Creating additional domain controllers 2003 for testing in a sandbox environment

Hello

We run many production servers in a windows 2003 environment.

To test future applications and internal development, we plan to create a test environment of sandbox for our production environment.

I read that conversion existing DC directly is problematic, what happens if we

-created additional servers in the virtual machine,

-dcpromo + synchronization the new servers with the production of DC

-Finally the sandboxing them?

There will be issues when the new domain controller is not accessible by the PDC? These DCs in sandbox will be fully functional?

Appreciate any feedback.

See you soon

RAMM

Hi Ramm,

Welcome to the forums.

It is a best practice to not virtualize a domain controller. It is better to create a new server and promote a domain controller.

You can divide your domain name and create a replica of lab but you always have to take care of is not to reconnect this isolated domain in production to avoid conflicts.

These are the steps to split a domain:

-create a virtual Windows machine with the same version and SP as production

-promote a domain controller

-Once the replication completed, isolate it from the network

-in the field of production, remove data from active directory to the remote server

-on the remote server, enter the FSMO roles, DNS and DHCP functionality

Some references:

Need to "clone" a domain controller

Creating a test lab environment active directory of your AD forest production

Virtualizing_Windows_Active_Directory.PDF

Good luck

Concerning

Franck

Tags: VMware

Similar Questions

  • Is it necessary to create additional rules not permitted for uses such as Regedit.exe etc when applying software restriction policy?

    Is it necessary to create additional rules not permitted for uses such as Regedit.exe etc when applying software restriction policy?

    Hello

    Please visit the following link. This should explain the software restriction policies in detail.

    http://TechNet.Microsoft.com/en-us/library/bb457006.aspx

  • Creating an ESXi Virtual Lab for testing and learning purpose

    I am new in this VMware technology. I have a few questions here. I am trying to set up a virtual test on my laptop environment. Is this possible?

    The laptop has processor i7, 12 GB memory and 2 x 500 GB HARD drive. I will use the second 500 GB to Openfiler iSCSI connection.

    Here are the questions.

    1. the laptop has only one LAN port, but I need to define HA and FT on it. Can I just add more virtual cards on ESXi hosts?

    2 workstation 7 by default has VMnet0, VMnet1 and VMnet8. Can I use them for ESXi hosts also or they should not be used?

    3. what options should I assign these virtual network adapters (NAT, host-only or custom)?

    When you create your host ESX (i) inside Workstation I would use just filled to the right network to start. Keep it simple to start. Set up as a virtual Workstation machine openfiler.

  • Domain controller 2003 desktop 10

    Hello

    I get a constant error when I try to promote a Windows Server 2003 guest on a DC on workstation 10.0.4.  The error is:

    "Security Accounts Manager initialization failed because of the following error: failed to start Directory Service." The error status: 0xc00002e1. If please clock OK to shutdown this system and reboot into Directory Services Restore Mode. »

    I get it constantly if I invited a completely clean install of the OS with no patches, an installation of SP2 fully patched or create a clone that is bound to a model - I used this model even many, many times with older versions of VMWare Workstation (on the same host) without problem and have done many installs own on previous versions of workstation without problem , so for the moment I can only assume it's related to something in 10 Workstation, as much as I can follow the same process on VirtualBox to create a domain controller 2003 (using the same installation for clean installation media) and get a DC without any problem with happiness.

    I have good knowledge of the AD and followed the instructions in the Microsoft KB articles (specifically KB258062) for the above error and am able to solve and get AD works fine, but then the next reboot the virtual machine the error returns.

    The log file of the client is attached.

    Any ideas?

    Hi all

    Just put an update here for all the world reference.  I solved this problem and a few others that I had where Server Manager on a server OS comments fails with CLR errors or updates would fail.

