Solved

Active Directory Cleanup

Posted on 2012-04-11
5
278 Views
Last Modified: 2012-04-12
Dear Expert,

We have windows 2003 Active Directory in one forest.
Please let us know how often we should perform AD clean up and how to do it.
If we upgrade to windows 2008 AD, is the procedure the same.

Thanks,

Charlie Chen
0
Comment
Question by:chencharlie1
5 Comments
 
LVL 10

Assisted Solution

by:George Khairallah
George Khairallah earned 125 total points
ID: 37835032
Depends what you mean by "Cleanup" ...
If you're talking about inactive user and things of that nature, there are a lot of different methods, and products to do this. There is one that I particularly like called AD Tiday : http://www.cjwdev.co.uk/Software/ADTidy/Info.html

Look at the website, and see if this would do what you're looking to do ...
0
 
LVL 12

Assisted Solution

by:xmlmagician
xmlmagician earned 125 total points
ID: 37835057
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 125 total points
ID: 37835083
You need to do a metadata cleanup in AD 2003 if you remove a DC without demoting it first - if it fails for example.
In 2008 AD there is no need to do this - deleting the computer account from AD performs an automatic cleanup
0
 

Author Comment

by:chencharlie1
ID: 37836420
Dear Experts:
Thanks for your valuable input.
If we are moving the Domain Controller to the new facility (in different Subnet), what is the right procedure to move DC?  Some of our existing users (about 100 users) are moving to the new facility and some of them (about another 100 users) are staying where they are now?

Regards,

Charlie
0
 
LVL 2

Accepted Solution

by:
robdl earned 125 total points
ID: 37836872
In this scenario (assuming you have multiple Domain Controllers), it seems best to gracefully demote the DC (all roles will transfer automatically to the anothher DC), move it to the new location, reload the OS and promote it back to a DC. It is important that you name it differently than it's previous NETBIOS name.

You can reload the OS as 2008 and run it in 2003 Domain mode until you are ready to upgrade.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now