Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


active directory migration and backup

Posted on 2015-01-18
Medium Priority
Last Modified: 2015-02-11
Hi All,

     I have 4 active directory servers as below.
dc1 windows 2003, runs dns, dhcp, global catalog
dc2 windows 2008 standard, runs dns, global catalog ( handling FSMO roles)
dc3 windows 2008 standard , dns
dc 4 windows 2012 standard

I need to migrate my domain level and make the windows 2012 the primary ( fsmo ) and remove the windows 2003, what is the best and recommend way to have a stable active directory in my network
Question by:ITMaster1979
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 37

Assisted Solution

Mahesh earned 1000 total points
ID: 40556392
I hope this is 2012 R2 and not 2012
U can migrate FSMO any time, that's not a problem

Now as far as upgrading functional level:
1st add one more 2012 \ 2012 R2 DC
Check event 13516 in file replication service events and 1394 under directory services for successful DC promotion
Also check if netlogon and sysvol shares are present on new 2012 DC
Check if all DCs are able to replicate with each other correctly and also check name resolution
Then move FSMO
Change any dns servers specified in DHCP scopes to new 2012 servers
change any static IP entries pointing to 2003 servers to 2012 DC servers, this is applicable to servers, desktops, network devices, printers and so on.
Then U need to 1st move DHCP to another server from existing 2003 DC, then demote 2003 DC

Then demote 2008 DC
Then raise functional level

Before demoting any DC, ensure that you will change primary DNS to point to 2012 \ 2012 r2 servers
As long as your DNS name resolution, AD replication, sysvol replication is working correctly your AD is OK
Besides that you may need additional security measures, delegations, policies, you can setup those letter once all your older OS DCs got demoted and everying from AD stand point is working correctly
LVL 24

Accepted Solution

VB ITS earned 1000 total points
ID: 40556950
He does not want to demote the 2008 DC, just the 2003 DC. The Forest and Domain Functional Levels must also be verified beforehand.

Here's what I would do before you introduce the first 2012 DC in your environment:

1. Check current AD Health

Check that your current environment is healthy by following the steps in these articles:
If you find any issues, you can use these articles to troubleshoot them:

- Troubleshoot AD health in Server 2003:
- Troubleshoot AD health in Server 2008:

2. Check Functional Levels

Check to make sure your Domain and Forest Functional Levels are at Windows Server 2003 at a minimum:
- Open Active Directory Users and Computers
- Right click on your domain name on the left pane
- Go down to Properties
- Your Domain and Forest Functional Levels will be displayed in the General tab towards the bottom
If your functional levels are not set to Windows Server 2003 then you'll need to raise them:

- Raising your Domain Functional Level:
- Raising your Forest Functional Level:

3. Introduce First 2012 Domain Controller

Now you're ready to introduce your first 2012 DC into your environment! Please see the below article which has step-by-step instructions to do this. Note that although this is a 2-part article, the second part just really shows you how to promote the 2012 server to a DC using PowerShell instead of the GUI.

You may notice that I have omitted the step to run adprep.exe - this is no longer required starting from Server 2012 as it runs automatically when you install the Active Directory Directory Services role. You can confirm this here:

4. Transfer FSMO Roles

Once you have verified that your new 2012 DC is functioning properly and your AD environment is healthy, you need to transfer the FSMO roles that may still be on the 2003 DC over to the new 2012 DC. Remember to also make sure your 2003 DC is no longer a Global Catalog server (steps are at the bottom of the below article):

5. Demote 2003 DC

This step is an easy one once you've performed the steps above. Just remember to transfer over all FSMO roles over to your other DCs before demoting your 2003 DC.

5. Raise AD Functional Levels (Optional)

Only perform this step if you no longer plan to introduce any further 2003 DCs to your environment. You must only raise your functional levels to the oldest version domain controller on your domain. For example if all your domain controllers are 2012 R2 then you can go all the way to 2012 R2. However if you have a Server 2008 DC then you can only raise the functional level to Windows Server 2008.

Raise Domain Functional Level:
Raise Forest Functional Level:

If you want to do some reading on functional levels to get a better understanding, please see this article:

6. Move Roles Off 2003 DC

Self explanatory step really. If you have specific roles on the old server that you need help with to transfer to your other servers then please let us know what these roles are.

7. Remove Old 2003 Server

After you have moved all the roles off the 2003 server, I would recommend you leave the server on for a few weeks. If no users report any errors, turn off the server and leave it off for a week or so. If you still don't hear anything then it's safe to remove this server from the domain, shut it down and re-purpose it or throw away or recycle it (remember to pull out the hard drives first or perform a military-grade wipe on them).
Hope this helps!

EDIT: Added steps 6 & 7.

Author Closing Comment

ID: 40602712

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
Here's a look at newsworthy articles and community happenings during the last month.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

671 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question