Solved

how do you create a work group when you already have a domain

Posted on 2008-06-25
12
197 Views
Last Modified: 2013-12-04
I have windows 2000 running as a primary domain controler with dns activated.  I specify a static ip address and I have a number of other machine running xp pro and vista business connecting to each other (also with static ip addresses) which is working fine.

I would like to setup a workgroup so that a number of xp and vista home macines can be seen on the network but I do nto want to disrupt my domain or break teh connections that I already have.  is this possible?

how do I setup a workgroup, and how do I connect to this workgroup if I am a member of the primary domain (ie how does the xp/vista pro machines connect to the xp/vista home machines and vice versa)

can you have a workgroup and a domain under the same umbrella (so to speak) if not what are my simple alternatives to acheiving my desired result?

thanks in advance
0
Comment
Question by:CiaranG
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 4
12 Comments
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21870595
You can configure a workgroup by simply configuring a unique workgroup name for the machines in question.  Domain-joined users will need a local username/password to access resources on any workgroup-joined machines, just like other workgroup members.

This will not "disrupt" anything, but I fail to see how it does anything but create additional complexity for your environment. Machines in a workgroup environment cannot be managed via Group Policy, and do not enjoy the centralized authentication service provided by AD.
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 21870618
Configure all computers to use same WINS server.
It may be necessary to also activate NetBIOS over TCP/IP (WINS-tab in TCP/IP-settings).
Configure the standalone clients to use a common name for its workgroup ('computer name'-tab under 'system properties').

Why are you using static IP configuration on the clients? DHCP will simplify when nead to change any TCP/IP-setting (WINS-server, DNS-server etc).

0
 

Author Comment

by:CiaranG
ID: 21872508
LauraEHunterMVP:
ho do I create this workgroup, and if this is too complex ho would you suggest that I acheive me goal?
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 21873152
You configure the clients through right-click 'My computer'->Properties->'Computer name'-tab. Click on 'Change'-button and fill in name for the workgroup in the input field.
As Laura said, it's better to join the clients to the domain, but you nead to upgrade the Home-OS to Pro-version to be able to join the domain.
0
 

Author Comment

by:CiaranG
ID: 21873208
HenJoh
I will not be in a position to upgrade the machines to the Pro versions so the workgroup is the way forward

you have described how to connect to a workgroup - i need to know how to create a workgroup!
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21873233
You will create a workgroup by following henhoj's comment 21873152 - simply configure each machine in question with the same workgroup name.
0
 

Author Comment

by:CiaranG
ID: 21873259
Laura
so on each of the machiens I just enter in the same work goup name - I do not need to configure this workgroup on the server.  is this correct?
can the machines who are on the domain also connect to the workgroup?
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 21873457
The computers are either member of a domain or a workgroup.
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21873616
There is no "server" configuration involved in creating a workgroup; that's what makes it a workgroup.
0
 

Author Comment

by:CiaranG
ID: 21873647
is there any way that the home machines could see the machines on the pro domain - and vice versa?  what do you recommend other than upgrading the home machines
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21873677
This is a separate question, has nothing to do with workgroup vs. domain.  As long as you have name resolution in place as described earlier, you can share files/folders on any computer.  Domain-joined computers can secure files/folders using AD accounts; workgroup-configured computers will need to configure a local user account on each computer that is hosting resources.
0
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 350 total points
ID: 21873701
Use the same WINS-server. Enable NetBIOS over TCP/IP

The computers outside of the domain will see the computers in the domain, but propably not access any resources when they're not authenticated to the domain. The same thing the other way.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question