Add existing Domain Tree into a forest

I see that there is the option in DCPROMO to add a CHILD or a DOMAIN TREE ROOT.
I have two existing domains, each has a root domain with two child domains. I have a need to join the two forests with one forest added to the other as a DOMAIN TREE.
Using DCPROMO I see that I could build the Forest structure from scratch. Is there anyway to join the existing FOREST ROOT as the DOMAIN TREE ROOT and retain all existing data in both forests?
Tom!

Using DCPROMO I see that I could build the Forest structure from scratch. Is there anyway to join the existing FOREST ROOT as the DOMAIN TREE ROOT and retain all existing data in both forests?
Unfortunately No. You need to establish trusts between your forests and start migrating resources to your destination domain. 
ADMT Series - 1. Preparing Active Directory
Mahdi Tehrani   |  
  |  
www.mahditehrani.ir
Please click on Propose As Answer or to mark this post as
and helpful for other people.
This posting is provided AS-IS with no warranties, and confers no rights.
How to query members of 'Local Administrators' group in all computers?

Similar Messages

  • Creating a new domain tree under the forest

    Hi
    I have one primary domain and one additional domain at moment so I want to create a new domain tree under the forest however during the configuration it gives me the below message ?
    the last time I installed without tick marking "Create DNS Delegation" option I had a lot of issue in replication and in DNS between my forest domain and this new tree domain.
    my main question would be:
    1- how to resolve this ?
    2- how to create a manual DNS delegation in Parent zone.?
    please suggest ?

    Hi greeMann,
    This is an expected behaviour and it can be ignored.  The error message occurs because this is the first DNS server so there is not a DNS server available to create the delegation from. 
    If you are not concerned that people in other domains or on the Internet will not resolve DNS name queries for computer names in the local domain, you can disregard the message and click Yes.
    Known Issues for Installing and Removing AD DS
    http://technet.microsoft.com/en-us/library/cc754463(WS.10).aspx
    Regards,
    Rafic
    If you found this post helpful, please give it a "Helpful" vote.
    If it answered your question, remember to mark it as an "Answer".
    This posting is provided "AS IS" with no warranties and confers no rights! Always test ANY suggestion in a test environment before implementing!

  • How to add existing jsp file to a project?

    I am trying out 10g developer preview. Looks like a lot of bugs are there in the tool. I would like to know how to add existing jsp file into a project. I tried the Import functionality, but it shows the option to create a project and include only Java files. Is there a way to do this? Thank you

    Just copy the files in the directory where the rest of your source file is.

  • Questions on WS2012 Essentials integration into an existing domain

    Hi,
    I've successfully installed WS2012 Essentials RTM into an existing forest, and it's taken over the operations masters as expected. (This is my home domain, with two DCs -a ws2012 datacenter on a server and a 2008 VM - pre-existing.) There's some mysterious
    behavior, though:
    Domain users, though they show and work perfectly from the full-blown ADUC and ADAC AD management tools (which are available on the Essentials server), don't show up in the Dashboard to control access to Essentials services like shared folders and remote
    web access.
    Users created in the dashboard do show up in the domain. Is there some new attribute that must be set to enable my domain users to show up in the dashboard?
    Computers, when attempting to enter the domain via the remote web access portal, are prompted to install the connector. Thinking this was like the WHS connector I started, but it wants to restart several times, input your new network user name and password,
    etc. I'm loathe to go through the process in test and break a perfectly configured notebook. This is already a domain-joined computer that can access the Essentials server perfectly well over the network.
    Apologies in advance if this is in documentation somewhere, but I suspect less has been written about the peculiarities of joining an Essentials server to a full domain than to an SBS domain.
    Thanks,
    Sean

    Hi,
    Users created in Dashboard could be viewed via Dashboard and ADUC; Users created in ADUC could ONLY be viewd via ADUC. It's by design.
    Only users created by Dashboard have rights to deal with remote access, I think you have already compared with the users in ADUC:
    I have tried to add these groups for this specific AD user. However, the users will not display in the Dashboard. Also the user still has no rights to visit RWA.
    I think it's related to the security. Even you have created an account in ADUC, the same account can't be created in Dashboard:
    So I think towards the Windows Server 2012 Essentails user management, action in Dashboard will be the best practice.
    It's really a good idea to show the AD users and add existed user to allow RWA. So you could submt your feed via the site below:
    Connect Feedback site is Open Now!
    Regards,
    James
    James Xiong
    TechNet Community Support

  • Question about adding Windows 2012 R2 Domain Controller, into a native Windows 2008 R2 single forest domain

