[857] in winnt

home help back first fref pref prev next nref lref last post

RE: new server

daemon@ATHENA.MIT.EDU (Kerem B Limon)
Thu Jun 13 20:47:26 2002

Mime-Version: 1.0
Message-Id: <p05111b00b92ee4b7950d@[18.152.2.36]>
In-Reply-To: <000101c2130a$5f032ec0$1b031212@mit.edu>
Date: Thu, 13 Jun 2002 20:47:26 -0400
To: "'Carrie Groves'" <cgroves@mit.edu>, "Bryant C. Vernon" <bcvernon@mit.edu>
From: Kerem B Limon <kerem.limon@MIT.EDU>
Cc: Windows Partners at MIT <winpartners@mit.edu>
Content-Type: text/plain; charset="us-ascii" ; format="flowed"

Carrie,

You can do this without buying 3rd party software, but there are some 
caveats you need to consider.

First of all, in order to simplify the transfer, I'd recommend 
installing Windows NT 4 Server on your new machine, being careful to 
bring it up as a BDC in your existing domain. This way, you will get 
it to sync its SID with the PDC and replicate the SAM database. Then, 
install drivers, updates, server apps you need on the new BDC.

Next, promote the new machine to PDC, which will automatically demote 
your old BDC. Don't remove the BDC from the network or the PDC SAM 
yet. What's left is to rename your NT 4 domain to the new name you 
like, and then remove the BDC.

For this, I recommend Sean Daily's (of--what is now--Windows/.NET mag 
fame) February 1999 article, "How to Rename Your NT Domain", also 
on-line at

http://www.winntmag.com/Articles/Index.cfm?ArticleID=4784

Sean has detailed the steps very carefully. When you skim the 
article, you will notice the primary concern are trust relationships, 
server apps, and services who are closely tied to the existing domain 
name; while I am not familiar with your setup, one MIT supported such 
app is the NetShield anti-virus software (and associated service) for 
NT 4 servers. You probably have this, and should carefully follow 
Sean's instructions in correctly migrating it. He also mentions 
others like Exchange, SQL Server, IIS, SMS, etc.

Finally, you _will_ need to rejoin the workstations to the new 
domain. Typically this involves repeating the process on every 
machine, but planning ahead (before changing the domain name), you 
could create a _local_ logon script for each of the workstations that 
would join them to the new domain to execute at login (albeit with 
cached credentials at that time since your old domain will be gone, 
hence _local_ script). For details, see the John Savill's 
Windows2000FAQ article at

http://www.windows2000faq.com/Articles/Index.cfm?ArticleID=13524

Note he describes how you can pre-configure the machine accounts such 
that normal users can join the domain without admin rights. They 
will, of course, need to reboot, which could also be scripted. With a 
little tweaking, you can use Mark Russinovich and Bryce Cogswell's 
Sysinternals utility PsShutdown. See

http://www.sysinternals.com/ntw2k/freeware/pstools.shtml
http://www.sysinternals.com/ntw2k/freeware/psshutdown.shtml

For other legacy (Windows 9x, Me) workstations, you might have to 
rejoin manually.

This should be able to get you going where you want. Since Sean's 
instructions involve shutting down a lot of domain services, I 
recommend doing this over a weekend or at least overnight to minimize 
impact on users; and order pizza should something go wrong :)

Regards,
Kerem

PS: In case you need it, the Sysinternals utility NewSID has the 
ability to replicate/generate SIDs

http://www.sysinternals.com/ntw2k/source/newsid.shtml

But since you pre-join the new machine to your existing domain, the 
SIDs for the DCs are sync'd and you shouldn't need it.

Kerem B. Limon
Consultant, Support Process
MIT Information Systems
Computing Help Desk / Software Release Team / Wireless Deployment Team


At 14:44 hrs -0400 02/06/13, Bryant C. Vernon wrote:
>Hi Carrie,
>
>You want the bad or the bad news?
>
>Unfortunately, all the domain computer IDs and user IDs contain the
>domain ID as well, so you would not be able to transfer them easily
>(i.e. without some serious hacking or tool)to a new domain. From my
>brief research into the problem, I have found a tool that would enable
>you to do the user transfers (including passwords) for a fairly good
>price, considering how many man hours it would take to redo everything
>manually. The tool is called Ideal Migration, and you can read more
>about it at the following URL: http://www.pointdev.com/IM_descr_us.htm.
>
>I am sure there are other tools available, and you may want to look into
>them for comparative shopping purposes.
>
>All the Best,
>-Bryant
>
>
>-----Original Message-----
>From: Carrie Groves [mailto:cgroves@MIT.EDU]
>Sent: Thursday, June 13, 2002 2:11 PM
>To: ntpartners@mit.edu
>Subject: new server
>
>Hi,
>
>I need to replace an NT domain controller with a newer model machine. I
>plan on changing domain names but all the computers and users who
>connect
>to it will be the same. Does anyone know of an easy way to transfer the
>computer and user IDs to the new domain controller? Or do I have to
>recreate them all?
>
>Thank you,
>
>Carrie Groves
>Network Administrator, SSIT
>Massachusetts Institute of Technology
>77 Massachusetts Ave 12-172
>Cambridge, Ma 02139
>(617)258-0714
><mailto:cgroves@mit.edu>


home help back first fref pref prev next nref lref last post