Solved

Forestprep and Domainprep 2008

Posted on 2010-11-07
23
531 Views
Last Modified: 2012-06-21
I'm about to get ready to install a Windows 2008 server into a 2003 mixed mode domain, making it a domain controller as soon as I can.  I know I have to run (the 32 bit versions) of adprep for forest and domain on the current domain controller.  My question is, will this take the domain down for users while the changes are being made?  Can they still work in their files while it is running?

There are about 20 workstations on the network.  Also 3 servers are running, two already domain controllers.  The two DCs are old and rather bad shape, and want to get this new server in pronto.

Anyway, I believe I have all the step by step instructions, but just not clear if adprep will stall out the network and users will be forced to sign off.
0
Comment
Question by:shonadle
  • 11
  • 8
  • 2
  • +2
23 Comments
 
LVL 8

Expert Comment

by:ShareefHuddle
ID: 34082051
No it will not. I would suggest running a dcdiag and a netdiag and try to remove all errors first if any.
0
 
LVL 5

Assisted Solution

by:balmasri
balmasri earned 100 total points
ID: 34082434
No effect.It would be transperent to users.Adprep will add some attributes & classes  to your schema . it will not touch the data. in other words : it's like adding columns in an excel sheet , the exisited data will not be affected.
 You can do it during working hours.

But Microsoft recommendations is to do the following:
backup your domain controllers ( System State).
disconnect the network cable the Server hold Schema Master .
extend the schema .
If everything is OK, then reconnect the domain controller. otherwise you have to restore the system state in DSRM.
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34082478
User will not come to know even there something cooking in the background running ADprep..:)

Adprep /forestprep & adprep /domainprep only add extra classes & attribute along with the permission to ensure that higher windows version is well supported with all the option.

i would suggest taking system state backup which is best with Ntback in case of restore required & also check any legacy application which might be not as compatible with schema ext as i didn't realize doing for hundred upgrade till now.

There is no requirement to do it in offline mode as there is no issue reported for upgradation as it add classes & attributes.

As there is few dc still i would suggest give some time to complete the replication & run dcdiag to ensure all is well.

0
 
LVL 10

Expert Comment

by:abhijitmdp
ID: 34086663
Adprep /forestprep & adprep /domainprep only add extra classes & attribute along with the permission to ensure that higher windows version is well supported with all the option so as per my experience this never effects to the daily business but you must take care of one thing that there must not any other ad appending/editing/backup/restore of ad server is going on the same time if they are running then the adprep and domainprep will stop running with an error but this will also never harm your current infrastructure.
0
 

Author Comment

by:shonadle
ID: 34087937
Thanks for your help.  I am getting error messages on adprep32 about call to function.  I'm curious, the server is actually overheating (I've been on them about this)  Can that cause adprep to fail as looking at technet's listings of normal call to function errors already check out.

I guess I just don't want to spin my wheels messing with the sysvol folders/permissions if it's the fact the server is running dangerously hot.
0
 
LVL 10

Expert Comment

by:abhijitmdp
ID: 34089705
Can u please post detailed error also check the event viewer for any errors related to adprep and post them as well.
0
 

Author Comment

by:shonadle
ID: 34093305
Glad to...

I have removed the AV. I will say the scripts folder is missing from the root of the shared SysVol.  Not sure how to put it there.

I did get domainprep without gpprep finished just when you add the gpprep it will fail.  Does this mean that the group policy might not necesarily carry over and I could move forward with setting up the 2008 server as a domain server?
ADPrep.log
0
 
LVL 24

Accepted Solution

by:
Awinish earned 400 total points
ID: 34093419
You can use D4 & D2 method.

  1. Stop the File Replication service on the problem domain controller.
   2. Start Registry Editor (Regedt32.exe).
   3. Locate and then click the BurFlags value under the following key in the registry:
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process at Startup
   4. On the Edit menu, click DWORD, click Hex, type D2, and then click OK.
   5. Quit Registry Editor.
   6. Move data out of the PreExisting folder.
   7. Restart the File Replication Service.

http://support.microsoft.com/kb/316790
Above article works for all dc.