    I current have a two server domain, both Windows 2008 R2 and fully updated.   The two servers are on subnet 10.0.1.0 /24
    - Windows 2008 R2 Server A: 10.0.1.1 (DC, GC, FSMO, DNS)
    - Windows 2008 R2 Server B: 10.0.1.2 (DC, GC)
    AD Domain: COMPANY.LOCAL
    I have a second connected subnet, 192.168.1.0 /24) which is routed to the 10.0.1.0/24 subnet and I would like to install a Windows 2012 R2 server onto a server on that subnet and make it a domain controller with AD-Integrated DNS and DHCP for the 192.168.1.0
    /24 subnet.
    - Windows 2012 R2 Server C: 192.168.1.1
    What are the proper progression steps, in order to bring up the Windows 2012 R2 server and then add it to my COMPANY.LOCAL domain and then promote it do a DC/GC/AD-Integrated DNS server?   Are they anything like the following:
    1. Install Windows 2012 R2 server (Server C)
    2. Point Windows 2012 R2 server DNS servers at Server's A and B
    3. Perform AD prep to extend AD schema to support Windows 2012 R2 domain controllers
    4. Promote Windows 2012 R2 server to domain controller (install local DNS service on Server C, during this step)
    * Question:  Will Windows automatically create a DNS zone for the Windows 2012 R2 subnet (192.168.1.0/24) AND also include the DNS zone from the previous Windows 2008 R2 domain (10.0.1.0 /24)?  Or will I need to add the 10.0.1.0 /24 zone to the DNS
    server on Server C, even though the DNS from the Windows 2008 R2 domain is AD integrated?

    Hi,
    Regarding the issue here, please take a look into below articles:
    System Requirements and Installation Information for Windows Server 2012 R2
    http://technet.microsoft.com/en-us/library/dn303418.aspx
    Release Notes: Important Issues in Windows Server 2012 R2
    http://technet.microsoft.com/en-us/library/dn387077.aspx
    Install a Replica Windows Server 2012 Domain Controller in an Existing Domain (Level 200)
    http://technet.microsoft.com/en-us/library/jj574134.aspx
    Here is an example for promoting Windows Server 2012 to a DC, see:
    Step-by-Step Guide for Setting Up A Windows Server 2012 Domain Controller
    http://social.technet.microsoft.com/wiki/contents/articles/12370.step-by-step-guide-for-setting-up-a-windows-server-2012-domain-controller.aspx
    As the server is promoted to a DC, DNS Zones will be replicated and synchronized to it automatically whenever the new one is added to an AD DS domain,  bascially there is no special need to add zones,  for more information, please see:
    Understanding Active Directory Domain Services Integration
    http://technet.microsoft.com/en-us/library/cc726034.aspx
    Hope this may help
    Best regards
    Michael
    If you have any feedback on our support, please click
    here.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • How can someone add servers and computers to a separate domain in a separate forest without having permissions to the other forest?

    Hello Community
        On an existing network I added separate domain in a separate forest using WS2012.
        Lets call it "MyDomain" and "MyForest" on WS2012.
        In MyDomain and MyForest I am the only domain administrator.
        The problem is if you go to "File Explorer" and click on "Network" in MyDomain in MyForest,
    I see that other server administrators have added their servers and workstations to
    MyDomain in MyForest but I never added them as users or administrators to my domain in my forest.
        So the question is how can a someone from a separate domain in
    a separate forest add servers and computers to MyDomain in Myforest
    when I haven't added them as user or administrators or given them
    any permission in MyDomain in MyForest?
        Thank you
        Shabeaut

    Using the network in file explorer, this shows machines that the computer has automatically detected using built in Microsoft processes. All this means is that you have other computers on the same physical network as yourself. These are no necessarily part
    of your domain. If the machines are set to respond, then so long as they receive a discovery request from your PC they will respond and populate that list. This does not mean they are part of your domain, or that they have access to any of your computers (
    apart from low level stuff like ping which does not rely on domain membership.)
    Apart from a Domain Admin, the only other people who can make changes to your domain are whoever is an Enterprise Admins. Domain Admins have control over their domains but Enterprise Admin have full permissions to the entire Active Directory infrastructure,
    no matter which forest or domain it is.