    The cause seems to be that I was to store the virtual machines on a Pool of storage R2 Server 2012 (Server R2 2012 is the host machine), where I had a couple of discs actually provide a RAID 0 configuration.  I now divide these discs so that they are quite "normal" disks and I shared my virtual machines manually between the discs and all my problems disappeared.

    This only seemed to affect my SATA III 2 TB disks that I have a couple of SSD in a Storage Pool and they seem to work fine (maybe a speed/cache associated effect?)

  • Commissioning for lack of Exchange because of the latency in Multi Site domain controllers

    Hi all

    I use using the OIM 11 g R2 PS2 BP04 with AD-connector version (11.1.1.6.0 & AD 2010) and the Version of the Exchange Connector (11.1.1.6.0 & Exchange 2010) and its installed on RHEL 6.5. We have 20:00 domain controllers and each of them is in a different site. Here is the list of domain controllers:

    DC-host1,DC-HOST2,DC-site2-host1,DC-SITE3-host1,DC-SITE4-host1...etc

    We use automatic configuration AD access strategies and resources the user Exchange and configured as domain controllers in AD IT resource:

    DC-HOST1 - primary

    DC-HOST2 - secondary

    AD resource provisioning works fine however when IOM tries to configure exchange to the user, its failure due to the latency issue b & w AD different Site of the domain controller. For example, "PRODTESTUSER12" is implemented successfully in AD and when IOM tries to configure exchange for this user, exchange server search for any available domain controller search for the user. It randomly selects an AD domain controller, I say DC-SITE2-HOST1 to search for the user. Since this domain contorller is on another site and it is latency, its not able to find the user of this domain controller, this is why available exchange fails for this user. See the below error:

    Target class = oracle.iam.connectors.icfcommon.prov.ICProvisioningManager

    < 21 may 2015 23:10:06 CEST > < error > < ORACLE. IAM. CONNECTORS. ICFCOMMON. Prov. ICPROVISIONINGMANAGER > < BEA-000000 > < oracle.iam.connectors.icfcommon.prov.ICProvisioningManager: createObject: error while creating user

    java.lang.RuntimeException: the operation could not be performed because the object 'PRODTESTUSER12' could not be found on 'anc-dc2k8 - 01.wssc.ad.root'.

    We have not specified this domain either under AD controller or Exchange resources.

    n Connector logs, I can see below:

    22/05/2015-10:55:19 < INFORMATION >: class-> Org.IdentityConnectors.Exchange.RemoteRunspaceInstance-> InvokeScript method, Message-> enter the method


    22/05/2015-10:55:19 < VERBOSE >: class-> Org.IdentityConnectors.Exchange.RemoteRunspaceInstance,-> InvokeScript method, Message-> Script: Set-ADServerSettings - ViewEntireForest: $true; Get-User "PRODTESTUSER21" - ReadFromDomainController

    I think, because of this script, Exchange Server recovers first of any domain controller available to search for the user. Yes, is there a way to restrict or put domain controller's favorite?

    There is a hotfix available for this problem. Here are the details:

    Patch 19692488: APPLICATION of MERGER on top of 11.1.1.6.0 FOR the BUGS 18310438 19478076

    Bugs resolved by this fix

    UPDATED EXCHANGE CONNECTOR SMTP PRIMARY ADDRESS 16813315 PROBLEM

    17949931 DELAY IN EXCHANGE / COMMISSIONING

    19478076 WITH REGARD TO THE EXCHANGE OF SUPPLY FAILURES.

    Concerning

    Suren

  • How to disable snapshots for domain controllers in ESXi 5? Or other best practices?

    Dear all,

    I need some aspects of assistance to the deactivation of snapshots for 2 VMS in my HA cluster running Active Directory to Windows 2008 R2.

    I read that best practices for virtual machines running that active Directory is never for them to snapshot.

    I'm worried about auto created by the systems periodically snapshots and the problem arises if a snapshot is to be reinstated by mistake.

    So, what are the best practices for virtual machines running as domain controllers? To deactivate the snapshot function or other recommended methods?

