Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 16, 2004

Windows Server 2003 Installation and Domain Consolidation


RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

I recently upgraded a client's network. The client has two offices--one in Los Angeles and one in New York--which, prior to the upgrade, weren't connected. The network upgrade plan included establishing a VPN to connect the two offices; setting up two new Windows 2003 servers (one serving as a file server and one running Microsoft Exchange Server 2003) in Los Angeles; and consolidating two Windows 2000 domains. Before the project began, each office was in a separate Win2K domain. Each domain was in native mode, and no active Windows NT 4.0 domain controllers (DCs) were on the network. Because the New York domain had more users (100), I decided to consolidate the Los Angeles domain (20 users) into the New York domain.

As you know, you need to run the Adprep utility from the Windows 2003 CD-ROM to prepare the Win2K domain before you can add the first Windows 2003 DC. Unfortunately, the New York domain had some problems that I had to clean up before I could introduce the Windows 2003 DC on the network. The New York domain had a DC that existed in Active Directory (AD) but was no longer active. Because the DC was no longer active, I couldn’t run DCPromo to demote this computer from a DC to a member server. I had to follow the steps in the Microsoft article "How to remove data in Active Directory after an unsuccessful domain controller demotion" (http://support.microsoft.com/?kbid=216498) to manually remove the DC entries from AD. After I removed the DC, I was able to run Adprep on the New York Win2K DC. Because I was in Los Angeles and the DC was in New York, I decided to share the \i386 directory on the Windows 2003 CD-ROM so that it was accessible to the New York DC. I used Win2K Terminal Services to connect to the New York DC, then ran Adprep. I was then able to run Dcpromo on the Windows 2003 server to make it a DC.

I installed Exchange 2003 on the new Windows 2003 server into the New York Exchange Site (New York was already running Exchange 2000), but into a separate Los Angeles Administrative group. That means the New York and Los Angeles locations can be managed by separate workgroup administrators. The Los Angeles office was running a UNIX-based email system with Eudora as the email client. Because the Los Angeles site had only 20 users, I manually created new accounts for them in the New York domain. I took the following steps to complete the migration:

1. I installed Microsoft Office Outlook 2003 on each Los Angeles workstation.
2. I transferred the existing Eudora mail to the Los Angeles Exchange server.
3. I transferred file server share information from the old Win2K server to the new Windows 2003 server.
4. During the transfer of the file server information, the workstations left the old Los Angeles domain and joined the consolidated New York domain.

We copied the Outlook 2003 setup files to a Windows 2003 share to make installation easier. Unfortunately, no one from the Win2K domain was able to access the share on the Windows 2003 server. Windows 2003 by default has Server Message Block (SMB) signing enabled. I still needed the Los Angeles workstations to belong to the Win2K domain, and I wasn’t ready to have them join the consolidated New York domain until I was comfortable that the email was working properly. To allow users from the Los Angeles domain to access the new Windows 2003 server in the New York domain, I temporarily disabled SMB signing on the Windows 2003 server. To do so, I set the following registry subkeys to the specified values:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters\enablesecuritysignature to 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters\requiresecuritysignature to 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters\enablesecuritysignature to 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters\requiresecuritysignature to 0

These settings permit the computers in the remote domain to access shares on the Windows 2003 server. Of course, when the Los Angeles workstations join the New York domain, I'll change the servers to require SMB signing.

Outlook 2003 has a great import utility to import Eudora mailboxes into Outlook, so users didn't lose any email messages. I installed Outlook on each workstation, verified that each workstation had the most recent service packs and patches, then moved the user's mail to Outlook. After importing the mail, I tested the system for a week, then moved the file shares to the new server and configured each workstation to join the consolidated New York domain.