  • How to add a function field into the existing matrix report

    Hi,
    I have a matrix report , now i wanted to add one moe field into the matrix which is getting the value from a function , this function is a part of the ref cursor query(group) , i'm able to get the value from the function but it cannot display on the existing matrix report. i wanted to add this in the repeating frame which is printing down. how could i do this , looking for your help. thanks . bcj

    Here the scenario like,
    Data from Table_1
    NAME UNITS DAYS RATE
    AAA 10 1 1.2
    BBB 12 2 3.1
    AAA 20 2 4.1
    CCC 23 1 5.2
    Here, In the matrix report the NAME and UNITS are row fields and 'DAYS' is column field , RATE would be the cell field, and
    Data from Table_2 ,
    NAME BASIC
    AAA 2
    AAA 2
    BBB 2
    CCC 3
    In the report i have to display the 'BASIC' along with the NAME in row level ( repeating frame printing down),
    To get the multiple 'Basic' for each 'Name' using a ref cursor .
    and, using a function to do further calculation based on the basic value
    begin
    select basic into v_basic where name =:name;
    return(caluculated_value);
    end;
    and return the calculated value to the report. But at that time cannot accommodate the value in the matrix report with other groups frequency.
    looking for your valuable help. Thanks Bcj

  • Can I add an Airport Express into an existing Non Airport Wireless Network?

    Hi -
    Is there any way I can add an Airport Express into an existing Linksys wireless (802.11g) network?. I would not mind switching completely over to Airport but I want to maintain a hybrid (part wired part wireless) configuration as I have now.
    thanks for any assistance!!
      Windows XP Pro  
    home built PC   Windows XP Pro   WRT54GS Lynksys 4 port + wireless G

    Hi skyelaird and welcome to the Discussions
    Is there any way I can add an Airport Express into an
    existing Linksys wireless (802.11g) network?.
    Yes.
    You would need to configure the Airport Express to join an existing wireless network (client mode).
    In this mode you can share a USB printer and stream AirTunes, however the ethernet port would be inactive.
    iFelix

  • Can't add Server 2012 to existing domain

    I'm getting this error:
    "Verification of replica failed.  The forest functional level is Windows 2000.  To install Windows Server 2012 domain or domain controller, the forest functional level must be Windows Server 2003."
    My forest level is set at 2008R2, per AD Domains and Trusts (on both the 08 servers and 2012).  The forest was set at 2003 before, so I demoted the old 2003 server and raised it to 2008 with no luck, then went ahead and went to 2008R2. 
    The 2012 server (clean install, no upgrades) is already a member of the domain.
    adprep /forestprep reports "forest wide information has already been updated" 
    Connectivity seems to be fine (ping, no firewalls) between the 2 08R2 DCs and the new 2012 server.  Weird thing is all the AD tools are installed in 2012, and I can even create new domain users from it. 

    Hello,
    You dont need manual schema upgarde for adding a new windows 2012 Domain controller. That is integrated with dcpromotion. Also you dont required the DCPROMO.
    Set DFL & FFL minimum 2003.
    See the below link for adding a 2012 DC for an existing domain.
    Install a Replica Windows Server 2012 Domain Controller in an Existing Domain (Level 200)
    As with previous versions of Windows Server, automated domain preparation for domain controllers that run Windows server 2012 does not run GPPREP. Run
    adprep.exe /gpprep manually for all domains that were not previously prepared for Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2. You should run GPPrep only once in the history of a domain, not with every upgrade. Adprep.exe
    does not run /gpprep automatically because its operation can cause all files and folders in the SYSVOL folder to re-replicate on all domain controllers.
    Still if you are facing issue. please upload the below outputs in skydrive & share us the link.
    repadmin /replsummary * >> repl.txt
    repadmin /showreps /v >> showreps.txt
    DCDIAG /V /C /D /E /s:dcname >> dcdiag-DCS.txt
    dcdiag /e /v /test:dns >> dns.txt
    ipconfig /all >> dcip.txt
    Regards
    Biswajit Biswas
    My
    Blogs|TechnetWiki
    Ninja
    Best regards Biswajit Biswas Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights. MCP 2003,MCSA 2003, MCSA:M 2003, CCNA, MCTS, Enterprise Admin

  • How can I add new row/column into existing jTable?

