Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Migration > domain controller migration

Reply
Thread Tools Display Modes

domain controller migration

 
 
ronaldo
Guest
Posts: n/a

 
      01-06-2010
I have a windows 2000 advance server sp4,
Because of hardware upgrade,I want to upgrade it window 2008 server.

This windows 2000 is only dc of a domain,
In order to migrate everything (e.g.
user account, policy, file share, security.....) of this server to new
machine,
does microsoft have any suggested procedure on this issue?

thank you
Roy


 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      01-06-2010
Hello ronaldo,

There is no way to inplace upgrade a Windows server 200 to Windows server
2008 directly. See here about a way to do it:

!!!NEVER START BEFORE HAVING CREATED AND TESTED A BACKUP OF YOUR DATA/MACHINE!!!

- Do you use any kind of Exchange in the 2000 domain? If yes, which one?

- On the old server open DNS management console and check that you are running
Active directory integrated zone (easier for replication, if you have more
then one DNS server)

- run replmon from the run line or repadmin /showreps(only if more then one
DC exist), dcdiag and netdiag from the command prompt on the old machine
to check for errors, if you have some post the complete output from the command
here or solve them first. For this tools you have to install the support\tools\suptools.msi
from the 2000 installation disk.

- run adprep /forestprep and adprep /domainprep and adprep /domainprep /gpprep
and adprep /rodcprep from the 2008 installation disk against the 2000 schema
master(forestprep) / infrastructure master(domainprep/rodcprep), with an
account that is member of the Schema/Enterprise/Domain admins, to upgrade
the schema to the new version (44) or 2008 R2 (47)

- you can check the schema version with "schupgr" or "dsquery * cn=schema,cn=configuration,dc=domainname,dc=local
-scope base -attr objectVersion" without the quotes in a command prompt

- Install the new machine as a member server in your existing domain

- configure a fixed ip and set the preferred DNS server to the old DNS server
only, think about disabling IPv6 if you are not using it, some known problems
exist with it. Follow (http://blogs.dirteam.com/blogs/paulb...dows-2008.aspx)
to disable it

- run dcpromo and follow the wizard to add the 2008 server to an existing
domain, make it also Global catalog and DNS server.

- for DNS give the server time for replication, at least 15 minutes. Because
you use Active directory integrated zones it will automatically replicate
the zones to the new server. Open DNS management console to check that they
appear

- if the new machine is domain controller and DNS server run again replmon,
dcdiag on both domain controllers. For using netdiag.exe on 2008, NOT 2008
R2, you have to download and install (http://www.microsoft.com/downloads/d...displaylang=en),
ignore the compatibility warning, or extract netdiag.exe only and copy it

- Transfer, NOT seize the 5 FSMO roles to the new Domain controller (http://support.microsoft.com/kb/324801
applies also for 2008/2008R2), FSMO should always be on the newest OS DC

- after transfer of the PDCEmulator role, configure the NEW PDCEmulator to
an external timesource and reconfigure the old PDCEmulator to use the domainhierarchie
now. Therefore run on the NEW "w32tm /config /manualpeerlist:PEERS /syncfromflags:manual
/reliable:yes /update" where PEERS will be filled with the ip address or
server(time.windows.com) and on the OLD one run "w32tm /config /syncfromflags:domhier
/reliable:no /update" and stop/start the time service on the old one. All
commands run in an elevated command prompt without the quotes.

