[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Active Directory 2000-Mixed mode

Posted on 2009-04-13
2
Medium Priority
?
281 Views
Last Modified: 2012-05-06
I am running into an issue with my Exchange 2003 server requiring my Global Catalog server to be on a Windows 2003 Server. Unfortunately, we are still using AD2000 on a Windows 2000 server. Without upgrading my domain to 2003 (which is what I think we did when we installed exchagne 2003), is it possible to make my 2003 server a domain controller and Global Catalog Server?
0
Comment
Question by:derekcook39
2 Comments
 
LVL 15

Expert Comment

by:zelron22
ID: 24130628
During the procedure for installing Exchange 2003 you would have had to extend the schema to support Exchange 2003.  Although this adds things to the 2000 schema, it isn't a full upgrade of active directory to 2003.

If you're asking if you can promote your Exchange 2003 member server to a domain controller, you can not.  At least, not without removing Exchange first.  Technically, the promotion would work, but Exchange would not.  Once Exchange is installed, you can neither promote nor demote the server.  If it's installed on a domain controller the machine has to remain a domain controller.

In order to upgrade your domain to 2003 you need to run the adprep /forestprep and adprep /domainprep off of the Server 2003 media.

I would recommend against promoting any production server to a domain controller as it will change permissions on it.  You should take a new server and promote that to 2003.  
0
 

Accepted Solution

by:
derekcook39 earned 0 total points
ID: 24130677
I am sorry. I did not make myself clear. My Exchange server is Exchange 2003 on a Win2003 server. I do not want to touch this server. The only reason I put that info in here is so that it was understood that I ran /domainprep and /forestprep.

In order to run RPC over HTTPS, Microsoft told me that I need to have a Win2003 Global Catalog server. I am installing Windows 2003 server right now. Next, I am sure I will have to run DCPROMO. Will my domain automatically be in 'mixed' mode now? Will this cause any problems? Will my AD still be 2000? I am not sure of what elase this will affect.

After the 'preps' have been run, is the next step dcpromo? Once this is a DC, I will make it a GC server. Is there anything more we need to do?
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question