1183 Windows 2003 Migration Strategies Gary L. Olsen Consultant Americas Escalation Team HP Services

Slides:



Advertisements
Similar presentations
Microsoft Active Directory
Advertisements

Active Directory: Beyond The Basics
COMP091 OS1 Active Directory. Some History Early 1990s Windows for Workgroups introduced peer-to-peer networking based on SMB over netbios (tcp/ip still.
AD Child Domains By: Joan Carter 05/29/2003. Who can bring up a child domain in AD.ASU.EDU?  Campus/college/VP level units  Considerations: Is there.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 1: Introduction to Active Directory.
70-297: MCSE Guide to Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure Chapter 2: Developing the Active Directory.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Introduction to Active Directory
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
By Rashid Khan Lesson 4-Preparing to Serve: Understanding Microsoft Networking.
Chapter 4 Introduction to Active Directory and Account Management
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Chapter 7 WORKING WITH GROUPS.
Vikram Thakur Introduction to Active Directory Structure.
Getting off NT4… Raj Natarajan National Technology Specialist.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 10: Configuring and Maintaining the Active Directory Infrastructure.
Active Directory Implementation Class 4
Module 1: Installing Active Directory Domain Services
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
(ITI310) SESSIONS : Active Directory By Eng. BASSEM ALSAID.
BZUPAGES.COM An Introduction to. BZUPAGES.COM Introduction Large corporations today face the following problems Finding a certain file. Seeing everything.
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 7: Active Directory Replication.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Chapter 4 Windows NT/2000 Overview. NT Concepts  Domains –A group of one or more NT machines that share an authentication database (SAM) –Single sign-on.
Module 6: Designing Active Directory Security in Windows Server 2008.
Chapter 7: WORKING WITH GROUPS
Designing Active Directory for Security
Active Directory Boundaries - Purpose Replication Boundaries Security Boundaries.
Module 13: Designing Active Directory Migrations in Windows Server 2008.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
Active Directory Operations Masters. Overview  Active Directory updates generally multimaster Changes can be made on any DC  Some exceptions — single.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
DEP313 Active Directory Restructuring with ADMT v-2
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Two Installing and Configuring Exchange Server 2003.
Module 7 Active Directory and Account Management.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
Module 11: Read-Only Domain Controllers. Overview Describe the Read-Only Domain Controllers role Use Read-Only Domain Controllers.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
V1.1 Mike Brannigan Enterprise Strategy and Senior Consultant In Place Windows NT 4.0 Upgrade.
Operations Master / FSMO Roles in Active Directory : Suhail Ashfaq Butt.
NT4 SP4 Security Jack Schmidt - Fermilab
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Introduction to Active Directory Domain Services
Module 1: Implementing Active Directory ® Domain Services.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
MCITP Guide to Microsoft Windows Server 2008 Enterprise Administration (Exam #70-647) Chapter 1 Designing Active Directory Domain Services.
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
Installing a Domain Controller
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Integration and Migration: Making the Move to Windows Server 2003 Michael Leworthy Windows Server Product Manager Microsoft Australia.
Hussain Ali Department of Computer Engineering KFUPM, Dhahran, Saudi Arabia Active Directory.
11 UPGRADING AND MIGRATING TO WINDOWS SERVER 2003 Chapter 12.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Module 8: Planning for Windows Server 2008 Active Directory Services.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
Migrating to Windows Server 2003 Active Directory.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Planning an Active Directory Deployment Lesson 1.
Overview of Active Directory Domain Services
Active Directory Replication (Part 1) Paige Verwolf Support Professional Microsoft Corporation © 1999 Microsoft Corporation. All rights reserved.
Examining a Windows NT Infrastructure (2)
Microsoft Active Directory
Presentation transcript:

1183 Windows 2003 Migration Strategies Gary L. Olsen Consultant Americas Escalation Team HP Services

Windows 2000: Active Directory Design and Deployment Author: Gary Olsen Publisher: New Riders ISBN:

Agenda  Migration Roadmap and Planning  Migration Plan: Upgrade vs Restructure  Functional Levels in Windows 2003  Moving from NT4 to Windows 2003  Moving from Windows 2000 to Windows 2003  Tools

HP’s Roadmap to a successful Windows 2000, 2003 infrastructure Current Design review Current Design review Plan & Design Assessment Manage Implementation Pilot Proof of Concept Proof of Concept Support

The Migration Plan  In-Place Upgrade – Upgrade NT PDC to Windows 2003 Interim Mode No W2k DCs Prepare for the “Pile-On” problem Convert to Windows 2003 Forest mode – Upgrade Windows 2000 to Windows 2003 Mixed Mode (by default) NT, W2K, W2K3 DCs Upgrade NT, W2K to W2K3 Convert to Windows 2003 Native Domain, Forest mode In-Place Upgrade vs Restructure

Windows NT 4 1 A 2 C 2 B Windows 2000/2003 A Kerberos B C Windows 2000/2003 A 3 OUOU 3OUOU Domain Upgrade

