SlideShare a Scribd company logo
1 of 20
Download to read offline
Upgrading Active Directory from 2003 –
2008 R2


Stanley Lopez, Senior Premier Field Engineer
Agenda
 Introducing Windows Server
 2008R2 into Active Directory
 Windows Server 2008R2 Setup
 Requirements
 Windows Server 2008R2 Upgrade
 Scenarios
 Preparing Active Directory
 DC Promo
Implementing Windows Server 2008R2

  New AD Features in Windows Server 2008R2
  Server Versions
  System Requirements
  Full versus Core Installation
  Upgrade Scenarios
  Time Configuration Registry Changes
  Well Known TCP / UDP Dynamic Port Changes
  Kerberos Improvements




                         3
New AD Features in Windows Server 2008R2
   Active Directory Domain Services role in Windows Server 2008/2008R2
   includes many new features that are not available in previous versions
   of Windows Server Active Directory:

     Auditing Enhancements
     Fine-Grain Password Policies
     Read-Only Domain Controllers (RODC)
     Restartable Active Directory Domain Services
     Database Mounting Tool
     DFSR Replication for SYSVOL
     AES(Advance Encryption Standard) Support for Kerberos
     User Interface Improvements
     Preventing Accidental Deletion
     Group Policy Changes (central store, admx, preferences)
     ADLDS

                                      4
Server Versions (only x64 available!)
 Windows Server 2008R2 Foundation
   Available through OEMs only on selected single processor servers, limited to
   15 user accounts
 Windows Server 2008R2 Standard
   Provides most server roles / features and supports Server Core Installation
 Windows Server 2008R2 Enterprise
   Provides Failover Clustering and Active Directory Federation Services
 Windows Server 2008R2 Datacenter
   Additional memory and processors, and unlimited virtual image use rights
 Windows 2008R2 Web Server
   Provides Web / Application / DNS server functionality. Other server roles not
   available.




                                       5
Minimum Storage Requirements for DCs
   500 MB for Active Directory transaction logs.
   500 MB for the drive containing the SYSVOL share.
   1.5 GB to 2 GB for the Windows Server 2008R2 operating system files
   0.4 GB for every 1,000 users in the directory for the NTDS.dit drive
   + 50% of Recommended Disk space for each additional Domain
   Additional storage for each application partition
   Consider pagefile and dump files as well

Recommended reading:
Step D1: Determine Domain Controller Configuration
http://technet.microsoft.com/en-us/library/cc268214.aspx
Performance Tuning Guidelines for Windows Server 2008 R2
http://www.microsoft.com/whdc/system/sysperf/Perf_tun_srv-R2.mspx
Assess hardware requirements
http://technet.microsoft.com/en-us/library/cc753439(WS.10).aspx
How to reclaim space after applying Windows 7/2008 R2 Service Pack 1
http://blogs.technet.com/b/joscon/archive/2011/02/15/how-to-reclaim-space-after-applying-service-
pack-1.aspx

                                                  6
Full versus Core Installation
 Windows Server Core installation provides an environment for
 running one or more of the following server roles:

   Active Directory Directory Services (AD DS)
   Active Directory Lightweight Directory Services (AD LDS)
   Active Directory Certificate Services (ADCS)
   Branch Cache Hosted Cache
   Dynamic Host Configuration Protocol (DHCP) Server
   Domain Name System (DNS) Server
   Hyper-V
   File server
   Print Services
   Windows Media Services
   Web Services
                                  7
Upgrade Scenarios
 Cross Platform Upgrades (32 bit to 64 bit) are not
 supported
 In-place upgrade from Windows 2000 is not supported
 Upgrading existing OS to Server Core is not supported
 Application compatibility issues
   Exchange Server Supportability Matrix (Supported AD environments)
   http://technet.microsoft.com/en-us/library/ee338574.aspx
   Supported Active Directory Environments by Office Communications Server Version
   http://technet.microsoft.com/en-us/library/ee692314(office.13).aspx
   Windows Vista, Windows Server 2008, Windows 7 and Windows Server 2008 R2
   Application Compatibility Update through Dynamic Update: June 2010
   http://support.microsoft.com/kb/982520/en-us
   Application Considerations When Upgrading to Windows Server 2008
   http://technet.microsoft.com/en-us/library/cc771576.aspx
   Known Issues When Upgrading to Windows Server 2008
   http://technet.microsoft.com/en-us/library/cc731003.aspx

                                          8
Time Configuration Registry Changes
    MaxPosPhaseCorrection (DWORD)
    HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeConfig
    The new default value for domain members and domain controllers is 172,800
    (48 hours)


    MaxNegPhaseCorrection (DWORD)
    HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeConfig
    The new default value for domain members and domain controllers is 172,800
    (48 hours)


   This is true for OS clean install and in-place upgrade as well…
   be aware of:
    The Windows Time Group Policy has incorrect defaults after you enable the
    Windows Time Service Group Policy in Windows Server 2008 or Windows Vista
    Service Pack 1 (961027)



                                              9
TCP / UDP Port Considerations

  Windows Server 2008+ aligns port ranges with IANA standards
     The default dynamic port range for TCP/IP has changed in Vista and 2008
     http://support.microsoft.com/kb/929851
     The default dynamic ports ranges are now:
     Win2008+/Vista+:         49152                    through 65535
     Win2003:                 1025                     through 5000
     To adjust dynamic ports:
     netsh int <ipv4|ipv6> set dynamicportrange <tcp|udp> start=number num=range



  Root domain connectivity needed
     Logoff takes several minutes if there is no LDAP connectivity to the forest root domain
     http://support.microsoft.com/default.aspx?scid=kb;EN-US;971198
     Cannot install AD if the DNS and LDAP traffic to the forest root domain is blocked
     http://support.microsoft.com/kb/975142/en-us




                                             10
Kerberos changes (AES)
     Changes in default encryption type cause security audit
     events 675 and 680 on Windows Server 2003 DCs
     It is possible to start pre-authentication with RC4 by
     modifying the DefaultEncryptionType registry value to
     0x17 hex (0x18 hex is AES).




http://blogs.technet.com/instan/archive/2009/10/12/changes-in-default-encryption-type-for-kerberos-pre-
    authentication-on-vista-and-windows-7-clients-cause-security-audit-events-675-and-680-on-windows-server-2003-
    dc-s.aspx

                                                        11
Other Known Issues
Topic                         2003    2008R2 Comment
AllowNT4Crypto               N/A      Disabled Third-party Server Message Block (SMB) clients may be incompatible with the secure default settings on Windows
                                               Server 2008 and Windows Server 2008 R2 domain controllers. Article 942564

DES                          Enable   Disabled The security principals and the services that use only DES encryption for Kerberos authentication are incompatible with
                             d                 the default settings on a computer that is running Windows 7 or Windows Server 2008 R2
                                               Article 977321
                                               Article 978055

CBT/Extended Protection       N/A     Enabled  See Microsoft Security Advisory (937811) and article 976918
for Integrated Authentication                  Control Extended Protection for Authentication using Security Policy
                                               http://blogs.technet.com/b/askds/archive/2009/12/10/control-extended-protection-for-authentication-using-security-
                                               policy.aspx
LMv2                         Enable   Disabled Computers that are running Windows 7 and Windows Server 2008 R2 may fail to be authenticated by non-Windows
                             d                 NTLM or Kerberos-based servers
                                               Article 976918
                                               You may experience one or more of the following symptoms:
                                               1.      Windows clients that support channel binding fail to be authenticated by a non-Windows Kerberos server.
                                               2.      NTLM authentication failures from Proxy servers.
                                               3.      NTLM authentication failures from non-Windows NTLM servers.
                                               4.      NTLM authentication failures when there is a time difference between the client and DC or workgroup server.

LMhash                       Enable   Disabled If you add Windows Server 2008 as the domain controller to an existing domain by using the default domain policy, the
                             d                 NoLMHash policy of the existing domain controller is disabled. Additionally, the NoLMHash policy in Windows Server
                                               2008 is enabled. Article 946405
Signing required             No       Yes       Domain controllers that run Windows Server 2008 and Windows Server 2008 R2 require (by default) that all client
                                                computers attempting to authenticate to them perform Server Message Block (SMB) packet signing and secure channel
                                                signing. http://technet.microsoft.com/en-us/library/cc731654(WS.10).aspx

EDNS                         N/A      N/A       Some DNS name queries are unsuccessful after you deploy a 2003 or 2008 R2-based DNS server
                                                http://support.microsoft.com/kb/832223
PDC lockouts, lmcompat       ?        3         When you see massive account lockouts from transitive NTLM authentication, there is likely a mismatch of the lanman
                                                authentication level between the clients and DCs in the path.
                                                http://blogs.technet.com/b/askds/archive/2011/02/22/i-moved-my-pdce-role-and-accounts-started-locking-out.aspx
Hotfix List                  N/A      N/A       For a sample list with recommended hotfixes, see askds Blog or evaluate SP1 (recommended).


                                                                              12
Preparing AD Environment for Windows Server 2008R2
   Create a lab first!
   Trigger garbage collection on all DCs
   Locate Schema Master and disable outbound replication
   Forestprep: Prepare an existing forest for a Windows Server 2008R2 DC
   Domainprep: Prepare an existing domain for a Windows Server 2008R2 DC
   Rodcprep: prepare an existing forest for Windows Server 2008R2 RODC
   Verify adprep logs
   Enable outbound replication
Note
       Use adprep32 on 32-bit systems instead
       Location of ADPREP debug logs has moved from %systemroot%system32debug to %systemroot%debugadprep
       ADPREP error lists can be found at:
       http://technet.microsoft.com/en-us/library/ee522994(WS.10).aspx#BKMK_AdprepErrors
       http://blogs.technet.com/askds/archive/2008R2/12/15/troubleshooting-adprep-errors.aspx
       Upgrade Domain Controllers: Microsoft Support Quick Start for Adding Windows Server 2008 or Windows Server
       2008 R2 Domain Controllers to Existing Domains
       http://technet.microsoft.com/en-us/library/upgrade-domain-controllers-to-windows-server-2008-r2(WS.10).aspx
       For creating a lab see: Testing for Active Directory Schema Extension Conflicts
       http://technet.microsoft.com/en-us/library/testing-for-active-directory-schema-extension-conflicts(WS.10).aspx
       SP1 and Directory Services (added on 14-Jan 2011):
       http://blogs.technet.com/b/askds/archive/2011/01/14/sp1-and-directory-services-what-s-new.aspx


                                                           13
RODC Considerations with ADPREP

  For the deployment of RODC: FFL must be 2003 or
  higher, so that linked-value replication is available
  If the RODC will be a global catalog server, you must
  also run adprep /domainprep in all domains in the
  forest.
  The first Windows Server 2008R2 domain controller in
  an existing Windows 2000, Windows Server 2003 or
  Windows Server 2008R2 domain cannot be created as a
  RODC
  Be aware of KB 949257 (invalid fsmoroleowner)



                           14
Identify Schema Version

     Determine the current version of the Active Directory schema by
     checking the value ObjectVersion attribute of the
     dn=schema,cn=configuration,dc=<root_domain> partition
 Example:
 dsquery * cn=schema,cn=configuration,dc=<root_domain> -scope base -attr
   objectVersion
 o   Applications track schema changes differently, you need to query
     different object each time.
 For example Exchange:
   dsquery * CN=ms-Exch-Schema-Version-Pt,cn=schema,cn=configuration,
   dc=<root_domain> -scope base -attr rangeUpper




                                    15
Schema Versions

  Checking the value ObjectVersion attribute of the
  dn=schema,cn=configuration,dc=<root_domain>
  partition


   Operating System                  Schema Version
   Windows 2000 Server                     13
   Windows Server 2003                     30
   Windows Server 2003 R2                  31
   Windows Server 2008                     44
   Windows Server 2008R2                   47


                            16
Active Directory Installation

   New Installation Options
   DCPROMO Enhancements
   Adding the DC Role using Server Manager
   Unattended Installation Options
   Global Catalog Options
   DNS Options




                           17
New DCPROMO Installation Options

  Pick Source Domain Controller
  Pick Destination Site
  DNS installed automatically (cover later in this module
  and in detail in the DNS module)
  Optional Global Catalog install
  Automatic reboot on completion
  Installs GPMC by default.




                             18
Demo




       19
Questions???

More Related Content

What's hot

Microsoft Defender for Endpoint
Microsoft Defender for EndpointMicrosoft Defender for Endpoint
Microsoft Defender for EndpointCheah Eng Soon
 
Identity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyIdentity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyDavid J Rosenthal
 
Microsoft Azure Active Directory
Microsoft Azure Active DirectoryMicrosoft Azure Active Directory
Microsoft Azure Active DirectoryDavid J Rosenthal
 
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021Alphorm
 
Microsoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewMicrosoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewDavid J Rosenthal
 
Cloud Adoption Framework - Overview_partner.pptx
Cloud Adoption Framework - Overview_partner.pptxCloud Adoption Framework - Overview_partner.pptx
Cloud Adoption Framework - Overview_partner.pptxabhishek22611
 
Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE)Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE)Anwesh Dixit
 
Windows Azure Active Directory
Windows Azure Active DirectoryWindows Azure Active Directory
Windows Azure Active DirectoryKrunal Trivedi
 
Azure Migrate
Azure MigrateAzure Migrate
Azure MigrateMustafa
 
Active Directory Proposal
Active Directory ProposalActive Directory Proposal
Active Directory ProposalMJ Ferdous
 
Introduction to Hyper-V
Introduction to Hyper-VIntroduction to Hyper-V
Introduction to Hyper-VMark Wilson
 
IDaaS を正しく活用するための認証基盤設計
IDaaS を正しく活用するための認証基盤設計IDaaS を正しく活用するための認証基盤設計
IDaaS を正しく活用するための認証基盤設計Trainocate Japan, Ltd.
 
Azure Site Recovery Bootcamp
Azure Site Recovery BootcampAzure Site Recovery Bootcamp
Azure Site Recovery BootcampAsaf Nakash
 
PCF-VxRail-ReferenceArchiteture
PCF-VxRail-ReferenceArchiteturePCF-VxRail-ReferenceArchiteture
PCF-VxRail-ReferenceArchitetureVuong Pham
 
Microsoft azure overview
Microsoft azure overviewMicrosoft azure overview
Microsoft azure overviewAli Mkahal
 
Windows server 2016 storage step by step complete lab
Windows server 2016 storage step by step complete labWindows server 2016 storage step by step complete lab
Windows server 2016 storage step by step complete labAhmed Abdelwahed
 

What's hot (20)

Microsoft Defender for Endpoint
Microsoft Defender for EndpointMicrosoft Defender for Endpoint
Microsoft Defender for Endpoint
 
Identity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyIdentity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor Technology
 
Présentation AzureAD ( Identité hybrides et securité)
Présentation AzureAD ( Identité hybrides et securité)Présentation AzureAD ( Identité hybrides et securité)
Présentation AzureAD ( Identité hybrides et securité)
 
Microsoft Azure Active Directory
Microsoft Azure Active DirectoryMicrosoft Azure Active Directory
Microsoft Azure Active Directory
 
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021
Alphorm.com Formation Microsoft Azure : Azure Active Directory 2021
 
Microsoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewMicrosoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security Overview
 
Azure 101
Azure 101Azure 101
Azure 101
 
Cloud Adoption Framework - Overview_partner.pptx
Cloud Adoption Framework - Overview_partner.pptxCloud Adoption Framework - Overview_partner.pptx
Cloud Adoption Framework - Overview_partner.pptx
 
Azure Active Directory
Azure Active DirectoryAzure Active Directory
Azure Active Directory
 
Azure Backup Simplifies
Azure Backup SimplifiesAzure Backup Simplifies
Azure Backup Simplifies
 
Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE)Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE)
 
Windows Azure Active Directory
Windows Azure Active DirectoryWindows Azure Active Directory
Windows Azure Active Directory
 
Azure Migrate
Azure MigrateAzure Migrate
Azure Migrate
 
Active Directory Proposal
Active Directory ProposalActive Directory Proposal
Active Directory Proposal
 
Introduction to Hyper-V
Introduction to Hyper-VIntroduction to Hyper-V
Introduction to Hyper-V
 
IDaaS を正しく活用するための認証基盤設計
IDaaS を正しく活用するための認証基盤設計IDaaS を正しく活用するための認証基盤設計
IDaaS を正しく活用するための認証基盤設計
 
Azure Site Recovery Bootcamp
Azure Site Recovery BootcampAzure Site Recovery Bootcamp
Azure Site Recovery Bootcamp
 
PCF-VxRail-ReferenceArchiteture
PCF-VxRail-ReferenceArchiteturePCF-VxRail-ReferenceArchiteture
PCF-VxRail-ReferenceArchiteture
 
Microsoft azure overview
Microsoft azure overviewMicrosoft azure overview
Microsoft azure overview
 
Windows server 2016 storage step by step complete lab
Windows server 2016 storage step by step complete labWindows server 2016 storage step by step complete lab
Windows server 2016 storage step by step complete lab
 

Viewers also liked

Checking the health of your active directory enviornment
Checking the health of your active directory enviornmentChecking the health of your active directory enviornment
Checking the health of your active directory enviornmentSpiffy
 
Agile in Action - Act 2: Development
Agile in Action - Act 2: DevelopmentAgile in Action - Act 2: Development
Agile in Action - Act 2: DevelopmentSpiffy
 
Cloud Brokering and Provisioning: How Technicolor Does It
Cloud Brokering and Provisioning: How Technicolor Does It Cloud Brokering and Provisioning: How Technicolor Does It
Cloud Brokering and Provisioning: How Technicolor Does It RightScale
 
VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...
VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...
VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...VMworld
 
Windows Server 2012 R2 Hyper V Component Architecture
Windows Server 2012 R2 Hyper V Component ArchitectureWindows Server 2012 R2 Hyper V Component Architecture
Windows Server 2012 R2 Hyper V Component ArchitectureRian Yulian
 
CTU June 2011 - Guided Hands on Lab on GPO - GPP
CTU June 2011 - Guided Hands on Lab on GPO - GPPCTU June 2011 - Guided Hands on Lab on GPO - GPP
CTU June 2011 - Guided Hands on Lab on GPO - GPPSpiffy
 
Why Upgrade To Windows Server 2012
Why Upgrade To Windows Server 2012Why Upgrade To Windows Server 2012
Why Upgrade To Windows Server 2012Aidan Finn
 
What's new in Windows Server 2012 R2
What's new in Windows Server 2012 R2What's new in Windows Server 2012 R2
What's new in Windows Server 2012 R2Christopher Keyaert
 
Best MCSA - SQL SERVER 2012 Training Institute in Delhi
Best MCSA - SQL SERVER 2012 Training Institute in DelhiBest MCSA - SQL SERVER 2012 Training Institute in Delhi
Best MCSA - SQL SERVER 2012 Training Institute in DelhiInformation Technology
 

Viewers also liked (20)

Checking the health of your active directory enviornment
Checking the health of your active directory enviornmentChecking the health of your active directory enviornment
Checking the health of your active directory enviornment
 
Agile in Action - Act 2: Development
Agile in Action - Act 2: DevelopmentAgile in Action - Act 2: Development
Agile in Action - Act 2: Development
 
Active Directory
Active Directory Active Directory
Active Directory
 
Cloud Brokering and Provisioning: How Technicolor Does It
Cloud Brokering and Provisioning: How Technicolor Does It Cloud Brokering and Provisioning: How Technicolor Does It
Cloud Brokering and Provisioning: How Technicolor Does It
 
VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...
VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...
VMworld 2013: IaaS Case Study: How the University of New Mexico Improved Serv...
 
Windows Server 2012 R2 Hyper V Component Architecture
Windows Server 2012 R2 Hyper V Component ArchitectureWindows Server 2012 R2 Hyper V Component Architecture
Windows Server 2012 R2 Hyper V Component Architecture
 
Microsoft Windows Network Auditing and Reporting Solution
Microsoft Windows Network Auditing and Reporting SolutionMicrosoft Windows Network Auditing and Reporting Solution
Microsoft Windows Network Auditing and Reporting Solution
 
Dhcp
DhcpDhcp
Dhcp
 
Active Directory Auditing and Reporting Tool
Active Directory Auditing and Reporting ToolActive Directory Auditing and Reporting Tool
Active Directory Auditing and Reporting Tool
 
What is active directory
What is active directoryWhat is active directory
What is active directory
 
70 640 Lesson03 Ppt 041009
70 640 Lesson03 Ppt 04100970 640 Lesson03 Ppt 041009
70 640 Lesson03 Ppt 041009
 
70 640 Lesson04 Ppt 041009
70 640 Lesson04 Ppt 04100970 640 Lesson04 Ppt 041009
70 640 Lesson04 Ppt 041009
 
CTU June 2011 - Guided Hands on Lab on GPO - GPP
CTU June 2011 - Guided Hands on Lab on GPO - GPPCTU June 2011 - Guided Hands on Lab on GPO - GPP
CTU June 2011 - Guided Hands on Lab on GPO - GPP
 
70 640 Lesson07 Ppt 041009
70 640 Lesson07 Ppt 04100970 640 Lesson07 Ppt 041009
70 640 Lesson07 Ppt 041009
 
70 640 Lesson05 Ppt 041009
70 640 Lesson05 Ppt 04100970 640 Lesson05 Ppt 041009
70 640 Lesson05 Ppt 041009
 
Why Upgrade To Windows Server 2012
Why Upgrade To Windows Server 2012Why Upgrade To Windows Server 2012
Why Upgrade To Windows Server 2012
 
70 640 Lesson02 Ppt 041009
70 640 Lesson02 Ppt 04100970 640 Lesson02 Ppt 041009
70 640 Lesson02 Ppt 041009
 
What's new in Windows Server 2012 R2
What's new in Windows Server 2012 R2What's new in Windows Server 2012 R2
What's new in Windows Server 2012 R2
 
Best MCSA - SQL SERVER 2012 Training Institute in Delhi
Best MCSA - SQL SERVER 2012 Training Institute in DelhiBest MCSA - SQL SERVER 2012 Training Institute in Delhi
Best MCSA - SQL SERVER 2012 Training Institute in Delhi
 
Itil process framework__rowe(40)
Itil process framework__rowe(40)Itil process framework__rowe(40)
Itil process framework__rowe(40)
 

Similar to Active Directory Upgrade

Windows 2008 R2 Security
Windows 2008 R2 SecurityWindows 2008 R2 Security
Windows 2008 R2 SecurityAmit Gatenyo
 
Reply 1 neededThere are a couple of options available when upg.docx
Reply 1 neededThere are a couple of options available when upg.docxReply 1 neededThere are a couple of options available when upg.docx
Reply 1 neededThere are a couple of options available when upg.docxsodhi3
 
Windows 2008 R2 Overview
Windows 2008 R2 OverviewWindows 2008 R2 Overview
Windows 2008 R2 OverviewAmit Gatenyo
 
Win08 R2 It Pro Overview
Win08 R2 It Pro OverviewWin08 R2 It Pro Overview
Win08 R2 It Pro Overviewguest092b9a8
 
Windows Server 2008 R2
Windows Server 2008 R2Windows Server 2008 R2
Windows Server 2008 R2Rishu Mehra
 
Microsoft Windows Server.pdf
Microsoft Windows Server.pdfMicrosoft Windows Server.pdf
Microsoft Windows Server.pdfJames Brown
 
Windows Server 2008 R2 Dev Session 01
Windows Server 2008 R2 Dev Session 01Windows Server 2008 R2 Dev Session 01
Windows Server 2008 R2 Dev Session 01Clint Edmonson
 
CSS computer system servicing-presentation.pptx
CSS computer system servicing-presentation.pptxCSS computer system servicing-presentation.pptx
CSS computer system servicing-presentation.pptxGelreyLugoJaysonAli
 
Keynote talk on Windows 8 - Jeff Stokes
Keynote talk on Windows 8 - Jeff StokesKeynote talk on Windows 8 - Jeff Stokes
Keynote talk on Windows 8 - Jeff StokesJeff Stokes
 
0505 Windows Server 2008 一日精華營 Part II
0505 Windows Server 2008 一日精華營 Part II0505 Windows Server 2008 一日精華營 Part II
0505 Windows Server 2008 一日精華營 Part IITimothy Chen
 
Active Directory 2008 R2 Updates
Active Directory 2008 R2 UpdatesActive Directory 2008 R2 Updates
Active Directory 2008 R2 UpdatesAmit Gatenyo
 
Virtual Server Presentation Dha
Virtual Server Presentation DhaVirtual Server Presentation Dha
Virtual Server Presentation Dhamcshinsky
 
Material modulo01 asf6501(6419-a_01)
Material   modulo01 asf6501(6419-a_01)Material   modulo01 asf6501(6419-a_01)
Material modulo01 asf6501(6419-a_01)JSantanderQ
 
Virtualization Seminar Beekelaar Dublin 18jan2007
Virtualization Seminar Beekelaar Dublin 18jan2007Virtualization Seminar Beekelaar Dublin 18jan2007
Virtualization Seminar Beekelaar Dublin 18jan2007rajsri
 
0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartI0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartITimothy Chen
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewAlexander Schek
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 Overviewjjalea
 

Similar to Active Directory Upgrade (20)

Windows sever 2008
Windows sever 2008Windows sever 2008
Windows sever 2008
 
Windows 2008 R2 Security
Windows 2008 R2 SecurityWindows 2008 R2 Security
Windows 2008 R2 Security
 
Reply 1 neededThere are a couple of options available when upg.docx
Reply 1 neededThere are a couple of options available when upg.docxReply 1 neededThere are a couple of options available when upg.docx
Reply 1 neededThere are a couple of options available when upg.docx
 
Windows 2008 R2 Overview
Windows 2008 R2 OverviewWindows 2008 R2 Overview
Windows 2008 R2 Overview
 
Win08 R2 It Pro Overview
Win08 R2 It Pro OverviewWin08 R2 It Pro Overview
Win08 R2 It Pro Overview
 
Windows Server 2008 R2
Windows Server 2008 R2Windows Server 2008 R2
Windows Server 2008 R2
 
Microsoft Windows Server.pdf
Microsoft Windows Server.pdfMicrosoft Windows Server.pdf
Microsoft Windows Server.pdf
 
Windows Server 2008 R2 Dev Session 01
Windows Server 2008 R2 Dev Session 01Windows Server 2008 R2 Dev Session 01
Windows Server 2008 R2 Dev Session 01
 
CSS computer system servicing-presentation.pptx
CSS computer system servicing-presentation.pptxCSS computer system servicing-presentation.pptx
CSS computer system servicing-presentation.pptx
 
Vikas Yadav
Vikas YadavVikas Yadav
Vikas Yadav
 
Keynote talk on Windows 8 - Jeff Stokes
Keynote talk on Windows 8 - Jeff StokesKeynote talk on Windows 8 - Jeff Stokes
Keynote talk on Windows 8 - Jeff Stokes
 
0505 Windows Server 2008 一日精華營 Part II
0505 Windows Server 2008 一日精華營 Part II0505 Windows Server 2008 一日精華營 Part II
0505 Windows Server 2008 一日精華營 Part II
 
Active Directory 2008 R2 Updates
Active Directory 2008 R2 UpdatesActive Directory 2008 R2 Updates
Active Directory 2008 R2 Updates
 
Virtual Server Presentation Dha
Virtual Server Presentation DhaVirtual Server Presentation Dha
Virtual Server Presentation Dha
 
Material modulo01 asf6501(6419-a_01)
Material   modulo01 asf6501(6419-a_01)Material   modulo01 asf6501(6419-a_01)
Material modulo01 asf6501(6419-a_01)
 
Virtualization Seminar Beekelaar Dublin 18jan2007
Virtualization Seminar Beekelaar Dublin 18jan2007Virtualization Seminar Beekelaar Dublin 18jan2007
Virtualization Seminar Beekelaar Dublin 18jan2007
 
0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartI0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartI
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 Overview
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 Overview
 
MCITP
MCITPMCITP
MCITP
 

More from Spiffy

01 server manager spiffy
01 server manager spiffy01 server manager spiffy
01 server manager spiffySpiffy
 
Agile in Action - Act 3: Testing
Agile in Action - Act 3: TestingAgile in Action - Act 3: Testing
Agile in Action - Act 3: TestingSpiffy
 
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?Spiffy
 
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)Spiffy
 
MS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for ThatMS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for ThatSpiffy
 
MS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and LouieMS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and LouieSpiffy
 
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7Spiffy
 
MS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on AzureMS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on AzureSpiffy
 
MS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome BitsMS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome BitsSpiffy
 
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure PlatformMS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure PlatformSpiffy
 
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure SolutionsMS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure SolutionsSpiffy
 
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data ProtectionMS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data ProtectionSpiffy
 
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid DeploymentMS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid DeploymentSpiffy
 
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...Spiffy
 
MS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application ControllerMS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application ControllerSpiffy
 
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize PerformanceMS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize PerformanceSpiffy
 
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...Spiffy
 
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...Spiffy
 
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...Spiffy
 
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...Spiffy
 

More from Spiffy (20)

01 server manager spiffy
01 server manager spiffy01 server manager spiffy
01 server manager spiffy
 
Agile in Action - Act 3: Testing
Agile in Action - Act 3: TestingAgile in Action - Act 3: Testing
Agile in Action - Act 3: Testing
 
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
Agile in Action - Keynote: Becoming and Being Agile - What Does This Mean?
 
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
Agile in Action - Act 1 (Set Up, Planning, Requirements and Architecture)
 
MS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for ThatMS TechDays 2011 - WCF Web APis There's a URI for That
MS TechDays 2011 - WCF Web APis There's a URI for That
 
MS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and LouieMS TechDays 2011 - NUI, Gooey and Louie
MS TechDays 2011 - NUI, Gooey and Louie
 
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
MS TechDays 2011 - Mango, Mango! Developing for Windows Phone 7
 
MS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on AzureMS TechDays 2011 - Generate Revenue on Azure
MS TechDays 2011 - Generate Revenue on Azure
 
MS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome BitsMS TechDays 2011 - HTML 5 All the Awesome Bits
MS TechDays 2011 - HTML 5 All the Awesome Bits
 
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure PlatformMS TechDays 2011 - Cloud Computing with the Windows Azure Platform
MS TechDays 2011 - Cloud Computing with the Windows Azure Platform
 
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure SolutionsMS TechDays 2011 - Simplified Converged Infrastructure Solutions
MS TechDays 2011 - Simplified Converged Infrastructure Solutions
 
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data ProtectionMS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
MS TechDays 2011 - SCDPM 2012 The New Feature of Data Protection
 
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid DeploymentMS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment
MS TechDays 2011 - Microsoft Exchange Server and Office 365 Hybrid Deployment
 
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
MS TechDays 2011 - How to Run Middleware in the Cloud Story of Windows Azure ...
 
MS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application ControllerMS TechDays 2011 - Cloud Management with System Center Application Controller
MS TechDays 2011 - Cloud Management with System Center Application Controller
 
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize PerformanceMS TechDays 2011 - Virtualization Solutions to Optimize Performance
MS TechDays 2011 - Virtualization Solutions to Optimize Performance
 
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
MS TechDays 2011 - Automating Your Infrastructure System Center Orchestrator ...
 
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
MS TechDays 2011 - Self-Service Private Cloud Management through Integrated P...
 
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...
MS TechDays 2011 - SCVMM 2012 Building of Private Clouds and Federation to th...
 
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...
MS TechDays 2011 - Operation Manager 2012 - New features to Enhance Enterpris...
 

Recently uploaded

DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 

Recently uploaded (20)

DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 

Active Directory Upgrade

  • 1. Upgrading Active Directory from 2003 – 2008 R2 Stanley Lopez, Senior Premier Field Engineer
  • 2. Agenda Introducing Windows Server 2008R2 into Active Directory Windows Server 2008R2 Setup Requirements Windows Server 2008R2 Upgrade Scenarios Preparing Active Directory DC Promo
  • 3. Implementing Windows Server 2008R2 New AD Features in Windows Server 2008R2 Server Versions System Requirements Full versus Core Installation Upgrade Scenarios Time Configuration Registry Changes Well Known TCP / UDP Dynamic Port Changes Kerberos Improvements 3
  • 4. New AD Features in Windows Server 2008R2 Active Directory Domain Services role in Windows Server 2008/2008R2 includes many new features that are not available in previous versions of Windows Server Active Directory: Auditing Enhancements Fine-Grain Password Policies Read-Only Domain Controllers (RODC) Restartable Active Directory Domain Services Database Mounting Tool DFSR Replication for SYSVOL AES(Advance Encryption Standard) Support for Kerberos User Interface Improvements Preventing Accidental Deletion Group Policy Changes (central store, admx, preferences) ADLDS 4
  • 5. Server Versions (only x64 available!) Windows Server 2008R2 Foundation Available through OEMs only on selected single processor servers, limited to 15 user accounts Windows Server 2008R2 Standard Provides most server roles / features and supports Server Core Installation Windows Server 2008R2 Enterprise Provides Failover Clustering and Active Directory Federation Services Windows Server 2008R2 Datacenter Additional memory and processors, and unlimited virtual image use rights Windows 2008R2 Web Server Provides Web / Application / DNS server functionality. Other server roles not available. 5
  • 6. Minimum Storage Requirements for DCs 500 MB for Active Directory transaction logs. 500 MB for the drive containing the SYSVOL share. 1.5 GB to 2 GB for the Windows Server 2008R2 operating system files 0.4 GB for every 1,000 users in the directory for the NTDS.dit drive + 50% of Recommended Disk space for each additional Domain Additional storage for each application partition Consider pagefile and dump files as well Recommended reading: Step D1: Determine Domain Controller Configuration http://technet.microsoft.com/en-us/library/cc268214.aspx Performance Tuning Guidelines for Windows Server 2008 R2 http://www.microsoft.com/whdc/system/sysperf/Perf_tun_srv-R2.mspx Assess hardware requirements http://technet.microsoft.com/en-us/library/cc753439(WS.10).aspx How to reclaim space after applying Windows 7/2008 R2 Service Pack 1 http://blogs.technet.com/b/joscon/archive/2011/02/15/how-to-reclaim-space-after-applying-service- pack-1.aspx 6
  • 7. Full versus Core Installation Windows Server Core installation provides an environment for running one or more of the following server roles: Active Directory Directory Services (AD DS) Active Directory Lightweight Directory Services (AD LDS) Active Directory Certificate Services (ADCS) Branch Cache Hosted Cache Dynamic Host Configuration Protocol (DHCP) Server Domain Name System (DNS) Server Hyper-V File server Print Services Windows Media Services Web Services 7
  • 8. Upgrade Scenarios Cross Platform Upgrades (32 bit to 64 bit) are not supported In-place upgrade from Windows 2000 is not supported Upgrading existing OS to Server Core is not supported Application compatibility issues Exchange Server Supportability Matrix (Supported AD environments) http://technet.microsoft.com/en-us/library/ee338574.aspx Supported Active Directory Environments by Office Communications Server Version http://technet.microsoft.com/en-us/library/ee692314(office.13).aspx Windows Vista, Windows Server 2008, Windows 7 and Windows Server 2008 R2 Application Compatibility Update through Dynamic Update: June 2010 http://support.microsoft.com/kb/982520/en-us Application Considerations When Upgrading to Windows Server 2008 http://technet.microsoft.com/en-us/library/cc771576.aspx Known Issues When Upgrading to Windows Server 2008 http://technet.microsoft.com/en-us/library/cc731003.aspx 8
  • 9. Time Configuration Registry Changes MaxPosPhaseCorrection (DWORD) HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeConfig The new default value for domain members and domain controllers is 172,800 (48 hours) MaxNegPhaseCorrection (DWORD) HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeConfig The new default value for domain members and domain controllers is 172,800 (48 hours)  This is true for OS clean install and in-place upgrade as well…  be aware of: The Windows Time Group Policy has incorrect defaults after you enable the Windows Time Service Group Policy in Windows Server 2008 or Windows Vista Service Pack 1 (961027) 9
  • 10. TCP / UDP Port Considerations Windows Server 2008+ aligns port ranges with IANA standards The default dynamic port range for TCP/IP has changed in Vista and 2008 http://support.microsoft.com/kb/929851 The default dynamic ports ranges are now: Win2008+/Vista+: 49152 through 65535 Win2003: 1025 through 5000 To adjust dynamic ports: netsh int <ipv4|ipv6> set dynamicportrange <tcp|udp> start=number num=range Root domain connectivity needed Logoff takes several minutes if there is no LDAP connectivity to the forest root domain http://support.microsoft.com/default.aspx?scid=kb;EN-US;971198 Cannot install AD if the DNS and LDAP traffic to the forest root domain is blocked http://support.microsoft.com/kb/975142/en-us 10
  • 11. Kerberos changes (AES) Changes in default encryption type cause security audit events 675 and 680 on Windows Server 2003 DCs It is possible to start pre-authentication with RC4 by modifying the DefaultEncryptionType registry value to 0x17 hex (0x18 hex is AES). http://blogs.technet.com/instan/archive/2009/10/12/changes-in-default-encryption-type-for-kerberos-pre- authentication-on-vista-and-windows-7-clients-cause-security-audit-events-675-and-680-on-windows-server-2003- dc-s.aspx 11
