Jump to content

Recommended Posts

Posted

Hello,

We're looking at migrating our current Domain Controller (Windows Server 2008) and it's replication (Windows Server 2008R2) to Windows Server 2012.

 

We were just wondering how anyone else has gone about this, as we will want to start from the ground up rather than a simple upgrade due to the fact the current DC has some major issues.

 

We will be migrating AD, Group Policy Management, DNS and DHCP.

 

 

(On another note, would anyone further recommend not having DNS/DHCP on the DC? I've seen threads about this in the past....!

Posted

What are the issues? Will they be replicated to a new domain controller when you add it to the domain? Might be worth sorting out the issues before upgrading the DC.

 

In terms of process, it's typically...

 

Move all FSMO roles to one DC (this DC must also have a copy of the Global Catalog)

demote the other DC and remove from domain

Prep the domain for a 2012 controller

build new DC and join domain, make sure it has global catalog and dns

Let it replicate

move FSMO roles to new DC

demote and remove other DC

raise domain function level

build other DC with 2012.

 

I tend to run DHCP on it's own server, just because...virtualisation (why not?)

 

IMHO, it's best practice that all DCs should be running DNS locally.

  • Thanks 1
Posted (edited)
What are the issues? Will they be replicated to a new domain controller when you add it to the domain? Might be worth sorting out the issues before upgrading the DC.

 

In terms of process, it's typically...

 

Move all FSMO roles to one DC (this DC must also have a copy of the Global Catalog)

demote the other DC and remove from domain

Prep the domain for a 2012 controller

build new DC and join domain, make sure it has global catalog and dns

Let it replicate

move FSMO roles to new DC

demote and remove other DC

raise domain function level

build other DC with 2012.

 

I tend to run DHCP on it's own server, just because...virtualisation (why not?)

 

IMHO, it's best practice that all DCs should be running DNS locally.

 

The way you've written this out makes it sound like it's much less difficult than I imagined?

Is this true?

 

 

The issues are mainly relating to Ranger and the fact that it's corrupt and cannot be removed from the system.

We've even had Ranger support at it and they've given up...

Edited by GRitchie
Posted

Totally not aware of what Ranger is or what effect it does/doesn't have on AD so not in a position to advise on that front.

 

But in general - and for all the DC's have upgraded over the years, yes it's that simple. Not that it doesn't make me paranoid and nervous each time I do it. I should add - take a Windows Backup of the System Settings for bare metal recovery as a fail safe you hope you never need - before doing any demotions/promotions. Can't be too careful.

 

The single most important step is the "Allow to replicate". Should happen automatically within about 4 hours, give or take. Definitely should be complete in 24 hours. I tend to leave servers at that stage for about 3 days because I'm paranoid something is going to go wrong.

 

I tend to make all DC's have DNS and Global Catalog whether they need it or not. That way FSMO roles can sit on one server and I don't need to work out how to split them up between servers.

 

So yep, should be that easy...

Posted

I see!

And, so excuse me for sound stupid, but having never done this before, could you explain what the Global Catalog is and where it's found?

Also, is 'FSMO roles' just the roles required for a DC?

Posted

At least one DC must contain a copy of the Global Catalog. My only interaction with it thus far has been a tick box when doing DCPROMO to make the DC contain a copy. Detail on the GC can be found here: https://technet.microsoft.com/en-gb/library/cc728188(v=WS.10).aspx

 

There are 5 FSMO roles. They equate to what would have been known as the Primary Domain Controller (PDC) in NT4 (and 2000?). Before you demote any server make sure the 5 roles are moved to the remaining server - https://support.microsoft.com/en-us/kb/223346/

 

And for ADPrepping prior to adding the first 2012 DC: Adprep in Windows Server 2012 - Active Directory Documentation Team - Site Home - TechNet Blogs

Posted (edited)

Excellent! That all makes sense.

 

If we were wanting to change the FQDN at the same time as the upgrade, does this make things much more difficult and the Domain Name itself.

Edited by GRitchie
Posted

Best practice, when you build the each new 2012 DC, would be to give it a computer name and IP that hasn't been used before by any DC.

 

As for changing the domain name. Never tried. It's supposed to be pretty easy in 2012 onwards. My fear (and why I've never tried) is that clients will need rejoining under the new domain name - don't know if that's true or not, but would make sense so never tried - don't want to visit 400 computers and rejoin them to the domain.

Posted

Found this guide here: https://mizitechinfo.wordpress.com/2013/06/10/simple-guide-how-to-rename-domain-name-in-windows-server-2012/

 

Doesn't look overly difficult but there seems to be a fair number of steps. Step 28 is going round each client and rejoining the domain - ouch :(

 

Shame, our domain name is lovingly called 'chaos.local'. I hate it. Last network manager had a thing for greek gods and named the servers after them - grrr. I've since renamed all servers to something sensible but I stuck with that domain name - arrggghhhh!!!!!

Posted
One thing - if you have Exchange 2007 or later installed in the domain, you cannot rename the domain. While you can certainly do your DC's as explained above, you can't change the domain name.
Posted

Is it truly a migration if you're looking to have a new Domain name?

 

If you're intent on doing this and will have to go down the route of re-adding the machines to the new domain, then you might be better off building an entirely new domain side by side. This will give you peace of mind that you're not breaking the old to make the new.

 

If you're not going to rename, then migration really is as simple as explained above. Thankfully we had no issues with our domain, so we just did an in place upgrade from 2008 R2 to 2012 R2. You don't need to demote or remove any roles from the machine and from our experience takes a couple of hours per server.

Posted
One thing - if you have Exchange 2007 or later installed in the domain, you cannot rename the domain. While you can certainly do your DC's as explained above, you can't change the domain name.

 

Really?

Why is this?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...