Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 346
  • Last Modified:

Reformatting my Domain Controller

GOAL: To reformat my Domain Controller and give it bigger hard drives with a new raid configuration. We only have one domain controller.  

OPTION: Using another windows server on site to become a secondary Domain Controller, replicate our data, and then reformat the main server. That sounds like the most seamless option, but I wonder if I will have problems with the main server after reformatting it; will it be easy to promote it back to being the main Domain Controller or will some conflict arise with the secondary?

Am I on the right track? If so, what should I be aware of going into this? If not, what would be a better way?
0
sevenpeaks
Asked:
sevenpeaks
  • 6
  • 4
  • 4
  • +3
1 Solution
 
Mike KlineCommented:
The first thing is that the concept of primary/secondary domain controller no longer apply.  Both DCs will have full writable copies of AD.
You will need to transfer the FSMO roles over to the new DC, make the new DC a global catalog server.
I'm assuming you are running active directory integrated DNS.  So install DNS on the second DC and that info will replicate.
Have the clients point to the second DC for secondary DNS.
What I would do is build the second DC.  Keep that online forever now, you always want at least two DCs.   Then just turn off the original DC to make sure your clients can logon ok and function ok.   When you are ok with that then you dcpromo and demote the orginal DC and reconfigure the RAID and rebuild and repromote.
Thanks
Mike
0
 
two_people_hkCommented:
I recommand you make a NT-backup before you make any change.
Secondary domain controller also a good idea to do so, after replication make sure you have change the GC and all the operation Master to the Secondary domain controller.
0
 
DatedmanCommented:
Why not use Symantec Backup Exec System Recovery Server (~$800) or the similar Acronis server product to  back up to an image and restore to the new hardware.  Works great and then you can use the product to do periodic backups in the future.
0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 
DatedmanCommented:
Still good to have another DC but it's much less painful and immensely quicker to use BESR in my experience.
0
 
jhoncoopCommented:
I would have to agree with Datedman's suggestion.  Using an image backup tool is the fastest and least painful way to get your domain controller's disk hardware upgraded.  Putting in place a temporary DC and moving your roles back and forth will typically result in a number of problems.  You can usually complete this type of upgrade in about 4 hours.  On a positive note, using a new RAID controller and hard drives gives you an easy restore path since all you will need to do is re-connect the original hard drives and RAID controllers to restore the server to its "before" state.
0
 
DatedmanCommented:
Yup but I'd make a new DC first anyway. :)
0
 
Mike KlineCommented:
Images and snapshots are not valid recovery methods
Florian had a funny cartoon yesterday to illustrate the point
http://www.frickelsoft.net/blog/?p=203
Thanks
Mike
0
 
DatedmanCommented:
Actually I do not agree.  Images are damned great recovery options IMO.   But just to simplify, if I am using an image to do an upgrade I like to demote the DC and then promote it again afterward.
0
 
Mike KlineCommented:
We will have to agree to disagree then...just not supported and can cause issues.
http://blogs.dirteam.com/blogs/jorge/archive/2006/03/08/597.aspx
Backup and restore of Active Directory  
 
Thanks
Mike
0
 
DatedmanCommented:
mk thx for the link, educational.  i prefer to use images to say, upgrade hardware and as i say best to demote/promote before/after, don't think i actually have backed up/restored AD with an image before but i know BESR gives you a warning about it (because once it gave me that warning in error [g].)
0
 
jhoncoopCommented:
In this case he has only a single DC so there is no possibility of corruption or USN conflicts because the only copy of the data is the information residing on the DC.  If you had the suggested second DC, then imaged based recovery can represent a problem and will require using the NTDS utilities to configure active directory as non-authoritative.  

As a hardware upgrade path using imaging will allow him to easily upgrade the hardware, yet rollback the process in the event there is any error with no impact on his configuration or network.
0
 
Mike KlineCommented:
Oh for building a new base sever yes I 100% agree on an image.  I was just talking about AD restores.
0
 
DatedmanCommented:
0
 
sevenpeaksAuthor Commented:
Thank you very much for the advice. It looks as though I will not be able to take advantage of the imaging software. I do appreciate the insights regarding taking the current DC down and bringing up another one. I will be making a move on this probably early next week and then divvy up some points.
0
 
sevenpeaksAuthor Commented:
I am having trouble backing up the State Data.  I tried through the command prompt using this command:
ntbackup backup systemstate /J BackupJob7-20-09 /F H:Backups\backup.bkf

but it would just briefly show a backup utility window and then close. There was no error in the command prompt and nothing in the folder I specified.

Then I tried to use the backup wizard from (the System tools menu, in Accessories) but I got this error:

Backup Status
Operation: Backup
Active backup destination: File
Media name: "State Backup.bkf created 7/20/2009 at 5:41 PM"

Volume shadow copy creation: Attempt 1.

Error returned while creating the volume shadow copy:0x8004230c.

Error returned while creating the volume shadow copy:8004230c
Aborting Backup.

----------------------

The operation did not successfully complete.

----------------------



Does anyone have any idea what would cause this?
0
 
sevenpeaksAuthor Commented:
Also, Volume Shadow Copy and Microsoft Software Shadow Copy Provider services are running, and set to automatic. I even restarted them, but the same error comes back.
0
 
sevenpeaksAuthor Commented:
Sorry it has taken me so long. I suggest that points be split between "mkline71" and " two_people_hk" 60% and 40% respectively. After finally getting this migration finished, the things they said were most pertinent and accurate.
0
 
Guy Hengel [angelIII / a3]Billing EngineerCommented:
Hi,

  you can object to the closing request, and perform the split yourself.

angel eyes
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

  • 6
  • 4
  • 4
  • +3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now