We help IT Professionals succeed at work.

how to convert aditional domain controller to primary domain controller

Last Modified: 2012-05-05
i am working on disaster recovery and i want to know if my domain goes fail, my hard disk corrupt or i loss my backup than how i change my ADC to PDC. means which right i have to give ADC to work as Primary Domain Controller. what steps in FSMO or other i have to take.

Thanks in advance

Watch Question

There is no such thing as  PDC within Windows 2003.
If you have a DR situation then depending on which FSMO roles the server(s) held, which failed, would depend on which roles you would need to seize.

You can seize a FSMO role via NTDSUTIL
Unlock this solution and get a sample of our free trial.
(No credit card required)
Brian PiercePhotographer
Awarded 2007
Top Expert 2008

One way to provide resilliance is to have two domain controllers, that way if one fails active directory is immediately availabl on the other and can systems be recovered quickly and without downtime.

To add a second domain copntroller Install Windows on another new machine

Assign the new computer an IP address and subnet mask on the existing network

Make sure that the preferred DNS server on new machine points to the existing DNS Server on the Domain (normally the existing domain controller)

Join the new machine to the existing domain as a member server

From the command line promote the new machine to a domain controller with the DCPROMO command from the command line Select Additional Domain Controller in an existing Domain

Once Active Directory is installed then to make the new machine a global catalog server, go to Administrative Tools, Active Directory Sites and Services, Expand ,Sites, Default first site and Servers. Right click on the new server and select properties and tick the Global Catalog checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

Make sure DNS is also installed on the new Domain Controller, assuming that you were using Active Directory Integrated DNS on the first Domain Controller, DNS will have replicated to the new domain controller along with Active Directory.

If you are using DHCP you should spread this across the domain controllers, In a simple single domain this is easiest done by Setting up DHCP on the second Domain controller and using a scope on the same network that does not overlap with the existing scope on the other Domain Controller. Dont forget to set the default gateway (router) and DNS Servers. Talking of which all the clients (and the domain controllers themselves) need to have their Preferred DNS server set to one domain controller, and the Alternate DNS to the other, that way if one of the DNS Servers fails, the clients will automatically use the other,

Both Domain Controllers by this point will have Active Directory, Global Catalog, DNS and DHCP. and the domain could function for a while at least should any one of them fail. However for a fully robust system you need to be aware that the first domain controller that existed will by default hold what are called FSMO Roles.

There are five of these roles that are held on a single server and are essential for the functioning of the network. If the second Domain Controller fails, then no problem as the FSMO roles are on the first Domain Controller. However if you intent to function with the second Domain Controller only, then the roles need to be moved to the Second Domain Controller. Ideally if this is a planned event you should cleanly transfer the FSMO roles, if it is an unplanned emergency the FSMO roles can be seized (see http://support.microsoft.com/kb/255504 or http://www.petri.co.il/transferring_fsmo_roles.htm)


see i have Domain Cntroller amdn Additional Domain Controller if Domian Controller Fail than how can i use Additional Domain Controller As a Domiain Controller
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.