• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Domain and Exchange Replacement

Soldier101

Gawd
Joined
Jan 8, 2002
Messages
639
The network that i have taken over has run it's course. There are active directory issues and extreme exchange issues.

We were thinking about setting up a new domain and migrating people over. The new domain would hold the new exchange server and would essentially be starting fresh. Has anyone here ever done this and if so do you have recommendations or possibly some documentation on how to make it as smooth as possible.
 
As long as you don't currently use SBS its not to bad. You can build a domain trust and migrate users/computers to the new domain. Then move file shares and such
 
I have not done it, a friend did, and had good success with exporting exchage mailboxes and moving them to the new server that was on a newer version of exchange(from server 03 exhange 03 to server 08 exchange 07 or 2010)
 
If AD is in that bad of shape you might have problems creating a trust, migrating users, Etc. I'd focus on fixing AD first. What kind of problems are you having?
 
It's not that complicated if you are not taking much with you from the old domain.

Setup new DC
Setup new Exchange
Setup new permissions and GPO's
Friday before migration have users export their current mailboxes into a PST
Over the weekend take all the workstations off the old domain, add to new domain (even better if you can re-image them while you're at it)
Once done copy all files from old file server onto usb drive or hard drive of some kind. Copy into new file server so they inherit new permissions.
Monday morning users import PST's into new exchange box.
......
Profit?
 
I've done it the "nuke 'n pave" way many times. This naturally only works on the smaller side of SMB...like, a network of under 100 users all in one location. Actually wicked easy 'n relatively fast if under 50 and just 1 person doing it.

Export all users mailboxes to PSTs. If it's a physically smaller office and you can boogie around to the all the workstations..do it there..to a neutral folder like C:\download.

Disable DHCP on old server..but leave on the network.
Put up new server...enable all services. Copy over contents from old server via \\servername\d$ <==basically from root of data volume

Run around and join workstations to new server/domain....setup basics of user profile.
Copy over only necessary stuff from old users profile in users directory (favorites, desktop stuff, My Documents if it wasn't mapped to server before, etc). You can even do most of this from a server by accessing \\workstationname\c$. Normally I'd include the .NK2 file (outlook nickname file)...but when changing to new domains...I've had issues with that..there's something wonky deep in the file that holds relationships to the old exchange server.

From workstation..setup Outlook to new server...and then import the persons old PST into their new mailbox on the new Exchange server.
 
I've done it the "nuke 'n pave" way many times. This naturally only works on the smaller side of SMB...like, a network of under 100 users all in one location. Actually wicked easy 'n relatively fast if under 50 and just 1 person doing it.

Export all users mailboxes to PSTs. If it's a physically smaller office and you can boogie around to the all the workstations..do it there..to a neutral folder like C:\download.

Disable DHCP on old server..but leave on the network.
Put up new server...enable all services. Copy over contents from old server via \\servername\d$ <==basically from root of data volume

Run around and join workstations to new server/domain....setup basics of user profile.
Copy over only necessary stuff from old users profile in users directory (favorites, desktop stuff, My Documents if it wasn't mapped to server before, etc). You can even do most of this from a server by accessing \\workstationname\c$. Normally I'd include the .NK2 file (outlook nickname file)...but when changing to new domains...I've had issues with that..there's something wonky deep in the file that holds relationships to the old exchange server.

From workstation..setup Outlook to new server...and then import the persons old PST into their new mailbox on the new Exchange server.

Pretty much what I did what here when we took over our remote location for the first time. Consider it moving all of their crap from their old domain to ours
 
depending on the amount of systems/users in the domain definitely changes the course of action.

how many users are in the domain?
current network design?
all one location? remote?
what os is on the workstations?
what os are you migrating from and to?
switch type, gb or 10/100?

as the others are mentioned, doing a migration from something that's already gone to hell will possibly bring issues into the new network. Starting from scratch may be a bit more work depending on how many systems there are but may be easier down the road.
 
Make sure the current environment is well documented before making changes, not a bad idea to have share names, permissions, etc documented since you want to reproduce it.

Also version of exchange matters too, newer versions don't support exmerge, so you'd have to import users mailboxes (pst) into Outlook. Do they have an SSL cert in exchange?

As others have pointed out its not too difficult, but you will have to touch each workstations, disjoin from domain and rejoin the new domain which means users profiles will change and that can be a pain.

