W2K migration and consolidation issues and answers



Similar documents
Active Directory at Virginia Tech Best Practices Self-Service. Service. Marc DeBonis Senior Systems Architect MIG Virginia Tech Nov 12 th, 2003

Creating the Conceptual Design by Gathering and Analyzing Business and Technical Requirements

Georgia Tech Active Directory Policy

ANNE ARUNDEL COMMUNITY COLLEGE ARNOLD, MARYLAND COURSE OUTLINE CATALOG DESCRIPTION

Windows 2000 Deployment Technical Challenges at the University of Colorado at Boulder

The safer, easier way to help you pass any IT exams. Exam : Designing and Implementing a Server Infrastructure.

Virginia Tech Active Directory Child Domain Usage Requirements

The Windows Server 2003 Environment. Introduction. Computer Roles. Introduction to Administering Accounts and Resources. Lab 2

Guide to Securing Windows NT/9x Clients in a Windows 2000 Network

1. Name of Course: Windows Server 2008, Enterprise Administrator

Designing and Implementing a Server Infrastructure MOC 20413

Windows Services. Support Windows and mixed-platform workgroups with high-performance, affordable network services. Features

Planning and Implementing Windows Server 2008

MCTS Guide to Microsoft Windows 7. Chapter 13 Enterprise Computing

Windows 2000 Security Architecture. Peter Brundrett Program Manager Windows 2000 Security Microsoft Corporation

Centralized Mac Home Directories On Windows Servers: Using Windows To Serve The Mac

70-413: Designing and Implementing a Server Infrastructure

Agency Pre Migration Tasks

WINDOWS 2000 Training Division, NIC

VNLINFOTECH JOIN US & MAKE YOUR FUTURE BRIGHT. mcsa (70-413) Microsoft certified system administrator. (designing & implementing server infrasturcure)

Active Directory and DirectControl

Designing and Implementing a Server Infrastructure

Designing and Implementing a Server Infrastructure

Administering Active Directory. Administering Active Directory. Reading. Review: Organizational Units. Review: Domains. Review: Domain Trees

Windows Server 2008 Active Directory Resource Kit

EXAM Designing and Implementing a Server Infrastructure. Buy Full Product.

Introduction to Active Directory Services

Forests, trees, and domains

考 試 編 碼 : 考 試 名 稱 : Recertification for MCSE: 版 本 : Demo. Server Infrastructure. original question and answer

Windows Server 2003 Active Directory: Perspective

Implementing Domain Name Service (DNS)

Build Your Knowledge!

Designing and Implementing a Server Infrastructure

Exam Number/Code: Exam Name: Designing and. Version: Demo. Implementing a Server Infrastructure. original question and answer

Active Directory Restructuring Recommendations

NetIQ Advanced Authentication Framework. Maintenance Guide. Version 5.1.0

CONFIGURING ACTIVE DIRECTORY IN LIFELINE

Designing and Implementing a Server Infrastructure

Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure

COURSE 20413C: DESIGNING AND IMPLEMENTING A SERVER INFRASTRUCTURE

70-647: Windows Server Enterprise Administration

Designing and Implementing a Server Infrastructure

Configuring the Active Directory Plug-in

State of Wisconsin. Active Directory (AD) Service Offering Definition (SOD)

MOC 20413C: Designing and Implementing a Server Infrastructure

Designing and Implementing a Server Infrastructure 20413C; 5 days, Instructor-led

Course 20413: Designing and Implementing a Server Infrastructure

OVERVIEW OF TYPICAL WINDOWS SERVER ROLES

Setting up a DNS MX Record for mail.corp.com p. 327 Installing Fedora on the Front-End Mail Server with the Postfix and SpamAssassin Packages

Introduction. Versions Used Windows Server 2003

Active Directory. By: Kishor Datar 10/25/2007

Websense Support Webinar: Questions and Answers

Designing and Implementing a Server Infrastructure

Desingning and Implementing a Server Infrastructure

PLANNING AND DESIGNING GROUP POLICY, PART 1

2003 O/S. when installed (gets installed as a stand alone server) to promoting to D.C. We have to install A.D.

Using SUSE Linux Enterprise Desktop with Microsoft * Active Directory Infrastructure

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

MCSE Objectives. Exam : TS:Exchange Server 2007, Configuring

Designing the Active Directory Structure

Faculty Details. : Assistant Professor ( OG. ),Assistant Professor (OG) Course Details. : B. Tech. Batch : : Information Technology

Setting Up Scan to SMB on TaskALFA series MFP s.

