What isthe effect of turning off Domain Controller 1 week before decommisisoning ?

People,

Before I'm doing the Windows Server 2003 decommissioning process, I'm thinking to turn it off for one week and see if there is any problem reported by some other application.

Is there any harm or potential issue when doing this way ?

The actual decommissioning process will be following the below steps:
Demoting Windows Server 2003 domain controller
      https://technet.microsoft.com/en-us/library/cc740017(v=WS.10).aspx

Note: before the DCPROMO process, I will leave it running for 2 hours to resolve the DC replication first and then begin the demotion.

ANy potential problem or pitfall please share it here.

THanks
LVL 9
Senior IT System EngineerIT ProfessionalAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Nagendra Pratap SinghDesktop Applications SpecialistCommented:
This is a good way of testing things.
0
Santosh GuptaCommented:
Hi,

There is no harm to down the domain controller before Decomm but Please make sure below before down.

1. Domain Controller should not hold any FSMO role.
2. Domain Controller should not has DHCP.
3. Make sure that there is another Domain Controller at that site.
4. There should be GC.
5. Check if there is any Scheduled tasks.
6. If you have other DHCP then active server should be configure as primary DNS.
0
Will SzymkowskiSenior Solution ArchitectCommented:
I personally would have to disagree with both comments above. Although Santosh has illustrated some good points (i.e. not having the DC as a FSMO role holder or DHCP holder) it is not a good practice to shutdown a DC for an extended period of time without decommissioning it first.

I say this because when you shutdown a DC there is a definate potential that you are going to run into issues. This is because when you shut down a DC all of the data about this DC still resides in Sites and Services / DNS etc. The most critical area where you will see issues arise is SRV lookups. Even if you point your clients / servers to different DNS servers the old 2003 DC is still listed under the _msdcs.domain.com folder where all of the SRV records are. This is a randomized process and could pick the 2003 DC that is not online.

The user might experience an error message stating "cannot contact the domain" or lang times because it is trying to contact a DC this is not reachable.

In my experience just make sure that you do the following...
- transfer the FSMO roles
- change the dhcp scopes to point to another DC for DNS
- check replication before and after the decommission
- run DCDiag /v (correct errors if any)

Do not just shutdown the DC as this will create issues.

Will.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Senior IT System EngineerIT ProfessionalAuthor Commented:
Yes, this old Server 2003 box dosn't run anything else as I have moved the roles into different server except DNS server role and the Domain Controller role.

so yes, once I turn it back on, I'll wait for few hours for the replication to stabilize and then perform DCPROMO, after that I will stop the DNS services then shut it down for another week.

is that the correct plan for decommisioning old DC ?
0
Will SzymkowskiSenior Solution ArchitectCommented:
As long as the DC is not holding any fsmo roles or any other services that are required (dns is fine). Just decommission the DC check replication and then turn off the DC. Do not power off the DC before you demote it.

Just demote it and then power it off.

Will.
0
Santosh GuptaCommented:
yes correct, if server is not required then no need to wait for replication after server back.
simply shutdown for few days, if no issue faced during server down  then demote it.
0
Will SzymkowskiSenior Solution ArchitectCommented:
DO NOT shut it down for a few days! As I have stated already this will cause issues when users try and reference SRV records. If the DC is no longer need demote it, period.

Will.
0
Senior IT System EngineerIT ProfessionalAuthor Commented:
ok, so after the decommissioning of the DC, the AD sites and services will be automatically recalculated and then recreated in between the AD sites to avoid AD replication issues ?

is that correct or do I need to create manual conenction in the AD sites and recovery before I decommission this old DC to make sure the new replacement DC can talk to the Data Centre domain controller ?
0
Senior IT System EngineerIT ProfessionalAuthor Commented:
Ok I've just found out one issue here.

The user account that I've created in the new Domain controller in the HQ office does not replicated to the Data Center Domain Controllers used by Exchange servers.

This is happening after turning off one very old DC, so how can I recreate the replication link in AD sites and Services safely ?
0
Santosh GuptaCommented:
it will automatically create.
0
Senior IT System EngineerIT ProfessionalAuthor Commented:
Thanks !
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.