Domain Restructure Windows NT 4 A C B Windows 2000/2003 “Pristine Domain” 1 A OUOU OUOU 3 4 Microsoft or 3 rd Party Migration Tool 2 1. Create pristine Windows 2000 forest/domain/OU structure 2. Configure Microsoft or 3 rd Party Migration Tool 3. Migrate global groups, machine accts and user accts from MUD 4. Migrate global groups, machine accts, user accts from Resource Domains to domain, OUs Accts, Groups can migrate to any domain/OU

In-Place Upgrade vs Restructure In-Place Upgrade  Maintains domain model  Retains Users, groups, trusts, settings, services, applications  Easier, cheaper  Higher Risk – destroys NT4 Structure  “Pile-on” bug  Collapse domains in multiple steps Domain Restructure  Allows one step domain collapse  Rebuild trusts, settings, applications, etc.  Expensive: Additional new hardware, Migration tool  Lower risk – keeps NT4 structure  Tear down and re-create with less impact on production

Functional Levels in Windows 2003

Functional Level Basics  Review of native and mixed mode  Functional levels as Active Directory versioning scheme  Domain Functional Level – Windows 2000 Native and Mixed – Windows 2003 Native and Mixed – Windows 2003 Interim (NT)  Forest Functional Level – Windows 2000 (none) – Windows 2003 Native – Windows 2003 Mixed  NOTE: – Windows 2003 Mixed – “Windows 2000 Native/Mixed” in the UI Default – Windows 2003 Native = “Windows 2003” in the UI

W2k FOREST Review: Win2k Native/Mixed Domains NT 4.0 BDC W2K DC Native Mixed

Win2003 FOREST Domain Functional Levels: Windows Server 2003 Native in W2K Forest NT 4.0 BDC W2K DC Windo ws Server 2003 DC Windows Server 2003 Native W2K Mixed W2k Native

Win2003 Mixed FOREST Domain Functional Levels: Windows Server 2003 “Interim” NT 4.0 BDC W2K DC Windo ws Server 2003 DC Windows Server 2003 Native

Win2003 Native FOREST Windows Server 2003 Forest “Native” level Windows Server 2003 Windows Server 2003 Native

Domain Level Domain VersionDomain Functionality Features EnabledDCs Supported 0Windows 2000 mixedBasic Windows 2000Windows NT 4.0, Windows 2000, Windows Server Windows 2000 nativeGroup nesting, Universal groups Windows 2000, Windows Server Windows Server 2003 interim mixed ??Windows NT 4.0 and Windows Server Windows Server 2003 interim native ??Windows Server DC rename, Logon timestamp, User password attribute, Security?? Windows Server 2003

Forest Level Forest Version Forest FunctionFeatures EnabledDCs Supported 0Windows 2000Basic Windows 2000Windows NT 4.0, Windows 2000, Windows Server Windows Server 2003 interim Link value replication and improved KCC algorithm. Still in mixed mode. Windows NT 4.0, Windows Server Windows Server 2003Whatever… all domains must be in native mode Windows Server 2003

Migration Plan

Win 2003 “Mixed’ FOREST 1. Upgrade all DCs in Forest to Windows Server 2003 NT 4.0 W2K Windo ws Server 2003 Windo ws Server 2003 Native Mixed W2K Native

W2003 Mixed FOREST 2. Raise Domain Functional Level to Windows Server 2003 (2003) – all domains NT 4.0 W2K Windo ws Server 2003 Windo ws Server 2003 Native

W2003 Forest Native 3. Raise Forest Functional Level to Windows Server 2003 (2003) NT 4.0 W2K Windows Server 2003 Windows Server 2003 Native

In-place upgrade Windows NT to Windows 2003

Process  Watch for the “Pile On” issue  Prepare DNS – Put W2K3 DNS server in NT domain – NT4 Clients can use it (but can’t register) – Ready for the W2K3 upgrade  Upgrade PDC first  Set Forest Functional level to “Interim” when running DCPROMO  Gradually upgrade BDCs  Switch Functional Level (forest and domain) to Windows 2003 (Native)

The Pile-On Issue  Basic: Win2K Pro workstations will authenticate to a Kerberos Key Distribution Center (KDC) – If no KDC, falls back to NTLM – UNLESS: It finds a KDC once…  Problem: In-place upgrade – PDC is upgraded to Win2k as DC (KDC) All W2k Pro clients, servers will authenticate to it – Flood slow WAN links – Won’t authenicate to local BDCs – Big Problem for W2K Member Servers

Pile-on Solution  Q – SP2 Required (prefer SP3) Regkey sets NT4 Emulation on PDC (no kerberos) – Problem – can’t Promote DC – needs Kerberos Another “fix” – “Neutralize” RegKey on other DCs – With sufficient DCs to handle the W2K Pro load, re-set the keys – Also see Q – Local Logon Process for Windows 2000  Requires – W2K or W2K3 DNS – W2K Trust