Rand Morimoto, Ph.D., MCITP. Michael Noel, MVF? MCITP. Omar Droubi, MCSE. Ross Mistry, MVF? MCITP

Planning for Windows Server 2008 Servers

Windows Server 2003 Active Directory MST 887. Course Outline

Designing a Windows Server 2008 Network Infrastructure

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Exam : Title : PRO: Windows Server 2008,Enterprise Administrator. Ver :

20413C: Designing and Implementing a Server Infrastructure

COURSE OUTLINE MOC 20413: DESIGNING AND IMPLEMENTING A SERVER INFRASTRUCTURE

What s in Installing and Configuring Windows Server 2012 (70-410):

PineApp Surf-SeCure Quick

Module 1: Overview of Network Infrastructure Design This module describes the key components of network infrastructure design.

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Active Directory Fundamentals

Designing and Implementing a Server Infrastructure

AV-006: Installing, Administering and Configuring Windows Server 2012

Designing and Implementing a Server Infrastructure

What we are going to cover...

Samba as an Active Directory Domain Controller

Freshservice Discovery Probe User Guide

Designing and Implementing a Server Infrastructure Course#20413B

Exam Name : Windows Server 2008,Enterprise Administrator. Version : Demo.

70-412: Configuring Advanced Windows Server 2012 Services

MCSE: server infrastructure Syllabus

Microsoft Exam

Mac OS X and Directory Services Integration

Microsoft Designing and Implementing a Server Infrastructure

Configuring and Troubleshooting a Windows Server 2008 Network Infrastructure (6421B)

MOC 6435A Designing a Windows Server 2008 Network Infrastructure

LearnKey's Windows Server 2003 Active Directory Infrastructure with Dale Brice-Nash

MCSE. 50 Cragwood Rd, Suite 350 South Plainfield, NJ Victoria Commons, 613 Hope Rd Building #5, Eatontown, NJ 07724

Active Directory & SQL Server

Getting Started Guide

Microsoft. Pro: Upgrading to Windows 7 MCITP Enterprise Desktop Support Technician.

SINGLE COURSE. 136 Total Hours. After completing this course, students will be able to:

70-685: Enterprise Desktop Support Technician

This is a distance learning course.

How to monitor AD security with MOM

Transcription:

W2K migration and consolidation issues and answers Marc DeBonis Virginia Tech IS&C Marc.DeBonis@vt.edu

Domain structure NT 4.0 NT system types Standalone (workstation or server, all 9x) Do not participate in a domain Local users and groups only (NT only) Member (workstation or server) Participate in a domain Local and domain users and groups Domain Controller (server only) Run domain, maintain domain user accounts, trust relationships Domain users and groups only

NT 4.0 Wrk 9x Srv Domain B Standalone Wrk Srv Domain A Trust Wrk Netbios? DNS WINS needed All trusts one way No trust transitive

Domain structure W2K W2K system types Standalone (workstation or server) Do not participate in Active Directory (AD) Local users and groups only Member (workstation or server) Participate in AD Local and domain users and groups Domain Controller (server only) Runs domain, maintains domain user accounts, maintains trust relationships, root or child of AD Domain users and groups, universal groups Organizational Units (OUs) help organize

W2K Wrk 9x Standalone Srv Root Wrk Netbios = dns DDNS needed All trusts two way All trusts transitive Srv Trust Child Wrk

AD overview Active Directory Combines the NT domain model into a hierarchical forest, based on an LDAP (X500) directory using domain name service (DNS) as a service location and naming mechanism Provides organizational units (OUs) to manage users, groups, computers, shared folders, etc. Provides local, global and universal groups for security and distribution control New security model allows fine-grain control of security attributes and role delegation

