Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.

Slides:



Advertisements
Similar presentations
UNIVERSITY OF EDUCATION BY H.M.ISHTIAQ RAFIQUE. Domain Name Structure.
Advertisements

Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Module 1: Installing Windows XP Professional
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Introduction to Active Directory
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Hands-On Microsoft Windows Server 2003 Administration Chapter 5 Administering File Resources.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Chapter 2 Installing Windows Server 2003, Standard Edition.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-270, MCSE/MCSA Guide to Installing and Managing Microsoft Windows XP Professional and Windows Server 2003 Chapter Nine Managing File System Access.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
5.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 5: Working with File Systems.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 7 Configuring File Services in Windows Server 2008.
Installing a New Windows Server 2008 Domain Controller in a New Windows Server 2008 R2.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
© N. Ganesan, Ph.D., All rights reserved. Active Directory Nanda Ganesan, Ph.D.
Chapter 7 WORKING WITH GROUPS.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Chapter 4: Active Directory Design and Security Concepts
Module 1: Installing Active Directory Domain Services
Overview of Active Directory Domain Services Lesson 1.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
Designing Active Directory for Security
Hands-On Microsoft Windows Server 2008 Chapter 5 Configuring, Managing, and Troubleshooting Resource Access.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 5: Active Directory Logical Design.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Active Directory Operations Masters. Overview  Active Directory updates generally multimaster Changes can be made on any DC  Some exceptions — single.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
Module 7 Active Directory and Account Management.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
Company Confidential 1 A Course on Global Catalog And Flexible Single Master Operations (Fsmo) Roles Prepared for: *Stars* New Horizons Certified Professional.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
V1.1 Mike Brannigan Enterprise Strategy and Senior Consultant In Place Windows NT 4.0 Upgrade.
Operations Master / FSMO Roles in Active Directory : Suhail Ashfaq Butt.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 11: Internet Authentication Service.
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Page 1 Active Directory and DNS Lecture 2 Hassan Shuja 09/14/2004.
Chapter 10 Chapter 10: Managing the Distributed File System, Disk Quotas, and Software Installation.
Module 1: Implementing Active Directory ® Domain Services.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
1 Active Directory Administration Tasks And Tools Active Directory Administration Tasks Active Directory Administrative Tools Using Microsoft Management.
OVERVIEW OF ACTIVE DIRECTORY
Module 12: Managing Operations Masters
Introduction to Active Directory
Integration and Migration: Making the Move to Windows Server 2003 Michael Leworthy Windows Server Product Manager Microsoft Australia.
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
11 UPGRADING AND MIGRATING TO WINDOWS SERVER 2003 Chapter 12.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
Global Catalog and Flexible Single Master Operations (FSMO) Roles BAI516.
11 GLOBAL CATALOG AND FLEXIBLE SINGLE MASTER OPERATIONS (FSMO) ROLES Chapter 4.
4.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 12: Implementing Security.
Chapter 6 Server Management: Domains Workgroup Domain Trust Relationship Examples.
Configuring the User and Computer Environment Using Group Policy Lesson 8.
11 IMPLEMENTING ACTIVE DIRECTORY Chapter 2. Chapter 2: IMPLEMENTING ACTIVE DIRECTORY2 REQUIREMENTS FOR ACTIVE DIRECTORY  Microsoft Windows Server 2003.
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Unit 3 NT1330 Client-Server Networking II Date: 1/6/2016
Global Catalog and Flexible Single Master Operations (FSMO) Roles
Chapter 9: Managing Groups, Folders, Files, and Object Security
Presentation transcript:

Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT

Upgrading Domains

The Domain Upgrade Process A domain upgrade:  Upgrades a PDC to Windows Server 2003 and Active Directory  Maintains existing users, groups, computers, and applications Prevent domain controller overload Upgrade the PDC to Windows Server 2003 Install and configure DNS Install Active Directory Verify domain controller operations Upgrade Windows NT 4.0 BDCs

Effects of a Domain Upgrade on Groups Forest and domain functional levels LocalGlobal Domain Local Universal Windows NT 4.0 (original domain) Windows 2000 Mixed (allows multiple operating systems) Windows 2000 Native (allows multiple operating systems) Windows Server 2003 Interim Windows Server 2003

