Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / Windows Server 2003 / Active Directory / July 2008

Tip: Looking for answers? Try searching our database.

Q: method to do ongoing synch from production AD to (isolated) lab AD

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Dark Helmet - 29 Jul 2008 05:11 GMT
Hi all,

I'm looking for some insights here as to how to best provide ongoing
reconcile between our production AD 2003 forest/domain and the isolated
lab environment built from a "mirror" of same.

Essentially, I have a requirement to capture the weekly changes in AD
(including Exchange 2003) and reconcile these changes in our isolated lab
(which has identical namespace, IP space, etc. as production).

If you need more info than this to assist, please let me know and I'll
try to flesh it out a bit more.

Thanks so much!

DH
Jorge Silva - 29 Jul 2008 12:28 GMT
Hi
-If the lab is isolated (no connectivity between them) them any change will
need to be reproduced manually or using a script to the Lab.
-To create the initial lab (mirror of the production environment) you can
use virtual machines (f you need help with this let me know), but to have a
continuous update of the production environment you need connectivity
between the DCs and any change in the DCs will be replicated to the DCs in
the production environment this is called a DR Site (disaster recovery site)
and is used for different proposes of your needs.
Signature

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services

Dark Helmet - 30 Jul 2008 08:18 GMT
Hi Jorge,

Thanks for your response--it sounds like it is not "doable" given the
current constraints.

Regards,

DH

> Hi
> -If the lab is isolated (no connectivity between them) them any change
[quoted text clipped - 6 lines]
> Site (disaster recovery site) and is used for different proposes of your
> needs.
Jorge Silva - 30 Jul 2008 19:30 GMT
Hi
It is not "doable" unless you want to recreate it each time that you need to
reproduce the prod environment in your lab (not very good).

Signature

I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services

Paul Bergson [MVP-DS] - 29 Jul 2008 18:02 GMT
Not really possible.  There are all kinds of on going changes with in AD.
Build a test AD environment and just try to keep the two similar, there is
no automated way to bring changes across.

Signature

Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

> Hi all,
>
[quoted text clipped - 12 lines]
>
> DH
Dark Helmet - 30 Jul 2008 08:28 GMT
Hi Paul,

That's kind of what I was afraid of.  I may simply have to do scheduled
complete refreshes of the lab environment to keep them as closely in
synch as possible.

I stumbled onto this program UMove (http://utools.com/UMove.asp) which
would seem to ease some of the pain of the initial build of the lab so I
will likely play around a bit with it and post back with my findings.

I also found Active Directory Change Reporter (http://www.netwrix.com/
active_directory_change_management.html) which I am hoping to leverage to
capture some of the changes to decide whether or not they are sufficient
to trigger a refresh of AD.

I appreciate the insights and I'll post back once I've had a chance to
build the lab and test these tools.

Regards,

DH  

> Not really possible.  There are all kinds of on going changes with in
> AD. Build a test AD environment and just try to keep the two similar,
> there is no automated way to bring changes across.
Meinolf Weber - 29 Jul 2008 18:25 GMT
Hello Dark,

Updating without connectivity will not be possible, except you make all changes
by hand.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> Hi all,
>
[quoted text clipped - 12 lines]
>
> DH
Dark Helmet - 30 Jul 2008 08:33 GMT
Hi Meinolf,

Further to my ramblings of earlier, I'm thinking that if I can use a
"staging" server to bridge networks (prod AD and the isolated Lab) that I
may be able to leverage the tools mentioned (Umove and AD Change
Reporter) to build the AD lab as well as thumbnail whether or not it is
time to rebuild/refresh the AD lab.

This is a challenge to be sure, but the client has a requirement to be
able to mirror production (data included) as closely as possible in the
isolated lab environment--fun fun!

Appreciate the insights and I will follow up with my findings once I've
had some time to test.

Regards,

DH

> Hello Dark,
>
[quoted text clipped - 25 lines]
>>
>> DH
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.