Solved

Active Directory Upgrade Question

Posted on 2011-02-24
4
377 Views
Last Modified: 2012-05-11
I have an existing domain in 2003 native mode. I want to transfer all my FSMO roles to a Windows 2008 server, decommission my local DC's, and be ready to upgrade the domain to 2008 when i've replaced all the other DC's. What tasks need to be performed and in what order?
0
Comment
Question by:leviatdr
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 121
ID: 34975188
In Summary (simplified)

1. Build new WIn2k8 servers.
2. Join to Domain.
3. Run adprep
4. Run DCPROMO on both Win2k8 machines to create DC's
5. Transfer Roles.
6. Decommision Win2k3 servers.


see Microsoft kb here

http://technet.microsoft.com/en-us/library/cc771433(WS.10).aspx

and EE solution here

http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_26550108.html
0
 
LVL 41

Accepted Solution

by:
Adam Brown earned 250 total points
ID: 34975224
Basically, you'll transfer the FSMO roles. Then demote your old DC by running DCPromo. Once that's done, you may want to run a metadata cleanup to make sure everything about the old DC is gone. Once that's done, you can Update the Domain Functional Level and then the Forest Functional level.

FSMO Transfer: http://support.microsoft.com/kb/255690
Metadata cleanup: http://www.petri.co.il/delete_failed_dcs_from_ad.htm
You can raise the Domain Functional level from ADUC by right clicking the domain and clicking Raise Domain Functional Level
Forest Functional Level is managed through Active Directory Domains and Trusts by right clicking "Active Directory Domains and Trusts" and selecting Raise forest functional level.
0
 
LVL 11

Assisted Solution

by:RickSheikh
RickSheikh earned 250 total points
ID: 34975245
Don't forget the DNS either. If there are any non-AD integrated zones, make sure you migrated them from older DC/DNS to new. Also check the standard forwarders and the conditional forwarders on new DC/DNS server and make sure they align with that what they were on older DNS boxes.

What about the time sync?

The PDCe syncs with an external time source, have you already taken care of that ?

http://technet.microsoft.com/en-us/library/cc784553%28WS.10%29.aspx
0
 

Author Comment

by:leviatdr
ID: 34975322
A comment was added at the last minute and i selected it by mistake. Solution should have been for hanccocka and acbrown2010.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Here's a look at newsworthy articles and community happenings during the last month.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question