timbo343 Posted July 26, 2019 Posted July 26, 2019 Has anyone done an upgrade of their domain from FRS to DFS / DFSR which is now required for Server 2019 as FRS is now depreciated. I've been reading up on some articles however i'm just not sure at the moment, anything to do with altering the domain like moving from FRS to DFS gives me heebee jeebees.
MrLudwig Posted July 26, 2019 Posted July 26, 2019 I did this on a Server 2016 domain at my last school without a problem. Only had 3 DC's so didn’t take very long. From what I remember it’s a fairly straightforward process.
XiJ Posted July 26, 2019 Posted July 26, 2019 Much easier and quicker than I expected. Mine you tend to only have 2 DC’s at most.
HPlum78 Posted July 26, 2019 Posted July 26, 2019 Yeah stright forward don't panic overly. All the usual apply like backups and that mind just because it's straightforward we don't know your setup and all that
Cache Posted July 26, 2019 Posted July 26, 2019 (edited) I did this last year, was painless, following this guide on our 2008R2 domain. https://techcommunity.microsoft.com/t5/Storage-at-Microsoft/Streamlined-Migration-of-FRS-to-DFSR-SYSVOL/ba-p/425405 Edited July 26, 2019 by Cache
free780 Posted July 27, 2019 Posted July 27, 2019 Yep I used that guide. I wrote out the commands required. Connected to all the DCs. The main thing was to be patient while everything replicates. I did try it on a test domain at first even with a mixture of Server OS'.
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 Before i start this upgrade, i've noticed the majority of our GPOs have ACL issues which i have found under *GPO*> Status Tab. Click the Detect Now button and it comes back with SYSVOL ACL problems even though the Grou Policies are replicating fine. I have tried the Burflags fix but this hasn't made any difference. I've tried resetting the permissions on the group policies and this doesn't work either. The next thing to try will be to demote and re-promote the DCs but im really unsure if this is actually going to work.
HPlum78 Posted July 27, 2019 Posted July 27, 2019 (edited) If they are replicating then the ACL's are also replicating demoting DC's is not going to fix the issue and may well introduce some others! Edited July 27, 2019 by HPlum78
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 (edited) Yeah everything seems to be replicating as usual i was worried to see the following: The majority are like the first 2 screen grabs but the third screen is only on a few GPs. 1. 2. 3. Even creating a new Group Policy gives either 1 or 2 but as mentioned everything seems to replicating OK. Could it just be a "bug" in Server 2016? I have a mixture of 2016 and 2019 DCs. DCDIAG reports no errors either! Edited July 27, 2019 by timbo343
HPlum78 Posted July 27, 2019 Posted July 27, 2019 Yeah I would get in to a position where FRS and DFS are running in parallel if their are no replication errors.
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 I think i've f'ed it up or something is stuck: DFSR was unable to copy the contents of the SYSVOL share located at C:\Windows\SYSVOL\domain to the SYSVOL_DFSR folder located at C:\Windows\SYSVOL_DFSR\domain. This could be due to lack of availability of disk space or due to sharing violations. Additional Information: Sysvol NTFRS folder: C:\Windows\SYSVOL\domain Sysvol DFSR folder: C:\Windows\SYSVOL_DFSR\domain Error: 367 (The process creation has been blocked.) Things aren't great at the moment... eeek
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 Ok, i dont think this is a good place to be as of now. When in now run dfsrmig /getmigrationstate i get 3 DCs that are giving issues. One is in the START stage and the other 2 are int he Wating for initial Sync stage - the trouble is i've gone right the way to eliminated and now feel like i'm in deeper water! Is there anything that can be run to see why these servers are no going to the next stage? I thought everything was going so well as the dfsrmig was reporting good things until now and i could see things being copied to the SYSVOL_DFSR folders on the domain controllers. Hopefully someone can get me out of this situation.
