Windows NT to 2000/XP Migration at SLAC

Slides:



Advertisements
Similar presentations
Establishing an OU Hierarchy for Managing and Securing Clients Base design on business and IT needs Split hierarchy Separate user and computer OUs Simplifies.
Advertisements

Security in the NT Environment at SLAC HEPNT at CERN December 4, 1998 Bob Cowles, SLAC.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
CS603 Active Directory February 1, 2001.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
ASU Windows 2000 AD Environment OU Presentation. Agenda OU structure Domain Admin Support OU Administrator Control/Access Migration from NT to W2K OU.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
1 SLAC Windows Migration Bob Cowles Presented for the SLAC Windows Migration Project HEPNT, Fermilab October 24, 2002.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Understanding Active Directory
11 WORKING WITH COMPUTER ACCOUNTS Chapter 8. Chapter 8: WORKING WITH COMPUTER ACCOUNTS2 CHAPTER OVERVIEW Describe the process of adding a computer to.
A centralized system.  Active Directory is Microsoft's trademarked directory service, an integral part of the Windows architecture. Like other directory.
HalFILE 3.0 Active Directory Integration. halFILE 3.0 AD – What is it? Centralized organization of network objects and security – servers, computers,
Chapter 7 WORKING WITH GROUPS.
Update to TIMGroup January Outline Introduction Where are we now? Where are we going? What can be done to prepare? What are the options?
Module 1: Introduction to Administering Accounts and Resources
Session 6 Windows Platform Dina Alkhoudari. Learning Objectives What is Active Directory Logical components of active directory Physical components of.
Chapter 4 Windows NT/2000 Overview. NT Concepts  Domains –A group of one or more NT machines that share an authentication database (SAM) –Single sign-on.
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
8.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 8: Introducing Computer Accounts.
Designing Active Directory for Security
Designing Group Security Designing security groups Designing user rights.
Windows 2000 Operating System -- Active Directory Service COSC 516 Yuan YAO 08/29/2000.
Module 13: Designing Active Directory Migrations in Windows Server 2008.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
Active Directory Operations Masters. Overview  Active Directory updates generally multimaster Changes can be made on any DC  Some exceptions — single.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Two Installing and Configuring Exchange Server 2003.
Active Directory Harikrishnan V G 18 March Presentation titlePage 2 Agenda ► Introduction – Active Directory ► Directory Service ► Benefits of Active.
1 Windows 2008 Configuring Server Roles and Services.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Module 1: Implementing Active Directory ® Domain Services.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
W2K Integration in the Kerberos5 based AFS cell le.infn.it Enrico M. V. Fasanelli I.N.F.N. – Sezione di Lecce Catania,
Module 3 Creating Groups and Organizational Units.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
DNS DNS overview DNS operation DNS zones. DNS Overview Name to IP address lookup service based on Domain Names Some DNS servers hold name and address.
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
OVERVIEW OF ACTIVE DIRECTORY
1 Chapter 13: RADIUS in Remote Access Designs Designs That Include RADIUS Essential RADIUS Design Concepts Data Protection in RADIUS Designs RADIUS Design.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
11 UPGRADING AND MIGRATING TO WINDOWS SERVER 2003 Chapter 12.
Module 3: Managing Groups. Overview Creating Groups Managing Group Membership Strategies for Using Groups Using Default Groups.
HNC COMPUTING - Network Concepts 1 Network Concepts Network Concepts Network Operating Systems Network Operating Systems.
7.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 7: Planning.
Module 1: Introduction to Windows 2000 and Networking.
MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition (70-294) Chapter 1: Overview of the Active.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
9.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 9: Planning.
W2K Migration Experiences Jack Schmidt Windows Policy Committee.
Essential Services Lesson 5. Objectives Naming Resolution In today’s networks, you assign logical addresses, such as with IP addressing. Unfortunately,
Overview of Active Directory Domain Services
O365 & AZURE ADDS Mladen Baranek, Miadria
Implementing Active Directory Domain Services
IMPLEMENTING NAME RESOLUTION USING DNS
Module 1: Introduction to Administering Accounts and Resources
100% Exam Passing Guarantee & Money Back Assurance
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
MCSA VCE
Active Directory Stored collection of information about objects
Unit 3 NT1330 Client-Server Networking II Date: 1/6/2016
Unit 7 NT1330 Client-Server Networking II Date: 7/26/2016
Network Administration
Microsoft Windows Server 2003 Active Directory Infrastructure
ASU West Windows 2000 Environment
Microsoft Active Directory
Designing IIS Security (IIS – Internet Information Service)
Unit 6 NT1330 Client-Server Networking II Date: 7/19/2016
Presentation transcript:

Windows NT to 2000/XP Migration at SLAC Dennis Wisinski SLAC Computing Services 16 April 2002 HEPiX-HEPNT April 2002

Overview Current NT configuration W2K infrastructure design Client migration

Current NT configuration Single master domain design Twelve resource domains scattered among departments One hidden domain (private network)

W2K infrastructure design DNS design Tree, domain, and OU design Domain controller placement Native vs. mixed mode Exchange 2000 Our “hidden” domain

DNS design Current BIND DNS will delegate control of a new domain win.slac.stanford.edu to our new Windows DNS Will run as AD integrated zone to enforce authentication of machines before allowing them to update DNS

DNS design (cont.) IIS web servers will also have entries in our BIND DNS server to prevent URLs from breaking Need to write scripts to keep DNS synchronized with our ORACLE “database of record” for computers

Tree, domain, and OU design Single tree/single domain chosen Keep simple to simplify administration Use departmental Organizational Units for delegation of authority to departmental administrators Other OUs may be needed (divisions, experiments, etc.)

Domain controller placement Business Services Division subnet Stanford Synchrotron Radiation Lab subnet Main SLAC network Possible “air gap” during intrusion

Native vs. mixed mode Plan to go to native mode from start Two-way trust between old NT4 master domain and new Win2k domain Add NT4 SID information to W2K user account history with ClonePrincipal or similar tool to assure access to NT4 domain resources

Native vs. mixed mode (cont.) Allows early testers to easily “live” in new Win2K environment Allows incremental migration of servers and user workstations Migration is easily reversible for individual users if there is a problem Use ReACLing tools as needed