Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PDC to BDC in Domain2?

Status
Not open for further replies.

JBruyet

IS-IT--Management
Apr 6, 2001
1,200
0
0
US
Is there a way to demote a PDC from Domain2 to a BDC in Domain1? If I can do THAT then I can install Win2k, DCPromo, and have users and groups and rights available, right?

Thanks,

Joe Brouillette
 
Not without reinstalling NT4. But if you reinstall the server as a BDC, then yes, you can do all of the things you mentioned.

ShackDaddy
 
Bummer. I was hoping to avoid the reinstallation but I figured there was a good chance I'd have to.

Thanks,

Joe Brouillette
 
I've just change my domain .....

If you have a bdc on domian1 and a pdc on domain2 you can perform these steps :

- Promote a BDC to PDC on domain1
- Change domain of the BDC (ex pdc domain1)
- Promote this BDC (ex pdc domain1) to PDC on domain2


Hope this help !

IBI :)
 
I've just change my domain .....

If you have a bdc on domain1 and a pdc on domain2 you can perform these steps :

- Promote a BDC to PDC on domain1
- Change domain of the BDC (ex pdc domain1)
- Promote this BDC (ex pdc domain1) to PDC on domain2


Hope this help !

IBI :)
 
Sorry IBI, but what you are describing will not work. Domain controllers are siamese twins with other domain controllers IN THEIR OWN DOMAINS. You can add one by installing a new one. You can remove one, by reformatting/reinstalling the OS. You cannot move a BDC from one domain to another. The BDC always has a copy of the domain SAM and shares the domain SID with the PDC. There isn't a mechanism for swapping one SAM and SID for another.

You can change the "domain name" on a BDC, but this doesn't change the actual domain. The only time you would want to change that name is when you are changing the name on all the DC's at once. Again, the name is cosmetic, it's the underlying domain SID that matters. That can't be changed without using unsupported 3rd party tools.

This is a big hassle, and always has been, and is one reason why you should upgrade to Windows2000 or .Net ....(or Lindows Server ( in a few years!)

ShackDaddy
 
HI Schackdaddy,
if you change first PDC's domain, after all BDC's domain and syncronize SAM database you haven't any problem.
In windows NT, a domain is uniquely identified by both a NetBIOS name and by a SID.Most Access Control List and other security features of windows identify the domain by a SID;therefore, it is possible to change the name of the domain with little distruption to network services.
I have just do it and I haven't any problem ...

IBI
 
Hi,

As ShackDaddy said, the main problem with moving the BDC is that it shares a common SID and security Database with the PCD. The recomended path for moving a server acting as PCD from one domain to another is reformatting and installing a new OS in the new domain.

However, there are some utilites that allow BDC's to be moved from one domain to another. One utiliy I know of is a freeware called NEwSID from sysinternals.

Follow this link for the info...

I personnaly would go with the format/reinstallation method to save my paranoia in the future.


I hope this helps...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top