Solved

FSMO Question

Posted on 2008-06-20
10
351 Views
Last Modified: 2010-04-18
Our Windows 2003 Domain Controller (the first in the forest, so I assume it has all the FSMO's on it) is running as both a DC and an Exchange server.  Since we do not want to rip off Exchange, we have decided to build a separate server, dcpromo it, and then move the FSMO's off to the new DC from the old DC/Exchange box.  Any problem in doing this? Would I be using the NTDSUTIL command?
0
Comment
Question by:cytogenadmin
10 Comments
 
LVL 70

Accepted Solution

by:
KCTS earned 500 total points
ID: 21831684
Exchnage will not like it one little bit if you DCPROMO the server it is on and make it so its not a DC anymore. Exchange on a DC is always a proplem - hense all the advice NOT to do it

If you want to add a second DC and move the FSMO roles - fine but its not going to achieve much.
- You can use the GUI - no need to use NTDSUtil http://www.petri.co.il/transferring_fsmo_roles.htm
0
 

Author Comment

by:cytogenadmin
ID: 21831756
What kind of problems can we run into with running DCPROMO on the Exchange server?  Would you recommend moving Exchange and leaving the DC alone?
0
 
LVL 3

Expert Comment

by:Rikketyrik
ID: 21831772
I have successfully promoted/demoted a DC with Exchange using the standard DCPROMO. However, I may have been lucky. I would tread lightly and make sure you have good backups and a no plans for the weekend before proceeding.

Don't forget to transfer the Shema Master role. (Extra steps to do so).
0
 
LVL 70

Expert Comment

by:KCTS
ID: 21831781
It will break !

You only course of action is to install exchnage on another server, member server not a DC, migrate the mailboxes to the new exchnage server then remove exchnage from the orginal server.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 13

Expert Comment

by:TheCapedPlodder
ID: 21831784
KCTS is right.  Do not DCPROMO the Exchange server back to be a member but I gather you aren't planning to do this anyway.

You are correct in that you can add a second DC and transfer the FSMO roles either by NTDSUTIL or through the MMC.

A few thoughts to share:

Ensure the new DC is also a GC.
Install DNS on the new DC and if you haven't already done so convert your DNS zones to be AD integrated.  Once this is done you can repoint all your clients to the new DNS server for primary DNS and use the exisiting DNS server as a secondary.
If the current DC is also running DHCP or WINS consider moving these functions to the new server.

Anything else you need, just shout.

Cheers,

TCP
0
 
LVL 3

Expert Comment

by:Rikketyrik
ID: 21831793
Moving Exchange would probably be the easiest and safest route to go with. That way you have Exchange on a clean machine. You will also have two clean DCs as well.

Before moving I would bring up the second DC and transfer the FSMO roles.
0
 
LVL 70

Expert Comment

by:KCTS
ID: 21831813
if you go to all the trouble of moving exchange PLEASE DON'T put it on another DC - that will achive ZERO
0
 
LVL 3

Expert Comment

by:Rikketyrik
ID: 21832115
Agreed. You are looking at 3 machines total.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now