ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Existing AD...prefer to create New Site?

    IT Discussion
    7
    25
    363
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FATeknollogee
      last edited by FATeknollogee

      Here's the deal on a job I'm taking over:
      Existing site with AD.
      The site has LOB app, file servers etc.
      This LOB app is an old version & will eventually go bye-bye.
      Every user "knows" the domain admin password...hahaha!!

      I'm adding some new gear:
      EdgeRouter 4
      EdgeSwitch ES-16-XG
      Edgeswitch ES48 Lite
      Edgeswitch ES24-500w
      new SM server: F29 w KVM to host new version of LOB

      I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

      What say you?

      J J 2 Replies Last reply Reply Quote 0
      • J
        JaredBusch @FATeknollogee
        last edited by

        @FATeknollogee said in Existing AD...prefer to create New Site?:

        Here's the deal on a job I'm taking over:
        Existing site with AD.
        The site has LOB app, file servers etc.
        This LOB app is an old version & will eventually go bye-bye.
        Every user "knows" the domain admin password...hahaha!!

        I'm adding some new gear:
        EdgeRouter 4
        EdgeSwitch ES-16-XG
        Edgeswitch ES48 Lite
        Edgeswitch ES24-500w
        new SM server: F29 w KVM to host new version of LOB

        I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

        What say you?

        This is very disruptive, but is what you should do from the IT perspective.

        You need buy in from the CEO/President though.

        F 1 Reply Last reply Reply Quote 2
        • S
          scottalanmiller
          last edited by

          You can just change the admin passwords, right? I mean a full rebuild is what I'd prefer to do. But very disruptive, as Jared says. But a clean start where you know everything has a LOT of benefits.

          O 1 Reply Last reply Reply Quote 1
          • F
            FATeknollogee @JaredBusch
            last edited by

            @JaredBusch said in Existing AD...prefer to create New Site?:

            @FATeknollogee said in Existing AD...prefer to create New Site?:

            Here's the deal on a job I'm taking over:
            Existing site with AD.
            The site has LOB app, file servers etc.
            This LOB app is an old version & will eventually go bye-bye.
            Every user "knows" the domain admin password...hahaha!!

            I'm adding some new gear:
            EdgeRouter 4
            EdgeSwitch ES-16-XG
            Edgeswitch ES48 Lite
            Edgeswitch ES24-500w
            new SM server: F29 w KVM to host new version of LOB

            I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

            What say you?

            This is very disruptive, but is what you should do from the IT perspective.

            You need buy in from the CEO/President though.

            Forgot to mention....it's a new owner/CEO.
            Buy in is a 1000%, he wants it cleaned up & done the right way.

            J O S 3 Replies Last reply Reply Quote 0
            • J
              JaredBusch @FATeknollogee
              last edited by

              @FATeknollogee said in Existing AD...prefer to create New Site?:

              @JaredBusch said in Existing AD...prefer to create New Site?:

              @FATeknollogee said in Existing AD...prefer to create New Site?:

              Here's the deal on a job I'm taking over:
              Existing site with AD.
              The site has LOB app, file servers etc.
              This LOB app is an old version & will eventually go bye-bye.
              Every user "knows" the domain admin password...hahaha!!

              I'm adding some new gear:
              EdgeRouter 4
              EdgeSwitch ES-16-XG
              Edgeswitch ES48 Lite
              Edgeswitch ES24-500w
              new SM server: F29 w KVM to host new version of LOB

              I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

              What say you?

              This is very disruptive, but is what you should do from the IT perspective.

              You need buy in from the CEO/President though.

              Forgot to mention....it's a new owner/CEO.
              Buy in is a 1000%, he wants it cleaned up & done the right way.

              Then, by all means, do it the right way.

              1 Reply Last reply Reply Quote 1
              • O
                Obsolesce @scottalanmiller
                last edited by

                @scottalanmiller said in Existing AD...prefer to create New Site?:

                You can just change the admin passwords, right? I mean a full rebuild is what I'd prefer to do. But very disruptive, as Jared says. But a clean start where you know everything has a LOT of benefits.

                But also, you have no idea what has been done, maliciously, accidentally, etc... from regular users, as everyone had Admin. From a security standpoint, you want to make sure there's no back doors created by anyone as well. When something like that has been exposed for so long by everyone, I'd prefer to redo it, if it's not too big. Perhaps it would be too disruptive, and may not work, but some effort then must be given in a full sweep.

                1 Reply Last reply Reply Quote 0
                • O
                  Obsolesce @FATeknollogee
                  last edited by

                  @FATeknollogee said in Existing AD...prefer to create New Site?:

                  @JaredBusch said in Existing AD...prefer to create New Site?:

                  @FATeknollogee said in Existing AD...prefer to create New Site?:

                  Here's the deal on a job I'm taking over:
                  Existing site with AD.
                  The site has LOB app, file servers etc.
                  This LOB app is an old version & will eventually go bye-bye.
                  Every user "knows" the domain admin password...hahaha!!

