From: jjj0923 on

Philip:

you wrote:

>
> Now run DCPromo again on the box to make it a *new* DC in a *new* Forest
> in
> a *new* Domain. This has nothing to do with,...and is not related in
> any
> way to,...the original Domain.
>

ok - no problem I'm fine with this

>
>
> Do DNS Zone Transfers between this DC and the DC of the old Domain
> (doesn't
> matter which DC, just pick one). Do this in both directions so that
> both
> Domains are fully aware of the opposite Domain's Zone contents.
>

why? - the dns on these boxes is caching only. I have no zones defined
on my domain controllers.

>
> Create a Full Two-Way Trust between the two Domians
>

How do I do this?

> Add the Domain Admins Group to the Administrators Group of the opposite
> Domain,...do this in both directions.
>
> Add the Domain User Group to the Users Group of the opposite
> Domain,...do
> this in both directions
>
> Download and use the ADMT Tool to migrate Objects from one Domain to
> the
> other. Do this *after* reading the Documentation for ADMT,...and only
> after
> you really understand what you read. There are only a very few limited
> ways to do it *right*,...and a whole bunch of ways to do it wrong.
>

thanks I have all the documentation for the admt tool.

ps: would you be interested in doing this on a contract basis remotely
through logmein?

how long should this take?


--
jjj0923
------------------------------------------------------------------------
jjj0923's Profile: http://forums.techarena.in/members/213984.htm
View this thread: http://forums.techarena.in/windows-server-help/774222.htm

http://forums.techarena.in

From: Phillip Windell on
"jjj0923" <jjj0923.4a4vlb(a)DoNotSpam.com> wrote in message
news:jjj0923.4a4vlb(a)DoNotSpam.com...
> why? - the dns on these boxes is caching only. I have no zones defined
> on my domain controllers.

No they can't be. You have to have full AD integrated DNS Zones to even
have Active Directory in the first place. *All* DCs should have DNS running
Full AD Integrated Zones and would replicate between each other (both
directions). Can you have a DC without DNS if it uses "another" machine for
DNS?,....yes,....should you?,....no,....will it probably become a
disaster?,....probably.

>> Create a Full Two-Way Trust between the two Domians
>>
>
> How do I do this?

It should be in the ADMT Docs. If not it is easily googled from Ms's site.

> thanks I have all the documentation for the admt tool.
>
> ps: would you be interested in doing this on a contract basis remotely
> through logmein?
>
> how long should this take?

Depends on how big the environment is and how big a mess you have,...and how
complex the Business Applications are with moving, installling, sharing,
etc. There is no exact answer for this.
Sometimes it is better to cleanup and fix what you have then to create a new
domain and do a migration,...it just depends on how screwed up the original
is

I've been working on one for 5 months and it isn't quite finihsed yet,...but
they don't always take that long.

You cannot do this remotely,...it has to be done in person with feet on the
ground and hands on the keyboards. You would need to find a local service
company (consultant?) to come in there and help if you can't do it yourself.
There is only a few ways to do it "right" and a gazzillion ways to screw it
up.


--
Phillip Windell

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------