Solved

2008 R2 Active Directory: Transfer PDC Emulator FSMO and External Time Source Sync

Posted on 2013-01-07
7
1,260 Views
Last Modified: 2013-01-18
Hi, we're planning to decommision a DC that currently holds all the FSMO roles.  We will be transferring all 5 roles to a single DC, which includes the PDC Emulator.  The existing PDC Emulator is configured to sync time with an external time source.  Does anyone have steps on what needs to be done on the future PDC emulator?  Thanks.
0
Comment
Question by:bsohn417
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 16

Accepted Solution

by:
Michael Ortega earned 167 total points
ID: 38750870
Transfer the FSMO roles and then setup your external time sync on the new DC.

To transfer FMSO roles: http://www.petri.co.il/transferring_fsmo_roles.htm

To setup external time sync (example only, you can use your own external peers of course):
W32tm /config /update /manualpeerlist:”pool.ntp.org time.windows.com 208.66.175.36 38.106.177.10” /syncfromflags:manual /reliable:YES
Net stop w32time
Net start w32time

Verify:
W32tm /query /configuration
W32tm /query /source
W32tm /stripchart /computer:<source>

MO
0
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 38750872
Another note, if you no longer have any Server 2008 or prior version DC's make sure to raise your forest functional level to 2008 R2, so you can take full advantage of a 2008 R2 active directory environment.

MO
0
 
LVL 22

Assisted Solution

by:mcsween
mcsween earned 166 total points
ID: 38750901
at the PDC emulator type the following command to set it to sync with external time source tick.usno.navy.mil and tock.usno.navy.mil.

w32tm /config /manualpeerlist:"tick.usno.navy.mil tock.usno.navy.mil" /syncfromflags:manual /reliable:yes /update

Open in new window


To move the FSMO roles
Open Active Directory Users and Computers
RC the domain name and select change domain controllers
select the domain controller the role is to be transferred to
RC the domain name and select Operations Masters
Click the change button on RID, PDC, and Infrastructure tabs
Close ADUC
Register the schema snap in (open a elevated command prompt and type regsvr32 schmmgmt.dll)
Start, Run, mmc, OK
File Add/Remove Snap In
AD Schema, Add, OK
Right Click AD Schema and select change domain controllers
Select the new Schema target server, OK
RC AD Schema and select Operations Master
Click change button

I would also read this article about where to put the FSMO roles.  It's not a good idea to have them all on the same server.
http://support.microsoft.com/kb/223346
0
Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 
LVL 57

Expert Comment

by:Mike Kline
ID: 38750963
Unless you notice your FSMO role holder is overloaded you can put them all on the same box.  That article is a bit dated.

Is this box also a DNS server?  If it is make sure clients are pointing to the new DC/DNS for DNS (both static and DHCP clients)

Thanks

Mike
0
 
LVL 8

Author Comment

by:bsohn417
ID: 38751138
Thanks Mike, it is a DNS/DHCP server as well and I'm running Network Monitor to see what is connecting to it via DNS.  Is there any particular order you would recommend transferring the FSMO roles?  Thanks.
0
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 38751251
There is no set defined order just make sure you get them all. I would not demote the old DC until you're certain you have all clients accessing the new DC for DNS.

MO
0
 
LVL 18

Assisted Solution

by:Sarang Tinguria
Sarang Tinguria earned 167 total points
ID: 38751554
I would first check the health of Proposed role holder using dcdiag /q
Then I will check replication health using repadmin /replsum
Then only I will move FSMO roles using one of the below two article

http://technet.microsoft.com/en-us/library/cc779716(v=ws.10).aspx

http://www.elmajdal.net/win2k8/Transferring_FSMO_Roles_in_Windows_Server_2008.aspx


I have written an article to configure time service in windows Domain env Please go through it and configure time server accordingly

http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/A_10789-Time-Service-Configuration.html


Do not use navy servers as your external time source it had issues in past read below article

Did Your Active Directory Domain Time Just Jump To The Year 2000?

http://blogs.technet.com/b/askpfeplat/archive/2012/11/19/did-your-active-directory-domain-time-just-jump-to-the-year-2000.aspx
0

Featured Post

Space-Age Communications Transitions to DevOps

ViaSat, a global provider of satellite and wireless communications, securely connects businesses, governments, and organizations to the Internet. Learn how ViaSat’s Network Solutions Engineer, drove the transition from a traditional network support to a DevOps-centric model.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question