Jump to content

Recommended Posts

Posted

Hi there,

We have an old 2012 R2 server. The school has finally purchased a replacement with Server 2022 on it.

They are very short on my time so trying to look at the best way to move everybody to the new one.

 

Orginarily, I would start a fresh with the new server as there are just under 100 systems. This would involve wiping the systems joined to the domain and adding them to the new server with a similar domain. The new server would have identical DHCP and DNS settings, but would not enable these until the old one is decomissioned. Not sure we are going to have the time for that.

Does anyone have any experience of using a swing server to take the existing domain and place it on a second server, and then to decomission the old one? How do shares work if they are all on the old server which you will get rid of? Same for GPOs, their settings would mostly point to files such as MSIs which would reside on the the old server which would be getting the chop.

 

Any advice would be greatly appreciated. I would rather do a fresh install but conscious they don't have a lot of time and have an unsupported OS so time is of the essence. Still feeling like fresh might be the best way as it will last them far longer than migrating stuff over.

Posted

Why do you want to create a new domain?

 

Cant you fire up the new server, join it to the 2012 domain, transfer FSMO roles, DNS, DHCP etc? This would eliminate the need to wipe the 100 devices & rejoin to the new domain. Would save you some work.

  • Thanks 3
Posted (edited)

EDIT: Beaten to it, but yeah... basically this...

 

Why do you want to create a new domain?

 

Cant you fire up the new server, join it to the 2012 domain, transfer FSMO roles, DNS, DHCP etc? This would eliminate the need to wipe the 100 devices & rejoin to the new domain. Would save you some work.

 

I would be less inclined to start afresh (but that's just me)...

 

I was in a similar situation a while ago (although I wasn't fortunate enough to have a new server purchased) although I still have a few bits to do.

 

And if that had been the case (new server) I would have set it up and joined it to the original Domain, not remove the old one, have the new one running beside it and transfer everything over at your leisure.

 

Then backup, backup, backup and in-place the 2012R2 to 2019, so that's at least the 'unsupported OS' problem dealt with and you have a 'spare' server.

Edited by Koldov
  • Thanks 3
Posted
Why do you want to create a new domain?

 

Cant you fire up the new server, join it to the 2012 domain, transfer FSMO roles, DNS, DHCP etc? This would eliminate the need to wipe the 100 devices & rejoin to the new domain. Would save you some work.

 

EDIT: Beaten to it, but yeah... basically this...

 

 

 

I would be less inclined to start afresh (but that's just me)...

 

I was in a similar situation a while ago (although I wasn't fortunate enough to have a new server purchased) although I still have a few bits to do.

 

And if that had been the case (new server) I would have set it up and joined it to the original Domain, not remove the old one, have the new one running beside it and transfer everything over at your leisure.

 

Then backup, backup, backup and in-place the 2012R2 to 2019, so that's at least the 'unsupported OS' problem dealt with and you have a 'spare' server.

 

Thank you both....

 

Ok so a few extra things I neglected to say.....

 

Old server has ranger on it - god knows why as it is so old, all of the stations also have ranger on. I don't want anything to do with that, just want vanilla.

Also, old server is in a state, it has not taken any updates for years, it is very unlikely it will in place. I have had lenghty discussions with MS about it and even they said, it is unlikely it will in place sucessfully, so I think we would need to totally wipe that and re build which is fine as I would like to repurpose it and use it for things such as Paxton Entry, Print Server, Inventry etc.

 

On the new server, I would ideally like to Azure AD Connect it if our basic licencing will allow for that so eventually, users would sign in to stations using their M365 logon and not our local AD logons which are all woefully non-cyber secutity compliant.

 

So it is a bit more complex than your average situation! :eek:

Posted
Thank you both....

 

Ok so a few extra things I neglected to say.....

 

Old server has ranger on it - god knows why as it is so old, all of the stations also have ranger on. I don't want anything to do with that, just want vanilla.

Also, old server is in a state, it has not taken any updates for years, it is very unlikely it will in place. I have had lenghty discussions with MS about it and even they said, it is unlikely it will in place sucessfully, so I think we would need to totally wipe that and re build which is fine as I would like to repurpose it and use it for things such as Paxton Entry, Print Server, Inventry etc.

 

On the new server, I would ideally like to Azure AD Connect it if our basic licencing will allow for that so eventually, users would sign in to stations using their M365 logon and not our local AD logons which are all woefully non-cyber secutity compliant.

 

So it is a bit more complex than your average situation! :eek:

 

I would never in place upgrade a DC, way too risky lol.

 

I'm unaware what ranger is, however my advice would be depending on how much time you have..

 

The safest option would be to fire the new server up, join to the 2012 domain, transfer FSMO roles across & test. Get everything replicated & set up so the new server is the Primary DC, and so that the new server is handling DNS+DHCP requests. Then test test test - once happy you can work on the rest of the bits (GPO's, shares etc..). If there isn't many, its probably easy enough to just copy the files over & re-create the shares.

 

Also yes, you will be able to use Azure AD connect, doesn't require any special licences.

  • Thanks 1
Posted

What os are the client computers running? Wasn't ranger stopped being supported quite some time ago?

