I've just installed a second DC(w2k3)in my w2k domain, I wish for this new DC to be the primary server authenticating logons etc. If I were to do a DR with the system state of this new DC would it be successful even though none of the fsmo roles are on it. I know how to transfer roles, i'm just not sure if I need do it. Also is there a remote utility that allows you to see which DC users are authenticating against? thanks for your help