    Please kindly share. Thank you.

    Rgds

    Leslie

    leschua75 wrote:

    .

    I'm worried about auto created by the systems periodically snapshots and the problem arises if a snapshot is to be reinstated by mistake.

    VMware has no system automatically taking portraits.

    Snapshots exist either because you made them manually, an application backup created. In this case, talk with your backup vendor.

  • Domain controllers Windows 2008 R2 with the forest functional level Windows 2003 taken over after the end of Windows 2003 support in July 2015

    Hello

    Anyone know if the Windows 2008 R2 with Windows 2003 forest functional level domain controllers will be always supported after Windows 2003 support ends in July 2015?

    Thank you

    This issue is beyond the scope of this site and must be placed on Technet or MSDN

    http://social.technet.Microsoft.com/forums/en-us/home

    http://social.msdn.Microsoft.com/forums/en-us/home

  • Windows 2003 Server keeps stopping every hour on and saying that he must run the Setup program to create a domain controller.

    WINDOWS 2003 SERVER STANDARD EDITION

    HELLO TECH TECHNICAL SUPPORT ENGINEERS.

    WE HAVE WINDOWS SMALL BUSINESS SERVER 2003 STANDARD EDITION,

    WE HAVE EVEN INSTALLED AND CONFIGURED IN A WORKING GROUP, WE DO NOT WANT TO CREATE A DOMAIN CONTROLLER,

    BUT OUR SERVER IS BLOCKING DOWN IN ANY ONE HOUR AND SAY TO RUN THE SETUP PROGRAM TO CREATE THE DOMAIN CONTROLLER.

    PLEASE SUGGEST, AS WE DO NOT WANT TO CREATE DOMAIN

    CONCERNING

    DECCAN TEAM

    Post in the Windows Server Forums:
    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer/

  • WLST Script to create the domain weblogic for IOM and OAM

    Hello

    I intend to set up PS3 IOM - OAM in the new environment. We intend to perform the installation in silent mode. Does anyone have example WLST to create the domain weblogic for IOM or OAM?

    Thank you

    Here is an example of OUD. I post this one since it's the simplest and shortest, but it is the same for OAM and IOM except that the script is much longer because they ask a lot more questions. You will need to export the variables used or replace them with the appropriate values for your system.

    wait-<>

    the value of timeout 600

    spawn ${OUD_BASE}/${WLS_NAME}/common/bin/config.sh mode = console

    # Create a WebLogic domain

    wait {}

    {"Enter the index number to select GOLD *" {send "1\n"}}

    # Choose the components of the Weblogic Platform

    wait {}

    {"Enter the index number to select GOLD *" {send "1\n"}}

    # | ___Oracle directory Services Manager - 11.1.2.3.0 [Oracle_OUD1] [3]

    wait {}

    {"Enter number exactly as it appears in the media *" {send "3\n"}}

    wait {}

    {"Enter number exactly as it appears in the media *" {send "n"}}

    # Change the domain information

    wait {}

    "" Enter the value of * "{send" ${OUD_DOMAIN_NAME} \n "}}"

    wait {}

    {"Enter the number of the option to select GOLD *" {send "n\n"}}

    # Select the target area for this domain directory

    wait {}

    {'Enter' new target location GOLD * {send "${OUD_BASE} / user_projects/domains\n"}}

    wait {}

    {'Enter' new target location GOLD * {send "n\n"}}

    # Configure password and username administrator

    wait {}

    {"Enter the number of the option to select GOLD *" {send "2\n"}}

    wait {}

    "" Enter new * "{send" ${WLS_PASS} \n "}}"

    wait {}

    {"Enter the number of the option to select GOLD *" {send "3\n"}}

    wait {}

    "" Enter new * "{send" ${WLS_PASS} \n "}}"

