Link to home
Start Free TrialLog in
Avatar of Albert Widjaja
Albert WidjajaFlag for Australia

asked on

Upgrading the Domain/Forest functionality level caveats and tips ?

Hi All,

I'm about to perform Domain and Forest Functionality level upgrade from Windows Server 2003 into WIndows Server 2012 R2 if possible, but I wonder what are the caveats and pitfalls ?

Note:

Single domain AD forest
4x Exchange Server 2010 SP3 OnPremise soon to be migrated to Office 365 in a few months.
2x Windows Server 2012 R2 Domain Controllers FSMO role holder (PDC, RID & Infrastructure master)
6x  Windows Server 2008 R2 Domain Controllers (Schema & Domain naming master)

I reckon that there is no roll back plan because this process cannot be rolled back.
Avatar of Albert Widjaja
Albert Widjaja
Flag of Australia image

ASKER

Do I need to reboot the Exchange Server or just restart some services which can cause email flow outage ?
SOLUTION
Avatar of Mahmoud Sabry
Mahmoud Sabry
Flag of Egypt image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Ah i see, so I will go to 2008R2 in this case because I still have some windows 2008 R2 as domain controllers
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
No I haven't transfer it because I do not know why I must use DFS ?

Is there any requirement ?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi Arnold and Mahmoud,

I have already turned off the old Windows Server 2003 machine & VMs in my single AD domain forest.
So before I performthe simple right click functional level upgrade, I just wondering why do I need to migrate the NTFRS

1.

Open Active Directory Domains and Trusts from the Administrative Tools folder.

2.

In the console pane of the Active Directory Domains and Trusts window, right-click the name of the domain for which you are migrating the SYSVOL folder, and then click Raise Domain Functional Level.

3.

In the Raise domain functional level dialogue box, in the Select an available domain functional level list, click Windows Server 2008, and then click Raise.

3.

In the warning message that mentions that raising the domain functional level affects the entire domain and cannot be reversed, click OK.

4.

In the confirmation message that indicates that raising the domain functional level succeeded, click OK.
Why in step #2 above is required to migrate the SYSVOL to somewhere else ?
you do not have to as part of raising forest/domain level given windows 2012 still has support for ntfrs replication of sysvol.
I would recommend performing the migration sooner rather than later to avoid complications down the line.

https://msdn.microsoft.com/en-us/library/windows/desktop/ff384840%28v=vs.85%29.aspx
Ah I see, so I guess, I can just  follow the 4 steps I described above to upgrade the domain/forest level during the business hours.

Source: https://technet.microsoft.com/en-us/library/cc730985.aspx

After that I will need to restart the Kerberos Key Distribution Center service in all Domain Controllers one by one.

is that correct ?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ok, now as for executing the Domain/Forest Functional level raise, where should I execute it from:

Windows Server 2008 R2 DC or from the Windows Server 2012 R2 DC into Windows Server 2008R2 straight away jumping from WIndows 2003 ?
You should run it on the Master dc.
Do you mean for my Infrastructure Master role holder DC ?

To raise the both Forest and Domain level to 2008R2 straight away?
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Will,

Many thanks for the update, however, I'm quite surprised that you mentioned about updating Rollup Update on Exchange Server 2010 SP3.

yes, I have On-Premise Exchange Server 2010 that I have just upgraded to SP3 few months ago, our current DFL/FFL is still on Windows Server 2003 and it is working without any issue ?

I have no plan to implement Exchange Server 2010 SP3 Update Rollup 10 (KB3049853) because everything is still working fine with no issue.

Is it really necessary to apply P3 Update Rollup 10 (KB3049853)as above just before raising the DFL/FFL into Windows Server 2008R2 ?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Ah yes, I see:

So during the waiting time, what and how should I check so I know when to proceed the next steps ?
Will's advice is spot on for this.

ensure that replicaiton is good using the following commands...
 repadmin /replsum
 repadmin /showrepl
 repadmin /bridgeheads
 DCDiag /v

Plus you can open AD on various DCs to make sure they all report the same domain/forest levels etc.
Thanks !