Crazy Idea, but will it work? Branch off DC to Seperate Network and Isolate a 'stale' copy of the Do

  • Thread starter Thread starter Scott Townsend
  • Start date Start date
S

Scott Townsend

We are in the process of segmenting out network and have some DCs in areas
they should not be in. (DMZs, etc)

There are a few servers that have a trust with our main domain so users
inside can Authenticate and Author Web pages on the Webservers.

I want to Do some reconfiguring of the placement of the servers and the
server roles with would eliminate the trust and put all of the servers in
one network segment. Though I don't want to have to reconfigure and add new
users to the webserver this month. I'd like to still use the Existing
Accounts and such on the one DC and then worry about changing the users on
the Webserver later.


Can I take the DC that is in the Webserver network, and make it so it no
longer can talk to the DCs on the internal network and then have it Seize
the FSMO roles and become a Standalone DC in the WEB network?

I know the Passwords and other Info wont be Sync'd Up with the 'Real'
domain, but will this work until I can get the time to reconfigure the
Webserver with other user accounts?

Thanks,
Scott<-
 
Scott let me start with a caution. I do not see this solution as a best
practice. The route you want to take is very risky.



In theory if you take the 'orphan' DC and this DC is a member of the Forest
root it would be possible to start this DC on an isolated network, seize all
FSMO roles, reassigned them to the new DC and do a metadirectory clean-up in
the original domain.







I would suggest that we try to solve the problem in another way.
 
Scott let me start with a caution. I do not see this solution as a best
practice. The route you want to take is very risky.



In theory if you take the 'orphan' DC and this DC is a member of the Forest
root it would be possible to start this DC on an isolated network, seize all
FSMO roles, reassigned them to the new DC and do a metadirectory clean-up in
the original domain.



I would suggest that we try to solve the problem in another way.
 
Back
Top