Server 2003 and 2012 Domain Controllers Concurrently?


I am preparing to migrated our Active Directory environment to be hosted on 2012 servers from 2003 and there is lots of information on this process on the internet.  It seems easy enough, though not to be taken lightly.  But to "cut over" fully, that is to shut down the old 2003 servers and point everything over to the new servers is a little more involved.  IE DHCP services as well as point all static configured network devices to the new DC (also DNS) will take longer.  

I would prefer to do this in stages, IE one week, get a few additional 2012 DC joined to the domain and replicating Active Directory and DNS services.  Run that for a week to suss out any potential issues as well as not having to do too much all at once in one day (recipe for problems in my opinion).  Then the next week, spend time migrating DHCP database to the new DC as well as updating the scope settings to point to the new DCs for DNS resolution.  Changing all of the static network devices DNS settings and then having one of the new DCs takeover all FSMO roles.

First and foremost, does this seem like a logic procedure and am I missing any steps.  I am guessing the new DC will pick up to use root hints as opposed to forwarders (which is what I want) from the DNS Zone replication data?

Second, will running 2003 with 2012 DCs in tandem for a couple of weeks cause problems, or is it ok?  

Who is Participating?
Will SzymkowskiConnect With a Mentor Senior Solution ArchitectCommented:
The process I would follow is below...
- Prep you 2003 DC's for 2012 DC's
- Promote the 2012 DC's to domain controllers
- verify replication it working properly
- Transfer the FSMO roles to one of your new 2012 DC's
- Update your DHCP clients to point to the new 2012 DC's
- Change all of your static IP address to point to the new DC's/DNS servers
- Demote your 2003 domain controllers
- Check and validate your replication and ensure 2003 DC's have been demoted properly
- Migrate your DHCP services to your new DC's

Post migration
- Migrate your SYSVOL Share to DFS-R

Matthew BorrussoConnect With a Mentor Commented:
Will is right on the money.
The only thing I will add is that when all is said and done, to remember to up the operating level of the forest and domain to level you need it to be.
Here is all the info you will need for that.
it_saigeConnect With a Mentor DeveloperCommented:
There are a few potential gothchas.  With regards to the promotion of the 2012 Servers:

You want to make sure that your current Forest and Domain Functional Levels are set to at least Windows Server 2003:

Understanding Active Directory Domain Services (AD DS) Functional Levels

You also may have to modify the component services on the 2003 DC that you are performing the ADPREP on.

Finally, Kerberos authentication can fail intermittently (Microsoft has a hotfix for this issue) -

Other than those that I can think of, the comments by Will and Mathew are spot on.

Cliff GaliherConnect With a Mentor Commented:
Will's outline seems accurate. I will add one caveat though. Your initial plan to add 2012 DCs and then wait a week seems a little too cautious. A DC with nothing pointing at it adds no real benefit, and I'm not sure you'd know of any significant problems because nothing is trying to use it. 24 hours is all it should take to see any replication issues, so that additional 6 days just seems like idle time.
CnicNVAuthor Commented:
Ok thanks everyone for the feedback.  It gives me more confidence going into this, I appreciate it :-)
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.