2

I was asked to help out in a problem, there is a domain still operating at a 2003 functional level, there are 2008 R2 member servers in this domain and we need to know if there is anything we have to do to plan or anticipate when trying to apply the GPO settings to the 2008 R2 member servers.
- Will I need a 2008 R2 server with GPMC in order to deploy the GPO settings or can we deploy them with the GP tools in 2003 server? - are there any gotchas we need to know about. Appreciate the feedback.


Our situation is that we have member servers we need to apply security settings for not Domain controllers, we have no intention of standing up 2008 DC's, we only need to know what's required or involved to successfully patch those 2008 R2 servers in a 2003 domain. Someone from another team mentioned the following: Requirements: ADPREP /forestprep, then ADPREP /domainprep /gpprep, this updates the GUIDs for the GPOs in order to enable the increased security requirements. There is no need to deploy a 2008 R2 or 2012 R2 Domain Controller, only a member server is needed to update the forest GUIDs, and when running the ADPREP /domainprep /gpprep is ran it will update both the domain GUIDs, and GPO GUIDs, without affecting the functionality of the forest or domain functional level.
My question is, are these steps required, we have no plans of using ADMX, we just have a GPO to apply server policies and that's it. I did search extensively and did not find any solution to this question. Thanks.

Sven
  • 98,649
  • 14
  • 180
  • 226
Angel V
  • 21
  • 2

2 Answers2

1

This has been asked here for member servers being added only. If you want to make the 2008 box a DC you will need to use ADPREP link here.

We have a 2003 domain functional level with 2008 members and DC's. All have GPO's applied created from 2008 and 2003 DC's, hope that helps.

0x0000001E
  • 147
  • 6
  • Some additional information on adding DC's here: https://technet.microsoft.com/en-us/library/cc733027(WS.10).aspx – 0x0000001E May 01 '15 at 10:02
0

... You dont need to run ADPREP for this ... same like you dont need to prep your AD for 2012 gpos with function level 2008r2... would be the same thing

Just deploy the policys.. download all the ADMX templates for this step

Cosmic542
  • 49
  • 2
  • Thanks, its my first time posting a question so I appreciate the info and that's what I thought. I figured it would be easy enough to just create a GPO and apply it. Thanks for confirming. – Angel V May 01 '15 at 23:43