Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Adding a 2003 AD server to a Win 2k domain with Exchange

Posted on 2006-11-15
14
Medium Priority
?
220 Views
Last Modified: 2010-04-18
I have a network (with multiple subnets) that is Windows 2k AD with five 2k BDCs. My Win2k Domain also has an Exchange 2k server running with AD.

I have a need to add a 2003 AD server for the purpose of authentication for a Internet Control/Content Filter. This device only works with Win 2003 AD.  

So my question is, since I don't want to have to upgrade my Exchange 2k licenses, is it possible to add a Windows 2003 AD server on to my domain without making any changes to the Exchange server? Would I also need to upgrade all my BDC servers to 2003?

I realize that I would have run domain and forest prep prior to adding the 2003 server, but I want to know whether that would cause an issue with the 2k Exchange server running AD.

Basically can an Exchange server running 2k with AD co-exist in a 2003 domain?

My domain is in a mixed environment.

Thank you.
0
Comment
Question by:cfgchiran
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
  • 4
14 Comments
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17953748
yes thats fine, just run your adprep tools and away you go, remember, you have to run those tools from the second CD in the R2 set if introducing R2 server
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 17956437
Thanks for the response. Do I need to uprgade all of the 2k AD servers to 2003, or can I just introduce a new server or upgrade just the primary domain controller?

So effectively I would have just one 2003 Primary Domain Controller, and a bunch of backup DCs running 2k and the Exchange Server (with Active Directory) running 2k as well.

What is the difference between running the prep tools from the 2nd CD vs the 1st CD? Or is it just that the tools are on the 2nd CD in 2003?

Thanks.
0
 
LVL 48

Assisted Solution

by:Jay_Jay70
Jay_Jay70 earned 400 total points
ID: 17960116
Morning, one small thing to get around is that there are no more PDC and BDC's since 2000 Server, all DC's are simply DC's. The differential point between them is that one (or more) hold FSMO roles.

You only have to run the adprep tools on the Schema master and it will replicate across to the other DC's. You can have both 2000 and 2003 DC's in the domain thats fine.

With R2 there is increased functionality and hence, a more advanced Schema. The adprep tool on the second CD will prepare your forest for this schema entry. If you dont run it from the second CD, DCPROMO will fail with an incopmpatible Schema error
(\CMPNENTS\R2\ADPREP)
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 1

Author Comment

by:cfgchiran
ID: 17968353
Thanks for the info. I am going to leave the question open for a couple more days to see if anybody has a different opinion.

And yes, I am aware that there is no longer PDCs and BDCs. What I meant by the PDC was the FSMO role holder, which is all one and the same for us.
0
 
LVL 2

Accepted Solution

by:
resourcepc earned 600 total points
ID: 17973715
Since you have Exchange 2000 in your 2000 AD environment, you will need to run the inetorgpersonprevent.ldf script first or you will mangle some of your Exchange attributes.  Check out the resolution in scenario 2 of this article before you run adprep /forestprep and adprep /domainprep

http://support.microsoft.com/kb/325379

If you follow this article, you shouldn't have any problems having a 2003 DC co-exist with your 2000 DCs and Exchange 2k.  If you are going to upgrade a DC to 2003 R2, you will have to run adprep from the 2nd cd from the \CMPNENTS\R2\ADPREP directory.  It will not allow you to add a 2003 R2 server until you do so.
0
 
LVL 2

Expert Comment

by:resourcepc
ID: 17973727
A little more info on the Exchange attributes that are renamed if you don't have run the inetorgpersonprevent.ldf script taken from the article I mentioned above....

The Exchange 2000 schema defines three inetOrgPerson attributes with non-Request for Comment (RFC)-compliant LDAPDisplayNames: houseIdentifier, secretary, and labeledURI.

The Windows 2000 inetOrgPerson Kit and the Windows Server 2003 adprep command define RFC-complaint versions of the same three attributes with identical LDAPDisplayNames as the non-RFC-compliant versions.

When the Windows Server 2003 adprep /forestprep command is run without corrective scripts in a forest that contains Windows 2000 and Exchange 2000 schema changes, the LDAPDisplayNames for the houseIdentifier, labeledURI, and secretary attributes become mangled. An attribute becomes “mangled” if "Dup" or other unique characters are added to the beginning of the conflicted attribute name so that objects and attributes in the directory have unique names.
0
 
LVL 2

Expert Comment

by:resourcepc
ID: 17973730
I've already been through the same migration (adding a 2003 DC to a 2000 forest with Exchange 2000) and had no problems as long as you follow the article above and run the script first.
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 17981052
resourcepc  - Thank you very much for your comments and suggestion. In other readings I did come across the same ideas you presented regarding Exchange and I am thankful that you pointed it out too.

Since I know adding a new server is almost always better than upgrading one, I will be adding a new 2003 DC, after doing both the Exchange prep first and then the domain and forest prep on my master DC, and then demoting that 2000 master DC.

You mentioned that I should run from the 2nd CD if upgrading the server. Since I am not upgrading, which CD should I run from? Or does it even matter? I just ordered the R2 media and licenses and should be getting it any day now.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17983645
you will still need to prep the domain from the second cd in the R2 set, it doesnt matter if youare upgrading an actualy server, you are still upgrading the domain
0
 
LVL 2

Expert Comment

by:resourcepc
ID: 17984872
If you are adding or upgrading a Windows 2003 R2 server then you need to run adprep from the 2nd CD.  Only if it's R2.  Obviously you'll just have 1 cd if you're just adding Server 2003 SP1.  You'll soon find out if you ran adprep from the proper CD because Windows won't let you run dcpromo until you've ran adprep /forestprep and adprep /domain prep correctly.

You'll still need to run the inetorgpersonprevent.ldf script first though.  

0
 
LVL 1

Author Comment

by:cfgchiran
ID: 17985124
Thank you both very much for your responses. If I receive the media and licenses in time I hope to do the upgrade over Thanksgiving weekend. I will post any questions I have during that time, if need be, but otherwise will write at completion of project.

Thank you both once again.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17985140
cheers mate and good luck
0
 
LVL 2

Expert Comment

by:resourcepc
ID: 17990312
Good luck, I'm sure you'll do just fine.
0
 
LVL 1

Author Comment

by:cfgchiran
ID: 18078013
Thanks guys - everything went off pretty well overall.
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn about cloud computing and its benefits for small business owners.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question