    Hi add!
    Can you help me how can I add new row/column into existing jTable?
    Tnx in adv!

    e.g
    Create two buttons inside the Table ( "Add New Row" ) and ("Add new Column")
    their handlers are:
    add new row:
    //i supose u already have
    DefaultTabelModel tablemodel = new DefaultTableModel(rowdata, columnNames);
    //and   
       JTabel jtable = new JTable(tablemodel);
    // Handler (row)
    jbtAddRow.addActionListener(new ActionListener(){
       public void actionPerformed(ActionEvent e) {
          if(jtable.getSelectedRow() >= 0 )
              tablemodel.insertRow(jtable.getSelectedRow(), new java.util.Vector());  
           else  
                tablemodel.addRow(new java.util.Vector());
        });to add new columns its the same but inside actionPerformed method:
    ask for e.g "Whats the name for the new column"
    then,
       tablemodel.addColumn(nameOfColumn, new java.util.Vector());   Joao
    Message was edited by:
    Java__Estudante

  • Importing existing database domain definitions into the DQS Domain management

    I have databases that domain based with rules and defaults. There are approximately 400 domains and 10,000 application attributes based upon various domains and associated with a default and/or rule. How can I leverage the existing domains into DQS. 
    I normally use formerly CA Erwin data modeling tool.  Is there a bulk import form either SQL server or ERwin?

    Hi Peter,
    I am not sure if you having problems getting started with DQS or you need to import (meta) data from a third party tool.
    If the former I recommend you follow the
    Enterprise Information Management using SSIS, MDS, and DQS Together tutorial. You can also get some overview information in the Microsoft Virtual Academy
    Implementing a Data Warehouse with SQL Server Jump Start course module 6.
    If the latter you will need to import the data from either Excel or SQL Server and apply all rules manually. Be sure to get your business people involved to handle (offload from you) all the data stewarding taks. The software is designed to used by normal
    business people, so leverage that.
    Good luck.
    Best regards,
    Arjen

  • Fail to add domain user into local group - RPC server unavailable

    Hi all,
    I have a server-1 which is join to domain A. I need to add a domain user from domain B to my server-1 local group. I keep getting "The RPC server is unavailable" error message.
    But i try to use another server-2 which also belong to domain A and same network segment as server-1, i do not encounter this error while adding domain B user onto it.
    The problematic server-1 is a Windows 2008 R2 SP1 server. It is install with IIS and MS SQL database 2008.
    Just one thing i am guessing whether is it the cause of the problem. Before server-1 join to domain A, i did not disable windows firewall. I disable it only recently. Could this has cause the problem on my server-1?

    Let's recap to make sure I understand exactly what  you have going on:
    - Server 1 and Server 2 are both on Domain A and in the same site, behind the same firewalls
    - Adding a user from Domain B works on Server 1 but not Server 2.
    - You get an RPC error while adding Domain B's user on Server 2.
    Is Domain B on the other end of some firewall?
    - Can you do a portqry to a DC in Domain B from Server 2 (http://www.microsoft.com/en-us/download/details.aspx?id=17148)
    - Run this command: portqry -n <DomainBFQDN> -p both -o 53,135,389,3268
       - We are testing DNS, RPC, LDAP and GC.  Do you see anything come back as filtered or not listening?
    - Do the same thing from Server 1 and compare the results.
    This sounds like a connectivity problem.
    Chris Ream

  • Pros and cons in setting AD domain trust into my AD domain for more than 10+ AD domain and some with same FQDN or label ?

    Hi,
    Can someone please share what is the pros and Cons of trusting AD domain for more than 10 different AD sites into my existing single domain forest let say ParentCompany.com ?
    At the moment I only have one single forest AD domain with the Domain and Forest functionality Windows Server 2003. The main domain controller FSMO role holder is in the Data Center spread across three different VMs running on Windows Server 2008 R2.
    The main/parent company has acquired smaller business chain of 15+ offices in which they have their own Domain Controller and also their own domain, sometimes they also got the same AD domain between them (no trust or whatsoever in those 15+ AD domain).
    Sounds crazy but yes, there is no standardization in them or whoever manage their IT infrastructure previously.
    I'm now considering what are the benefits of creating the AD domain and trust versus importing those AD objects into my domain and then decommission them.
    No need to worry about Exchange Server since all of the user in those sites connecting to the RDS to my ParentCompany.com terminal servers.
    My requirements or goal are as follows:
    1. Simplify the AD domain structure & maintenance
    2. Try to avoid the disruptions of the user in terms of downtime and selecting multiple different domain everytime they login to their PC or SharePoint sites.
    any kind of help and suggestion would be greatly appreciated.
    Thanks.
    /* Server Support Specialist */