HPlum78 Posted July 27, 2019 Posted July 27, 2019 Don't panic it's still serving the sysvol and netlogon via FRS 1
HPlum78 Posted July 27, 2019 Posted July 27, 2019 (edited) Download the graphical replication tool it's in the docs run it and let's go from there. In fact here:- https://www.microsoft.com/en-gb/download/details.aspx?id=30005 Edited July 27, 2019 by HPlum78 1
HPlum78 Posted July 27, 2019 Posted July 27, 2019 If needs be I will take a look at this with you will send you my number if we decide that would be any use. 1
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 If needs be I will take a look at this with you will send you my number if we decide that would be any use. Thanks, I think i might have found an answer - let me try it first. https://support.microsoft.com/sw-ke/help/4493934/sysvol-dfsr-migration-fails-in-place-upgrade-dc I'm working through the Issue occurs in the Eliminating phase as i have 2x 2016 DCs at the moment which is where i think the sticking point is. I honestly didn't know that 2019 had retired FRS.
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 If needs be I will take a look at this with you will send you my number if we decide that would be any use. Don't suppose you are around tomorrow (sunday) are you? I have removed the 2019 server but yet dfsrmig /getmigrationstatus is still showing ('Waiting For Initial Sync') - Primary DC and ('Waiting For Initial Sync') - Writable DC
snagrat Posted July 27, 2019 Posted July 27, 2019 2019 shouldn’t have let you promote it if you are still running FRS, so how did you get a 2019 DC?
HPlum78 Posted July 27, 2019 Posted July 27, 2019 Yeah I can be available tomorrow, I think @snagrat is right mind it a requirement of sever 2019 to use DFSR for the domain shares.... (I will stand to be Corrected though) Did you get the graphical AD Rep tool installed?
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 The 2019 server was an inplace upgrade to 2019 which apparently lets you use FRS. If it's a fresh 2019 server then it won't let you use FRS. I see the SYSVOL_DFRS replication is FRS Management which is something i didnt see populated on the 2019 server however still no further forward with the Waiting for Initial Sync on the 2 2016 servers. As for the AD replication status tool, i've run it but im not sure if it's actually telling me anything that i don't already know, that being SYSVOL is replicating as well as AD.
HPlum78 Posted July 27, 2019 Posted July 27, 2019 Ah OK that explains why it's allowed you to use FRS missed that you where doing it as an in place.
HPlum78 Posted July 27, 2019 Posted July 27, 2019 Repadmin /SyncAll /AeD run that on the DC's that do not hold the PDC emulator.
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 (edited) I *think* it's working and the SYSVOL folder has now disappeared from C:\WINDOWS and is now using SYSVOL_DFSR and replication seems to be working.... eeeek! Well, i've tried creating a new GPO in group policy and it's replicated to both servers and Group Policy is not giving any errors. So, what have i done! I browsed in the registry to "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DFSR\Parameters\SysVols\Migrating SysVols" and noticed both DCs had the key "Is Primary"=dword:00000000 set to 0 so not one DC was taking control of the domain. I set this to 1 on one DC. Then i looked in ADSIEDIT.MSC and browsed to OU=Domain Controllers > CN=*ServerName* > CN=DFRS-LocalSettings > CN=Domain System Volume int the middle pane right clicked CN=SYSVOL Subscription, selected Properties and looked for msDFSR-Options this had a value of . I set this to 1, clicked on and crossed everything thinking what on earth have i done! Gave it about 1 min and ran dfrsmig /getmigrationstate and noticed only 1 DC was there, the one that i had not been working on. Tested group policy and noticed things were replicating. Ran dfrsmig /getmigrationstate again and now get a message saying C:\Windows\system32>dfsrmig /getmigrationstate All domain controllers have migrated successfully to the Global state ('Eliminated'). Migration has reached a consistent state on all domain controllers. Succeeded. So i presume that this is now setup! And also, i've checked the Status of GPOs that were having replication issues, these have now been cleared up. Edited July 27, 2019 by timbo343 4
timbo343 Posted July 27, 2019 Author Posted July 27, 2019 So i guess now if i add a 2019 server to the domain, it should use the SYSVOL_DFSR to replicate from and create it's own SYSVOL folder as before or will it create a SYSVOL_DFSR folder?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now