Page 1 of 1 1
Topic Options
#116485 - 2004-03-22 11:21 AM OT AD sub-tree/node/domain without access to root?
Richard H. Administrator Offline
Administrator
*****

Registered: 2000-01-24
Posts: 4946
Loc: Leatherhead, Surrey, UK
Sorry about the vagueness of the topic, I couldn't think how to word it and at the moment I'm pretty clueless about Active Directory except in very broad concepts

We are currently an entirely NT4 domain based shop. Before the end of the year we will have started the migration to AD, probably Windows 2003 based.

I have a remote site in another country which needs to rebuild their server, and wants to rebuild as AD to get the benefits now rather than wait a year when we will be ready to integrate them.

Seems reasonable enough to me with the proviso that they will need to provide all the support themselves until we get AD skills up to speed here.

The problem is that their domain will be a sub-domain of the corporate domain.

The question at last - is it possible for them to configure AD locally as part of the corporate structure even though they do not have access to the root? If so, how much buggeration will be caused when they join and (presumably) mandatory settings are inherited?

Hopefully that made some kind of sense - any pointers to relevant white papers gratefully received.

Top
#116486 - 2004-03-22 12:57 PM Re: OT AD sub-tree/node/domain without access to root?
ChristopheM Offline
Hey THIS is FUN
*****

Registered: 2002-05-13
Posts: 311
Loc: STRASBOURG, France
according to me, you can't.
during the installation, the new server needs to have access to the global catalog. So, if it is the first, it can't access to an other...
_________________________
Christophe

Top
#116487 - 2004-03-22 01:11 PM Re: OT AD sub-tree/node/domain without access to root?
Howard Bullock Offline
KiX Supporter
*****

Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
AD in W2K is strictly a top affair that needs to be well thought out. I would advise against letting someone deploy their own prior to the proper Forest ROOT being established by corporate. Windows 2003 is suppose to have prune and graft capabilities (which I have not see) but I have not yet read you can change the Forest Root.

Definately need to run that past M$ to see if they will be providing you a method of having such a domain become a child of your new Forest.
_________________________
Home page: http://www.kixhelp.com/hb/

Top
#116488 - 2004-03-22 03:31 PM Re: OT AD sub-tree/node/domain without access to root?
Co Offline
MM club member
***

Registered: 2000-11-20
Posts: 1342
Loc: NL
You can rename domains and restructure trees in Windows 2003. I'm not sure if this solves the root-domain problem...

http://www.microsoft.com/windowsserver2003/downloads/domainrename.mspx

http://download.microsoft.com/download/9/6/5/965e6899-e086-4b3e-8ed6-516ea07ea225/Domain-Rename-Intro.doc

Why don't you creat a root-domain at corporate and leave it for what it is... Add the remote domain as a child.






Edited by Co (2004-03-22 03:55 PM)
_________________________
Co


Top
#116489 - 2004-03-25 09:43 AM Re: OT AD sub-tree/node/domain without access to root?
Richard H. Administrator Offline
Administrator
*****

Registered: 2000-01-24
Posts: 4946
Loc: Leatherhead, Surrey, UK
Thanks all for the comments and pointers to documentation.
Top
#116490 - 2004-03-25 03:03 PM Re: OT AD sub-tree/node/domain without access to root?
masken Offline
MM club member
*****

Registered: 2000-11-27
Posts: 1222
Loc: Gothenburg, Sweden
Why do you need more than one domain? It is almost never necessary and only causes problems. Use Sites and OU's instead. Set up the AD there that you want in your own office later, and do it on Win2003 servers, the benefits are huge, w2k3 is what AD should have been to start with.

When you are to install the new DC in your office later, just ask the other dudes to do a system state backup to file, e-mail it over (or remote control it all yourself or whatever), after you've set the new site up (your office) in AD. Then use that backupfile to restore/import the whole existing AD to your site. This way you'll have the whole domain (with the two sites) synced in notime.


Edited by masken (2004-03-25 03:08 PM)
_________________________
The tart is out there

Top
#116491 - 2004-03-25 03:50 PM Re: OT AD sub-tree/node/domain without access to root?
Richard H. Administrator Offline
Administrator
*****

Registered: 2000-01-24
Posts: 4946
Loc: Leatherhead, Surrey, UK
Quote:

Why do you need more than one domain



Hmm. Well I may not - I started by saying I know little about AD
The corporate structure is immensely complicated and very large - we are actually completley different companies with individual personalities.

This is further complicated by the fact that the inter-country links are not particularly large, so replication has to be kept down to a minimum.

To make life even more complicated my organisation fits into the middle level of this tree - we have a corporate head office "above" us (who are Win2K AD), we are NT 4.0 and the country in question will come "under" us in terms of responsibility.

Even starting to think about it is giving me a headache.

I think I'll ask them to hold off - it sounds like the corporate head office will need to get a much more detailed structure in place first.

Top
#116492 - 2004-03-29 11:51 AM Re: OT AD sub-tree/node/domain without access to root?
masken Offline
MM club member
*****

Registered: 2000-11-27
Posts: 1222
Loc: Gothenburg, Sweden
Sounds like a healthy strategy

Planning is the largest and most important part of AD... the techpart is relatively easy.

I always follow the KiSS strategy (Keep it Simple Stupid )


Edited by masken (2004-03-29 11:53 AM)
_________________________
The tart is out there

Top
Page 1 of 1 1


Moderator:  Arend_, Allen, Jochen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 640 anonymous users online.
Newest Members
ManuvdWielNL, Sir_Barrington, batdk82, StuTheCoder, M_Moore
17887 Registered Users

Generated in 0.059 seconds in which 0.026 seconds were spent on a total of 12 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org