Solved

Moving FSMO Roles

Posted on 2016-10-12
5
140 Views
Last Modified: 2016-10-28
Hello All,

How to move FSMO roles from windows server 2008 R2 to windows server 2012 R2? we have almost 5 ADC and 6 RODC the reason i am asking this question here i would like to know what will be expecting errors or any downtime?

before i get start with ntdsutil or any other method i would like to chose the safest way to prevent upcoming problems.

Note: we have 3 roles on one server and 2 roles on another server.

Regards
Abdul..
0
Comment
Question by:Abdul Wahid
5 Comments
 
LVL 7

Expert Comment

by:No More
ID: 41841225
First at all run Netdom query FSMO  in command line to find out exactly which server has FMSO roles
(good to check twice and write it down)

There are few options NtdsUtil or you can use AD sites and AD users and computer (snap-ins) to seize FSMO roles

Definitely join those 2012 r2 servers to domain, as domain controllers so you can seize those roles

Downtime  - depends if you have many shares, roaming profiles and if you have some other roles on those servers like ADCS etc,

Best way is to write it down what server roles and data need to be moved to new servers and then plan it, but you shouldn't have any serious downtime, are those RODC used for VPN connections ?
1
 
LVL 14

Accepted Solution

by:
Todd Nelson earned 500 total points
ID: 41841345
Moving FSMO roles is essentially a non-event.

Use this article for moving Active Directory FSMO roles ... http://trunkofmemorie.blogspot.co.uk/2012/12/how-to-change-fsmo-roles-in-windows-2012.html

You should never have to use ntdsutil to move FSMO roles unless one of your domain controllers crashed and is not receoverable--even with RODCs.

This article will help you to understand the best placement of each role ... https://support.microsoft.com/en-us/kb/223346
0
 
LVL 6

Expert Comment

by:Niten Kumar
ID: 41841362
The first thing to do before you move any FSMO roles is best check on AD Health and Replication.  To check the replication and DC health dcdiag and repadmin command line utilities should be used.  

1.  Run dcdiag /q on each domain controller  (shouldn't get any failed tests here)
2.  Run Repadmin /replsum on any of the domain controllers (shouldn't get any errors here)
3.  Repadmin /showrepl  (should be all successful)

Then use netdom to verify the current fsmo role holder.  (Command:  netdom query fsmo)

You can transfer roles using GUI and there is no need to use ntdsutil here.
1
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 41841436
Just to only extend thread. If you wish you might also read articles on my blog which explains transferring FSMO roles operation in variety of ways.

For Windows Server 2012/2012R2 DCs or Windows client at least with PowerShell version 3.0
http://kpytko.pl/active-directory-domain-services/transferring-fsmo-roles-with-powershell/

Using management consoles
http://kpytko.pl/active-directory-domain-services/transferring-fsmo-roles-from-gui/

and the least convenient way but possible in command-line with ntdsutil
http://kpytko.pl/active-directory-domain-services/transferring-fsmo-roles-from-command-line/

Of course, you cannot transfer FSMO role to RODC, target DC(s) must be writeable DC. During transferring FSMO role, there is short break but mostly invisible to the clients in the network. However, this is good practice to do that during maintenance windows or out of business hours.

When you transfer PDC Emulator role, please advertise new time server in your domain. To do that, follow this article at http://kpytko.pl/active-directory-domain-services/advertising-new-time-server-in-domain-environment/

I hope this would help you in the action.

Regards,
Krzysztof
1

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
changing harddisk on computer in corporate 10 46
powershell question need assistance 10 32
Dropbox in Windows Server 2008 4 31
set-aduser powershell command issue 2 30
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question