 

Def install hyper-v role on new server and virtualise all the new servers. Fire up a new DC, should still be able to transfer roles to it by joining to the old domain I would have thought, but I don't know much about Ranger. Hopefully you can then just un-install this from the clients, once they are all gone decommission the old server.

 

If you are planning to use 365 logins, would an alternative plan be to not buy a new server and have a fairly rapid migration to the cloud? Spend the money on A3 licencing instead.

  • Thanks 1
Posted
Thank you both....

 

Ok so a few extra things I neglected to say.....

 

Hahah, yeah just one or two important things... :p

 

I know how hard it is to be succinct enough so that people don't have to read through pages of waffle, but still try to put all the relevant info into a post (and then you get all the replies with things you've already thought about that won't work and all the helpful suggestions about doing things that aren't actually possible for your situation)...

 

Just out of interest, you mention being pushed for time (which is the worst situation to be in when having to make decisions you might regret later on - PPP... and all that), is that because of the unsupported 2012R2/Ranger situation, or for some other reason (lack of support time or new role taken over - which would explain the state it's in, etc.)?

 

Old server has ranger on it - god knows why as it is so old, all of the stations also have ranger on. I don't want anything to do with that, just want vanilla.

Also, old server is in a state, it has not taken any updates for years, it is very unlikely it will in place. I have had lenghty discussions with MS about it and even they said, it is unlikely it will in place sucessfully, so I think we would need to totally wipe that and re build which is fine as I would like to repurpose it and use it for things such as Paxton Entry, Print Server, Inventry etc.

 

On the new server, I would ideally like to Azure AD Connect it if our basic licencing will allow for that so eventually, users would sign in to stations using their M365 logon and not our local AD logons which are all woefully non-cyber secutity compliant.

 

So it is a bit more complex than your average situation! :eek:

 

Yeah and so all that puts it safely well over my head, so imma stay subscribed, grab my popcorn and wish you luck!

 

;)

  • Thanks 1
Posted
Install Hyper - V if you can and split roles up into vm’s

 

Thanks, on the new server? Could do, but I am going to have the current older one going spare in the future. It is an HP ML390 G9 I think, so it has a few years left in it. Or could stick VMware on it in future and use that for role splitting maybe?

Posted
Thanks, on the new server? Could do, but I am going to have the current older one going spare in the future. It is an HP ML390 G9 I think, so it has a few years left in it. Or could stick VMware on it in future and use that for role splitting maybe?

 

Why not have VMWare or Hyper V on both then. Put new DC on new server, transfer roles, decomm DC on old server (do a P2V of old server to a seperate VM if need be but if you don't need it then don't bother) make old server a VMWare or Hyper V host then you have 2 servers for a while.

 

Or as others have said go M365 and have minimal services on site.

Posted

p2v the old, run it as a VM on the new server and in place upgrade it to 2022. Job done.. works a charm… if you have extra time sure migrate to new VMs (remember standard can licence 2 standard VMs)

 

inplace upgrading a DC is supported and does work.

  • Thanks 1
Posted

I haven't tried many different ways, but p2v made it really straightforward and low risk. You can be certain that everything will continue to work and have no downtime other than the equivalent of a server reboot - actually just while you move the network cables from one to the other.

 

Then as others have suggested, create a new DC. Then create more VMs and gradually split roles across. (I actually put an extra DC on it in a separate VM which lots of people thought was mad, but I stand by - it meant that in effectively a single server school, I could carry out maintenance on the DC during working hours. I then put most of the other roles in one more VM, but depending on requirements and resources of the server I might split it out more now.)

 

In a similar situation to you, I didn't put anything that would affect real-time service on the old server. I put an extra DC on it, an extra backup (we were using cloud backup, but I thought a local copy might be useful) and a WDS/MDT deployment server.

  • Thanks 1
Posted

Get the old server as updated as you can. Virtualise it with Hyper-V, then export each VM (DC, FS etc) you have created.

 

Install Hyper-V on the new server and then mount the VMs. I would then in place upgrade each VM (on the new server) to 2019/2022 if you have the licensing.

 

Lots of people suggest that you should never ever.... ever in place upgrade a DC. I however, have never had any issues doing this (I am probably very lucky lol) and I know a lot of techs that in-place upgrade everything with 0 issues.

  • Thanks 1
Posted

VMs make "omg, what if you break it?" obsolete.

 

However if you want an excuse to redo everything in a more modern way...

 

https://www.microsoft.com/en-us/download/details.aspx?id=56570 might work

 

Install Hyper-V on new server, install a windows server VM on that, create a new domain.

 

Test move everything to new server

 

If that works, set up automatic installation of client machines so there's 0 work to do per machine

 

Move all staff to onedrive, with MFA, move your shared drives to sharepoint.

 

Make a list of any specific configurations per machine, any software that's not on every computer.

 

First day of summer, re-migrate every account to new server.

 

Over summer redo all the client machines, move pupils' files, set a schedule for teacher laptops. Explain that in week X don't bother coming on site to use computers

  • Thanks 1
Posted

MS do support in-place OS upgrades for Domain Controllers although over the years they have lets say flipped and flopped on the best approach for this, the current documentation that I can find here https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-domain-controllers guides you in the way of introducing the new OS version and then migrating to the newly deployed OS.