Another Pile-on Solution Downlevel Trust Put W2k Pros in W2k Test Resource Domain W2K Pros Authenticate to W2k DC NT4 “A” W2K “B” Win2k DC PDC

Setting 2003 Interim Level

Migrating from Windows 2000 to Windows 2003

In-Place Upgrade from Windows 2000  Easy and seamless upgrade process – No restructuring necessary – No forest, domain, OU or site topology planning necessary – No user/ workstation/ profile migration necessary  Full compatibility between 2003 DC and Windows 2000 DC – 2003 DC can play any FSMO role in Windows 2000 forest – Upgrade from Windows 2000 or build new replica  Preparing forest and domains are separate steps from introducing the first 2003 DC

Impact on current Windows 2000 environment  Schema extensions (ADPrep) – Affects every DC – W2K and W2K3 – Can’t go back  Group Policy – Over 200 new settings Software Restriction Policies RSOP  New Cool W2K3 tools – Available thru XP too!  Little impact on replication traffic:

Pre-upgrade Checklist  Check the HCL  System State Backup – At least 2 DCs in each domain +forest root  Inventory Domain Controllers in the forest – Windows 2000 SP3 (best) – Windows 2000 SP2 (minimum)  Verify end to end AD replication throughout the forest – W2K3 or XP: Repadmin /Replsum  Verify FRS Replication  FSMO role owners inventory  Event Logs – errors, warnings of interest  Disk Space inventory

ADPrep /ForestPrep  REQUIRED To upgrade Windows  Location: Windows 2003 Server CD \i386\adprep.exe Runs on the Schema Master server  May cause full replication to Windows 2000 GCs  Extends the AD schema  Adjusts ACLs on special containers  Creates special container when finished successfully – CN=Windows2002Update,CN=ForestUpdates,CN=Configuration,DC=  Upgrade without ADPrep first yields errors…

Moving to Windows 2003: Restructuring

Inter-forest scenario: Migrating from Windows NT/2000 to 2003 AmericasEMEAAsiaPac Accounts Server Resources

Restructuring considerations  Need to preserve the SID when crossing the domain boundary  Use SIDHistory attribute: – Available only in Windows 2000 native mode

Scenario 1: NT-W2K3 Migration  New GUID  New SID  Must use SIDHistory  NT4 -> Win2K  NT4 -> 2003  Win2K -> 2003 Accoun ts

Scenario 2: Inter-Forest Migration  New GUID  New SID  Must use SIDHistory  Win2K -> Win2K  Win2K -> 2003  > 2003 W2K-W2KW2K-W2K W2K-W2K3W2K-W2K3 W2K3-W2K3W2K3-W2K3

Scenario 3: Intra-Forest (between domains)  Same GUID  New SID  Must use SIDHistory  Win2K -> Win2K  Win2K -> 2003  > 2003

Scenario 4: Domain rename  Objects are intact  2003 forest only

 What you can do (The Good): – Rename a DC. – Rename a domain: DNS or NETBios or both! – Rename and restructure domains in a forest.  Restrictions (The Bad): – Can’t do it if Exchange is deployed in forest Earliest support is Titanium SP1 – Can’t Rename A DC that has Certificate Services installed – Can Rename a domain that has Microsoft CA installed but it is very ugly – Must be in Windows 2003 Native Forest mode: Only W2K3 DCs in Forest – Can rename root domain but can’t change domain that is forest root. Intra-forest scenario: Domain rename

Domain Rename A.com C.A.com B.A.com D.B.A.com The Original…

Domain Rename A.com C.A.com B.A.com D.C.A.com Move to new Parent (grandchild)

Domain Rename A.com C.A.com B.A.com D.A.com Move to New Parent (Child)

Domain Rename A.com C.A.com B.A.com D.com New Domain Tree

Domain Rename Z.com C.Z.com B.Z.com D.B.Z.com Still the old “A” domain – just called “Z” now

Domain Rename  Gotchas – MUST LOCK DOWN THE ENTIRE FOREST DURING DOMAIN RENAME PROCESS – DCs in renamed domain won’t replicate with DCs in original domain. Replication limbo Two replication topologies What happens to password, other changes?

Domain Rename “Limbo State” my.company.com your.company.com C D E B A No Replication

Domain Rename  Gotchas continued – Applications that depend on domain name may have problems. – Affects DFS/FRS – Resources Trusts. Secure channels to workstations (ouch!). Shares, mapped drives, logon scripts. – Does NOT support “Grafting” or Merging of forests.  HP will be renaming corporate Windows 2000 domain from CPQCorp.net to HPQCorp.net

Technologies: ADMT V2  Inter-forest and Intra-forest restructuring  Inter-forest password migration: – Source: NT4 (incl. syskey) – Windows – Target: Windows 2000 – Windows 2003  Command line interface – Batch mode migration  Scripting interface  Migration delegation  Extensive reporting capabilities

Technologies: 3 rd Party  NetIQ  Quest Software  Aelita  bindView

Interex, Encompass and HP bring you a powerful new HP World. Questions?