Solved

Active Directory - Function Level and adding a new DC

Posted on 2012-03-26
11
324 Views
Last Modified: 2012-03-26
I have two DC's, DC1 & DC2. Both are running windows server 2008 R2. My domain function Level is Windows Server 2003. Will i need to do an adprep/ forestprep/ or domainprep or can i just go ahead and dcpromo and install?

Thanks.
0
Comment
Question by:earlyriser99
  • 5
  • 3
  • 3
11 Comments
 
LVL 9

Expert Comment

by:Geodash
Comment Utility
So the old 2003 DC's are gone and demoted from the network?
0
 
LVL 9

Assisted Solution

by:Geodash
Geodash earned 250 total points
Comment Utility
This is a good article on Domain function levels fro 2008.

http://www.petri.co.il/raising-windows-server-2008-active-directory-domain-and-forest-functional-levels.htm

You said can you go ahead and run a dcpomo and install, but you say the w2k8r2 are already DC's. Are you just wanting to raise the function level or add a new DC?
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
Comment Utility
If both DCs are running Windows 2008 R2 then your schema version should be at 47 so you won't need a schema update for AD


....until you go to Windows 8 :)   http://adisfun.blogspot.com/2012/03/windows-server-8-beta-schema-version.html

Thanks

Mike
0
 

Author Comment

by:earlyriser99
Comment Utility
Soooo...A little background. Hired at a new company as the new IT guy, old IT guy left and nobody knows anything. Just going by what i have found. But yes, only two domain controllers which are dc1 and dc2, both 2008 server r2. There are no windows 2003 dc's.
0
 
LVL 9

Assisted Solution

by:Geodash
Geodash earned 250 total points
Comment Utility
Then you do not have to do any preps, just raise the function level if you are positive that all pre-w2k8 servers are gone
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 

Author Comment

by:earlyriser99
Comment Utility
Soooo.....What would happen if i raised the function level and there was a 2003 server dc that i didn't know about?
0
 
LVL 9

Assisted Solution

by:Geodash
Geodash earned 250 total points
Comment Utility
It would not let you do it. If the 2003 DC were properly demoted without error, it will let you. If it still detects a pre-2008 DC, it will not let you change the level meaning it would need to be removed and have the metadata cleaned out, through ADSIedit if it wasn't removed cleanly.
0
 

Author Comment

by:earlyriser99
Comment Utility
Ok...So just to be clear. I can add the 2008 r2 DC with no problems. If i want to raise the function level i can do that at a later time correct?
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 250 total points
Comment Utility
use tools like repadmin, event logs and dcdiag to look at the health of the servers.  Active Directory Topology Diagrammer is a nice free tool for you to build some visio diagrams.

It's tough being new and the old guy not leaving any documentation.

...but going to 2008 R2 Forest functional level and then enabling the recycle bin is a nice easy first win.

Thanks

Mike
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 250 total points
Comment Utility
Yes and Yes to your last questions.
0
 
LVL 9

Assisted Solution

by:Geodash
Geodash earned 250 total points
Comment Utility
You don't ever have to change it technically. But is recommended if you want the full w2k8r2 functionality eventually. You are fine leaving it if you want.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

This is my first article in EE and english is not my mother tongue so any comments you have or any corrections you would like to make, please feel free to speak up :) For those of you working with AD, you already are very familiar with the classi…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now