Solved

Domain Controller upgrade

Posted on 2008-06-17
10
211 Views
Last Modified: 2013-12-05
I have an old windows 2000 server acting as domain controller, as well as file and print server.
I also have a brand new server 2003/64bit acting as a member server.
What i wish to do i promote the new server to act as a domain controller as well. This will give me 2 domain controllers on the network.
I know this can be done.
My problem is that i have never done this before.
Can someone please advise me how this is done, plus any pit falls to avoid.
Note - win server is only 32 bit, new server is 64 bit. Will this cause a problem.
What else will need to be done. Must i transfer dns as well.
0
Comment
Question by:dexterhome
  • 5
  • 4
10 Comments
 
LVL 70

Accepted Solution

by:
KCTS earned 250 total points
ID: 21802416
Essentially is no different from using a 32bit server

The first job is to prepare the domain for the new DC by running ADPREP If the new Windows 2003 server is the R2 version you need to run Adprep  from the \CMPNENTS\R2\ folder on CD2, if its not R2 then use adprep from the i386 folder (you may need to get the 32 bit version of this - If so download the trial copy)

Put the CD in the 2000 machine, you need to run

adprep /forestprep
and
adprep /domainprep

From the command line promote the new machine to a domain controller with the DCPROMO command from the command line Select Additional Domain Controller in an existing Domain

Once Active Directory is installed then install DNS. You can do this through Add/Remove Programs->Windows Components->Networking Services->DNS.  If you are using Active Directory Integrated DNS then DNS will br replicated from the other DC/DNS.

Next make the new machine a global catalog server, go to Administrative Tools, Active Directory Sites and Services, Expand, Sites, Default first site and Servers. Right click on the new server and select properties and tick the Global Catalog checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

If necessary install DHCP on the new DC. You can do this through Add/Remove Programs->Windows Components->Networking Services->DHCP.

You will then need to remove any existiing DHCP prior to authorising the new DHCP Server. When setting up the new DHCP server dont forget to set the default gateway (router) and DNS Servers. Talking of which all the clients (and the domain controllers themselves) need to have their Preferred DNS server set the new domain controller.

Both Domain Controllers by this point will have Active Directory, Global Catalog, DNS and the domain could function for a while at least should any one of them fail.

If you really want to move the FSMO roles from the old DC then:-

Transfer all the FSMO roles to the new DC: See http://www.petri.co.il/transferring_fsmo_roles.htm
0
 
LVL 31

Assisted Solution

by:Henrik Johansson
Henrik Johansson earned 250 total points
ID: 21802540
Having 32bit and 64bit DCs in the same domain doesn't matter.

Use the adprep-command from Win2k3 to do a adprep/forestprep and adprep/domainprep
Confirm that the DNS-zone allows dynamic updates, so the new DC can register its records correctly.
When the AD-prep is done, use dcpromo on the new DC.

On the DNS zone-properties->Change the zone-type to be stored in AD.
Add the DNS-zone on the new DC.
Configure both DCs to use its own IP as primary DNS-server and the other DC as secondary DNS-server.
0
 
LVL 5

Author Comment

by:dexterhome
ID: 21820922
How will this effect the group policy.
I wish to use GPO's to change settings on workstations but some features are not available on the win 2000 gpe to allow changes to win Xp ws. (mainly firewall settings)
Will i be able to use the editor in the win serv 2003 machine?
will it downgrade the group policy to match win 2000?
will it upgrade the gpe to match 2003?

please advise.
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 21821048
Yes, you can use GPMC to manage GPOs for both Win2000,XP,2003
If the GPO-feature isn't available for Win2000, it will not affect those computers.

GPMC is downloadable at http://www.microsoft.com/downloads/details.aspx?FamilyId=0A6D4C24-8CBD-4B35-9272-DD3CBFC81887&displaylang=en
0
 
LVL 5

Author Comment

by:dexterhome
ID: 21821195
Problem is that the GPMC tool is not supported under win 2003/64.
So i will have to use the standard GP from the AD.
This is where I think I will have the miss match.
If GPO's edited in win server 2003/64 will they/can they replicate to the win server 2000 AD.
What will happen with the DC promo.
The AD will be transferred(copied) across 2 different platforms. One systems AD will have to be either upgraded or downgraded to meet each other.
Which way will it go. I presume it will level the AD at the the windows 2000 GP/AD.
In which case this will not give me the features i require.

Sorry. I may actually be morphing questions.
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 21821406
You will have one AD with one domain with two domain controllers, and the GPOs will replicate between both DCs in the domain without any problem.
You can install GPMC on a XP-machine instead of neading to logon to the DCs to edit the GPOs. Also install adminpak.msi to get ADUC and other AD-tools on the XP-machine.
0
 
LVL 5

Author Comment

by:dexterhome
ID: 21821944
I see. I thought that the GP was controlled by the editor but clearly is not.
I have downloaded the adminpak and installed and used. this simplifies a lot of items.

Thanks for that.

Just got to upgrade the domain controllers now.

Will the system require restarting when running the DC promo updates.

0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 21822709
Yes, dcpromo requires reboot.
Remember to run adprep/forestprep and adprep/domainprep with the Win2k3-version of the command before running dcpromo on the Win2k3-server.
0
 
LVL 5

Author Comment

by:dexterhome
ID: 21829562
I will try what has been advised in a test environment before applying to actual systems.
Will most likely take a week or two.
I will post back when have tested.
0
 
LVL 5

Author Closing Comment

by:dexterhome
ID: 31473499
Thank you for all the information. Finally got around to doing the job and it went all ok.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

Have you considered what group policies are backwards and forwards compatible? Windows Active Directory servers and clients use group policy templates to deploy sets of policies within your domain. But, there is a catch to deploying policies. The…
Know what services you can and cannot, should and should not combine on your server.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now