Solved

Adding a 2nd Domain (DC2) Controller and Retiring (DC1)...

Posted on 2016-11-11
6
62 Views
Last Modified: 2016-11-12
Future Scenario to Be Realistic in 2 weekends:
1. Current Active Directory DC1 (10.0.0.5) is 5 years old and customer wants to upgrade hardware.
2. Same current 5yr old hardware is DC1(10.0.0.5) using Windows 2012 Server with the latest updates.
3. Customer wants to upgrade their current hardware (DC1) and software to Windows 2012 R2.
4. Will Install Windows 2012 R2 on new hardware, promote to a DC2 (10.0.0.6) and Add new DC2 (10.0.0.6) to the current DC1 (10.0.0.5).
After doing so, DC2 (10.0.0.6) should replicate DC1's(10.0.0.5) Active Directory settings.
5.  Will enable DHCP on DC2 (10.0.0.6) and disable DC1(10.0.0.5) as the DHCP server.
6.  Will also allow DC2(10.0.0.6) to be the primary DNS server under DHCP's DNS settings for LAN PCs.
7.  domain.local wil remain the same and will not change.  
8.  DCs are strictly local and .com is nor will be necessary hence, domain.local will suit the company fine for the type of business that it is.

**What steps should I take to retire DC1 after DC2 (10.0.0.6) has joined the Domain as a Domain Controller (DC2) and DC2 propagates DC1's Active Directory settings?
1) Do I simply demote DC1 after approximately 24hours/1day as well as remove the Active Directory server role?
2) If so, will DC2 allow for new computers to join the domain.local once DC1 has been demoted and shutdown?
3)  How do I migrate the FSMO role(s) if necessary to DC2?
0
Comment
Question by:eitconsulting
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 7

Accepted Solution

by:
No More earned 500 total points
ID: 41884457
1,Join DC2 to domain as Domain cotroller

2.transfer FSMO roles https://winsvr.wordpress.com/2012/12/17/transferring-fsmo-roles-from-ws-2008r2-dc-to-ws-2012-dc/

3. Export DHCP settings, install DHCP role on DC2, shutdown DHCP on DC1 import DHCP settings on DC2 and promote

4. Uninstall DHCP and Demote DC1,

You could also give DC2 IP address of DC1 after DC1 is shutdown
0
 

Author Comment

by:eitconsulting
ID: 41884460
David:
 Sounds pretty straight forward.  Despite the link using Windows 2008R2 in its example, should still work with Win2012 (Win2008 in link) to 2012R2 (Win2012 in link)?
0
 
LVL 7

Expert Comment

by:No More
ID: 41884463
Yes, it's same, but the link is in nice detail
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 7

Expert Comment

by:No More
ID: 41884465
ALso with the DHCP it's up to you one way or the other you will have little downtime few minutes, you could also just install DHCP role on server DC2 and completely ignore export import, depending on settings in current DHCP
0
 
LVL 96

Expert Comment

by:Lee W, MVP
ID: 41884470
Can I be blunt?

You realize this is basic AD configuration?  If you have never done this before why are you experimenting with a client's network first?  You should be setting up a lab environment and learning this stuff first.

So, in a lab environment, you should transfer the FSMO roles (there are multiple ways of doing this, PowerShell, NTDSUtil, or the GUI interfaces.
Make sure the DHCP servers are no longer assigning the old server as a DNS server.

Make sure the new server(s) are Global Catalog server(s).

I would suggest turning OFF the DC you want to remove for a couple of days to ensure everything is working properly.  But before that - and before even promoting the new DC, run DCDIAG /C /E /V and REPADMIN /SHOWREPL to ensure AD is healthy.

If this stuff is too new to you, you would be wise to hire/partner with someone with experience or get proper training.
0
 

Author Closing Comment

by:eitconsulting
ID: 41884485
David, great link with a way to do it via the GUI.  I've used the ntdsutil in the past and it also had real examples using both the ntdsutil and powershell.  Thank you.

Lee, but we're having so much fun experimenting with the client's actual production AD environment.  Deep breaths!!  We used Microsoft's disk2vhd app to convert and export the client's AD server successfully to our VM lab.  I'm merely asking a question here as I typically do here as well as on SpiceWorks and TechRepublic for important feedback in order to possibly learn of new and/or more efficient ways to do the things we do.
1

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question