 

Now that Broadcom has acquired VMware I am going to bet with the licensing changes that will come most schools will not have the money to run VMware when it comes to renewal (but hay that's the Broadcom way!) so core install on the new server and Hyper-V may well be the way... that said I don't know the spec of the new server and what the architecture needs to look like.

  • Thanks 1
Posted
You see to be saying you're time short, but minded to do the most time consuming possible approach (greenfield everything). A fresh, clean start sounds appealing with a promise of a wonderful future but it rarely works out like that. I back the approach of Jmak and others both as being the least amount of time and lowest impact/ highest quality approach.
Posted
What spec is the new server and what roles does the old one currently hold? I assume this is a single server domain, presumably for a primary?

 

Get the old server as updated as you can. Virtualise it with Hyper-V, then export each VM (DC, FS etc) you have created.

 

Install Hyper-V on the new server and then mount the VMs. I would then in place upgrade each VM (on the new server) to 2019/2022 if you have the licensing.

 

Lots of people suggest that you should never ever.... ever in place upgrade a DC. I however, have never had any issues doing this (I am probably very lucky lol) and I know a lot of techs that in-place upgrade everything with 0 issues.

 

Thanks everyone for your posts, I really appreciate it.

The school wants to continue with on prem but I am slowly convincing staff that this is quite old fashioned and they are starting to see the benefits of M365.

It is a primary, yes.

 

Are you saying you could p2v using HyperV? I know this was possible with VMware but I have not used HyperV in years.

My only concern with using HyperV was the fact that this server has a BIOS based RAID which again, I have never used to using a seperate RAID controller. I am assuming if I used VMware, I would need to install the software for the BIOS RAID on every VM (It has some IIS web based interface)?

 

The spec for the new server is farily decent:

HP M350 G11

Intel® Xeon® Silver 4410Y

64gb RAM

4 x 1GB NIC

1 x MR408i Storage Controller

2 x 240GB SSD - RAID 1 for Host Server OS

4 x 600gb SAS - RAID 6 for Storage

Server 2022 Standard installed

Posted
Thanks everyone for your posts, I really appreciate it.

The school wants to continue with on prem but I am slowly convincing staff that this is quite old fashioned and they are starting to see the benefits of M365.

It is a primary, yes.

 

Are you saying you could p2v using HyperV? I know this was possible with VMware but I have not used HyperV in years.

My only concern with using HyperV was the fact that this server has a BIOS based RAID which again, I have never used to using a seperate RAID controller. I am assuming if I used VMware, I would need to install the software for the BIOS RAID on every VM (It has some IIS web based interface)?

The spec for the new server is farily decent:

HP M350 G11

Intel® Xeon® Silver 4410Y

64gb RAM

4 x 1GB NIC

1 x MR408i Storage Controller

2 x 240GB SSD - RAID 1 for Host Server OS

4 x 600gb SAS - RAID 6 for Storage

Server 2022 Standard installed

 

I believe it is possible with Hyper-V. Have a read from this article - https://www.nakivo.com/blog/convert-physical-machine-hyper-v-vm/

Posted
Disk2VHD does it well, and you dont even need to power off the VM. i cant remember if your OS has VM extensions built in which my be a headache but it will work.
  • Thanks 1
Posted
Disk2VHD does it well, and you dont even need to power off the VM. i cant remember if your OS has VM extensions built in which my be a headache but it will work.

Yeah that's it! I couldn't remember the name (mondays!!)

  • Thanks 1
Posted

With a machine that spec, I'd roll up a hypervisor (of your choosing, Hyper-V or VMWare are mainstream and should both support that hardware on the latest versions), create new VMs per role as redundant services, then migrate the roles over.

 

E.G. with the old server still running, build up a new DC, give it the DHCP role and add it into the DHCP pool; Give it the AD and DNS roles and add it to the existing domain...

 

With files, DFS role to the existing server and set up DFS so that it is using a namespace to access the files (this won't affect any of your existing shares). Then roll up a new VM file server, give it the same roles and add it to the DFS namespace and copy all the files across to it; Change your domain shares to reference the new DFS paths; do a final data copy, then decommission the old file server.

 

Once all that is done, any additional services can be dealt with as you need to, or do a P2V from the old server to another VM to buy you time to sort the rest out.

  • Thanks 2
Posted
MS do support in-place OS upgrades for Domain Controllers although over the years they have lets say flipped and flopped on the best approach for this, the current documentation that I can find here https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-domain-controllers guides you in the way of introducing the new OS version and then migrating to the newly deployed OS.

 

Now that Broadcom has acquired VMware I am going to bet with the licensing changes that will come most schools will not have the money to run VMware when it comes to renewal (but hay that's the Broadcom way!) so core install on the new server and Hyper-V may well be the way... that said I don't know the spec of the new server and what the architecture needs to look like.

 

I read that a bit too quick then and read Bromcom not Broadcom.

 

Phew.

 

GJE

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...