110 likes | 419 Views
Overview Introduction Upgrade Paths Why are we upgrading? NT4 Domains Test Domain for UTas AD Current Production AD 2003 New Production AD 2008 Changes Reference Articles Questions/Comments?. Active Directory Upgrade Project Information Session. Active Directory Upgrade. Introduction
E N D
Overview • Introduction • Upgrade Paths • Why are we upgrading? • NT4 Domains • Test Domain for UTas AD • Current Production AD 2003 • New Production AD 2008 • Changes • Reference Articles • Questions/Comments? Active Directory Upgrade Project Information Session
Active Directory Upgrade Introduction • Project is being run according to PMM@UTas • Project Manager is Paul Fahey, ITR Newnham • Technical Lead is Tristan Roberts, ITR Hobart • Timeline • Consultation & hardware procurement November 2009 • Testing December 2009 • Production upgrade January 2010 • Review (including further meeting with Computing Support Staff ) February 2010
Active Directory Upgrade Upgrade Paths • Server 2008 R2 • Was our preferred option • Brings some increased functionality over 2008 • Unfortunately too ‘new’ to have sufficient vendor support – yet • May revisit in 12 months • We will be using the 2008 R2 schema extensions • Server 2008 • Not supported by Novell dirXML Loader v2.01 • Novell is to be turned off by end of November 2009 • Another of Paul Fahey’s projects • Supported by other vendors of ITR applications, eg: • Microsoft (ISA Proxy, SQL Server, Exchange 2007 & 2010 etc etc) • CommVault (Backup & Archive) • Sun Identity Manager 8.1 • BlackBerry • McAfee ePO • TRIM • Radiator
Active Directory Upgrade Why are we upgrading? • Microsoft Support • Mainstream Support for Server 2003 ends in July 2010 • Moving away from x86 to x64 operating systems • Currently we have a mix of 32 and 64 bit operating systems • 64 bit allows us the flexibility of effectively utilising greater than 4gb RAM • Introducing physical domain controllers for CCC, NHM & SBY • Dell PowerEdge R300, 4 core / 8gb RAM • Sandy Bay server located at Engineering for physical security and site resilience • Additional features • Server Core DCs • Read Only DCs • Others that rely on functional level of the domain
Active Directory Upgrade NT4 Domains • CENTRAL • Still used for some SAMBA authentication (Tasman P: drives) • ITS_ADMIN • Starnet • Notes BlackBerry server We would like to decommission these unsupported domains as part of this project
Active Directory Upgrade Test Domain for UTas AD • Configuration • Root domain of ad.test (2 DCs – NHM & SBY) • Child domain of utastest.ad.test (3 DCs – NHM & 2 SBY) • Applications • Microsoft Exchange 2007 SP2 & Exchange 2010 • Microsoft Identity Integration Server 2003 • Microsoft System Center Configuration Manager 2007 R2 • Microsoft Office Communications Server 2007 R2 • CommVault 8.0 SP2 • Novell dirXML • VMWare
Active Directory Upgrade Current Production AD 2003
Active Directory Upgrade New Production AD 2008
Active Directory Upgrade Changes • Schema changes • Required before any 2008 server can be promoted to DC • We will be using 2008 R2 schema extensions for upgrade flexibility later • Large number changes from 2003 to 2008, only minor changes from 2008 to 2008 R2 • Domain functional level • Can only be raised once all DCs have been upgraded to 2008 • Enables DFS replication for SYSVOL • Enables fine grained password policies • Enables last interactive logon information • Enables Advanced Encryption Services support for Kerberos • Forest functional level • Can only be raised once all DCs have been upgraded & the Domain functional level raised • No additional features
Active Directory Upgrade Reference Articles • Microsoft - http://technet.microsoft.com/en-us/library/cc755093(WS.10).aspx • Sun IDM 8.1 - http://docs.sun.com/app/docs/doc/820-5592/ahwad?a=view • BlackBerry Exchange Server (calculating required number of NSPI connections) - http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17325 • McAfee - https://kc.mcafee.com/corporate/index?page=content&id=KB52397 • TRIM - http://h20195.www2.hp.com/V2/GetPDF.aspx/4AA2-9973ENA.pdf • Radiator - http://www.open.com.au/radiator/technical.html • CommVault -http://documentation.commvault.com/commvault/release_8_0_0/books_online_1/english_us/system_requirements/system_requirements.htm
Active Directory Upgrade Questions/Comments?