|
John - it sounds like Mark is talking about a 2000 domain -
not that it makes too much of a difference, but 2000 doesn't know about
functional levels (especially not about forest functional levels). Mark,
correct me if I'm wrong.
However, since in 2000 the domain mode really only effects
the domain, you should be able to revert to mixed mode by turning back the
clock. I wouldn't do so by restoring every DC though - I'd just restore
one (the PDCE) and then DCPROMO the rest. Any other option would be too risky -
although the other suggestion made by Phil to keep one DC offline during the
process and then if required to seize roles on it is also a good one.
Nevertheless, all other DCs need to be cleaned from the metadata and
re-promoted. Not nice, but the "most supported" way.
Ofcourse, you'll want to discuss a point of no-return: this
would be after you've started to leverage the new features of the native domain,
such as creating Universal Security Groups and nesting these into UGs of other
domains, leveraging SIDhistory (although I hear this also works in mixed
mode, but is not supported...) From: John Reijnders [mailto:[EMAIL PROTECTED] Sent: Mittwoch, 5. November 2003 09:37 To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] native mode The rollback possibility is a interesting issue.
I've looked into this and came across the following quote from Microsoft:
"While the Windows Server 2003
functional level provides a number of features and advantages, you might choose
not to move to this functional level if your environment is not ready. For
example, you might choose not to enable the Windows Server 2003 functional level
for one of the following reasons: ... bla bla 1 bla bla 2 ...
3.You need to retain the ability to fall back to Windows NT
4.0."
This gives me the
feeling that the "move to native mode rollback" is not possible/supported. But
... curious as I am ... why not? Of course, you can get in all sorts of trouble
when you apply changes that use the native mode features. This could be the one
and only reason why a rollback is not supported, but as a user/customer I
want to be able to revert my changes whenever I don't like them :-) ... Let's
dig into this ...
The ntMixedDomain attribute
on the domainDNS object is set to
1 when a domain is converted to native mode. Looking at how functional levels operate in
Windows 2003 domains... There's
a new attribute in the schema,
actually multiple attributes, but they're defined as msDS-Behavior-Version. For
a domain functional level, it's
written to the domain container. For a forest functional
level, it's written to the partitions
container.
So, I'm having the feeling that it is possible to revert the move to
native mode by restoring EVERY DC in the DOMAIN with a backup made before the
change. I don't think it's necessary to restore every DC in the FOREST because
the ntMixedDomain attribute is stored in the domain partition, not in the
configuration partition... However, undoing an increase in Forest Functional
Level in Windows Server 2003 appears to need a restore of every DC in the
forest...
Any other ideas?
Cheers!
John
p.s. Throwing the users/developers in the dungeons like Joe suggests is
probably a better idea .... uuuh, I mean test lab in stead of dungeon
of course ;-) ...
|
- [ActiveDir] native mode Creamer, Mark
- RE: [ActiveDir] native mode Joe
- RE: [ActiveDir] native mode John Reijnders
- RE: [ActiveDir] native mode GRILLENMEIER,GUIDO (HP-Germany,ex1)
- RE: [ActiveDir] native mode Mulnick, Al
- RE: [ActiveDir] native mode John Reijnders
- RE: [ActiveDir] native mode GRILLENMEIER,GUIDO (HP-Germany,ex1)
- RE: [ActiveDir] native mode deji Agba
- RE: [ActiveDir] native mode GRILLENMEIER,GUIDO (HP-Germany,ex1)
- RE: [ActiveDir] native mode Creamer, Mark
- RE: [ActiveDir] native mode Jorge de Almeida Pinto
- RE: [ActiveDir] native mode rrutherford
- [ActiveDir] Native Mode Sudhir Kaushal
- RE: [ActiveDir] Native Mode Simon Geary
