Solved

W2K3 Forest Trust roll-back

Posted on 2013-02-01
7
374 Views
Last Modified: 2013-02-21
Hi - we are in the process of merging two companies and looking at implementing a 2 way forest trust.

Both companies are operating AD at 2003 functional level. Our DC's are running on server2008R2 in a vmware environment.

Can anyone offer some advice as to a roll-back plan? We are confident with the steps involved to establish the forest trust and have been doing some tests in an isolated environment but not sure of what to expect in a worst case scenario?

Thanks
Shaughn
0
Comment
Question by:snymas
7 Comments
 
LVL 119

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 250 total points
ID: 38843599
In a worse case scenario the trust relationship would not establish, and would be broken, just as the relationship is now.

As with any change to production environment , I would recommend a full backup (not a vmware snapshot) or ALL DCs.
0
 
LVL 10

Expert Comment

by:Pramod Ubhe
ID: 38843637
Yes, the worst case would be the trust won't work as expected.
For roll back, you just need to revert the steps that will be used to create the trust.
0
 
LVL 10

Expert Comment

by:millardjk
ID: 38846672
Forest trusts are a form of credentialling; you're exchanging tokens that permit one AD forest to automatically authenticate users in the other forest to access resources.

Rollback is easy: delete the authorization in forest A and forest B users can no longer access its resources.
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 

Expert Comment

by:prosynexperts
ID: 38854847
thank You for your comments. If the forest trust does not stablish properly, could we have any big authentication issues? We might need to go back to our AD backups and restore all DCs across all sites. Is that correct?
0
 
LVL 10

Expert Comment

by:millardjk
ID: 38855828
If you have problems establishing the trust, you will have issues with users in forest A accessing resources in forest B (and vice-versa). Unless you have inherent issues in ether forest to begin with (you've run a dcdiag to see how healthy they are, right?), you won't have any intra-forest issues after attempting to set up the trust--succeed or not.
0
 

Author Comment

by:snymas
ID: 38857470
Hi millardjk, thank you for all your replies.
Yes, you are right. DCdiag shows no errors. Server healthy on my end. Not sure our sister company. I'll ask them if they have run it fo reasurance as I know they were having issues. I have advised them to take AD backups from all their DCS. I am just concerned as their systems had a couple of major glitches lately. If the trusts are not sucessful we can always delete the authorization, right?
Just one more thing, if the trust is sucessful PC's will get a scrolldown menu with the second domain/forest, right?
Is there anything else we would need to do?
Will exchange synch contacts, GAL?
Many thanks
0
 
LVL 10

Accepted Solution

by:
millardjk earned 250 total points
ID: 38857497
1) if not successful, you can delete the trusts and you're back to where you are today
2) if the sister co is having issues, trust could link up, but your side could have issues accessing them while they access your side w/o probs [most likely failure scenario]
3) should have dropdown populated, but if not, can still manually enter domain\user or user@domain and login
4) exchange is a completely different animal, and I can't begin to tell you how it would work, especially w/o knowing the version of Exchange. In short, that's a different question for Experts Exchange.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Stacked switch question 7 40
Do hyper-v and VMware clash 4 82
VMWare fails to boot after update 15 37
Deploying DAG on Exchange 2013 Standard edition 10 52
This article will show you how to create an ISO CD-ROM/DVD-ROM image (*.iso), and MD5 checksum signature, for use with VMware vSphere Hypervisor 6.5 (ESXi 6.5). It's a good idea to compare checksums, because many installations fail because of a corr…
This article outlines why you need to choose a backup solution that protects your entire environment – including your VMware ESXi and Microsoft Hyper-V virtualization hosts – not just your virtual machines.
Teach the user how to configure vSphere clusters to support the VMware FT feature Open vSphere Web Client: Verify vSphere HA is enabled: Verify netowrking for vMotion and FT Logging is in place or create it: Turn On FT for a virtual machine: Verify …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question