domain, to create Backup server

Posted on 2006-06-14
Medium Priority
Last Modified: 2010-04-19
We have a small office with 12 client computers with XP Professional. We have a Windows Server 2003 Standard version [SAY BOX 1] which is the Domain Controller for say DOMAIN 1. I purchased a SBS 2003 server [ SAY BOX 2], which has the exchange server. I installed the SBS with a different domain and it became a domain controller of a different domain say DOMAIN 2.

Now what I need

1. Actually both the servers to be part of the same domain. [ The reasoning is if one fails I want the other for backup, as I see both can be peers ]. So both should be able to handle as ADs for users.

2. From some research, I have learnt that it is not wise to have the exchange server as well as the Domain controller on the same box. So my options are to keep running the AD on BOX 1 and activate or configure BOX 2 as the exchange server.

Some of the question are
1. Now I have two domains -- Need to come back to one domain. Which domain to kill and how?
2. How do I bring BOX 2 [with whatever domain suggestion you may have] as a backup to the BOX 1 as far as the active directory is concerned. i.e. to handle the logging and roaming profiles of the users, if BOX 1 were ever to get un-workable.

Please help me with definte steps how to proceed.

Question by:wajahatkhan
LVL 48

Expert Comment

ID: 16908492
no can do

no trusts with SBS domains

and only one SBS server per domain

no way around it mate

Expert Comment

ID: 16908667
What Jay Jay70 said is true.  Your only hope is to demote your first domain control and join it and the pc's to the other domain. Now if you didn't have sbs then you could work some other options.

It sounds like you want redundancy in your domain for authentication.  Because windows 2k3 is multi master you can make your 2k3 stardard machine a DC and if your sbs server crashed everyone would be able to still logon. You just couldn't added new accounts because the FSMO server is down. Also if you have roaming profiles you may get errors logging in if they where on your server that crashed.  Hope that helps. Please reply if you want more info. Good luck.

FSMO Explained  http://computerperformance.co.uk/w2k3/W2K3_FSMO.htm
LVL 96

Accepted Solution

Lee W, MVP earned 1000 total points
ID: 16908757
Hi wajahatkhan,
> 1. Now I have two domains -- Need to come back to one domain. Which
> domain to kill and how?
Kill the original domain - by using the Active Directory Migration Tool to migrate your users and computers from the original domain to the new domain.  Then reinstall the old machine and make it a DC.  As has been touched on, the SBS server MUST be your FSMO master server, but it CAN have other DCs in the network.  So, though there is no such thing as a PDC in Active Directory domains, the SBS box becomes your "primary".

> 2. How do I bring BOX 2 [with whatever domain suggestion you may have]
> as a backup to the BOX 1 as far as the active directory is concerned.
> i.e. to handle the logging and roaming profiles of the users, if BOX
> 1 were ever to get un-workable.
You use the DCPROMO command to create a new domain controller.

You are correct, Exchange should not be installed on a Domain Controller - BUT, SBS is an exception - it's designed to run everything and should run everything.  Note - FORGET WHAT YOU KNOW about managing a Windows domain (well, not really, but keep reading).  SBS is intended to be managed through the wizards WHEREEVER AND WHENEVER POSSIBLE.  If there's a wizard for the action you need, USE IT.  Failing to do so can cause problems.  In fact, I wouldn't even use ADMT to migrate the computers - just the users.  You should use the ConnectComputer web site to join the computers to the SBS domain (remove them from their existing domain, join them to the new domain AFTER you create the users.

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

LVL 74

Assisted Solution

by:Jeffrey Kane - TechSoEasy
Jeffrey Kane - TechSoEasy earned 1000 total points
ID: 16910837
The research you have done is for standard Windows servers.  Please read http://sbsurl.com/itpro for an overview of how SBS is different.

You actually CAN add an SBS to an existing domain, but that will mean reinstalling your SBS from scratch.  See this KB for the how-to:

I would note however, that it states specifically in the article that it is not really intended to be a migration method.  The problem that you'll have by joining the SBS to an existing domain is that the workstations will not have all of the features necessary to be easily managed through the SBS as it was designed.  Assuming that you didn't already have Exchange deployed, and the fact that you only have 12 workstations, I would really suggest that you build your SBS following all best practices and then individually migrate the workstations to the new domain.  This would require that you unjoin them from the current domain.  

If you have never installed and configured an SBS, the I would highly recommend that you read http://sbsurl.com/start and follow it through.  Probably the biggest mistake I see is workstations that aren't added using the connectcomputer wizard as described in all SBS documentation (and visually here:  http://sbsurl.com/add).  

There are very few restrictions with SBS, but one of them is that you must run all server components on the same box.  That means you cannot install Exchange on a different server.  The thing is that the design of SBS is pretty good... all of these things work very well together if you let them, and don't attempt to second-guess the engineers that designed it.

If you do want to install a second Server 2003 on your network, you should review http://sbsurl.com/addserver to make sure it's done correctly.



Author Comment

ID: 16916351
Thanks everybody for their advice. Especially leew and techsoeasy. Here is what I think I will be having to do.

1. Start using the DOMAIN that was created with SBS.
2. Enter all the users and add computers on SBS.
3. Change the domain on the 2003 standard server and add that server to the domain of the SBS.

Some questions still remain on the topic

1. Can I migrate the user profiles etc from the current AD (on 2003 Standard, domain 1) to the future AD (on SBS, domain 2). CAN YOU PLEASE SPECIFY SOME DETAILED STEPS ON DOING IT.
2. How can I change the 2003 windows standard server from domain 1 to add it as another domain controller on domain 2. [Probale steps are.. Demote the server from being a domain controller, then change the domain and add it to the new domain of SBS]. CAN YOU PLEASE SPECIFY SOME DETAILED STEPS ON DOING IT.
3. Can the windows server 2003 server be then used a domain controller for the new domain of the SBS.


LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 16916905
The detailed steps are in this guide:  http://sbsurl.com/migrate.  It's effective for either Win 2000 Server, SBS2000 or Server 2003.

You should just demote the older server and put it into a workgroup, then follow this guide to add it to your network:  http://sbsurl.com/addserver

Yes, it can be a DC if you like.

Finally, I wouldn't migrate the profiles from the old domain if you don't need to... unless you were using roaming profiles before.  Then you can use ADMT as described in the migrate paper above.  If you weren't using roaming profiles... moving the workstations to a workgroup first will preserve the user profile and then using the connectcomputer wizard as SBS requires will migrate it to the new domain.


Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The articles for turning off the Client firewall policy on the internet are for SBS 2008 and don't really help for SBS 2011. They actually moved the Client firewall policy. In 2011, the client firewall policy has moved to the SBS computers conta…
I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question