Solved

create a second domain controller and then make primary controller

Posted on 2013-10-28
9
558 Views
Last Modified: 2013-11-04
I have a windows 2000 server.  Very old.  I just installed a 2012 server standard to the same domain.  I would like to activate windows active directory on the new controller but there are several AD roles to choose.  Which ones do I select to make it a domain controller.  Then after I am done, I would like to promote it as the primary controller to the domain.

How can I accomplish this?  Is this too big of a jump?
0
Comment
Question by:al4629740
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
9 Comments
 
LVL 22

Assisted Solution

by:Nick Rhode
Nick Rhode earned 166 total points
ID: 39606890
That is a pretty big jump.  AD function level has to be at least 2003.

http://social.technet.microsoft.com/Forums/windowsserver/en-US/22825611-af8e-48ca-bef7-98bb981b2f5a/migrate-a-windows-server-2000-to-2012?forum=winserverDS

How many systems do you have in your environment?
0
 

Author Comment

by:al4629740
ID: 39606924
Less than 20 pcs
0
 
LVL 22

Assisted Solution

by:Nick Rhode
Nick Rhode earned 166 total points
ID: 39606943
With that small of an environment you could probably clean it up by just deploying a fresh environment with a new domain and join the systems to it if you wanted or needed to cleanup your infrastructure.  Otherwise my earlier link has some guides to upgrading and migrating.
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 
LVL 95

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 167 total points
ID: 39606972
You cannot make the 2012 server a DC in your environment Until you get rid of the 2000 server as a DC and put a 2003 or later DC on the network.  (I'm not but I don't think you can jump to 2008 - I think you need 2003 or 2003 R2).  This means you need to:

1. install a 2003 Server, join it to the domain, promote it to be a domain controller.
2. transfer the FSMO roles to the 2003 server.
3. demote the 2000 server so that it is no longer a DC.
4. change the domain and forest functional levels of AD.
5. install the 2012 server and join it to the domain
6. promote the 2012 server to a DC
7. transfer the FSMO roles to the 2012 server
8. demote the 2003 server
9. remove the 2003 server from the domain
10. transfer the remaining services and features of the 2000 server to the 2012 server.  (You may have to adjust some SMB protocol settings to allow the 2000 server to talk to the 2012 server).

If you've never done this and aren't expecting to make this your day job (doing such migrations), I HIGHLY recommend you hire a consultant with experience to do this transition for you.  It will go much faster and much smoother and though you'll potentially have to cut a higher check, the costs in terms of lost productivity and potential issues in the future will almost certainly be less.

Finally, VIRTUALIZE - 2012 makes this easy and virtualization, while adding a small layer of complexity, adds a HUGE layer of flexibility!  (And Hyper-V in 2012 is FREE!)
0
 

Author Comment

by:al4629740
ID: 39607091
In a nutshell what is hyper V?
0
 
LVL 35

Assisted Solution

by:Seth Simmons
Seth Simmons earned 167 total points
ID: 39607249
hyper-v is microsoft's hypervisor for creating and running virtual machines; competitor to VMware

and yes, you can install a 2008 R2 server and make it a domain controller to migrate the 2000 server to.  the 2003 limit is the domain/forest functional level which is required for a 2012 domain controller which you can't achieve until the 2000 server is gone.  a 2008 R2 server can work in a 2000 native functional mode

http://technet.microsoft.com/en-us/library/understanding-active-directory-functional-levels%28v=ws.10%29.aspx

you can migrate to that first, raise the forest/domain functional level to 2003, 2008 or 2008 R2 then put in your 2012 domain controller
0
 

Author Comment

by:al4629740
ID: 39607288
What if I just take rhodes suggestion and just migrate all the computers onto a new domain?
0
 
LVL 35

Assisted Solution

by:Seth Simmons
Seth Simmons earned 167 total points
ID: 39607299
that's up to you; you can go that route especially with a small number of machines like this and if purchasing 2008 R2 isn't an option

you would also have to create the user accounts again and work on migrating that since user objects won't have the same SID - just keep that in mind also.  with that many client machines it shouldn't be too bad
0
 
LVL 95

Accepted Solution

by:
Lee W, MVP earned 167 total points
ID: 39607872
>  with that many client machines it shouldn't be too bad
I disagree - the last time I did a domain of 15 users from scratch it took 5 days to settle everything down.  Doing a migration - if you know what you're doing, should take about 1-2 days depending on how well patched your servers are and how fast your systems and internet connection are.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Virtual SQL Server 2014 Standard 35 113
GPO Not Applying 5 57
local resources on a virtual host 8 63
Server 2012 ADMX 1 25
Table of Contents: Lesson 1 - Installing Windows Server 2012 (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2012/A_11592-Become-an-Administrator-Installing-Windows-Server-2012.html) Lesson 2 - Configuring Ser…
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question