Possible to migrate a 2008 domain to server 2003 r2?

Please tell me that it is possible to migrate a 2008 domain to a server 2003 R2 domain????

If not I'm screwed.

Also, an associate of mine seems to think doing a migration like this during work hours would not effect usage.  We would be doing an interforest migration, so it appears it would be cloning the info, not removing it.  Correct?

This is my first time doing this, bear with my stupid questions please:)

Thank you
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Please tell me that it is possible to migrate a 2008 domain to a server 2003 R2 domain????

No idea. I never heard of anyone going backwards.  If the 2008 DCs are still running at 2003 or 2003R2 Functional Levels then you don't migrate at all,...you just promote a couple of 2003R2 DCs into the domain and DCPromo the 2008's out,...which leaves behind only the 2003R2 DCs and the 2008's are gone.

so it appears it would be cloning the info, not removing it.  Correct?

Yes,...except a machine can only be joined to one Domain at a time,...so "machines" are moved,....but user accounts are "copied".

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Since this is an inter-forest migration I think this will work. Just create the trust, delegate DNS zones and then use ADMT to migrate the accounts. You will not experience any issues while doing this in office hours unless you migrate computer accounts. During migration Computers accounts are moved to the target domain, whereas for user accounts you have option to either move or copy it to the target domain. In case you run into issues you can post the errors on Experts-Exchange and we will help you out.
cas_threeAuthor Commented:
Is there documentation on creating the trusts and delegate dns zones?

The guide I was following is http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=19188.

But this is for Server 2008 R2, do the same rules apply?

Thank you
IT Pros Agree: AI and Machine Learning Key

We’d all like to think our company’s data is well protected, but when you ask IT professionals they admit the data probably is not as safe as it could be.

To directly answer the question, I second the use of ADMT...  You're basically going to create a new 2003 domain, and then "pretend" that you're consolidating two domains my migrating the resources from one to the other.  The one downside is that your new domain will HAVE TO BE a new namespace because ADMT is going to have to know about both domains separately, and you're probably going to need 2-way trusts setup (2 forest trusts)...  Migrate all the users and groups, then migrate ONE workstation and see if you can log in with the new 2003 domain user account and access everything in the new and old domain.  If so, then after hours, migrate the servers and workstations.  Plan for a long night - You're going to probably have to track down firewall rules and permissions preventing ADMT from completing on some machines...

BUT, my first question would be WHY do you want to do this?  Is it a LICENSING problem or a technical one?  Does SOMETHING not work on your 2008 domain now that it's upgraded?

Also, I'd ask what is the domain functional level?  If you haven't upgraded the domain and forest functional level beyond 2003 native, then you should actually be able to just install a 2003 domain controller into the 2008 domain, transfer all the FSMOs and then shut down the 2008 DCs, and you'll be back on 2003 again....  I'm not sure if you'll be able to cleanly DCPROMO down the last 2008 DC or not, or if you'd have to forcibly rip it out with ADSIUTIL, but as long as you can get a 2003 domain controller to JOIN the domain, then wait for the replication to occur, you should be good to go WITHOUT any migration.
One more thing about the last method I mentioned...  Tell me what your Forest and domain functional levels are, and I can probably do this in a lab, if you're not comfortable/able to do it in a lab first..  I could probably get some screenshots or more detailed steps in advance then..

Everyone is just repeating what I said the first time around  :-)
@PWindell   Sorry about that.. you're right - SOmehow I missed that one, and keyed into the ADMT message and tried to expand upon that..    I agree with you then!!  :-)
cas_threeAuthor Commented:
172pilotSteve, I do not have access to a lab to test this unfortunately.

Give me a few secs to the get the information you are asking for, if you are able to test in  lab enviroment I would be extremely greatful!
cas_threeAuthor Commented:
Ok, both forest and domain functional levels are at Windows Server 2003.  And it looks like the trusts between the domains is already set up. When right clicking the domain in AD Domains and Trusts, on the Trusts tab, they each see the other domain.

So should I follow the steps in the guide I mentioned above or is that a different guide I should follow for 2003?
Ok, both forest and domain functional levels are at Windows Server 2003.

Then forget the whole thing!!!!
You ALREADY HAVE a 2003 Domain,...the fact that the DCs are 2008 is irrelevant.
You're question was "Possible to migrate a 2008 domain to server 2003 r2?",....the Answer is,...."You already have,...and still have,....a 2003 Domain".

1. DC Promo into the Domain a couple 2003 DCs (even if only temporary).
2. DCPromo the 2008 DC out of the Domain
3. If step one was temp DCs,...now DCPromo the permanent 2003 DCs in if you were wanting to reuse the hardware the 2008 is on.
Agree w/ PWindell..   Only would add that you might have to wait for replication between each step, and/or move the FSMO roles around as you promote/demote servers - I am not sure if it will move FSMO roles automatically if you dcpromo down the DC that has them...  BUT, it's safe to just go ahead and try..

Yes. I would give it a good hour or more between steps.

DCPromo automatically moves the FSMO Roles off of the DC as it is demoted,..so no need to mess with them (unless you just want to,...but I never do).  But the CG needs to be set manually on one or all of them.

You can tweak the FSMO distribution after you are down to the final permanent DCs at the very end.
cas_threeAuthor Commented:
SATACSServerInfo.docxSo I made a list of what is at at each location, this is what I came up with, please see attached.  Is there any other critical info I need to know before starting this? I'm doing this tomorrow afternoon and extremely nervous about it since I have not done this before.

Thanks so much for all of your help on this.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.