Solved

Reformatting my Domain Controller

Posted on 2009-07-08
19
328 Views
Last Modified: 2012-05-07
GOAL: To reformat my Domain Controller and give it bigger hard drives with a new raid configuration. We only have one domain controller.  

OPTION: Using another windows server on site to become a secondary Domain Controller, replicate our data, and then reformat the main server. That sounds like the most seamless option, but I wonder if I will have problems with the main server after reformatting it; will it be easy to promote it back to being the main Domain Controller or will some conflict arise with the secondary?

Am I on the right track? If so, what should I be aware of going into this? If not, what would be a better way?
0
Comment
Question by:sevenpeaks
  • 6
  • 4
  • 4
  • +3
19 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 24810355
The first thing is that the concept of primary/secondary domain controller no longer apply.  Both DCs will have full writable copies of AD.
You will need to transfer the FSMO roles over to the new DC, make the new DC a global catalog server.
I'm assuming you are running active directory integrated DNS.  So install DNS on the second DC and that info will replicate.
Have the clients point to the second DC for secondary DNS.
What I would do is build the second DC.  Keep that online forever now, you always want at least two DCs.   Then just turn off the original DC to make sure your clients can logon ok and function ok.   When you are ok with that then you dcpromo and demote the orginal DC and reconfigure the RAID and rebuild and repromote.
Thanks
Mike
0
 
LVL 5

Expert Comment

by:two_people_hk
ID: 24810423
I recommand you make a NT-backup before you make any change.
Secondary domain controller also a good idea to do so, after replication make sure you have change the GC and all the operation Master to the Secondary domain controller.
0
 
LVL 10

Expert Comment

by:Datedman
ID: 24810429
Why not use Symantec Backup Exec System Recovery Server (~$800) or the similar Acronis server product to  back up to an image and restore to the new hardware.  Works great and then you can use the product to do periodic backups in the future.
0
 
LVL 10

Expert Comment

by:Datedman
ID: 24810439
Still good to have another DC but it's much less painful and immensely quicker to use BESR in my experience.
0
 
LVL 3

Expert Comment

by:jhoncoop
ID: 24810465
I would have to agree with Datedman's suggestion.  Using an image backup tool is the fastest and least painful way to get your domain controller's disk hardware upgraded.  Putting in place a temporary DC and moving your roles back and forth will typically result in a number of problems.  You can usually complete this type of upgrade in about 4 hours.  On a positive note, using a new RAID controller and hard drives gives you an easy restore path since all you will need to do is re-connect the original hard drives and RAID controllers to restore the server to its "before" state.
0
 
LVL 10

Expert Comment

by:Datedman
ID: 24810487
Yup but I'd make a new DC first anyway. :)
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24811209
Images and snapshots are not valid recovery methods
Florian had a funny cartoon yesterday to illustrate the point
http://www.frickelsoft.net/blog/?p=203
Thanks
Mike
0
 
LVL 10

Expert Comment

by:Datedman
ID: 24812318
Actually I do not agree.  Images are damned great recovery options IMO.   But just to simplify, if I am using an image to do an upgrade I like to demote the DC and then promote it again afterward.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24814721
We will have to agree to disagree then...just not supported and can cause issues.
http://blogs.dirteam.com/blogs/jorge/archive/2006/03/08/597.aspx
Backup and restore of Active Directory  
 
Thanks
Mike
0
 
LVL 10

Expert Comment

by:Datedman
ID: 24814776
mk thx for the link, educational.  i prefer to use images to say, upgrade hardware and as i say best to demote/promote before/after, don't think i actually have backed up/restored AD with an image before but i know BESR gives you a warning about it (because once it gave me that warning in error [g].)
0
 
LVL 3

Expert Comment

by:jhoncoop
ID: 24814782
In this case he has only a single DC so there is no possibility of corruption or USN conflicts because the only copy of the data is the information residing on the DC.  If you had the suggested second DC, then imaged based recovery can represent a problem and will require using the NTDS utilities to configure active directory as non-authoritative.  

As a hardware upgrade path using imaging will allow him to easily upgrade the hardware, yet rollback the process in the event there is any error with no impact on his configuration or network.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24814792
Oh for building a new base sever yes I 100% agree on an image.  I was just talking about AD restores.
0
 
LVL 10

Expert Comment

by:Datedman
ID: 24814879
0
 

Author Comment

by:sevenpeaks
ID: 24864083
Thank you very much for the advice. It looks as though I will not be able to take advantage of the imaging software. I do appreciate the insights regarding taking the current DC down and bringing up another one. I will be making a move on this probably early next week and then divvy up some points.
0
 

Author Comment

by:sevenpeaks
ID: 24905958
I am having trouble backing up the State Data.  I tried through the command prompt using this command:
ntbackup backup systemstate /J BackupJob7-20-09 /F H:Backups\backup.bkf

but it would just briefly show a backup utility window and then close. There was no error in the command prompt and nothing in the folder I specified.

Then I tried to use the backup wizard from (the System tools menu, in Accessories) but I got this error:

Backup Status
Operation: Backup
Active backup destination: File
Media name: "State Backup.bkf created 7/20/2009 at 5:41 PM"

Volume shadow copy creation: Attempt 1.

Error returned while creating the volume shadow copy:0x8004230c.

Error returned while creating the volume shadow copy:8004230c
Aborting Backup.

----------------------

The operation did not successfully complete.

----------------------



Does anyone have any idea what would cause this?
0
 

Author Comment

by:sevenpeaks
ID: 24906092
Also, Volume Shadow Copy and Microsoft Software Shadow Copy Provider services are running, and set to automatic. I even restarted them, but the same error comes back.
0
 

Author Comment

by:sevenpeaks
ID: 25102792
Sorry it has taken me so long. I suggest that points be split between "mkline71" and " two_people_hk" 60% and 40% respectively. After finally getting this migration finished, the things they said were most pertinent and accurate.
0
 
LVL 142

Expert Comment

by:Guy Hengel [angelIII / a3]
ID: 25102814
Hi,

  you can object to the closing request, and perform the split yourself.

angel eyes
0

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
File Server Migration from 2003 to 2008R2 3 30
User profile Size Report 3 40
GPO warning 15 27
What is this Task? 4 42
Starting in Windows Server 2008, Microsoft introduced the Group Policy Central Store. This automatically replicating location allows IT administrators to have the latest and greatest Group Policy (GP) configuration settings available. Let’s expl…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now