• Status: Solved
  • Priority: High
  • Security: Public
  • Views: 127
  • Last Modified:

FSMO roles transfer

Expert out there, I would appreciate your recommendation on keeping Windows 2012 and Windows 20008 domain controllers.
 We have added Windows 2012 domain controllers in windows 2008 R2 . The FSMO roles are on Windows 2008 R2 with functional level with windows 2008.
We are about to install new Exchange servers where windows 2012 DC reside.
1 Should we have to move FSMO roles to Windows 2012 including schema master?
If so
How do we do?,  do we have to run Domain prep , forest prep etc  since Windows 2012 is upper version and schema version is not same as windows 2008.
3 Solutions
Cliff GaliherCommented:
2008 is very near end if life. Retire them.

Don't install exchange on a DC. *EVER!*

Schema versions apply to domains and forests, bot individual servers. You don't need to adprep or forestprep to move FSMO roles.
yo_beeDirector of Information TechnologyCommented:
You should always adprep your Schema if you are installing a newer version of the AD, but it should run automatically when you add the 2012 ADDS Role.


You do not have to move the FSMO role, but as Cliff mentioned it probably is a good idea to start thinking about sun setting the 2008 machine and moving the FSMO roles would be the first steps.

This a very straight forward propose and there is plenty of How To: or step by steps out on the internet.  

Here are a few links

I will also reinforce what Cliff stated (Exchange should never be run on your DC)   Your DC should have very limited access to it other than authentication validation.
Cliff GaliherCommented:
Based on the OP's original post, it sounds like the DCs are already in  place, thus my statement that schema changes wouldn't be necessary. Just to clarify.
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

sara2000Author Commented:
May be, I have not give enough info. No we are not going to install Exchange on DC !!.
Yes , we have Windows 2012 and Windows 2008. The FSMO roles are on Windows 2008 at present.
I noticed the schema version is not same on all DCs .
Installation of Exchange requires schema update. Always better to keep the schema closer to Exchange.
Cliff GaliherCommented:
If the schema version is not the same on all DCs in the same domain then you have bigger issues. That is not a healthy AD at that point.
Cliff GaliherCommented:
And again, to clarify  this is a bigger issue. Just running adprep to get the DCs to the same schema version won't solve the issue. The mismatch is highlighting a replication issue and the schema version is just one symptom. You really need to assess the health of the environment and address underlying errors.
Jose Gabriel Ortega CCEO J0rt3g4 Consulting ServicesCommented:
Well what I'd do is to update the whole infrastructure:
Install 2 servers 2012 R2.
 I'd take 1 server 2012 r2 for AD
 after instalation I'd move the FSMO  

Domain prep and forest prepare old procedures from 2003, the new is just to move the FSMO roles like this:

After that, I'd remove the 2008 r2 servers (Demotion and decommission), then possibly format them with 2012 r2 and use them as a file server and print server ( or exchange server), or (secondary domain controller).

After you have all the DCs under 2012 R2 you can update the Domain Functional Level to 2012 r2 like this

And after you have all the servers on your infrastructure updated to 2012 r2 you can update the FOREST functional level to 2012 like this:

Finally, I'd do the installation of the exchange 2016 on the other server 2012R2.

And probably create a DAG (after install 2012 R2 server on the actual 2008 r2 and install exchange server on that server too).
Aaron GuilmetteTechnology Solutions ProfessionalCommented:
How did you determine that the schema version isn't the same on all DCs?

Typically, we run something like:

Get-ADObject (Get-ADRootDSE).schemaNamingContext -Property objectVersion

Which is checking the objectVersion of the Schema Naming Context object.

Before you get too far ahead of yourself, I'd run a DCDIAG (or alternatively, DCDIAG /V) and REPADMIN /REPLSUMMARY to start looking at the replication health of your environment.
Shaun VermaakTechnical Specialist/DeveloperCommented:
Please run elevated and post out.txt
Repadmin /showrepl * > Out.txt

Open in new window

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Tackle projects and never again get stuck behind a technical roadblock.
Join Now