how to convert aditional domain controller to primary domain controller

Posted on 2007-10-08
Last Modified: 2012-05-05
i am working on disaster recovery and i want to know if my domain goes fail, my hard disk corrupt or i loss my backup than how i change my ADC to PDC. means which right i have to give ADC to work as Primary Domain Controller. what steps in FSMO or other i have to take.

Thanks in advance

Question by:sitg
    LVL 4

    Expert Comment

    There is no such thing as  PDC within Windows 2003.
    If you have a DR situation then depending on which FSMO roles the server(s) held, which failed, would depend on which roles you would need to seize.

    You can seize a FSMO role via NTDSUTIL
    LVL 30

    Accepted Solution

    First let's be clear on terminology - no such thing as a PDC anymore, that term went by the wayside in Windows NT 4.0

    The answer to your question will depend on the length of the outage, and whether you expect your other domain controller(s) to be returned to service.  

    If the outage will only last for a few hours, you'd likely only need to seize the PDC Emulator FSMO role over to the other domain controller, as described here:, confirm that the other DC is a Global Catalog server, as described here:, and configure the DR DC with an authoritative time source, as described here:

    For a more extended outage or one where your other DCs will not be returning to service, you'll need to perform the steps above, and in addition seize all 5 FSMO roles and perform a metadata cleanup to remove references to the failed DC(s) from your production environment:

    LVL 70

    Expert Comment

    One way to provide resilliance is to have two domain controllers, that way if one fails active directory is immediately availabl on the other and can systems be recovered quickly and without downtime.

    To add a second domain copntroller Install Windows on another new machine

    Assign the new computer an IP address and subnet mask on the existing network

    Make sure that the preferred DNS server on new machine points to the existing DNS Server on the Domain (normally the existing domain controller)

    Join the new machine to the existing domain as a member server

    From the command line promote the new machine to a domain controller with the DCPROMO command from the command line Select Additional Domain Controller in an existing Domain

    Once Active Directory is installed then to make the new machine a global catalog server, go to Administrative Tools, Active Directory Sites and Services, Expand ,Sites, Default first site and Servers. Right click on the new server and select properties and tick the Global Catalog checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

    Make sure DNS is also installed on the new Domain Controller, assuming that you were using Active Directory Integrated DNS on the first Domain Controller, DNS will have replicated to the new domain controller along with Active Directory.

    If you are using DHCP you should spread this across the domain controllers, In a simple single domain this is easiest done by Setting up DHCP on the second Domain controller and using a scope on the same network that does not overlap with the existing scope on the other Domain Controller. Dont forget to set the default gateway (router) and DNS Servers. Talking of which all the clients (and the domain controllers themselves) need to have their Preferred DNS server set to one domain controller, and the Alternate DNS to the other, that way if one of the DNS Servers fails, the clients will automatically use the other,

    Both Domain Controllers by this point will have Active Directory, Global Catalog, DNS and DHCP. and the domain could function for a while at least should any one of them fail. However for a fully robust system you need to be aware that the first domain controller that existed will by default hold what are called FSMO Roles.

    There are five of these roles that are held on a single server and are essential for the functioning of the network. If the second Domain Controller fails, then no problem as the FSMO roles are on the first Domain Controller. However if you intent to function with the second Domain Controller only, then the roles need to be moved to the Second Domain Controller. Ideally if this is a planned event you should cleanly transfer the FSMO roles, if it is an unplanned emergency the FSMO roles can be seized (see or

    Author Comment

    see i have Domain Cntroller amdn Additional Domain Controller if Domian Controller Fail than how can i use Additional Domain Controller As a Domiain Controller

    Featured Post

    Maximize Your Threat Intelligence Reporting

    Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

    Join & Write a Comment

    As network administrators; we know how hard it is to track user’s login/logout using security event log (BTW it is harder now in windows 2008 because user name is always “N/A” in the grid), and most of us either get 3rd party tools, or just make our…
    Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now