Migrate existing PDC/DHCP/DNS 2003 server to new 2003 server

Posted on 2005-04-18
Medium Priority
Last Modified: 2010-03-18
Currently our network is split between three servers:
- Server1 (2003 Standard): PDC, AD, DNS, DHCP, IIS 6.0 (for OWA), Exchange
- Server2 (2003 Datacenter Edition): Print & File Server
- Server3 (2000 Standard): IIS 5.0 for FTP and Web hosting (Server sits in the DMZ)

I want to add a new server (2003 Standard) to the network, make it the PDC and take the authentication load off of the exchange server. What pitfalls should I watch out for during this process and what is the best way to go about doing this?  I'd like to leave Server1 setup as a BDC but also have the flexibility to add another server to the mix for BDC purposes (not exactly resource hungry with a 100person userbase so they are somewhat cheap).  

I've given 500pts for the question because I'll be asking for a lot of detail in the responses and a bunch of hand holding ( I'm a programmer not a network admin, or so I keep telling my bosses that).  
Question by:CorpulantCoder
  • 4
  • 3
LVL 71

Accepted Solution

Chris Dent earned 2000 total points
ID: 13817447

Just a note first... I know you had no intention of doing it... but it's very important that you don't demote Server1 (that is, don't stop it being a Domain Controller). That kind of thing is completely unsupported by MS and may be impossible to fix if it breaks.

I notice you only have Exchange acting as DNS, do you want the new server to become a backup for that as well?

May as well add in the usual, you should take a full backup of your existing DCs before doing this to ensure there is always a way back in the case of serious failure.

Install the new server and get it online as a Domain Controller. Give it 30 minutes to an hour to ensure it's had a chance to replicate with the domain then check for any errors in the Application, System and Directory Service Event Logs.

DNS Server

If you do want to set it up as DNS as well then follow these steps:

1. Check that the new server uses your existing DNS Server
2. Ensure the DNS Component is Installed on the Server and that the Service is Started
3. Open DNS Manager
4. Expand Forward Lookup Zones
5. Create a New Zone. This should be Primary Active Directory Integrated. The name should be the same as your current Domain Name (e.g. mydomain.local)
6. Verify that the new zone is set to Allow Secure Dynamic Updates
7. Expand Reverse Lookup Zones
8. Create a New Zone. This should be Primary Active Directory Integrated. The name should be the same as your current Network Range (e.g. 192.168.12.x)
9. Verify that the new zone is set to Allow Secure Dynamic Updates

Under each zone you should immediately see all your existing DNS records - including entries like _msdcs. Once again check Event Viewer for errors, including the DNS Log.

If this completes successfully you can change the server and clients to check DNS information from this server rather than Exchange.

Global Catalog

It is advisable to make this server a Global Catalog. Exchange makes heavy use of Global Catalog Servers, so it would be a good idea to leave this role running on Exchange as well.

To configure this open Active Directory Sites and Services, find your new server, select NTDS Settings and open the Properties. You should see a little tick box for Global Catalog. Tick this for your new server.

FSMO (Flexible Single Master Operations) Roles

This is pretty much the last of it, transferring these roles to the new server will leave much less for your Exchange Server to take care of. These steps should cover moving each of them.

1. Ensure you are logged on as a member of the Schema Admins Group.
2. Load the NTDS Utility:


3. To check which server currently has the FSMO roles type the following into NTDSUtil:

Connect to Server <Name of the new DC>
Select Operation Target
List Roles for Connected Server

This will show you the location of each of the 5 operations roles. They're probably all on the Exchange server at this point.



To take you back to FSMO Maintenance.

4. Transfer the Roles to the new server. We're already connected to the right server (Connections part above). These commands perform a online transfer of each of the roles to the new server:

Transfer RID Master
Transfer Schema Master
Transfer Infrastructure Master
Transfer PDC
Transfer Domain Naming Master

Each of those should complete successfully.

5. Make sure they're in the right place now by checking the roles for the server again:

Select Operation Target
List Roles for Connected Server

You should now see they are all running on your 2003 server. If that all worked correctly type Quit until it lets you out of NTDSUtil.

As before, check each of the Event Logs for errors to see if anything broke during that and check Exchange is still working without problem.

That should do it for now, let me know if any of that isn't clear or needs further detail, or just if you run into any problems.



Author Comment

ID: 13858042
Thanks for the great reply.  Should have the new server in house within a week or two.  I'll leave the question unawarded until then so I can pick your brain in case any issues arise.  Thanks again.
LVL 71

Expert Comment

by:Chris Dent
ID: 13858051

Pleasure :)
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.


Author Comment

ID: 13968788
Well everything went well and I now have the servers set up as follows:
Server1 (2003): DNS, WINS, DHCP, AD, Global Catalog, FSMO roles owner
Server2 (2003): DNS, WINS, AD, Exchange

The only issue I've run into now is with Active Directory.  In the past, when adding a new user I would go to AD, add them, and in the process a mailbox would be created for them.  I can still do this via AD on the Server2 but attempting to do so on Server1 leaves me with no exchange interface.  Is there something I missed during setup or is this the way things should be? Will I always have to go back to the Exchange server to administer a user's mailbox settings or is it possible to do it from any server with AD configured? Thanks.
LVL 71

Expert Comment

by:Chris Dent
ID: 13968973

All you need is to add the Exchange system tools on Server1, they have all the plug-in's that allow you to add and administer mailboxes.


Author Comment

ID: 14026243
Well everything is up and running smoothly. Thanks for the help Chris.
LVL 71

Expert Comment

by:Chris Dent
ID: 14026250

Pleasure, glad it's all working :)

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
An article on effective troubleshooting
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …
Suggested Courses

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question