W2K pros Provides a wide range of new benefits, features and functionality Value Lower TCO Reliability uptime (17% > NT 4, 50% > 9x) Mobility Laptop support, hibernation, APM Manageability Group policies, MMC, delegation Performance speed (27% > 9x) Security VPN, IPsec, LT2P, biometrics Internet IE 5, WebDav, Active Desktop Data Access Intellimirror, DFS, offline store Hardware PnP, USB, Firewire

W2K cons Requires significant time, money, and personal investment Training issues for admins and end users Operating system, client access license, and add on services costs Significant change in code base, many new features, greater chance of errors Slow adoption, smaller knowledge base Requires infrastructure changes, DNS

HOKIES/VT AD root NT Hokies (w2k.vt.edu) Netbios ~25 NT DNS (ageon.w2k.vt.edu) AGECON CEE UNIVDEV ITS CS User accounts reside in root, resources in children

HOKIES/VT AD root

Domain migration When NT domain = DNS zone Read the rules of engagement (ROE) Move domain user accounts to Hokies Define member servers and workstations to follow the DNS naming convention netbios name = DNS hostname domain name = DNS zone Secure resources based on Hokies accounts Upgrade current domain controllers to w2k Bring domain in as a child domain of the VT AD root (Hokies)

Migration example Hokies (w2k.vt.edu) Users in AIS OU Hokies (w2k.vt.edu) AIS (ais.vt.edu) Users & Resources AIS Resources (ais.vt.edu) & (ais.w2k.vt.edu)

Domain consolidation When NT domain? DNS zone (or multiple NT domains exist in same DNS zone) Bring domain administrators into new w2k child domain called DNS zone (political) Define member servers and workstations to follow the DNS naming convention netbios name = DNS hostname domain name = DNS zone Create OUs in new W2K child domain, each OU contains groups, computers, shares, printers, etc. corresponding to old NT domains NT domain administrators given admin control over corresponding OU (role delegation)

Consolidation example Hokies (w2k.vt.edu) Users in CC OU Hokies (w2k.vt.edu) VTUSD 4HELP (cc.vt.edu) CC-OP Users and resources exist in each NT domain here CC (cc.vt.edu) & (cc.w2k.vt.edu) Resources 3 OUs exist here VTUSD, 4HELP & CC-OP

Migration vs. Consolidation When to do which? Migrate when a NT domain already matches 1:1 for a DNS zone Consolidate when there is a many:1 ratio for NT domains to DNS zones Administration issues A ladder of trust is required for consolidation Root level = Enterprise Administrators Domain level = Domain Administrator(s) OU level = Delegated rights to user or group account(s) This is a political issue rather than technical

NT/9x AD extension client Gives you Site awareness (closest DC is used) Active Directory Service Interfaces (ADSI) DFS fault tolerance client Active Directory Windows Address Book NTLM version 2 authentication Does not give you Kerberos support Group Policy nor IntelliMirror support IPsec nor L2TP support SPN nor mutual authentication

Standalone or Member? Only member workstations and servers have computer accounts in a child domain With a computer account an authenticated user can Browse the AD non-anonymously (shares, printers, etc.) Kerberos and IPsec security Secure local resources via non local accounts and groups Group policies Intellimirror, DFS, offline store Use cached credentials for login Dynamically registered IP/DNS via DHCP Access resources in other domain secured by Hokies ID

In conclusion W2K significantly enhances the Windows OS family These enhancements necessitate centralized system and service management for the W2K infrastructure Migration and consolidation allow the NT domain administrator to move into W2K AD while delegating roles and reducing domain redundancy Available AD client extensions provide some backwards compatibility for those systems unable or unwilling to migrate to the W2K AD Users must login to a W2K child domain to gain all the features and functionality of W2K and AD

W2K migration and consolidation issues and answers Marc DeBonis Virginia Tech IS&C Marc.DeBonis@vt.edu