Switching to Native Mode

G

Guest

We are ready to make the switch from a W2K mixed mode to native mode. Just wondering what changes are the users going to notice (client machines are either W2K Professional of Windows XP Professional)? For example, they are used to seeing "NTGROUP1" as our domain name on their Windows login screens (NTGROUP1 being our pre-windows 2000 domain name). After switching to native mode, is NTGROUP1 going to be replaced with "ourcompany.com" in the domain name field?

Also, if users access our fileserver resources from home through VPN, they are prompted for a username and password. They are used to typing NTGROUP1\username - how is this going to change? Will the user need to enter (e-mail address removed) as their username?

Thanks!
 
S

Steve Dodson [MSFT]

Clients will not see a difference:

1) They will still see the netbios domain name in the drop-down box in
msgina
2) They can still use domainname\username OR the UPN name to log into the
domain

In Windows 2000 Native Mode, we enable a number of features, foremost:

a. Universal groups

b. Group nesting
Native mode allows for a new user group type (the Universal group). Group
nesting
allows groups to contain or "nest" other groups as members, such as Global
groups
within Global groups, and Domain Local groups within Domain Local groups.

c. Use of domain local groups as members of the Windows 2000 local computer
groups.

Windows 2000 member servers allow the use of Domain Local groups from the
domain to
exist on the local computer. These Domain Local groups can be used to
assign
permissions and rights on the member server.

d. Enabling of SID history.

Since none of these features are understood or accomplished by Windows NT4
Domain
Controllers, before making the transition to Native Mode you should ensure
that
there are no existing Windows NT4.0 BDCs being utilized.

Determining When to Move to Native Mode
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/default.asp?url=/
windows2000/techinfo/reskit/en-us/deploy/dgbf_upg_lsno.asp

Some KB Articles that explain this:

240305 Windows NT-Based BDCs No Longer Synchronize After a Windows 2000
Domain
http://support.microsoft.com/?id=240305

231273 Group Type and Scope Usage in Windows
http://support.microsoft.com/?id=231273

318862 Universal Group Scope Is Incorrectly Documented in Windows 2000 Help
http://support.microsoft.com/?id=318862

186153 Modes Supported by Windows 2000 Domain Controllers
http://support.microsoft.com/?id=186153

Of course once you go to native mode, you cannot rename your domain name
without upgrading to server 2003 since native mode assumes there are no
longer BDC's in the domain.

Hope That Helps!

Steve Dodson [MSFT]
Directory Services

--------------------
Thread-Topic: Switching to Native Mode
thread-index: AcOXTUtd9u8R6LszRFym03bhf+qjMw==
X-Tomcat-NG: microsoft.public.win2000.active_directory
From: "=?Utf-8?B?QWxsaXNvbiBXcmlnaHQ=?="
Subject: Switching to Native Mode
Date: Mon, 20 Oct 2003 14:01:12 -0700
Lines: 5
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
Newsgroups: microsoft.public.win2000.active_directory
NNTP-Posting-Host: TK2MSFTCMTY1 10.40.1.180
Path: cpmsftngxa06.phx.gbl!cpmsftngxa10.phx.gbl
Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.active_directory:52522
X-Tomcat-NG: microsoft.public.win2000.active_directory

We are ready to make the switch from a W2K mixed mode to native mode.
Just wondering what changes are the users going to notice (client machines
are either W2K Professional of Windows XP Professional)? For example, they
are used to seeing "NTGROUP1" as our domain name on their Windows login
screens (NTGROUP1 being our pre-windows 2000 domain name). After switching
to native mode, is NTGROUP1 going to be replaced with "ourcompany.com" in
the domain name field?

Also, if users access our fileserver resources from home through VPN, they
are prompted for a username and password. They are used to typing
NTGROUP1\username - how is this going to change? Will the user need to
enter (e-mail address removed) as their username?

Thanks!

--

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

Note: For the benefit of the community-at-large, all responses to this
message are best directed to the newsgroup/thread from which they
originated.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top