Solved

Moving FSMO Roles

Posted on 2016-10-12
5
103 Views
Last Modified: 2016-10-28
Hello All,

How to move FSMO roles from windows server 2008 R2 to windows server 2012 R2? we have almost 5 ADC and 6 RODC the reason i am asking this question here i would like to know what will be expecting errors or any downtime?

before i get start with ntdsutil or any other method i would like to chose the safest way to prevent upcoming problems.

Note: we have 3 roles on one server and 2 roles on another server.

Regards
Abdul..
0
Comment
Question by:Abdul Wahid
5 Comments
 
LVL 7

Expert Comment

by:No More
ID: 41841225
First at all run Netdom query FSMO  in command line to find out exactly which server has FMSO roles
(good to check twice and write it down)

There are few options NtdsUtil or you can use AD sites and AD users and computer (snap-ins) to seize FSMO roles

Definitely join those 2012 r2 servers to domain, as domain controllers so you can seize those roles

Downtime  - depends if you have many shares, roaming profiles and if you have some other roles on those servers like ADCS etc,

Best way is to write it down what server roles and data need to be moved to new servers and then plan it, but you shouldn't have any serious downtime, are those RODC used for VPN connections ?
1
 
LVL 14

Accepted Solution

by:
Todd Nelson earned 500 total points
ID: 41841345
Moving FSMO roles is essentially a non-event.

Use this article for moving Active Directory FSMO roles ... http://trunkofmemorie.blogspot.co.uk/2012/12/how-to-change-fsmo-roles-in-windows-2012.html

You should never have to use ntdsutil to move FSMO roles unless one of your domain controllers crashed and is not receoverable--even with RODCs.

This article will help you to understand the best placement of each role ... https://support.microsoft.com/en-us/kb/223346
0
 
LVL 6

Expert Comment

by:Niten Kumar
ID: 41841362
The first thing to do before you move any FSMO roles is best check on AD Health and Replication.  To check the replication and DC health dcdiag and repadmin command line utilities should be used.  

1.  Run dcdiag /q on each domain controller  (shouldn't get any failed tests here)
2.  Run Repadmin /replsum on any of the domain controllers (shouldn't get any errors here)
3.  Repadmin /showrepl  (should be all successful)

Then use netdom to verify the current fsmo role holder.  (Command:  netdom query fsmo)

You can transfer roles using GUI and there is no need to use ntdsutil here.
1
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 41841436
Just to only extend thread. If you wish you might also read articles on my blog which explains transferring FSMO roles operation in variety of ways.

For Windows Server 2012/2012R2 DCs or Windows client at least with PowerShell version 3.0
http://kpytko.pl/active-directory-domain-services/transferring-fsmo-roles-with-powershell/

Using management consoles
http://kpytko.pl/active-directory-domain-services/transferring-fsmo-roles-from-gui/

and the least convenient way but possible in command-line with ntdsutil
http://kpytko.pl/active-directory-domain-services/transferring-fsmo-roles-from-command-line/

Of course, you cannot transfer FSMO role to RODC, target DC(s) must be writeable DC. During transferring FSMO role, there is short break but mostly invisible to the clients in the network. However, this is good practice to do that during maintenance windows or out of business hours.

When you transfer PDC Emulator role, please advertise new time server in your domain. To do that, follow this article at http://kpytko.pl/active-directory-domain-services/advertising-new-time-server-in-domain-environment/

I hope this would help you in the action.

Regards,
Krzysztof
1

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Synchronize a new Active Directory domain with an existing Office 365 tenant
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now