Effects of a Domain Upgrade on Trust Relationships To protect resource security: Audit memberships in all administrative groups 1 1 Review DACLs for important resources 2 2 Windows Server 2003 Domains 2-Way Transitive Trust 2-Way Transitive Trust 2-Way Transitive Trust Res1 Forest Root Acct1 Acct2 One-Way Non-Transitive Trust One-Way Non-Transitive Trust 2 One-Way Non-Transitive Trust Windows NT 4.0 Domains Res1 Acct1 Acct2 Upgrade

Implications of Upgrading a PDC What happens during a PDC upgrade? The forest functional level can be set at either:  Windows 2000 mixed  Windows Server 2003 interim Security level permissions are set at either:  Permissions compatible with pre-Windows 2000  Permissions compatible only with Windows 2000 or Windows Server 2003 The upgraded PDC holds the PDC emulator operations master role

How to Upgrade a Windows NT 4.0 PDC Select Upgrade for the installation type Verify that you are using a static IP address Configure DNS client settings Configure partitions as NTFS Add a newly installed domain controller 1 1 Transfer operations master roles 2 2 Reformat disk on upgraded domain controller and perform a clean installation 3 3 Transfer back any operations master roles 4 4 Process minimizes adverse effects from any corrupted data on the PDC prior to upgrade To upgrade a PDC: Best practice to add additional domain controllers: Install Active Directory 5 5

How to Verify Domain Controller Operations Verify trust relationships Verify new user accounts can be created Verify new user object replication Verify successful logon To verify Active Directory is functional: At this point a complete recovery is still possible without any data loss Diagnostic tools: Use dcdiag.exe to verify the Active Directory service Use Repadmin.exe/showreps to verify the parent domain Use nltest.exe/bdc_query: domainname to verify the BDC replication status

How to Develop a Recovery Plan for a Domain Upgrade Recovery plan: Details steps to roll back directory services migration Recovery plan: Details steps to roll back directory services migration Rollback strategy: A plan to return production environment to the state before changes Remove all computers running Windows Server 2003 Promote the offline BDC to a PDC Recovery tasks: Add a BDC to any domain that contains only a single domain controller Document configuration of services and applications Back up all services and applications to tape Synchronize all BDCs with PDC Take a fully synchronized BDC offline before upgrades are performed Periodically start protected BDC while still in Windows 2000 mixed domain To ensure that a domain can be rolled back:

How to Prevent the Domain Controller from Overloading On the domain controller to be upgraded, browse to HKEY_LOCAL_MACHINE\SYSTEM\ CurrentControlSet\Services\ Netlogon\Parameters 1 1 Repeat the procedure on each domain controller 3 3 After additional domain controllers have been added, set the value of the NT4Emulator registry key to 0, or delete the key 4 4 Add the REG_DWORD entry NT4Emulator with the value Overload occurs when too many client computers request authentication from too few domain controllers

How to Neutralize Windows NT 4.0 Domain Controller Emulation The Active Directory installation will fail if the domain controller is configured to prevent domain controller overload Use NeutralizeNT4Emulator for the new entry name 3 3 Change the DWORD value 2 2 In the Edit DWORD Value dialog box, type Double-click the new entry name 4 4 Click Registry, and then click Exit 6 6 On the client computer, browse to HKEY_LOCAL_MACHINE\ SYSTEM\CurrentControlSet\Services\Netlogon\Parameters 1 1

How to Add Additional Domain Controllers Process for upgrading a Windows NT 4.0 BDC: Upgrade operating system to Windows Server Run the Active Directory Installation Wizard 2 2 Add additional domain controllers for fault tolerance and load balancing Add new servers running Windows Server 2003 to the domain and then install Active Directory Take a Windows NT 4.0 BDC offline, reformat hard disk, then install Windows Server 2003 and Active Directory Upgrade a Windows NT 4.0 BDC to Windows Server 2003 Options :

How to Complete the Upgrade To complete the domain upgrade: Reconfigure the DNS service 1 1 Eliminate anonymous connections to domain controllers 3 3 Raise domain and forest functional levels 4 4 Move users and computers to an OU 5 5 Add Windows NT 4.0 BDCs to the domain if necessary 2 2