Note: D2 has to be set as burflag on problem DC.


Gpprep error can be ignored, as i did that error comes but never had any issue.




0
 
LVL 24

Expert Comment

by:Awinish
ID: 34093502
I hope you followed the link.

Is adprep /forestprep & adprep /domainprep
completed successfully w/o any error.

http://blogs.dirteam.com/blogs/sanderberkouwer/archive/2008/03/02/transitioning-your-active-directory-to-windows-server-2008.aspx
0
 

Author Comment

by:shonadle
ID: 34093523
Yes, forestprep and domainprep were updated successfully.  When I tried to do a adprep /domainprep /gpprep I get the call back function error.

Would it be better to just try to promote the 2008 server now or attempt to do the D2 fix?
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34093561
Untill all the errors are gone, dcpromo might not work properly so its better to do D2 fix.

Run dcdiag & check there is no error event then only dcpromo 2008 dc.

Gpprep error you can ignore.


0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 

Author Comment

by:shonadle
ID: 34093591
I get dcdiag errors.  Will the above fix this do you think?
ddiag.txt
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34093600
Oh, my mistake the gpprep error is due to script folder is missing, id didn't noticed the error which is trying to assign the permission on sysvol folder.

http://technet.microsoft.com/en-us/library/dd464018%28WS.10%29.aspx#BKMK_CallBack

First correct the sysvol issue & run adprep /domainprep /gpprep again.

http://blogs.technet.com/b/askds/archive/2008/12/15/troubleshooting-adprep-errors.aspx
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34093622
Your dc1 doesn't have netlogons shared so thats the reason & it will not allow to configure 2008 as an DC until you rectify the sysvol error.

Use Burflag to copy the sysvol completely from other dc so it should have all the folder with proper permission.

Sysvol can take time to replicate the data from other dc.

0
 

Author Comment

by:shonadle
ID: 34093633
The problem is I can't add a SCRIPTS folder to the sysvol shared.  I can add a new folder but it won't let me rename it.  Is it safe to give myself rights on that folder (administrator)?
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34093657
You don't do it manually as scripts folder is shared netlogon, which can break the sysvol, follow the article & it will do it automatically & if there is no dc, copy the sysvol folder with scripts & policy folder & after doing D2, it will share automatically, don't change anything manual which can cause serious damage.


 
0
 

Author Comment

by:shonadle
ID: 34093696
Ok, just one final question.  The directions say to move data out of the preexisting folder before I restart the service.  What is the folder it's speaking of?
0
 

Author Comment

by:shonadle
ID: 34093719
Actually a second question, because I want to do this right.  I have to do this on both DCs, the one that is holding the netlogon and sysvol folders should have the D4 registry add and the other server (where it will replicate to) should have the D2?
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34093761
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34093789
Dc which is having healthy sysvol with no FRS error in event log don't need any settings on that, the D2 is only required on problem domain controller.

So just do D2 on problem dc or else copy the files shown in technet link.

0
 

Author Comment

by:shonadle
ID: 34095236
Thank you.  It turned out to be a wrap error that was causing replication issues.  But the D2 fixed it.

Now the new 2008 domain controller is up and the FSMO roles have been transferred.  Something you said has made me nervous though so I wanted to ask.  

There are 2 scripts in the SCRIPTS folder.  One is outdated and needs to be removed as it's calling up instation of software we no longer use.  The other needs to be edited for network mappings to connect to the new server.  My question is, am I safe to just edit the script files (will make a backup) using notepad and save or should this be done another way?
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34095282
Scripts in SCRIPTS folder can be removed but SCRIPTS folder which is shared as netlogon should not be touched.

Glad, everything is working fine now, yes due to journal wrap error it happens, windows 2008 is better to overcome Journal wrap condition.
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 400 total points
ID: 34095372
I mean you can safely remove content inside the script folder like old scripts or bat file or any other..
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now