Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 68
  • Last Modified:

exhange 2007, exchange 2013

We  have a resource forest set up.
 We have resource domain, where all resource, such as mailboxes, file/print servers are kept and there is user domain, where only user accounts are kept.
 User account in resource domain is disabled. Mailbox is linked to user account in the user domain. This is done by LinkedMasterAccount attribute in the user account.
 we have 1 hub and client access server ( which is also DC) and 1 mailbox server sitting on xxx. lan domain which is in resource domain.
  We have another DC which is xxx.com which have all enabled accounts.

 We have 2300 users and divded into 16 storage groups

 We are planning to upgrade to exchange 2013

 Our Action Plan

 A)      We want to keep the same resource setup.
 B)      Build separate windows server 2012 and make it DC in same resource forest set up
 C)      Replicate DC from exchange 2007 ( CAS and Hub Server) to new windows server 2012 DC as disabled AD accounts.
 D)      Install exchange 2013 on windows server 2012 and build DAG involving 3 mailbox servers
 E)      Move mailbox from exchange 2007 to 2013

 Please add to my plan if I am missing something
0
pramod1
Asked:
pramod1
  • 4
  • 4
1 Solution
 
Joshua HopkinsPresidentCommented:
Looks about right.  Just wondering if there is a reason not to go to Exchange 2016?  It does have better security features and controls.
0
 
pramod1Author Commented:
my company decided, any how 2 questions

1) what methods should I use to replicate DC which has disabled ad accounts to new DC.
2) any articles in creating legacy namespaces, or with EWS, OWA to work in middle of transition
0
 
Schnell SolutionsSystems Infrastructure EngineerCommented:
Hello pramod1,

Your design will work, but if possible (resources available) consider:
- Do not co-locate your DC with Exchange. This separation can be easily justified as far as you have +2000 mailboxes. Additionally, if you are implementing the DAG that you specified in 'E', it will be mandatory.
- If possible, use Windows Server 2012 R2 (Maybe you already mean R2 explicitly, but just in case).
- You can also go with Exchange 2016 as Joshua says, it will be better from multiple perspectives. However, in this scenario as far as you cannot transition directly from 2007 to 2016, you will need to stop at 2013 (or 2010) and then upgrade to 2016. The latter means that you will complete two transitions (AKA migrations).

In general terms your plan sounds good, of course... as you know there are many small details involved in the process.

Note: On step C, be aware that if your accounts are disabled, and you replicate them to a different DC, you will continue exactly with the same [disabled] accounts. It does not require any additional task.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
pramod1Author Commented:
thanks, but any methods I should use to replicate from disabled DC to new DC,
0
 
pramod1Author Commented:
what do you mean by do not co-locate? I didn't get it very clear
0
 
Schnell SolutionsSystems Infrastructure EngineerCommented:
Answers:

1. If your accounts are already disabled in your domain, they will continue disabled on the other DC. This is the same domain and you will have the same set of basic properties in all your DCs as far as all these properties are going to be replicated.

2. You can find general information about the virtual directories here: https://technet.microsoft.com/EN-US/library/ff952752(v=exchg.150).aspx. And instructions to manage them here: https://technet.microsoft.com/EN-US/library/ff952752(v=exchg.150).aspx#Managing virtual directories.

The specific case of how to change the virtual directory will depend on many internal details of the environment and how you handle your different servers/sites.
0
 
Schnell SolutionsSystems Infrastructure EngineerCommented:
I mean do not install together your ADDS Role (Domain Controller) with your Exchange roles.

If you want a DAG, you cannot combine a Mailbox with a DC.
Independently of using a DAG or not, if possible... consider to use  a separate server as a DC.
0
 
pramod1Author Commented:
If I set up nee DC how will it replicate from old dc
0
 
Schnell SolutionsSystems Infrastructure EngineerCommented:
When the DCPROMO process completes it ensures that all the critical data is replicated. After that, automatic replication objects are created in Active Directory to maintain the replication in two ways between the new and old servers.
0

Featured Post

Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

  • 4
  • 4
Tackle projects and never again get stuck behind a technical roadblock.
Join Now