• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 575
  • Last Modified:

Create 2003 AD replica test lab on virtual servers / different hardware

Problem: I need to merge 2 forests GAL’s using Microsoft Identity Integration server, this needs to be done in a test lab first.

Ok so I know I can import accounts and objects in to 2 replica forests using CSVDE but I really want all the full AD partitions to be there for a true representation. The tricky bit is the fact that I want to restore AD on to 2 virtual hosts, I can find documentation on how to restore to different hardware under Windows 2000 but nothing on 2003. Ideally I want all AD factors to be as close to the production systems as possible.
  • 2
2 Solutions
Create the VM with all necessary services while it has network access to your production domain.
dcpromo it. Wait for replication.
Switch the VM to an internal network on the VM, do NEVER EVER bring it back in contact with your production domain again!
Remove the VM from your AD:
How to remove data in Active Directory after an unsuccessful domain controller demotion

Seize the FSMO roles on the VM:
How To View and Transfer FSMO Roles in Windows Server 2003

Transfer the Licensing server to the VM:
In AD Sites and Services, right-click "License Server" in the right pane, choose Properties, and move it to the new server.

To be able to transfer files between the VM and your production network (apart from using iso images or CDs):
* Install the MS Loopback NIC as additional NIC on the virtual server, give it an address different from your normal subnet; disable NetBIOS over TCP/IP on this NIC. Change the IP address on the VM accordingly.
* Bind the VM's NIC (or the virtual switch if you're using one) to the Loopback NIC.
* Transfer the files to a folder on the VS, map this folder from the VM using the loopback NIC.
I do this all the time.
The only variation I make to the process outlined above is that I COPY the Virtual Machine files to another location.
I then change the network configuration of the copy of the virtual machine to isolate it.
The original is then booted up and removed from the domain correctly using DCPROMO. Dropped in to a workgroup and then deleted.

All the warnings as above apply.

microrAuthor Commented:
Cheers OBDA - i did think of that myself, but i dont really want to introduce another DC unless it is actually needed even with Sembee's suggestion of the clean removal, which i aslo thought of. I was thinking more along the lines of a backup / restore procedure.........
microrAuthor Commented:
Well i had to go down the suggested route in the end, the test GAL integration worked a charm - now onto the production stuff!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now