After the workstations joined the New York domain, I noticed that the workstations behaved differently. I installed Group Policy Management Console (GPMC) on the Windows 2003 server and looked at the Group Policy settings. Unfortunately, the Default Domain Policy was modified to point the workstations to a Software Update Services (SUS) server in New York and to synchronize off-line files with the New York Server. This setup would cause serious stress on the WAN link between Los Angeles and New York, so I removed these Group Policy settings from the Default Domain Policy, created separate policies, and linked them at the site level. In general, I suggest that you don't modify the Default Domain Policy and instead create separate Group Policy Objects (GPOs). This approach gives you more flexibility when linking GPOs. After I made the Group Policy changes, I transferred the users' data to the new server. Finally, I installed SUS on the Los Angeles server so that the workstations will automatically receive the latest patches.

Tip
Microsoft recently updated its to Knowledgebase search engine. I think the changes make it more difficult to search for articles because the search engine by default only searches Knowledgebase articles related to a specific product. Depending on the nature of the problem, you might not know what product to specify when performing a search. This update is probably in preparation for Microsoft’s new search engine, which will compete with Google. You can still access the Knowledgebase through the link http://support.microsoft.com/search/?adv=1. Then search for all products by clicking Specify a product or version, then clicking All products. However, I still find the new search engine difficult to use. The next time you need to find something on the Microsoft site, go to www.google.com/microsoft and just type in the relevant keywords. In addition to articles, you’ll find other relevant sources to help you solve your specific problem.

End of Article



Reader Comments
Why use registry to change SMB signing options? It is better to change options through group policy object od local security policy?

Anonymous User November 16, 2004 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...

More fun TechEd 2005 Resources

Kevin points out some more TechEd resources ...


Active Directory (AD) Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

User Provisioning and Access Control

Managing Unix/Linux with Microsoft System Center Operations Manager 2007 Cross Platform Extensions Beta

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Microsoft Exchange & Windows Connections event returns to Las Vegas Nov 10 - 13
Connections returns to Las Vegas for this exciting event where each attendee will receive SQL Server 2008 standard with 1 CAL. Co-located with Microsoft ASP.NET, SQL Server, and SharePoint Connections with over 250 in-depth sessions.

Free Online Event! Virtualization:Get the Facts!
Register now and attend this free, live in-depth online conference on November 13 and 20, 2008, produced by Windows IT Pro. All registrants are eligible to receive a complimentary one-year digital subscription to Windows IT Pro (a $49.95 value)!

Check Out Hyper-V Video on ITTV
Watch Karen Forster's interview on Hyper-V's performance on ITTV.net.

Ease Your Scripting Pains with the Flexibility of PowerShell!
Join MVP Paul Robichaux on December 11, 2008 at 11:00 AM EDT as he equips you with PowerShell basics in 3 introductory lessons, each followed by a live Q&A session—all on your own computer!

Latest Advancements in SSL Technology
There are a variety of different kinds of SSL to explore to ensure customer data is kept confidential and secure. In this paper, we will discuss some of these SSL advances to help you decide which would be best for your organization.

PASS Community Summit 2008 in Seattle on Nov 18-21
The don’t-miss event for Microsoft SQL Server Professionals. Register now and you’ll enjoy top-notch Microsoft and Community speakers and more.



Speed Up Your PC!
Try Diskeeper 2008 with InvisiTasking Free Now!

Get Protected -- Data Protection Manager 2007
Protect your virtualized environment with Data Protection Manager

Agent-less Remote Backup Service, Free 30 Day Trial
Award winning remote backup service at a competitive price with no min GB/month. Sign up Now!

ScriptLogic Cartoon Caption Contest
Submit your caption and you will be entered to win $198.42

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Maximize Your SharePoint Investment: Get Your Data Moving
Watch this web seminar now to learn how to maximize your SharePoint investment! Join us as we take a look at the complex business of securing, accessing and managing vast amounts of information in a global network and various ways to get your data moving.

List Your Products in Our Technology Resource Directory
Don't miss the chance to post your free listing in this comprehensive directory for IT and developer professionals, powered by Windows IT Pro. But hurry! Deadline ends Oct. 9.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing