Hi, I have a situation. I just got customer who had deployed 2 x 2K3 R2 AD
and
had it sync with each other at the main office. They also deployed exchange
2007 at the main office. However, they split the network between 2 sites and
have moved 1 of the AD to a site office, but these 2 AD have not been
connected for the last 3 months. To access the domain and exchange, they
create the same new user account on the 2 AD server and exhange 2007. So
site office users login in to the site office AD, but access exchange via the
main office AD and exhange.

Question: If they connect the network together now and tried to sync the 2
AD, will the new accounts created on both sites conflict with each other or
will they just sync with each other and the users on both sides would
continue to work as per normal? Thanks.

Gilbert

Re: AD Sync Problem by Lanwench

Lanwench
Mon May 05 10:32:21 PDT 2008

Gilbert <Gilbert@discussions.microsoft.com> wrote:
> Hi, I have a situation. I just got customer who had deployed 2 x 2K3
> R2 AD and
> had it sync with each other at the main office. They also deployed
> exchange 2007 at the main office. However, they split the network
> between 2 sites and have moved 1 of the AD to a site office, but
> these 2 AD have not been connected for the last 3 months. To access
> the domain and exchange, they create the same new user account on the
> 2 AD server and exhange 2007. So site office users login in to the
> site office AD, but access exchange via the main office AD and
> exhange.
>
> Question: If they connect the network together now and tried to sync
> the 2 AD, will the new accounts created on both sites conflict with
> each other or will they just sync with each other and the users on
> both sides would continue to work as per normal? Thanks.
>
> Gilbert

They will conflict. They have nothing to do with each other- the SIDS are
different. This could be pretty ugly overall - three months is a long time
for the DCs not to have contact with each other. I don't remember what the
max time is and perhaps someone else will post, but I'd expect a slew of
problems to come up when they finally can talk to each other again. Just
make sure there are good backups of *everything*.



Re: AD Sync Problem by Meinolf

Meinolf
Mon May 05 13:57:37 PDT 2008

Hello Gilbert,

The tombstone lifetime for 2003 R2 is with a fresh install 180 days, if the
machine was upgraded from 2003 SP1 only 60 days. So for fixing you replication
problem i think you have first to go back to a state where the 2 accounts
with the same name not exists or rename/delete one of them, can also work
because the SID is different.

Determine tombstone lifetime:
http://technet2.microsoft.com/WindowsServer/en/library/f3df8a52-81ea-4a1d-9823-4e51fbd3422a1033.mspx?mfr=true

Here you can start for replication problems:
http://technet2.microsoft.com/windowsserver/en/library/c8ab0711-da74-43de-83d7-5e9009fc66d11033.mspx?mfr=true

http://technet2.microsoft.com/windowsserver/en/library/4a1f420d-25d6-417c-9d8b-6e22f472ef3c1033.mspx?mfr=true



Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> Hi, I have a situation. I just got customer who had deployed 2 x 2K3
> R2 AD and had it sync with each other at the main office. They also
> deployed exchange 2007 at the main office. However, they split the
> network between 2 sites and have moved 1 of the AD to a site office,
> but these 2 AD have not been connected for the last 3 months. To
> access the domain and exchange, they create the same new user account
> on the 2 AD server and exhange 2007. So site office users login in to
> the site office AD, but access exchange via the main office AD and
> exhange.
>
> Question: If they connect the network together now and tried to sync
> the 2 AD, will the new accounts created on both sites conflict with
> each other or will they just sync with each other and the users on
> both sides would continue to work as per normal? Thanks.
>
> Gilbert
>



RE: AD Sync Problem by Gilbert

Gilbert
Mon May 05 22:36:00 PDT 2008

Can I try to do this:

Have another AD server sync with the main office, than bring over to the
site office and use a VPN to maintain the sync. Those users at site office
who joins the AD at the site office will need to rejoin the new AD (but
before this happens, the existing site AD must be offline). Those users who
joined the AD at the main office but are shifting to the site office would
still be able to connect.

Thanks.



