Solved

Changing domain controller

Posted on 2007-11-22
10
1,119 Views
Last Modified: 2012-06-21
We have two windows 2003 server based servers. One of them is a domain controller the other one is a member server, which used to be the main exchange server. I transferred the main exchange server role to a third member server and made this server just a member exchange server, but nothing resides in it. That means I can easily remove the exchange server from this server.

Now I want to promote this server to the main domain controller and the old domain controller to backup domain controller. What steps should I follow not to mess up our system in the process? Please advise.
Thank you,
0
Comment
Question by:URWB
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 6

Accepted Solution

by:
MorDrakka earned 255 total points
ID: 20337721
Hi,

There is not really something like a backup domain controller in w2k w2k3. Unless you count he FSMO's.

I would do the following actions:

- run DCPROMO on new 'to be' DC
- After DCpromo is ready move the FSMO(Five single master operations) to your new DC.

FSMO roles are:  
- Rid master
- Domain Master
- Schema Master
- Infrastructure Master
- PDC emulator.

Hope this helps!
0
 
LVL 6

Assisted Solution

by:MorDrakka
MorDrakka earned 255 total points
ID: 20337722
Here is additional info on how to move these roles:

http://www.petri.co.il/transferring_fsmo_roles.htm
0
 
LVL 6

Assisted Solution

by:-DJL-
-DJL- earned 75 total points
ID: 20337752
You'll also want to make the new server a Global Catalog server.

Run the Active Directory Sites and Services snap-in. Expand the Sites until you locate the server that you wish to become a Global Catalog. Right-click the NTDS Settings icon, under the server, and click Properties. On the General tab, check the Global Catalog box.

Wait a few hours and then remove the Global catalog from the old server.
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 170 total points
ID: 20338002
You might also want to make the new DC a DNS server and point the clients (via DHCP or TCP/IP settings), to use one DC as the preferred DNS server and the other as alternate DNS server.
0
 
LVL 6

Assisted Solution

by:-DJL-
-DJL- earned 75 total points
ID: 20338071
Thinking about it some more I'd keep both servers as Global Catalog servers
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 170 total points
ID: 20338109
Ok let me summ that lot up as there is a lot going on here:
Run DCPROMO on the machine that you whsh to become a Domain Controller to make it DC.

Install DNS (the AD integrated zone should replicate automatically - may take a little while)

Make the new machine a global catalog server - go to Active Directory Sites and Services, Expand Sites, Expand Servers, expand the server in question, right click NTDS settings, select properties and tick Global Catalog.

Transfer the FSMO roles to the new machine

Configure the clients to use one DC (the new one) as the preferred DNS server and the other as the alternate DNS server - either in the DHCP options or via the TCP/IP settings.

BTW the DCs should each point to themselves for preferred DNS server
 
0
 

Author Comment

by:URWB
ID: 20434768
Unfortunately, I managed to do the above task only today. I think I've done everything as per your instructions and everything seems fine; except for one thing.

When I tried to transfer the Infrastructure operations master role from the old DC to the new one I got the following message:

"<new DC> is a global catalog (GC) server. The infrastructure operations master role should not be transferred to a GC server. Please see help for more infomation. Are you certain you want to transfer the infrastructure operations master role to this GC server?

For this message I selected Yes. Would that create any problem to the configuration?

Thank you for your prompt assistance.
0
 

Expert Comment

by:jdschauer
ID: 21049665
What are the negatives to having a Global Catalog on a Domain Controller?
0
 
LVL 6

Expert Comment

by:-DJL-
ID: 21049681
If all your domain controllers are Global Catalog servers then you can ignor the message.  If you have domain controllers not running as GC's then you should move the Infrastructure role to one of those servers.
0
 
LVL 70

Expert Comment

by:KCTS
ID: 21049714
In a multi-domain environment if some and not all DCs are GCs and the Infrastrcuture master is a GC it can result in phantom objects - see http://support.microsoft.com/kb/248047
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question