Windows 2000 Domain Rename
Can I rename my Windows 2000 Domain?
The short answer is YES and NO.
Passwords Haven’t Disappeared Yet
123456. Qwerty. Iloveyou. No, these are not exercises for people who are brand new to typing. Shockingly, they are among the most common passwords that end users choose in 2021. Research has found that the average business user must manually type out, or copy/paste, the credentials to 154 websites per month. We repeatedly got one question that surprised us: “Why would I ever trust a third party with control of my network?
You can rename a Windows 2000 Server AD Domain only if it’s still configured as a Mixed mode domain.
Note: Windows Server 2003 AD Domains CAN be renamed (see Windows 2003 Domain Rename page for more info).
MS KB 292541 has more info:
Although you can rename a Windows 2000 domain in some situations that are described in this article, Microsoft highly recommends that you decide on the Fully Qualified Domain Name (FQDN) for DNS before you actually create a new domain or before you upgrade the domain from Windows NT 4.0 to Windows 2000. After you create the domain, you cannot rename a Windows 2000 domain controller. Renaming the domain involves a considerable amount of work, and it is only possible in a scenario that meets the following conditions:
- You have to keep the Windows 2000 domain in Mixed mode. After you change it to Native mode, you cannot return the domain to Mixed mode, thereby rendering renaming impossible. To determine the mode in which the domain is currently running, expand Active Directory Users and Computers, right-click the domain name, and then click Properties. The mode appears in the Domain operation mode dialog box.
- Because the domain is in Mixed mode, it must also either have one or more existing Windows NT 4.0 backup domain controllers (BDCs), or computers that are available to use as Windows NT 4.0 BDCs.
Because you must demote all existing Windows 2000 domain controllers to member servers before you rename the domain controller, review the following information in terms of logistics:
- The renaming can only take place after you revert the domain back to Windows NT 4.0, and then during the upgrade to Windows 2000, after you have renamed it with the desired DNS (FQDN) name. The NetBIOS domain name remains the same.
- If you have created one or more child domains, you have to revert the child domains back to Windows NT 4.0 first, and then revert the parent domain. Next, you rename the parent when you upgrade it to Windows 2000, and then you bring the child domain up again when you upgrade it to Windows 2000. The amount of time that this process requires depends on the number of Windows 2000 domain controllers that are in the domain, in addition to their physical location.
If your scenario meets the conditions listed in the “Summary” section of this article, you can use the following steps to rename the Windows 2000 domain. These steps involve a single domain situation. If a child domain exists:
- Complete the same steps to revert the domain back to Windows NT 4.0 on the child domain first, and then you stop after you complete step 6.
- Complete steps 1 through 8 on the parent domain.
- After you revert the parent domain back to Windows NT 4.0, and then upgrade it back to Windows 2000 with the desired name, you can complete the final upgrade steps to Windows 2000 on the former child domain, during which you make it a Windows 2000 child domain again.
To Rename a Windows 2000 Domain
- Create a backup of any and/or all domain controllers that may be involved in this process.
- If there are no existing Windows NT 4.0 BDCs in the Windows 2000 domain, then you have to install one that is preferably running service pack 6 or 6a. If you want, you can install a second BDC and then physically remove it from the domain to serve as a backup for the domain information as it contains all of the domain user accounts, and the Security Accounts Manager (SAM) and security information.
- Allow sufficient time for this BDC to acquire all domain security and SAM information. To force a full SAM/security database replication, run the following command on the BDC:
net accounts /sync
A record of the successful full replication events should be logged in the System log.
- If there is only one Windows 2000 domain controller in the domain, leave the Windows NT 4.0 BDC connected to the network, and then physically remove the Windows 2000 domain controller from the network. Make sure that the Windows 2000 domain controller is isolated from the rest of the network. If it is plugged into a hub, make sure it is not connected to the rest of the domain. If you have only one Windows 2000 domain controller, you can perform step 6 now before you continue with the demotion of the Windows 2000 domain controller.
- You must now demote all the Windows 2000 domain controllers to member servers by running the dcpromo command on the actual domain controller. To run this command, click Start, click Run, type dcpromo, and then click OK. If there are more than one Windows 2000 domain controller, run dcpromo on each of them to make each one a member server, until there is only one Windows 2000 domain controller remaining.
- Now you can disconnect the Windows 2000 domain controller from the network, while leaving the Windows NT 4.0 BDC connected. Run dcpromo on this last domain controller, and be sure to choose the last domain controller in the domain option. When this completes, and the computer restarts, it will be a member server in a work group, which you can then rejoin to the domain if you want to. If you disconnected one Windows 2000 domain controller in step 4, then you simply run the dcpromo command on it as described in this step.
Note: To run dcpromo successfully, the network adapter must detect a network connection. Therefore, the Windows 2000 domain controller must be attached to an active hub or switch, even if there are no other connections to the hub or switch, and it is isolated from everything else which is desired.
- Open Server Manager on the Windows NT 4.0 BDC and promote this computer to a primary domain controller (PDC). If a message appears stating that it cannot contact the PDC and asks if you want to continue, click Yes, and then complete the promotion. When this is complete and the server restarts, verify in Server Manager that the computer it is now described as the PDC.
- Upgrade this Windows NT 4.0 PDC to Windows 2000. When the Windows 2000 upgrade is complete, the computer restarts to begin the Active Directory installation. During this process, enter the desired domain name.
- If you have demoted other Windows 2000 domain controllers earlier, you can now promote them back to domain controllers by running dcpromo on them.
You may find these related articles of interest to you:
- Delete Failed DCs from Active Directory
- How to Install Active Directory on Windows 2000
- How to Install Active Directory on Windows 2000 (for Lamers)
- How to Install Active Directory on Windows 2003
- How to Install a Replica DC in an Existing AD Domain on Windows 2000
- How to Install a Replica DC in an Existing AD Domain on Windows Server 2003
- Install DC from Media in Windows Server 2003
- Joining a Domain in Windows XP Pro
- Troubleshooting Dcpromo Errors
- Unattended Installation of Active Directory
- Windows 2003 ADPrep
- Windows 2003 ADPrep Fix for Exchange 2000
- Windows 2003 Domain Controller Rename
- Windows 2003 Domain Rename
Download Windows Server 2003 Active Directory Domain Rename Tools (v1.2, April 2003, 93kb)
Understanding How Domain Rename Works (Doc, 362kb)
Step-by-Step Guide to Implementing Domain Rename (Doc, 1.2mb)