Also, as others have said, no point in migrating from something that is already broken, start fresh, copy data, mailboxes.
 
It's not that complicated if you are not taking much with you from the old domain.

Setup new DC
Setup new Exchange
Setup new permissions and GPO's
Friday before migration have users export their current mailboxes into a PST
Over the weekend take all the workstations off the old domain, add to new domain (even better if you can re-image them while you're at it)
Once done copy all files from old file server onto usb drive or hard drive of some kind. Copy into new file server so they inherit new permissions.
Monday morning users import PST's into new exchange box.
......
Profit?

You need to move the x400 email addresses over as well otherwise they will get errors and bounce backs when replying to old emails
(This is the issues that YeOldStonecat was having when he copied the NK2, fyi)

Also, add the computers to the new domain and log in as the user. It will create a new profile, then restart the computer, log in a domain admin and copy the old profile into the new profile.

I don't know what types of users you are used to, but I would never have the users export their own mailboxes to PST, that is insane, in my opinion, you are going to lose tons of data due to user error.
As other have mentioned with the PST files, ex-merge them from the old server, don't waste your time going to each computer and copying them.

I would sync-toy all of the files from one server to the other as well. Otherwise you are going to hit a blackberry backup file or something, and your file copy will fail and you will have to find where it stopped.
 
Last edited:
Make sure the current environment is well documented before making changes, not a bad idea to have share names, permissions, etc documented since you want to reproduce it.

Also version of exchange matters too, newer versions don't support exmerge, so you'd have to import users mailboxes (pst) into Outlook. Do they have an SSL cert in exchange?

As others have pointed out its not too difficult, but you will have to touch each workstations, disjoin from domain and rejoin the new domain which means users profiles will change and that can be a pain.

Also, as others have said, no point in migrating from something that is already broken, start fresh, copy data, mailboxes.


You can use exmerge with Exchange 2007 (and probably 2010). You just have to put the Exchange 2003 management tools and CDO/Mapi on a separate computer and use that.

I keep thinking of things as I go along.
I would rename all of the computers after you unjoin from the old domain and before joining to the new domain. If your network is like most other's the names are all random. You can start at one end of the office start with 01, and number up from there. You can then figure out who has a computer based on it's computer name. Just map out some kind of plan. Maybe name the accounting computers accounting04, etc..

If any computers have static IPs, create a DHCP reservation on the new server and set them to DHCP.

You need to delete and re-connect all network printers too.

Be glad that you don't have to throw a knife-edge blackberry server cut-over into the mix as well.
 
Last edited:
I've done it the "nuke 'n pave" way many times. This naturally only works on the smaller side of SMB...like, a network of under 100 users all in one location. Actually wicked easy 'n relatively fast if under 50 and just 1 person doing it.

Export all users mailboxes to PSTs. If it's a physically smaller office and you can boogie around to the all the workstations..do it there..to a neutral folder like C:\download.

Disable DHCP on old server..but leave on the network.
Put up new server...enable all services. Copy over contents from old server via \\servername\d$ <==basically from root of data volume

Run around and join workstations to new server/domain....setup basics of user profile.
Copy over only necessary stuff from old users profile in users directory (favorites, desktop stuff, My Documents if it wasn't mapped to server before, etc). You can even do most of this from a server by accessing \\workstationname\c$. Normally I'd include the .NK2 file (outlook nickname file)...but when changing to new domains...I've had issues with that..there's something wonky deep in the file that holds relationships to the old exchange server.

From workstation..setup Outlook to new server...and then import the persons old PST into their new mailbox on the new Exchange server.

I am assuming the wonky thing with the NK2 file is only for internal email addresses. The way the file is constructed it has the Exchange "address" in there and once you change to a new server, it still tries to send to the old server and fails... even though the email address is the same and looks the same to the user.

You can use a program like NK2Edit (which rocks) to delete all the internal email addresses in the NK2 file.

Or you can just blow it away entirely.

In Outlook 2010 the NK2 file is replaced by a different file. If upgrading to Outlook 2010 you will need to put the NK2 in the proper folder and then run "outlook.exe /importnk2" from the Run dialog.
 
As I mentioned above, you can also recreate the x400 addresses on the new exchange server and those "internal" emails will still work.

Don't you love out the "Suggested Contacts" from Outlook 2010 sync onto everyone's iPhones and they the have duplicate contacts of everyone, and keep pulling up the ones from "Suggested" that don't have phone numbers in them.
 