- you can see in the event viewer (Directory service) that the roles are
transferred, also give it some time

- reconfigure the DNS configuration on your NIC of the 2008 server, preferred
DNS itself, secondary the old one

- if you use DHCP do not forget to reconfigure the scope settings to point
to the new installed DNS server



Demoting the old DC(if needed)

- reconfigure your clients/servers that they not longer point to the old
DC/DNS server on the NIC

- to be sure that everything runs fine, disconnect the old DC from the network
and check with clients and servers the connectivity, logon and also with
one client a restart to see that everything is ok

- then run dcpromo to demote the old DC, if it works fine the machine will
move from the DC's OU to the computers container, where you can delete it
by hand. Can be that you got an error during demoting at the beginning, then
uncheck the Global catalog on that DC and try again

- check the DNS management console, that all entries from the machine are
disappeared or delete them by hand if the machine is off the network for ever

- also you have to start AD sites and services and delete the old servername
under the site, this will not be done during demotion

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I have a windows 2000 advance server sp4,
> Because of hardware upgrade,I want to upgrade it window 2008 server.
> This windows 2000 is only dc of a domain,
> In order to migrate everything (e.g.
> user account, policy, file share, security.....) of this server to new
> machine,
> does microsoft have any suggested procedure on this issue?
> thank you
> Roy



 
Reply With Quote
 
ronaldo
Guest
Posts: n/a

 
      01-10-2010
In the case is very simple one.
In the windows 2000 AD, there are 1 and only 1 server.
We have no exchange server in the AD.
We use the 2000 server as file server.
So, does it make the migration simpler?


"Meinolf Weber [MVP-DS]" <meiweb@(nospam)gmx.de> wrote in message
news:. com...
> Hello ronaldo,
>
> There is no way to inplace upgrade a Windows server 200 to Windows server
> 2008 directly. See here about a way to do it:
>
> !!!NEVER START BEFORE HAVING CREATED AND TESTED A BACKUP OF YOUR
> DATA/MACHINE!!!
>
> - Do you use any kind of Exchange in the 2000 domain? If yes, which one?
>
> - On the old server open DNS management console and check that you are
> running Active directory integrated zone (easier for replication, if you
> have more then one DNS server)
>
> - run replmon from the run line or repadmin /showreps(only if more then
> one DC exist), dcdiag and netdiag from the command prompt on the old
> machine to check for errors, if you have some post the complete output
> from the command here or solve them first. For this tools you have to
> install the support\tools\suptools.msi from the 2000 installation disk.
>
> - run adprep /forestprep and adprep /domainprep and adprep /domainprep
> /gpprep and adprep /rodcprep from the 2008 installation disk against the
> 2000 schema master(forestprep) / infrastructure
> master(domainprep/rodcprep), with an account that is member of the
> Schema/Enterprise/Domain admins, to upgrade the schema to the new version
> (44) or 2008 R2 (47)
>
> - you can check the schema version with "schupgr" or "dsquery *
> cn=schema,cn=configuration,dc=domainname,dc=local -scope base -attr
> objectVersion" without the quotes in a command prompt
> - Install the new machine as a member server in your existing domain
