All the AD server components are Windows 2003. There are Windows 2000 desktops and application servers.

The migration is a site-by-site user (and computer) migration into an existing AD forest which is well established. This means that my environment needs to fit in to the existing structure.

The requirement for merged loopback processing already means that I need to get some changes made higher up the tree to reduce the number of policies that are applied - I assume that each policy is applied in order at the client rather than receiving a neatly summarised policy?