    wait {}

    {"Enter the number of the option to select GOLD *" {send "n\n"}}

    # Configuration mode field-> 1 | Development mode

    wait {}

    {"Enter the index number to select GOLD *" {send "1\n"}}

    # Java SDK selection

    wait {}

    {"Enter the index number to select GOLD *" {send "2\n"}}

    wait {}

    {'Enter' new JVM Directory GOLD * {send "${JAVA_HOME} \n"}}

    wait {}

    {'Enter' new JVM Directory GOLD * {send "n\n"}}

    # Select Optional Configuration

    wait {}

    {"Enter the index number to select GOLD *" {send "1\n"}}

    wait {}

    {"Enter the index number to select GOLD *" {send "n"}}

    # Configure the Administration Server

    # Change "Listen port.

    wait {}

    {"Enter the number of the option to select GOLD *" {send "3\n"}}

    wait {}

    "" Enter the value of * "{send" ${ODSM_PORT} \n "}}"

    # Change 'SSL enabled.

    wait {}

    {"Enter the number of the option to select GOLD *" {send "4\n"}}

    wait {}

    {"Enter the index number to select GOLD *" {send "1\n"}}

    # Change 'SSL listening Port.

    wait {}

    {"Enter the number of the option to select GOLD *" {send "4\n"}}

    wait {}

    "" Enter the value of * "{send" ${ODSM_SPORT} \n "}}"

    # Then

    wait {}

    {"Enter the number of the option to select GOLD *" {send "n\n"}}

    # wait for install

    wait {}

    {"Successfully created * field *" {send "\n"}}

    EXPRESSIONS OF FOLKLORE

  • I created a domain name for my site, but it's just to show my domain name on the Web site. How can I get my website to show?

    I created a domain name for my site, but it's just to show my domain name on the Web site. How can I get my website to show?

    You can follow the steps outlined in the document below to add the domain: -.

    Add a domain name to your site using the service DNS of BC

  • The extension I created will not install for testing. He always says not compatible with Firefox 23.0.1.

    I'm wearing an extension of Chrome to Firefox. The extension is called The Unofficial Openstudy App and is found on the Chrome Web Store. I have all ready for testing, but it will not install the XPI file. It is said that 'no compatible with Firefox 23.0.1.' I tried to change the minversion and maxversion in install.rdf file, but it DOES NOT WORK. Why is this?

    Connection to xpi:
    http://www.fast-files.com/GetFile.aspx?file=65730

    Content of the install.rdf file for those who do not wish to download:

    <?xml version="1.0" encoding="UTF-8"?>
    <RDF xmlns="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:em="http://www.mozilla.org/2004/em-rdf#">
      <Description about="urn:mozilla:install-manifest">
        <em:id>[email protected]</em:id>
        <em:type>2</em:type>
        <em:name>The Unofficial OpenStudy App (TUOSA)</em:name>
        <em:version>4</em:version>
        <em:creator>dumbsearch</em:creator>
        <em:contributor>Emoticon</em:contributor>
        <em:description>The Unofficial OpenStudy App (TUOSA) is a Firefox extension that extends and enhances the current functionality of OpenStudy.</em:description>
        <em:optionsURL>chrome://tuosa/content/options.xul</em:optionsURL>
     <em:iconURL>chrome://tuosa/skin/icon.png</em:iconURL>
    
     <!-- Firefox -->
     <em:targetApplication>
       <Description>
      <em:id>com.dumbsearch.tuosa</em:id> <!-- Firefox -->
      <em:minVersion>16.0</em:minVersion>
      <em:maxVersion>25.0</em:maxVersion>
       </Description>
     </em:targetApplication>
      </Description>
    </RDF>

    you need to replace

    com.dumbsearch.tuosa
    

    with the guid fixed for firefox:

    {ec8030f7-c20a-464f-9b0e-13a3a9e97384}
    

    https://developer.Mozilla.org/en-us/docs/Install_Manifests#targetApplication

    https://addons.Mozilla.org/en-us/Firefox/pages/appversions/

  • Remove 1 of the 3 domain controllers in a Windows environment

    I have a Windows domain that has Windows 2003 and 2008 R2 servers to support workstations, SharePoint and exchange among other things. There are 3 domain controllers. The first domain controller created on window 2003 server. Later, more 2 domain controllers were added on Windows 2008 R2. During the promotion of each of the servers in DC, each of them were activated as DNS and Global catalog servers. In addition, both 2008 DHCP configuration on them were servers and one Server 2008 R2 is configured as primary and the second as the secondary. The 2003 is just a DC member. I made main hold all 5 FSMO roles and replication works as well on both servers.
    I now have to demote the first Windows Server 2003, and then it must be taken out of the area. But whenever I have to run DCPromo to demote the server he kept a message that no other DC cannot be contacted, and when I try to disable the NIC in Server 2003, replication will stop automatically on the two 2008 R2.

    Any help please.
    Thanks in advance.

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • Problems with cross certification over a link to low bandwidth to the domain controllers in the same forest

    I need to explain to a user a simple explanation on why this is not an effective solution for filing committed in different places trying to share a single file. The file is an excel document and the original file would be shared at 4 different locations on 4 separate domain controllers. The link is weak across all domains at best and the file is accessible by several people at the same time. Server 2003

    Hello

    I suggest you send the same question in the Microsoft Technet Forum for assistance. We have a dedicated team to help you with such questions.
    http://social.technet.Microsoft.com/forums/en/category/windowsxpitpro

  • Creating a domain with the administration server on a remote computer

    Hello

    I do not understand how to create the following architecture:

    physical machine #1: installation of weblogic server = > for the administration server
    physical machine #2: installation of weblogic server + OSB = > for the osb server 1
    physical machine #3: install the weblogic Server + OSB = > intended to be the server of the osb 2.

    If I create my machine field #1 I don't see any options of the OSB in the product list (I tried to copy all the pots in the directory of models of the installation of the OSB on machine #2, but it doesn't seem to work) so I can't create a domain for my server osb.
    If I create my #2 machine field, I see all the options of the OSB in the product list and I can create my domain but I can't make a pack / unpack the machine #1 because I have an error message so I don't know how do to transfer my domain name to the #1 the machine and then start the server administration here.

    All of the documentation I find examples with adminserver running on the same physical computer as osb 1.

    Could someone point me in the right direction?
    Thanks a lot for your help
    Emilien

    Hello Emilien,.

    You must install the same products on 3 servers for this to work.

    It also means that you need an additional license for the #1 server, so that may be an expensive route for :-)

    What about Peter

  • Model reusable SQL Oracle to create a DDL/DML Scripts for Oracle database

    Hello


    I have an obligation to set up a model of Oracle SQL to create the Scripts DDL/DML reusable for Oracle databases.
    Only the Oracle DBA will run scripts permissions is not a problem.

    The workflow for any DOF is as follows:-

    (1) new table

    a. check whether the table exists in the views system/admin.
    b. If the table exists then give message "Table exists".
    c. If the table does not exist then run DDL code

    (2) add the column

    a. check if the column exists for a given table of the system/admin views
    b. If the column exists in the specified table.
    B1. backup table.
    B2. ALTER table alter column
    B3. check data or execute convert dml sauvegardΘ to the new change script.
    c. If the column does not exist
    C1. backup table
    C2. ALTER table add column
    C3. Run dml to populate the column with the default value.

    The DML scripts are to populate the base tables with the data required for business operations.

    (3) addition of new line

    a. check if the line exists by comparing the old values of each column with the new values to be added for the new record.
    b. If there is, to give message line is
    c. If not exists, add the new record.

    (4) update existing record (we createtime columns in these tables as well as changes can be tracked)

    a. check if the row exists using the primary key.
    b. If there is.
    B1. off the record by using the "active" column of the table
    B2. Add new record with the necessary changes.
    c. If does not exist, add the new record with the necessary changes.