>
> - configure a fixed ip and set the preferred DNS server to the old DNS
> server only, think about disabling IPv6 if you are not using it, some
> known problems exist with it. Follow
> (http://blogs.dirteam.com/blogs/paulb...dows-2008.aspx)
> to disable it
>
> - run dcpromo and follow the wizard to add the 2008 server to an existing
> domain, make it also Global catalog and DNS server.
>
> - for DNS give the server time for replication, at least 15 minutes.
> Because you use Active directory integrated zones it will automatically
> replicate the zones to the new server. Open DNS management console to
> check that they appear
>
> - if the new machine is domain controller and DNS server run again
> replmon, dcdiag on both domain controllers. For using netdiag.exe on 2008,
> NOT 2008 R2, you have to download and install
> (http://www.microsoft.com/downloads/d...displaylang=en),
> ignore the compatibility warning, or extract netdiag.exe only and copy it
>
> - Transfer, NOT seize the 5 FSMO roles to the new Domain controller
> (http://support.microsoft.com/kb/324801 applies also for 2008/2008R2),
> FSMO should always be on the newest OS DC
>
> - after transfer of the PDCEmulator role, configure the NEW PDCEmulator to
> an external timesource and reconfigure the old PDCEmulator to use the
> domainhierarchie now. Therefore run on the NEW "w32tm /config
> /manualpeerlist:PEERS /syncfromflags:manual /reliable:yes /update" where
> PEERS will be filled with the ip address or server(time.windows.com) and
> on the OLD one run "w32tm /config /syncfromflags:domhier /reliable:no
> /update" and stop/start the time service on the old one. All commands run
> in an elevated command prompt without the quotes.
>
> - you can see in the event viewer (Directory service) that the roles are
> transferred, also give it some time
>
> - reconfigure the DNS configuration on your NIC of the 2008 server,
> preferred DNS itself, secondary the old one
>
> - if you use DHCP do not forget to reconfigure the scope settings to point
> to the new installed DNS server
>
>
>
> Demoting the old DC(if needed)
>
> - reconfigure your clients/servers that they not longer point to the old
> DC/DNS server on the NIC
>
> - to be sure that everything runs fine, disconnect the old DC from the
> network and check with clients and servers the connectivity, logon and
> also with one client a restart to see that everything is ok
>
> - then run dcpromo to demote the old DC, if it works fine the machine will
> move from the DC's OU to the computers container, where you can delete it
> by hand. Can be that you got an error during demoting at the beginning,
> then uncheck the Global catalog on that DC and try again
>
> - check the DNS management console, that all entries from the machine are
> disappeared or delete them by hand if the machine is off the network for
> ever
>
> - also you have to start AD sites and services and delete the old
> servername under the site, this will not be done during demotion
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> I have a windows 2000 advance server sp4,
>> Because of hardware upgrade,I want to upgrade it window 2008 server.
>> This windows 2000 is only dc of a domain,
>> In order to migrate everything (e.g.
>> user account, policy, file share, security.....) of this server to new
>> machine,
>> does microsoft have any suggested procedure on this issue?
>> thank you
>> Roy

