The Best Methods for Connecting the Current AD Infrastructure with the Univention Corporate Server

Hello Everyone :hugs:,

At the moment, I’m tasked with merging my organization’s present Active Directory (AD) architecture with Univention Corporate Server (UCS). I’ve read through some of the tutorials and material, but I’m still not sure what procedures to follow to guarantee a seamless integration without messing with our current configuration.

Below is a quick synopsis of our current surroundings:

  • We have an AD running on Windows Server that handles file sharing, group policies, and user accounts for several departments.
  • In order to administer Linux-based servers and apps and to keep AD synchronised, we wish to implement UCS.
  • Our aim is to have UCS function as a secondary domain controller and to enable users to connect in to Windows and Linux systems using their current AD credentials.

I’m primarily seeking suggestions or counsel regarding the following matters:

Synchronisation: How can I get UCS and AD users, groups, and policies in sync with one other? Are there any limitations or potential dangers that I should be mindful of? :thinking:

Data Migration: Without resulting in downtime or data loss, how can I move current AD data—such as user profiles and permissions—to UCS? :thinking:

Security Considerations: In order to avoid unauthorised access or data breaches, are there any security best practices or configurations I should put in place while integrating UCS with AD? :thinking:

Long-Term Maintenance: When operating a hybrid UCS-AD environment, what long-term maintenance considerations need to be made? :thinking: What is your approach to updating, backing up, and troubleshooting? :thinking:

https://help.univention.com/t/ucs-5-0-update-fails-due-to-ucr-templates-are-not-compatible-with-python-3-package-univention-management-console-server/google-cloud-platform

Any guidance, insights, or materials you could provide would be highly valued. Thank you :pray: in advance for your help and support.

Hi smith_john,

I’m sure you read the docs :wink:

Installation
Just make sure to make your choices right the first time. It will be difficult to change the drive partitioning later in the process.

My personal suggestion would be:

2.7. Partitioning the hard drive
Guided - Use entire disk and set up LVM
Separate `/home`, `/usr`, `/var` and `/tmp` partition

Once installed, join the current domain and see what was copied from the Windows AD. Install the “Active Directory-compatible Domain Controller” and you can use RSAT to see things like AD and GPO.

What do you mean by running a hybrid UCS-AD domain? Are you planning to run both (UCS & Windows) alongside?

People have successfully transferred from Windows to UCS, leaving behind the MS server world. There’s plenty of information on this forum and in the docs. Word of warning, if you plan on running business on UCS consider buying subscription plan.
Also, have patience with this forum and search before you ask :slight_smile:

Mastodon