    Could you please help with some ideas that can get this done with precision?
    I tried several ways, but I am not able to set up something that meets all the requirements.

    Thank you

    If it helps at all. Sometimes we have a requirement for a DDL statement to be rerunable and her only error if something completely unexpected happens.

    It's a little monstrous, but basically, we wrap all DDL in a dynamic statement and capture errors that would indicate that the DDL script has already been run:

    Here's a bit of a model:

    declare
       w_ddl varchar2(32767);
    begin
       begin
          --
          dbms_output.put_line('Creating table TABLE_NAME');
          --
          w_ddl := 'CREATE TABLE MY_SCHEMA.TABLE_NAME
                    ( COLUMN_1     DATE          NOT NULL
                     ,COLUMN_2  VARCHAR2(10)  NOT NULL
                     ,COLUMN_3  DATE
                    )';
           --
          execute immediate w_ddl;
          --
          dbms_output.put_line('Successfully created table TABLE_NAME');
          --
       exception
          when others then
             if sqlcode = -955 then
                dbms_output.put_line('Table Already exists.');
             else
                dbms_output.put_line('creation of table TABLE_NAME failed:');
                dbms_output.put_line(sqlerrm);
                raise;
             end if;
       end;
    
      begin
          --
          dbms_output.put_line('Creating unique primary key constraint for TABLE_NAME');
          --
          w_ddl := 'ALTER TABLE MY_SCHEMA.TABLE_NAME ADD (
                   CONSTRAINT TABLE_NAME
                   PRIMARY KEY
                   (TABLE_NAME_ID) USING INDEX)';
           --
          execute immediate w_ddl;
          --
          dbms_output.put_line('Successfully created primary key on TABLE_NAME_ID');
          --
       exception
          when others then
             if sqlcode = -02264 then
                dbms_output.put_line('constraint already exists.');
             else
                dbms_output.put_line('creation of primary key failed:');
                dbms_output.put_line(sqlerrm);
                raise;
             end if;
       END;   
    
    <>
    

    It works well with our scripts to autmoated and help us when we iterate through development and back in if needed test environments.

    In this way, we can add the DDL statements to the deployment script and run the script again without error to set the database to the State required without having to run the newly created statement only.

    Sometimes this approach translates into a creation followed a statement alter table statement to add a column, but the end result of the script is always the same, and the deployment script can be controlled at source between iterations of development that is without having to restore the ddl changes to test the modified DDL script.

    hope that gives you some ideas.

Maybe you are looking for

  • Envy: No sound after upgrade to HP

    I did all the updates that HP had in the meantime for my desire and lost sound from my PC. I have ten updated drivers and it did not fix the problem. I was able to restore before the updates & sound returns. Why is happening...?  This kind of questio

  • Can't stay online for more than 2 seconds

    Hello! Recently, I have a problem with my account, I can't stay connected for more than a few seconds and then it disconnects. I tried everything, same journal in other devices, such as my Android phone and the iPad, it's defenetly a problem with my

  • System Exec.vi displays strange errors

    Hello I would like to launch an application of part 3 and let him reduced to a minimum. I could easily run through the cmd "manually" using its directory and run it. Then I tried to use a batch (RunCMWrun.bat) file to the root of C, and it can also l

  • installation of DirectX omitting S1023

    I have a computer that is running Windows XP SP3 and I try to install the DirectX SDK 9 June 2010 release.  I downloaded and saved on the desktop, but after the execution of the it, I get the error message that "an internal error has occurred."  When

  • When you try to open a program, get the area "Choose the program you want to use to open this file".

    When I try and open a program I get the box "choose the program you want to use to open this file. Also, when I try and access any of my icons in my control panel, I get a message saying 'C:\WINDOWS/system32/rundll32.exe. Aplication not found. "