>
>



 
Reply With Quote
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      01-11-2010
Hello ronaldo,

Then you can follow the way described before.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> In the case is very simple one.
> In the windows 2000 AD, there are 1 and only 1 server.
> We have no exchange server in the AD.
> We use the 2000 server as file server.
> So, does it make the migration simpler?
> "Meinolf Weber [MVP-DS]" <meiweb@(nospam)gmx.de> wrote in message
> news:. com...
>
>> Hello ronaldo,
>>
>> There is no way to inplace upgrade a Windows server 200 to Windows
>> server 2008 directly. See here about a way to do it:
>>
>> !!!NEVER START BEFORE HAVING CREATED AND TESTED A BACKUP OF YOUR
>> DATA/MACHINE!!!
>>
>> - Do you use any kind of Exchange in the 2000 domain? If yes, which
>> one?
>>
>> - On the old server open DNS management console and check that you
>> are running Active directory integrated zone (easier for replication,
>> if you have more then one DNS server)
>>
>> - run replmon from the run line or repadmin /showreps(only if more
>> then one DC exist), dcdiag and netdiag from the command prompt on the
>> old machine to check for errors, if you have some post the complete
>> output from the command here or solve them first. For this tools you
>> have to install the support\tools\suptools.msi from the 2000
>> installation disk.
>>
>> - run adprep /forestprep and adprep /domainprep and adprep
>> /domainprep /gpprep and adprep /rodcprep from the 2008 installation
>> disk against the 2000 schema master(forestprep) / infrastructure
>> master(domainprep/rodcprep), with an account that is member of the
>> Schema/Enterprise/Domain admins, to upgrade the schema to the new
>> version (44) or 2008 R2 (47)
>>
>> - you can check the schema version with "schupgr" or "dsquery *
>> cn=schema,cn=configuration,dc=domainname,dc=local -scope base -attr
>> objectVersion" without the quotes in a command prompt
>> - Install the new machine as a member server in your existing domain
>> - configure a fixed ip and set the preferred DNS server to the old
>> DNS server only, think about disabling IPv6 if you are not using it,
>> some known problems exist with it. Follow
>> (http://blogs.dirteam.com/blogs/paulb...9/03/19/disabl
>> ing-ipv6-on-windows-2008.aspx) to disable it
>>
>> - run dcpromo and follow the wizard to add the 2008 server to an
>> existing domain, make it also Global catalog and DNS server.
>>
>> - for DNS give the server time for replication, at least 15 minutes.
>> Because you use Active directory integrated zones it will
>> automatically replicate the zones to the new server. Open DNS
>> management console to check that they appear
>>
>> - if the new machine is domain controller and DNS server run again
>> replmon, dcdiag on both domain controllers. For using netdiag.exe on
>> 2008, NOT 2008 R2, you have to download and install
>> (http://www.microsoft.com/downloads/d...id=96A35011-FD
>> 83-419D-939B-9A772EA2DF90&displaylang=en), ignore the compatibility
>> warning, or extract netdiag.exe only and copy it
>>
>> - Transfer, NOT seize the 5 FSMO roles to the new Domain controller
>> (http://support.microsoft.com/kb/324801 applies also for
>> 2008/2008R2), FSMO should always be on the newest OS DC
>>
>> - after transfer of the PDCEmulator role, configure the NEW
>> PDCEmulator to an external timesource and reconfigure the old
>> PDCEmulator to use the domainhierarchie now. Therefore run on the NEW
>> "w32tm /config /manualpeerlist:PEERS /syncfromflags:manual
>> /reliable:yes /update" where PEERS will be filled with the ip address
>> or server(time.windows.com) and on the OLD one run "w32tm /config
>> /syncfromflags:domhier /reliable:no /update" and stop/start the time
>> service on the old one. All commands run in an elevated command
>> prompt without the quotes.
>>
>> - you can see in the event viewer (Directory service) that the roles
>> are transferred, also give it some time
>>
>> - reconfigure the DNS configuration on your NIC of the 2008 server,
>> preferred DNS itself, secondary the old one
>>
>> - if you use DHCP do not forget to reconfigure the scope settings to
>> point to the new installed DNS server
>>
>> Demoting the old DC(if needed)
>>
>> - reconfigure your clients/servers that they not longer point to the
>> old DC/DNS server on the NIC
>>
>> - to be sure that everything runs fine, disconnect the old DC from
>> the network and check with clients and servers the connectivity,
>> logon and also with one client a restart to see that everything is ok
>>
>> - then run dcpromo to demote the old DC, if it works fine the machine
>> will move from the DC's OU to the computers container, where you can
>> delete it by hand. Can be that you got an error during demoting at
>> the beginning, then uncheck the Global catalog on that DC and try
>> again
>>
>> - check the DNS management console, that all entries from the machine
>> are disappeared or delete them by hand if the machine is off the
>> network for ever
>>
>> - also you have to start AD sites and services and delete the old
>> servername under the site, this will not be done during demotion
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> I have a windows 2000 advance server sp4,
>>> Because of hardware upgrade,I want to upgrade it window 2008 server.
>>> This windows 2000 is only dc of a domain,
>>> In order to migrate everything (e.g.
>>> user account, policy, file share, security.....) of this server to
>>> new
>>> machine,
>>> does microsoft have any suggested procedure on this issue?
>>> thank you
>>> Roy



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Unable to add computer to domain Nik Active Directory 5 12-18-2009 08:29 PM
SBS2003 R2 to SBS 2003 - to swing or not to swing.... Jim Windows Small Business Server 21 11-30-2009 05:10 PM
The local domain controller could not connect with - 2008 boe Active Directory 9 11-22-2009 01:05 AM
Slow Vista startup Jedi940 Windows Vista Performance 1 01-13-2008 08:50 PM
NVIDIA GeForece 6800 and Vista w2m Windows Vista Hardware 19 06-11-2007 11:34 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59