  • 12. Other Known Issues Topic 2003 2008R2 Comment AllowNT4Crypto N/A Disabled Third-party Server Message Block (SMB) clients may be incompatible with the secure default settings on Windows Server 2008 and Windows Server 2008 R2 domain controllers. Article 942564 DES Enable Disabled The security principals and the services that use only DES encryption for Kerberos authentication are incompatible with d the default settings on a computer that is running Windows 7 or Windows Server 2008 R2 Article 977321 Article 978055 CBT/Extended Protection N/A Enabled See Microsoft Security Advisory (937811) and article 976918 for Integrated Authentication Control Extended Protection for Authentication using Security Policy http://blogs.technet.com/b/askds/archive/2009/12/10/control-extended-protection-for-authentication-using-security- policy.aspx LMv2 Enable Disabled Computers that are running Windows 7 and Windows Server 2008 R2 may fail to be authenticated by non-Windows d NTLM or Kerberos-based servers Article 976918 You may experience one or more of the following symptoms: 1. Windows clients that support channel binding fail to be authenticated by a non-Windows Kerberos server. 2. NTLM authentication failures from Proxy servers. 3. NTLM authentication failures from non-Windows NTLM servers. 4. NTLM authentication failures when there is a time difference between the client and DC or workgroup server. LMhash Enable Disabled If you add Windows Server 2008 as the domain controller to an existing domain by using the default domain policy, the d NoLMHash policy of the existing domain controller is disabled. Additionally, the NoLMHash policy in Windows Server 2008 is enabled. Article 946405 Signing required No Yes Domain controllers that run Windows Server 2008 and Windows Server 2008 R2 require (by default) that all client computers attempting to authenticate to them perform Server Message Block (SMB) packet signing and secure channel signing. http://technet.microsoft.com/en-us/library/cc731654(WS.10).aspx EDNS N/A N/A Some DNS name queries are unsuccessful after you deploy a 2003 or 2008 R2-based DNS server http://support.microsoft.com/kb/832223 PDC lockouts, lmcompat ? 3 When you see massive account lockouts from transitive NTLM authentication, there is likely a mismatch of the lanman authentication level between the clients and DCs in the path. http://blogs.technet.com/b/askds/archive/2011/02/22/i-moved-my-pdce-role-and-accounts-started-locking-out.aspx Hotfix List N/A N/A For a sample list with recommended hotfixes, see askds Blog or evaluate SP1 (recommended). 12
  • 13. Preparing AD Environment for Windows Server 2008R2 Create a lab first! Trigger garbage collection on all DCs Locate Schema Master and disable outbound replication Forestprep: Prepare an existing forest for a Windows Server 2008R2 DC Domainprep: Prepare an existing domain for a Windows Server 2008R2 DC Rodcprep: prepare an existing forest for Windows Server 2008R2 RODC Verify adprep logs Enable outbound replication Note Use adprep32 on 32-bit systems instead Location of ADPREP debug logs has moved from %systemroot%system32debug to %systemroot%debugadprep ADPREP error lists can be found at: http://technet.microsoft.com/en-us/library/ee522994(WS.10).aspx#BKMK_AdprepErrors http://blogs.technet.com/askds/archive/2008R2/12/15/troubleshooting-adprep-errors.aspx Upgrade Domain Controllers: Microsoft Support Quick Start for Adding Windows Server 2008 or Windows Server 2008 R2 Domain Controllers to Existing Domains http://technet.microsoft.com/en-us/library/upgrade-domain-controllers-to-windows-server-2008-r2(WS.10).aspx For creating a lab see: Testing for Active Directory Schema Extension Conflicts http://technet.microsoft.com/en-us/library/testing-for-active-directory-schema-extension-conflicts(WS.10).aspx SP1 and Directory Services (added on 14-Jan 2011): http://blogs.technet.com/b/askds/archive/2011/01/14/sp1-and-directory-services-what-s-new.aspx 13
  • 14. RODC Considerations with ADPREP For the deployment of RODC: FFL must be 2003 or higher, so that linked-value replication is available If the RODC will be a global catalog server, you must also run adprep /domainprep in all domains in the forest. The first Windows Server 2008R2 domain controller in an existing Windows 2000, Windows Server 2003 or Windows Server 2008R2 domain cannot be created as a RODC Be aware of KB 949257 (invalid fsmoroleowner) 14
  • 15. Identify Schema Version Determine the current version of the Active Directory schema by checking the value ObjectVersion attribute of the dn=schema,cn=configuration,dc=<root_domain> partition Example: dsquery * cn=schema,cn=configuration,dc=<root_domain> -scope base -attr objectVersion o Applications track schema changes differently, you need to query different object each time. For example Exchange: dsquery * CN=ms-Exch-Schema-Version-Pt,cn=schema,cn=configuration, dc=<root_domain> -scope base -attr rangeUpper 15
  • 16. Schema Versions Checking the value ObjectVersion attribute of the dn=schema,cn=configuration,dc=<root_domain> partition Operating System Schema Version Windows 2000 Server 13 Windows Server 2003 30 Windows Server 2003 R2 31 Windows Server 2008 44 Windows Server 2008R2 47 16
  • 17. Active Directory Installation New Installation Options DCPROMO Enhancements Adding the DC Role using Server Manager Unattended Installation Options Global Catalog Options DNS Options 17
  • 18. New DCPROMO Installation Options Pick Source Domain Controller Pick Destination Site DNS installed automatically (cover later in this module and in detail in the DNS module) Optional Global Catalog install Automatic reboot on completion Installs GPMC by default. 18
  • 19. Demo 19