domain questions

Hello Everyone,
We are running a windows active directory domain. We have a single domain in a single forest, pretty simple setup. Single site about 200 user accounts.

I have 3 domain controllers:
one is windows server 2003 standard
one is windows server 2008 standard (64bit)
the other is windows server 2008 standard (64bit).

All are global catalogs and the FSMO roles are held by the 2 windows server 2008 domain controllers. the domain is running at functional level 2000. The 2003 standard server is also a file server and one of the 2008 servers is also an exchange server.

I need to upgrade my active directory to 2008 to install a newer version of exchange. I will eventually move to 2008r2 or 2013 domains.

So, this is the plan:
1. first, we will demote the server 2003 domain controller.
2. Then we will raise the functional level to 2008.
3. Then we will promote a new domain controller, which will run 2008 r2.
4. Then we will migrate to exchange 2010.
5. Then we will add another 2008 r2 domain controller.
6. Then demote the 2 2008 domain controllers.
7. Then raise the functional level again.
(there would be at least one week, maybe multiple weeks between steps)

So, my question is... does this generally sound okay? Does this make sense? Any red flags?

One question I had is whether or not the 2 2008 machines are going to be okay running a functional level 200 domain without the 2003 domain controller.

Also, did Microsoft remove any features through the upgrades? Maybe some group policy options? We don't really do anything special. Some login scripts, basic user account access. Some terminal services options. We publish an exchange certificate, network drives, and some screensaver options through active directory.

Anyway, any input or feedback would be very helpful.

Who is Participating?
yo_beeConnect With a Mentor Director of Information TechnologyCommented:
You are fine with leaving the Domain and forest levels remaining at 2000 even if you do not have a 2000 or 2003 in your environment.
Feature wise you will gain not lose functionality once you raise the domain a. Forest to 2008.

Run netdiag and dcdiag before doing a Dcpromo on your 2003 box to make sure all things are good in your domain. Once those diags logs are validated for no issues then I would run dcpromo on your 2003 box.
Once all good on that front you can raise your forest and domain level to gain the extra functionality that comes with 2008.
CoralonConnect With a Mentor Commented:
Sounds like a perfectly reasonable plan.  They don't strip anything in the Win2k8, or Win2k8R2.. but they do add new restrictions and 'features' that can make life more difficult.  UAC is the most obvious one...

IMHO, given you do not have windows 2000 DC, you should raise the domain/forest functional level to 2003.

Others pointed out that raise in level adds features, group policy preferences, DFS-r
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

SandeshdubeyConnect With a Mentor Senior Server EngineerCommented:
Even with Win2003 DC you should be able to install exchange 2010/2013 but the you need to raise the DFL/FFL to Win2003.See this for more details.

However you can remove the Win2003 DC from network and install new Win2008 R2 server.Once all the DCs are Win2008 you can raise the functional level to Win2008.

Raising the domain functional level will provide new features as other suggested.For example Fine grained password policy,preferences, AD recycle bin(DFL/FFL Win2008 R2),DFSR,etc.

What is the Impact of Upgrading the Domain or Forest Functional Level?

Note the existing group policy will not be impacted and the same will be available in Win2008/R2 DC.

Hope this helps
yo_beeDirector of Information TechnologyCommented:
I do not see a reason not to raise the FFL and DFL to 2008 if you never plan to install a 2003 DC again.
kevinhsiehConnect With a Mentor Commented:
My only question is why are you going to an old version of Windows Server and Exchange? Windows 2012 and Exchange 2013 are current, and Windows Server 2012 R2 will be released in about 10 days. I would look at going to Windows 2012 and Exchange 2013.
Jack5BackAuthor Commented:
Thanks Everyone.

I appreciate what you are saying. Essentially, my environment spans so many different versions of exchange and active directory already. Getting the domain to 2008r2 and exchange to 2010 would be such a huge step forward for us. I am also migrating away from Essential Business Server, so I am wary of any potential problems that is going throw in.

I believe that once I am on 2008r2 and exchange 2010, moving forward from their is going to be a much more manageable process for us. I don't planning on stopping at 2008r2 & exchange 2010, that's just the next attainable goal. So, I am just taking it "one step at a time".

I've been told that exchange 2013 is dramatically different from 2007 & 2010, so I don't want to underestimate that step. And, because I don't see anything in 2013 that is particularly valuable to my organization, I am in no hurry to get their.
SteveConnect With a Mentor Commented:
firstly, your plan will work fine but may be a little over complicated.

secondly, it is true that exch 2013 & server 2012 are available, but that doesn't mean you have to use them. There are costs, hardware compatibility, drivers, upgrade paths and CALs to consider, If you have reasons to stick to 2008R2 & exch 2010 then you go ahead, but it is worth checking up the new versions are a suitable option.

I need to upgrade my active directory to 2008 to install a newer version of exchange.
thirdly, if this whole process is triggered by the exchange upgrade, you may not need to do most of what you have planned.
exchange 2010 needs domain/forest level 2003 or higher and you can achieve that without changing your infrastructure at all.

Is there more to your query than this? are there other upgrade requirements you are trying to satisfy?
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.