mdrabble Posted April 13, 2021 Posted April 13, 2021 Did an inplace upgrade from 2012r2 to 2019 on all 3 of my domain controllers back in January and thought all was well until last week when I was starting to see some GPO errors when running gpupdate on some computers. Turns out DC-01 which also holds FMSO roles and Certificate Authority stopped replicating and no matter how much troubleshoot I cannot get it to replicate again! So I am thinking, move FMSO roles to roles to another DC (which is easy enough) - but what about moving the CA? Never done this, so no idea how easy/difficult it is. Once moved all roles, I will demote the server and then spin up a new VM to take its place. Anyone moved their CA to a different server? Any gotchas i need to worry about? Cheers
mdrabble Posted April 14, 2021 Author Posted April 14, 2021 Thankfully I don’t have to do any moving of roles as found a solution which seems to have worked a treat. Stop dfsr service Give admin full control of system volume information folder Move dfsr folder to a safe location Restarted dfsr service Dfsr folder was recreated and folders were resync’d Probably not the correct way of doing things but it worked.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now