                  I'm adding some new gear:
                  EdgeRouter 4
                  EdgeSwitch ES-16-XG
                  Edgeswitch ES48 Lite
                  Edgeswitch ES24-500w
                  new SM server: F29 w KVM to host new version of LOB

                  I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

                  What say you?

                  This is very disruptive, but is what you should do from the IT perspective.

                  You need buy in from the CEO/President though.

                  Forgot to mention....it's a new owner/CEO.
                  Buy in is a 1000%, he wants it cleaned up & done the right way.

                  Yeah, I'd redo it if they can deal with the down time when everything is switched over.

                  F 1 Reply Last reply Reply Quote 0
                  • S
                    scottalanmiller @FATeknollogee
                    last edited by

                    @FATeknollogee said in Existing AD...prefer to create New Site?:

                    @JaredBusch said in Existing AD...prefer to create New Site?:

                    @FATeknollogee said in Existing AD...prefer to create New Site?:

                    Here's the deal on a job I'm taking over:
                    Existing site with AD.
                    The site has LOB app, file servers etc.
                    This LOB app is an old version & will eventually go bye-bye.
                    Every user "knows" the domain admin password...hahaha!!

                    I'm adding some new gear:
                    EdgeRouter 4
                    EdgeSwitch ES-16-XG
                    Edgeswitch ES48 Lite
                    Edgeswitch ES24-500w
                    new SM server: F29 w KVM to host new version of LOB

                    I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

                    What say you?

                    This is very disruptive, but is what you should do from the IT perspective.

                    You need buy in from the CEO/President though.

                    Forgot to mention....it's a new owner/CEO.
                    Buy in is a 1000%, he wants it cleaned up & done the right way.

                    Nice, don't get that very often.

                    F 1 Reply Last reply Reply Quote 0
                    • F
                      FATeknollogee @scottalanmiller
                      last edited by

                      @scottalanmiller said in Existing AD...prefer to create New Site?:

                      @FATeknollogee said in Existing AD...prefer to create New Site?:

                      @JaredBusch said in Existing AD...prefer to create New Site?:

                      @FATeknollogee said in Existing AD...prefer to create New Site?:

                      Here's the deal on a job I'm taking over:
                      Existing site with AD.
                      The site has LOB app, file servers etc.
                      This LOB app is an old version & will eventually go bye-bye.
                      Every user "knows" the domain admin password...hahaha!!

                      I'm adding some new gear:
                      EdgeRouter 4
                      EdgeSwitch ES-16-XG
                      Edgeswitch ES48 Lite
                      Edgeswitch ES24-500w
                      new SM server: F29 w KVM to host new version of LOB

                      I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

                      What say you?

                      This is very disruptive, but is what you should do from the IT perspective.

                      You need buy in from the CEO/President though.

                      Forgot to mention....it's a new owner/CEO.
                      Buy in is a 1000%, he wants it cleaned up & done the right way.

                      Nice, don't get that very often.

                      Ain't that the truth?

                      1 Reply Last reply Reply Quote 0
                      • F
                        FATeknollogee @Obsolesce
                        last edited by

                        @Obsolesce said in Existing AD...prefer to create New Site?:

                        @FATeknollogee said in Existing AD...prefer to create New Site?:

                        @JaredBusch said in Existing AD...prefer to create New Site?:

                        @FATeknollogee said in Existing AD...prefer to create New Site?:

                        Here's the deal on a job I'm taking over:
                        Existing site with AD.
                        The site has LOB app, file servers etc.
                        This LOB app is an old version & will eventually go bye-bye.
                        Every user "knows" the domain admin password...hahaha!!

                        I'm adding some new gear:
                        EdgeRouter 4
                        EdgeSwitch ES-16-XG
                        Edgeswitch ES48 Lite
                        Edgeswitch ES24-500w
                        new SM server: F29 w KVM to host new version of LOB

                        I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

                        What say you?

                        This is very disruptive, but is what you should do from the IT perspective.

                        You need buy in from the CEO/President though.

                        Forgot to mention....it's a new owner/CEO.
                        Buy in is a 1000%, he wants it cleaned up & done the right way.

                        Yeah, I'd redo it if they can deal with the down time when everything is switched over.

                        I can't have downtime, the existing stuff/site needs to keep running as-is for now.

                        O 1 Reply Last reply Reply Quote 0
                        • O
                          Obsolesce @FATeknollogee
                          last edited by

                          @FATeknollogee said in Existing AD...prefer to create New Site?:

                          @Obsolesce said in Existing AD...prefer to create New Site?:

                          @FATeknollogee said in Existing AD...prefer to create New Site?:

                          @JaredBusch said in Existing AD...prefer to create New Site?:

                          @FATeknollogee said in Existing AD...prefer to create New Site?:

                          Here's the deal on a job I'm taking over:
                          Existing site with AD.
                          The site has LOB app, file servers etc.
                          This LOB app is an old version & will eventually go bye-bye.
                          Every user "knows" the domain admin password...hahaha!!