I've done it the "nuke 'n pave" way many times. This naturally only works on the smaller side of SMB...like, a network of under 100 users all in one location. Actually wicked easy 'n relatively fast if under 50 and just 1 person doing it.

Export all users mailboxes to PSTs. If it's a physically smaller office and you can boogie around to the all the workstations..do it there..to a neutral folder like C:\download.

Disable DHCP on old server..but leave on the network.
Put up new server...enable all services. Copy over contents from old server via \\servername\d$ <==basically from root of data volume

Run around and join workstations to new server/domain....setup basics of user profile.
Copy over only necessary stuff from old users profile in users directory (favorites, desktop stuff, My Documents if it wasn't mapped to server before, etc). You can even do most of this from a server by accessing \\workstationname\c$. Normally I'd include the .NK2 file (outlook nickname file)...but when changing to new domains...I've had issues with that..there's something wonky deep in the file that holds relationships to the old exchange server.

From workstation..setup Outlook to new server...and then import the persons old PST into their new mailbox on the new Exchange server.

Yea I generally don't import the nk2 files if I can help it. It isn't usually worth either moving the x400 emails over or cleaning up the nk2 files.

Past really 50 to 100 workstations it is better to make a trust between the domains and take your time to move stuff over.

You need to move the x400 email addresses over as well otherwise they will get errors and bounce backs when replying to old emails
(This is the issues that YeOldStonecat was having when he copied the NK2, fyi)

Also, add the computers to the new domain and log in as the user. It will create a new profile, then restart the computer, log in a domain admin and copy the old profile into the new profile.

I don't know what types of users you are used to, but I would never have the users export their own mailboxes to PST, that is insane, in my opinion, you are going to lose tons of data due to user error.
As other have mentioned with the PST files, ex-merge them from the old server, don't waste your time going to each computer and copying them.

I would sync-toy all of the files from one server to the other as well. Otherwise you are going to hit a blackberry backup file or something, and your file copy will fail and you will have to find where it stopped.

The big thing to know about exmerge is that it uses the old style pst files so it can only export mailboxes up to the old 2 gig limit. If you have set users to unlimited(since with exchange 03 you can only define limits to the 2 gig point) you need to export the mailboxes using outlook. I've read of some other ways with screwing around with crashing exmerge and doing multi point files but really it isn't a good option.


As far as the burn and rebuilt I was doing just that in a small office earlier today. The controller in the office decided to see what the big power button on the front of the server's ups did. Managed to corrupt exchange and both stores(sbs03). I spend a few hours yesterday trying everything I could think of and read on getting the store service to start, re installed exchange, etc before giving up and reloading.
 
I am assuming the wonky thing with the NK2 file is only for internal email addresses. The way the file is constructed it has the Exchange "address" in there and once you change to a new server, it still tries to send to the old server and fails... even though the email address is the same and looks the same to the user.

You can use a program like NK2Edit (which rocks) to delete all the internal email addresses in the NK2 file.

Or you can just blow it away entirely.
.

Yup..that's it..even if the addy's are the exact same. That's why I mentioned I leave those behind on this kind of migration...some users moan 'n groan because they miss their ability to be lazy..but oh well.
 
User Profile Wizard from ForensiT works amazing if you want to make your life easy for moving domains and profiles on local machines.
 
Thanks for the responses guys, maybe you can help in this.

The only reason why creating a new fresh exchange server and domain is even entering my mind is because I'm having the following issues (someone above asked what my domain issues were) If I can fix these I don't need an entirely new domain.

Here is my current setup

3 DC's....we shall call them DC1, DC2, DC3
2 Exchange servers 1 2k3 and 1 2k7. (previous admin botched the migration so some public folders are still on old server apparently)

If we disable DC1, the exchange servers fail to work...and if they are powered off they wont even boot without DC1 being live, even if we hardcore them to use DC2 or 3.

DC1 is a 2k3 box.
DC2 and 3 are both 2k8 boxes.

How in the fuck do I fix this so that DC1 is no longer needed. So I can raise the domain level and use just my 2k8 boxes.....if I can make it to where shit works without DC1 being live or in the mix then I can keep the current domain and just install the new exchange and move everything over without having to fuck with a new domain all together.

Thanks for any assistance.
 
Back
Top