    Can someone please share what is the pros and Cons of trusting AD domain for more than 10 different
    AD sites into my existing single domain forest let say ParentCompany.com ?
    I think you mean 10 AD domains.
    Managing multiple domains can be difficult for administration. I usually recommend using a single domain in a single forest with OUs to separate resources whenever it is possible.
    However, if you can't do that then you can simply create trust relationships between your domains. The advantage is that you can enable access to resources to different domains. I do not see cons here.
    The main/parent company has acquired smaller business chain of 15+ offices in which they have
    their own Domain Controller and also their own domain, sometimes they also got the same AD domain between them (no trust or whatsoever in those 15+ AD domain). Sounds crazy but yes, there is no standardization in them or whoever manage their IT infrastructure
    previously.
    I'm now considering what are the benefits of creating the AD domain and trust versus importing those
    AD objects into my domain and then decommission them.
    I would recommend consolidating your domains into a single one. ADMT is a migration tool that you can use. The advantage would be the ease of administration. Also, by having multiple DCs for the same domain across sites, you will take benefit of High Availability
    of your and DRP.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • How to copy existing query report into new query report in SQ00

    Hi Experts,
    Hi Experts,
    I want to add fields "company code" "'region" to existing  query report AQZZ/SAPQUERY/FKF1============
    (list of vendor address) for this i done as following:
    1.In SQ01  go to "EDIT->other user group" and i selected user group as /SAPQUERY/FK
    2.I typed F1 in query field and click change button
    3.I clicked next screen button and entered into "change query f1: select fields screen".here i clicked "basic list" button and searched company code checkbox and saved it as result company code is appearing in the standard report"AQZZ/SAPQUERY/FKF1============"
    but unfortunately there is no region field(LFA1-REGIO) for this i think i should copy the existing  query report  into new query report(Ex:Z_LIST_OF_VEND) which should be 14 characters.please tell me briefly how to do this because this is first time i am using SQ00.
    one more issue is when i selected "edit-otheruser group" and choosing /SAPQUERY/FK  i  am getting only infoset "/SAPQUERY/FIKD" but i should need Info set: "/SAPQUERY/FIDD" please tell me how to add the previous one into user group.i think if i got /SAPQUERY/FIDD into usergroup  /SAPQUERY/FK i can add region also into Query report as i mentioned above by going SQ01 ...............................
    please help regarding this which should be very beneficiary to my carrier.
    Regards,
    naresh

    Hi Experts ,
    I solved issue by changing infoset in SQ02 by means of assigning field to field group and changed the query in SQ00.
    Regards,
    naresh.

  • How to Create a new RODC in an existing domain

    Hello everyone,
    Is anybody could help me with DCPROMO install on RODC 2008 R2 ? I wanna join to an Existing forest. "Create a new RODC in an existing domain". If you could write me step by step cmd would be nice.
    Thank's

    by cmd you mean from command promt?
    If, use something like this:
    dcpromo /unattend:c:\ua.txt
    The file should contain at least this info:
    [DCInstall]
    ReplicaOrNewDomain=ReadOnlyReplica
    ReplicaDomainDNSName=my.domain.com
    SiteName=yoursite
    InstallDNS=Yes
    ConfirmGc=Yes
    CreateDNSDelegation=yes
    UserDomain=my.domain.com
    UserName=user
    Password=P"ssword
    SafeModeAdminPassword=P"ssword123
    CriticalReplicationOnly=Yes
    RebootOnCompletion=Yes
    Best Regards,
    Jesper Vindum, Denmark
    Systems Administrator
    Help the forum: Monitor(alert) your threads and vote helpful replies or mark them as answer, if it helps solving your problem.

Maybe you are looking for

  • Idoc in status 03 - not received by receiving system

    Hello All, I have researched a lot on this topic on the forum - but what I am facing is something peculiar - so posting the complete scenario. I have three interfaces based on change pointers mechanism where change pointers have been activated for me

  • Installation of central instance - memory settings

    Hi All, I have a question about the memory settings reg. the ABAP / Java Add-In installation (Central system). Installation of CI: When I install the central instance, I provide a value for the Instance Memory Management. Installation of DI: In the s

  • Helve Font in Adobeforms

    Hello - We are converting from SAPscript to Adobe Print Forms using the Adobe LiveCycle Designer. Our SAPscripts use the Helve font which is not available in the LiveCycle Designer. We were able to purchase and download a Helvetica font into the Wind

  • Trying to return the size of the bag's range

    can some one help me with these... im not sure if i just need to do a return statement. if someone can give some advice that would be great.. thanks         public interface BagOverIntRange {       * Returns the size of the bag's range (high - low +

  • Discoverer payroll report questions

    Hi all, I know this may not be the correct board for this but here goes. I have to create a disco report for payroll and it involves salary history and is mainly based on customer sql folders in the business area. I am trying to get the salary histor