Solved

Backup of AD on domain controller

Posted on 2011-02-24
7
435 Views
Last Modified: 2012-05-11
We have a file server running windows server 2008 standard with AD on it, this is a domain controller.  We have another windows 2008 server running terminal services and is not a domain controller.  We have another server running windows 2003 server on it and it is not being used for anything nor is it a domain controller.  We would like to have either the terminal server or the 2003 server to have a backup of AD on it that could be used if the file server went down.  Can anyone give us a hand on how this would be accomplished so that replication of AD would take place and would the terminal server or the 2003 server be the best choice.
0
Comment
Question by:ine2003
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 3

Expert Comment

by:rabindrajha
ID: 34971863
however this is not the easy task, when you are talking about enterprise level. if you have less user, you have many choices. you might be interested in this...
http://technet.microsoft.com/en-us/library/bb727048.aspx
0
 
LVL 2

Expert Comment

by:helpdesk_ninja
ID: 34971923
I would recommend making that Terminal Services server into a Domain Controller.  I know that if you have Active Directory originally running on a 2003 server, you can replicate it to 2008... but I don't believe you can do the opposite.  Hop on your Terminal Services server and add the Domain Controller role.  It will then go through some basic questions about your AD environment and will run dcpromo at the end.  Once you reboot, it should begin replicating Active Directory data on it's own and advertise itself as a Domain Controller.  I don't know the specifics of your network setup, but this is the process we use for our environment.

Hope this helps!

Nick
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34972013
I would not put the DC on a terminal server.
What is your forest Functional level and domain level?

This will determine if you can promote the 2003 server to a DC.

follow the steps in this link but do not change the level just note what it is.

http://www.windowsnetworking.com/articles_tutorials/Determining-Functional-Level-Windows-Server-2003.html
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 
LVL 59

Assisted Solution

by:Darius Ghassem
Darius Ghassem earned 250 total points
ID: 34972421
You DO NOT put AD services on a Terminal Server this is a no no and you should not be done.

If your current forest and domain functional levels are set to Windows 2008 Server you would not be able to add Windows 2003 Server like Ken said.

You need to check this first.

Second if you are at a lower level you can add another DC very easily

http://technet.microsoft.com/en-us/library/cc733027(WS.10).aspx
0
 

Author Comment

by:ine2003
ID: 34972526
The functional levels are as follows

Domain - Windows Server 2008
Forest - Windows Server 2008

I guess then this rules out using either of the servers for this purpose.  I guess the next step would be buying a new server and setting it up as a DC with AD and the repication would take place automatically.
0
 
LVL 27

Accepted Solution

by:
KenMcF earned 250 total points
ID: 34972595
Getting another server would be the best way since your DFL and FFL are 2008. You do not want a DC on a terminal server.

http://technet.microsoft.com/en-us/library/cc733027%28WS.10%29.aspx
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 34972965
I would have to agree another server would be the best solution. I would recommend installing Hyper-v so in future you could use the same hardware for multiple virtual machines
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question