Solved

Update Child Domain to 2008 from 2003 concerns

Posted on 2011-03-16
7
245 Views
Last Modified: 2012-05-11
Hello
Within my company we now run 2008 at the top of the Forest, then within that forest sits our parent domain, who are running 2003 currently, and then we are a child domain of theirs and we run a 2003 domain as well.

The question is, been as at forest level it is 2008, can I update my domain to 2008 also, even though my parent domain is on 2003? Or does my parent domain also have to be 2008 before I upgrade?
0
Comment
Question by:RPUKsupport
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 15

Expert Comment

by:JBond2010
ID: 35146202
You need to run Forest/Prep - Domain/Prep by your comment you have already done this.

When you upgrade all the Server to 2008, you can then raise the Forest and Domain Functional Levels to 2008.
0
 
LVL 15

Expert Comment

by:JBond2010
ID: 35146228
It is also worth noting that in order to raise these levels you need to be a member of the Domain Admins group or Enterprise Admins group. You can do this from Active Directory Domains and Trusts.
0
 
LVL 10

Expert Comment

by:Muzafar Momin
ID: 35146271
you can update the domain to 2008 it will not impact
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 6

Expert Comment

by:Tonypeswani
ID: 35146275
0
 

Author Comment

by:RPUKsupport
ID: 35146279
Thanks, I know how to do that part, I was unsure of the local domain level as I am the child domain of a 2003 domain if that makes sense.
Sounds like all I need to do is get a couple of 2008r2 servers and go from there?
0
 
LVL 15

Accepted Solution

by:
JBond2010 earned 250 total points
ID: 35146288
Once you have raise the Domain and Forest functional levels there is no going back. So, make sure you have access everything to prepare for the upgrade.

Also, know which Domain Controllers hold the FSMO Roles. This is very important. There are 5 FSMO Roles, The Schema Master Role, Domain Naming Master Role, the Infrastructure Master Role, the RID Master Role and PDC Emulator Role.

Make sure to transfer these Roles to a Windows Server 2008 Domain Controller.

Because, you have a child Domain you will have 3 FSMO Roles - The RID Master, the Infrastructure Master and the PDC Emulator. These 3 roles are Domain Wide. The Schema Master and the Domain Naming Master are Forest Wide and they reside on the first Domain Controller installed in the Forest.
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 250 total points
ID: 35146664
Domain functional level depends on level of OS running in it & forest functional level depends on DF.L
You raise the DFL when all the OS of DC(not to confuse with memberserver, in windows 2003 domain you can run member server with windows 2000)is at same level.
You need to run adprep32.exe /domainprep on child domain & still you can introduce windows 2008 DC with FFL set to windows 2008.

Take a look at my artcile.
http://awinish.wordpress.com/2011/03/04/upgrade-from-windows-2003-to-20082008-r2-domain-controllers/
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question