We have 4 domain controllers, each serving a physical location. Replication between the servers has failed and there are multiple Kerberos errors. Our server provider has dug deeper and found multiple issues, and have recommended new DCs.<\/p>\n
Advertisement
We would like to remain on the same domain name to save having to de-domain/re-domain client PCs, and to preserve local settings in their profile (ost files, browser saved passwords etc).<\/p>\n
Advertisement
Our supplier has advised against replicating one of our existing DCs to a new DC as it could bring across existing issues, so they plan to create a new DC on the same domain.<\/p>\n
Is there any way to bring over the users and groups from the old DC preserving the SIDs? We have folder redirection to a file server, and if they are just created on the new DC the SIDs will not match the permissions.<\/p>\n
Or is there a way to selectively replicate a DC, choosing which items to replicate (Ideally GPOs, and users and groups). Other server roles such as DNS and DHCP can be easily recreated.<\/p>\n
We have 4 domain controllers, each serving a physical location. Replication between the servers has failed and there are multiple Kerberos errors. Our server provider has dug deeper and found multiple issues, and have recommended new DCs.<\/p>\n
We would like to remain on the same domain name to save having to de-domain/re-domain client PCs, and to preserve local settings in their profile (ost files, browser saved passwords etc).<\/p>\n
Our supplier has advised against replicating one of our existing DCs to a new DC as it could bring across existing issues, so they plan to create a new DC on the same domain.<\/p>\n
Is there any way to bring over the users and groups from the old DC preserving the SIDs? We have folder redirection to a file server, and if they are just created on the new DC the SIDs will not match the permissions.<\/p>\n
Or is there a way to selectively replicate a DC, choosing which items to replicate (Ideally GPOs, and users and groups). Other server roles such as DNS and DHCP can be easily recreated.<\/p>\n
As long as you/they are promoting the new DCs in the existing Domain, all user information will transfer automatically. No “transfer process.”<\/p>\n
Unless there’s something missing from your description, your MSP is making a good recommendation. DC’s should be considered mostly<\/em> disposable, so when there’s a problem with one, it’s generally best to just spin up a new one from scratch to replace it.<\/p>","upvoteCount":8,"datePublished":"2024-08-13T13:41:26.450Z","url":"https://community.spiceworks.com/t/copying-users-to-a-new-domain-controller/1105466/2","author":{"@type":"Person","name":"kwelch007","url":"https://community.spiceworks.com/u/kwelch007"}},{"@type":"Answer","text":"
I’ve probably not described it well.<\/p>\n
They do not want to add the new DC to the existing domain and promote it as they think it may bring over issues from an existing DCs. So their recommendation is to create a new DC on the same domain, then build the GPOs and Users/groups before putting it into use - but I think the new SIDs for users would then be an issue.<\/p>\n
I’m going to suggest again trying to add the new DC and promote it, but they’ve already said they don’t want to.<\/p>","upvoteCount":1,"datePublished":"2024-08-13T14:04:17.028Z","url":"https://community.spiceworks.com/t/copying-users-to-a-new-domain-controller/1105466/3","author":{"@type":"Person","name":"Edward6534","url":"https://community.spiceworks.com/u/Edward6534"}},{"@type":"Answer","text":"
They are going to try and create another DC with the same domain name as the existing domain but not join it to the same domain?<\/p>\n