JoeBloggs Posted June 26, 2013 Posted June 26, 2013 Hi there, just need some quick advice on the following. I am replacing our Master Domain Controller which is on 2003. I have built a new 2003 server and I have made it a DC. What are the next steps I need to take to make the new server the Master DC and demote / turn off the other? Thanks!
ChrisH Posted June 26, 2013 Posted June 26, 2013 Transfer FSMO roles Update DHCP entries for clients for things like DNS servers Make sure you are happy with everything DCPROMO the old server 1
ricki Posted June 26, 2013 Posted June 26, 2013 Hi i know this will be a silly question but why sre you not using a later version of windows server ???????
JoeBloggs Posted June 26, 2013 Author Posted June 26, 2013 Hi i know this will be a silly question but why sre you not using a later version of windows server ??????? We have approx 20 servers at 20 different sites, each site having its own DC. Some sites DCs are on 2008 and some are on 2003. I can't upgrade the master dc to 2008 and have member 2003 dc servers and I don't have the money to upgrade them all
ADMaster Posted June 26, 2013 Posted June 26, 2013 We have approx 20 servers at 20 different sites, each site having its own DC. Some sites DCs are on 2008 and some are on 2003. I can't upgrade the master dc to 2008 and have member 2003 dc servers and I don't have the money to upgrade them all why not? Money is one reason, but technically they can have member 2003 servers. I ran a 2008 and 2003 DC together on the same domain until I demoted the 2003. I currently have 2008 DC's with 2003 member servers and a 2012 eval member server. I plan to do similar with 2012, install a 2012 DC then a some point in the future demote 2008. 1
JoeBloggs Posted June 26, 2013 Author Posted June 26, 2013 It was my understanding that you can't have a Windows Server 2008 Master Domain Controller with Window Server 2003 Member Domain Controllers. Do you have a link to verify this ?
PhoneUser1 Posted June 26, 2013 Posted June 26, 2013 (edited) Point to note for OP. When you demote the server/transfer the roles, do not format or remove the old server for at least 2 weeks, just in case. If anything does go wrong or clients and services go looking for the old server, at least you can put the roles back whilst you sort out the problem. Dos_Box Edited June 26, 2013 by PhoneUser1
fiza Posted June 26, 2013 Posted June 26, 2013 There is no such thing as a Master Domain Controller. You can have 2008 and 2003 domain controllers you just wont be able to raise your domain functional level to 2008 (to get the extra benefits a 2008 domain offers). PeteNetLive - KB0000239 - Deploying a Windows Server 2008 Domain Controller in a Windows 2003 Domain Used to be Primary Domain Controllers in NT days. 1
JoeBloggs Posted June 27, 2013 Author Posted June 27, 2013 (edited) What do you mean by master domain controller? Ben Primary Domain Controller (server which holds FSMO roles) Edited June 27, 2013 by JoeBloggs
3s-gtech Posted June 27, 2013 Posted June 27, 2013 ^^Those only exist pre Server 2000 I believe. There are no PDCs any more, DCs are just peers (though one will hold the FSMO roles etc). You can happily have a Server 2008 onwards DC with Server 2003 DCs, you just won't be able to raise the functional level. If you're building Server 2003 servers now, you're making more work for yourself. Windows updates (security fixes etc) cease next year. If you update them to 2003 R2 at least, you get an extra year of support. 1
JoeBloggs Posted June 27, 2013 Author Posted June 27, 2013 Thanks for the replies. The Domain Function Level is at 2003, I did this when I added my first Winodws Server 2008 DC. I have basically been calling my "master/primary" domain controller, the DC which holds the FSMO roles. (currently on 2003) Am I right in thinking then that I can transfer the FSMO roles from 2003 to my 2008 DC? I am sure I read somewhere that when your domain & functional level are both at 2003, you can add read-only 2008 DCs
fiza Posted June 27, 2013 Posted June 27, 2013 You can move your fsmo roles to the 2008 DC. "To deploy an RODC, at least one writable domain controller in the domain must be running Windows Server 2008. In addition, the functional level for the domain and forest must be Windows Server 2003 or higher. " Taken from this article : AD DS: Read-Only Domain Controllers
ADMaster Posted June 27, 2013 Posted June 27, 2013 It sounds like you are putting all of the FSMO roles on one machine. If you only have one DC that will do, but if you have multiple DC’s the FSMO roles should be split. See this MS article FSMO placement and optimization on Active Directory domain controllers
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now