                          I'm adding some new gear:
                          EdgeRouter 4
                          EdgeSwitch ES-16-XG
                          Edgeswitch ES48 Lite
                          Edgeswitch ES24-500w
                          new SM server: F29 w KVM to host new version of LOB

                          I'm thinking I should start from scratch, create a "new" domain & not fight the existing "admins" (aka user base?

                          What say you?

                          This is very disruptive, but is what you should do from the IT perspective.

                          You need buy in from the CEO/President though.

                          Forgot to mention....it's a new owner/CEO.
                          Buy in is a 1000%, he wants it cleaned up & done the right way.

                          Yeah, I'd redo it if they can deal with the down time when everything is switched over.

                          I can't have downtime, the existing stuff/site needs to keep running as-is for now.

                          There will be down time with a new domain, you'll need to rejoin all devices to the new domain, that will require a reboot.

                          Everyone will need to log in with their new credentials, and so they can get access to AD-authenticated shares and resources.

                          New DNS settings. New DHCP auth and dns settings for DHCP server.

                          Etc...

                          You can set up the new domain completely in parallel, and then migrate from old domain to new domain as well. I have done that twice, but it was like 4 or so years ago and at that time it wasn't a 100% translation. Maybe it's better now, I don't know, but with a new domain there will be some kind of down time.

                          If you can't have any down time, then you will do as I had above and do a full sweep through everything, and as Scott said, start changing admin passwords lol.

                          1 Reply Last reply Reply Quote 1
                          • F
                            FATeknollogee
                            last edited by

                            I've got to figure out how I can run in parallel with 2 different network/subnets

                            DashrenderD 2 Replies Last reply Reply Quote 0
                            • J
                              jmoore @FATeknollogee
                              last edited by

                              @FATeknollogee said in Existing AD...prefer to create New Site?:

                              new SM server: F29 w KVM to host new version of LOB

                              What is LOB?

                              F 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @FATeknollogee
                                last edited by

                                @FATeknollogee said in Existing AD...prefer to create New Site?:

                                I've got to figure out how I can run in parallel with 2 different network/subnets

                                Why change the IP scheme?

                                F 1 Reply Last reply Reply Quote 0
                                • F
                                  FATeknollogee @jmoore
                                  last edited by

                                  @jmoore said in Existing AD...prefer to create New Site?:

                                  @FATeknollogee said in Existing AD...prefer to create New Site?:

                                  new SM server: F29 w KVM to host new version of LOB

                                  What is LOB?

                                  Line of Business

                                  J DashrenderD 2 Replies Last reply Reply Quote 0
                                  • J
                                    jmoore @FATeknollogee
                                    last edited by

                                    @FATeknollogee Oh, thanks

                                    1 Reply Last reply Reply Quote 0
                                    • DashrenderD
                                      Dashrender @FATeknollogee
                                      last edited by

                                      @FATeknollogee said in Existing AD...prefer to create New Site?:

                                      I've got to figure out how I can run in parallel

                                      This will definitely be the most challenging part.

                                      Getting people still on the old systems to be able to connect to the new systems.

                                      I'd consider setting up domain trusts

                                      with 2 different network/subnets

                                      I suppose this could be a good idea, you could setup each subnet with it's own DHCP server so DNS is right for each domain - but each domain will need to know about the DNS of the other anyhow, assuming you setup Domain trusts.

                                      1 Reply Last reply Reply Quote 0
                                      • DashrenderD
                                        Dashrender @FATeknollogee
                                        last edited by

                                        @FATeknollogee said in Existing AD...prefer to create New Site?:

                                        @jmoore said in Existing AD...prefer to create New Site?:

                                        @FATeknollogee said in Existing AD...prefer to create New Site?:

                                        new SM server: F29 w KVM to host new version of LOB

                                        What is LOB?

                                        Line of Business

                                        LOL - I thought he was asking what the app was, i.e. the name of the app.

                                        J 1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender
                                          last edited by

                                          Are you also going to rebuild all the users computers?

                                          F 1 Reply Last reply Reply Quote 0
                                          • F
                                            FATeknollogee @Dashrender
                                            last edited by

                                            @Dashrender said in Existing AD...prefer to create New Site?:

                                            @FATeknollogee said in Existing AD...prefer to create New Site?:

                                            I've got to figure out how I can run in parallel with 2 different network/subnets

                                            Why change the IP scheme?

                                            Preference & it's an easy way to identify "rogue" devices.
                                            Current scheme is 192.168.1.x
                                            I'll do a 10.200.10.x (or something similar)
                                            Which means I should never see any device with a 192.168.1.x address on the network.

                                            J 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post