Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Active Directory Cleanup

Posted on 2012-04-11
5
Medium Priority
?
291 Views
Last Modified: 2012-04-12
Dear Expert,

We have windows 2003 Active Directory in one forest.
Please let us know how often we should perform AD clean up and how to do it.
If we upgrade to windows 2008 AD, is the procedure the same.

Thanks,

Charlie Chen
0
Comment
Question by:chencharlie1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 10

Assisted Solution

by:George Khairallah
George Khairallah earned 500 total points
ID: 37835032
Depends what you mean by "Cleanup" ...
If you're talking about inactive user and things of that nature, there are a lot of different methods, and products to do this. There is one that I particularly like called AD Tiday : http://www.cjwdev.co.uk/Software/ADTidy/Info.html 

Look at the website, and see if this would do what you're looking to do ...
0
 
LVL 12

Assisted Solution

by:xmlmagician
xmlmagician earned 500 total points
ID: 37835057
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 500 total points
ID: 37835083
You need to do a metadata cleanup in AD 2003 if you remove a DC without demoting it first - if it fails for example.
In 2008 AD there is no need to do this - deleting the computer account from AD performs an automatic cleanup
0
 

Author Comment

by:chencharlie1
ID: 37836420
Dear Experts:
Thanks for your valuable input.
If we are moving the Domain Controller to the new facility (in different Subnet), what is the right procedure to move DC?  Some of our existing users (about 100 users) are moving to the new facility and some of them (about another 100 users) are staying where they are now?

Regards,

Charlie
0
 
LVL 2

Accepted Solution

by:
robdl earned 500 total points
ID: 37836872
In this scenario (assuming you have multiple Domain Controllers), it seems best to gracefully demote the DC (all roles will transfer automatically to the anothher DC), move it to the new location, reload the OS and promote it back to a DC. It is important that you name it differently than it's previous NETBIOS name.

You can reload the OS as 2008 and run it in 2003 Domain mode until you are ready to upgrade.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question