"Gilbert" wrote:

> Hi, I have a situation. I just got customer who had deployed 2 x 2K3 R2 AD
> and
> had it sync with each other at the main office. They also deployed exchange
> 2007 at the main office. However, they split the network between 2 sites and
> have moved 1 of the AD to a site office, but these 2 AD have not been
> connected for the last 3 months. To access the domain and exchange, they
> create the same new user account on the 2 AD server and exhange 2007. So
> site office users login in to the site office AD, but access exchange via the
> main office AD and exhange.
>
> Question: If they connect the network together now and tried to sync the 2
> AD, will the new accounts created on both sites conflict with each other or
> will they just sync with each other and the users on both sides would
> continue to work as per normal? Thanks.
>
> Gilbert
>

RE: AD Sync Problem by Gilbert

Gilbert
Tue May 06 00:26:01 PDT 2008

Hi Meinolf,

Thanks for your feedback. i just found out that they connect all users to
the main office AD first before shifting to the site office. They do not
join the AD at the site office. This is so that they can access the exchange
which is at the main office. Once at the site office, they connect to
exchange via internet to access exchange via http. So looks like site office
AD, even though they have the same account created in the site office AD,
because their computers was originally joined to the main office, they don't
actually connect to the site office AD... am I correct to assume this? if
so, than i can use a new server to sync with the main office AD, using bring
this new AD to the site office, setup VPN and allow the site office users to
logon using the new AD... Correct?

Gilbert


"Meinolf Weber" wrote:

> Hello Gilbert,
>
> If i understand you correct you will take a DC form the main office to the
> site office and connect it there. Then you will rejoin the clients.
> But what about your users? If they try to work with the account from the
> main office DC, ofcourse first you have to reset the passwords from all of
> them. Also you have to save all Data from them, so they have no lost of there
> work, how will you handle this? Think they will not be so happy with your
> solution.
> Ofcourse this is also a way of cleaning anything up. Afterwards i think you
> will NEVER connect the site DC to the domain and do a metadata cleanup in AD?
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
> > Can I try to do this:
> >
> > Have another AD server sync with the main office, than bring over to
> > the site office and use a VPN to maintain the sync. Those users at
> > site office who joins the AD at the site office will need to rejoin
> > the new AD (but before this happens, the existing site AD must be
> > offline). Those users who joined the AD at the main office but are
> > shifting to the site office would still be able to connect.
> >
> > Thanks.
> >
> > "Gilbert" wrote:
> >
> >> Hi, I have a situation. I just got customer who had deployed 2 x 2K3
> >> R2 AD and had it sync with each other at the main office. They also
> >> deployed exchange 2007 at the main office. However, they split the
> >> network between 2 sites and have moved 1 of the AD to a site office,
> >> but these 2 AD have not been connected for the last 3 months. To
> >> access the domain and exchange, they create the same new user account
> >> on the 2 AD server and exhange 2007. So site office users login in
> >> to the site office AD, but access exchange via the main office AD and
> >> exhange.
> >>
> >> Question: If they connect the network together now and tried to sync
> >> the 2 AD, will the new accounts created on both sites conflict with
> >> each other or will they just sync with each other and the users on
> >> both sides would continue to work as per normal? Thanks.
> >>
> >> Gilbert
> >>
>
>
>

RE: AD Sync Problem by Gilbert

Gilbert
Tue May 06 01:30:02 PDT 2008

Thanks! :)

"Meinolf Weber" wrote:

