Migrating from Microsoft Windows NT Server 4.0 to Windows Server 2003

Completing Post-Upgrade Tasks

After you upgrade all domain controllers in the domain to Windows Server 2003, complete the following post-upgrade tasks:

Eliminate Anonymous Connections to Domain Controllers

After you upgrade all the servers in the domain hosting services that run as Local System and use Anonymous or null credentials when accessing a domain controller, such as Windows NT 4.0 RAS servers, remove the Everyone and Anonymous Logon groups from the Pre-Windows 2000 Compatible Access built-in group . This task increases the security of your domain by preventing anonymous connections to domain controllers.

To remove groups from the Pre-Windows 2000 Compatible Access Group by using the command line

When using the net localgroup command to add or delete any group or group member name that includes spaces, such as the Anonymous Logon group, you must enclose the group name in quotation marks.

Raise Domain and Forest Functional Levels

Although the Windows Server 2003 domain functional level provides a number of features and advantages, enable this functional level only when you have upgraded all your Windows NT 4.0 BDCs and you are certain that your environment is ready.

Important  

If you raise the domain and forest functional levels to Windows Server 2003, this action cannot be reversed and you cannot add Windows NT 4.0 “based or Windows 2000 “based domain controllers to the environment. Any existing Windows NT 4.0 or Windows 2000 “based domain controllers in the environment will no longer function. Before you raise functional levels to take advantage of advanced Windows Server 2003 features, ensure that you will never need to install domain controllers that run Windows NT 4.0 or Windows 2000 in your environment.

After you determine that your environment is ready, use Active Directory Domains and Trusts to enable the Windows Server 2003 domain functional level.

After you upgrade all domain controllers to Windows Server 2003, raise the forest functional level to Windows Server 2003 to take advantage of all Windows Server 2003 forest-level features.

For more information about enabling functional levels and the features available at the Windows Server 2003 domain and forest functional levels , see Enabling Advanced Windows Server 2003 Active Directory Features in Designing and Deploying Directory and Security Services in the Microsoft Windows Server 2003 Deployment Kit (or see Enabling Advanced Windows Server 2003 Active Directory Features on the Web at http://www.microsoft.com/reskit).

Complete the Upgrade

Complete the following tasks to finalize the upgrade process:

After you complete the above tasks successfully, the upgrade process is complete.

Категории