Solved

Need to remove un-necesary lower level AD Child Domain as part of new server install/migration.

Posted on 2008-06-12
5
259 Views
Last Modified: 2010-03-05
We have a W2003 AD Domain "city.local" and a child domain of "library.city.local"
The Domain controller for "Library.city.local" is a W2000 AD system - that is being replaced with a W2003R2 system.
The parent Domain is W2003.
It has been decided that the child domain is not required.
We want to find the best method to eliminate the child domain - to minimize the effect on several PC systems
and a Terminal Server that uses a GPO lockdown. A new terminal server will also be introduced.
Wish to transfer as many objects (Computer accounts, users, policies) as possible trying to minimize effort.
There are several PC's that use a hardware lockdown system and GPO lockdowns.
We can do it the hard way - move PC's to workgroup, export AD accounts,etc but looking for time saving steps.
0
Comment
Question by:BobPrinceExpert
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 13

Expert Comment

by:martin_babarik
ID: 21772981
Hi, I'd say this article is the info you are looking for:
http://support.microsoft.com/kb/326480/en
Let me know if there is something you want to be explained further.
Regards

Martin
0
 
LVL 7

Accepted Solution

by:
ManicD earned 500 total points
ID: 21777574
you may also want to lookup information about "movetree" to move AD objects between domains.

This seems like a several step process, first upgrade to 2003, second move the objects across, demote Domain controllers for the child domain, then promote them to the parent domain(if required)
0
 
LVL 1

Author Comment

by:BobPrinceExpert
ID: 21793389
We will look in to "movetree" as that sounds like it fit's in to what we plan to do.
Basically since we are installing new servers - we will set them up in the parent domain.
THen sounds like we can use "movetree" to move over objects that we still need.
In some cases - we have some generic users - so probably recreate them - but move over GPO's,etc.
Thanks for the tip.
Bob
0

Featured Post

Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Want Win 10 Pro to search like Server 2010 or 2012 27 114
NTP time source for DC 3 52
Changing logon server question 5 67
Removing Exchange 2003 3 17
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question