> Hello Gilbert,
>
> That's easy to figure out. On a site office machine logon and in a command
> windows type SET. In the output you can find the logonserver.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
> > Hi Meinolf,
> >
> > Thanks for your feedback. i just found out that they connect all
> > users to the main office AD first before shifting to the site office.
> > They do not join the AD at the site office. This is so that they can
> > access the exchange which is at the main office. Once at the site
> > office, they connect to exchange via internet to access exchange via
> > http. So looks like site office AD, even though they have the same
> > account created in the site office AD, because their computers was
> > originally joined to the main office, they don't actually connect to
> > the site office AD... am I correct to assume this? if so, than i can
> > use a new server to sync with the main office AD, using bring this new
> > AD to the site office, setup VPN and allow the site office users to
> > logon using the new AD... Correct?
> >
> > Gilbert
> >
> > "Meinolf Weber" wrote:
> >
> >> Hello Gilbert,
> >>
> >> If i understand you correct you will take a DC form the main office
> >> to the
> >> site office and connect it there. Then you will rejoin the clients.
> >> But what about your users? If they try to work with the account from
> >> the
> >> main office DC, ofcourse first you have to reset the passwords from
> >> all of
> >> them. Also you have to save all Data from them, so they have no lost
> >> of there
> >> work, how will you handle this? Think they will not be so happy with
> >> your
> >> solution.
> >> Ofcourse this is also a way of cleaning anything up. Afterwards i
> >> think you
> >> will NEVER connect the site DC to the domain and do a metadata
> >> cleanup in AD?
> >> Best regards
> >>
> >> Meinolf Weber
> >> Disclaimer: This posting is provided "AS IS" with no warranties, and
> >> confers
> >> no rights.
> >> ** Please do NOT email, only reply to Newsgroups
> >> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
> >>> Can I try to do this:
> >>>
> >>> Have another AD server sync with the main office, than bring over to
> >>> the site office and use a VPN to maintain the sync. Those users at
> >>> site office who joins the AD at the site office will need to rejoin
> >>> the new AD (but before this happens, the existing site AD must be
> >>> offline). Those users who joined the AD at the main office but are
> >>> shifting to the site office would still be able to connect.
> >>>
> >>> Thanks.
> >>>
> >>> "Gilbert" wrote:
> >>>
> >>>> Hi, I have a situation. I just got customer who had deployed 2 x
> >>>> 2K3 R2 AD and had it sync with each other at the main office. They
> >>>> also deployed exchange 2007 at the main office. However, they
> >>>> split the network between 2 sites and have moved 1 of the AD to a
> >>>> site office, but these 2 AD have not been connected for the last 3
> >>>> months. To access the domain and exchange, they create the same
> >>>> new user account on the 2 AD server and exhange 2007. So site
> >>>> office users login in to the site office AD, but access exchange
> >>>> via the main office AD and exhange.
> >>>>
> >>>> Question: If they connect the network together now and tried to
> >>>> sync the 2 AD, will the new accounts created on both sites conflict
> >>>> with each other or will they just sync with each other and the
> >>>> users on both sides would continue to work as per normal? Thanks.
> >>>>
> >>>> Gilbert
> >>>>
>
>
>

Re: AD Sync Problem by Lanwench

Lanwench
Tue May 06 06:02:16 PDT 2008

Gilbert <Gilbert@discussions.microsoft.com> wrote:
> Hi Meinolf,
>
> Thanks for your feedback. i just found out that they connect all
> users to the main office AD first before shifting to the site office.
> They do not join the AD at the site office. This is so that they can
> access the exchange which is at the main office. Once at the site
> office, they connect to exchange via internet to access exchange via
> http. So looks like site office AD, even though they have the same
> account created in the site office AD, because their computers was
> originally joined to the main office, they don't actually connect to
> the site office AD... am I correct to assume this? if so, than i
> can use a new server to sync with the main office AD, using bring
> this new AD to the site office, setup VPN and allow the site office
> users to logon using the new AD... Correct?

How is this going to solve the problem of your having two users for each
person (one in AD in each office)?
You're going to have problems with this.

>
> Gilbert
>
>
> "Meinolf Weber" wrote:
>
>> Hello Gilbert,
>>
>> If i understand you correct you will take a DC form the main office
>> to the site office and connect it there. Then you will rejoin the
>> clients.
>> But what about your users? If they try to work with the account from
>> the main office DC, ofcourse first you have to reset the passwords
>> from all of them. Also you have to save all Data from them, so they
>> have no lost of there work, how will you handle this? Think they
>> will not be so happy with your solution.
>> Ofcourse this is also a way of cleaning anything up. Afterwards i
>> think you will NEVER connect the site DC to the domain and do a
>> metadata cleanup in AD?
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>
>>> Can I try to do this:
>>>
>>> Have another AD server sync with the main office, than bring over to
>>> the site office and use a VPN to maintain the sync. Those users at
>>> site office who joins the AD at the site office will need to rejoin
>>> the new AD (but before this happens, the existing site AD must be
>>> offline). Those users who joined the AD at the main office but are
>>> shifting to the site office would still be able to connect.
>>>
>>> Thanks.
>>>
>>> "Gilbert" wrote:
>>>
>>>> Hi, I have a situation. I just got customer who had deployed 2 x
>>>> 2K3 R2 AD and had it sync with each other at the main office.
>>>> They also deployed exchange 2007 at the main office. However,
>>>> they split the network between 2 sites and have moved 1 of the AD
>>>> to a site office, but these 2 AD have not been connected for the
>>>> last 3 months. To access the domain and exchange, they create the
>>>> same new user account on the 2 AD server and exhange 2007. So
>>>> site office users login in to the site office AD, but access
>>>> exchange via the main office AD and exhange.
>>>>
>>>> Question: If they connect the network together now and tried to
>>>> sync the 2 AD, will the new accounts created on both sites
>>>> conflict with each other or will they just sync with each other
>>>> and the users on both sides would continue to work as per normal?
>>>> Thanks.
>>>>
>>>> Gilbert