Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Replace Domain Controller 1

Status
Not open for further replies.

MarkDym

Technical User
Apr 23, 2004
101
GB
Hello folks

I have done a fair amount of research on how to add/replace a 2003 Active Directory Domain Controller. I intend to add a second domain controller (DC2), then after I am sure it is working as it should, I will demote the original DC (DC1), and remove it from the network. However, there are a couple of areas which I do not quite understand and would be grateful for some comments.

My first query regards Group Policy. Will replication automatically deal with group policy or will I need to backup the original from DC1, then restore to DC2 to make sure that GP will run as expected?

Also, with regards to the Operations Masters Roles, will transferring all of them to DC2 be sufficient? What I mean is, are there any other steps I should take to ensure that DC2 holds and runs these roles?

My plan of attack is as follows:

Install and configure 2003 standard edition
Join to domain
Run DCPROMO and create an additional Domain Controller
Create new Global Catalog Server
Create secondary DNS Server
Create 100/100 DHCP failover Server
Transfer all 5 FSMO's
Either rely on replication or backup/restore GPO

My main worry is regarding the transfer of the FSMO's - essentially, I want the original DC to be 100% redundant and the replacement DC to be 100% authoritative should the original fail/when the original is removed.

Many thanks in advance for any help with this.
 
you have the correct plan of attack. your GPO's will copy over with dcpromo so dont worry about that. Follow your plan, then shut down the 1st/old DC and see if all works as expected, if it dont bring the 1st/old DC backup and figure out what went wrong. if you are happy with the results then bring the old dc up and dcpromo it out of the domain.

RoadKi11
 
Many thanks for the positive feedback, Roadki11. The new server is in our office, I'm just waiting for the OS to arrive and then I will get cracking.

Cheers!
 
Having a second DC that replicates is a very good thing sometimes...

If the server you build crashes because of a raid controller or something, then your backups dont restore as easy as you thought, having that second server chugging away is well worth it.

Do you need the server for some other reason, or are you just getting rid of it for the sake of getting rid of it?
 
Captaincrunch00:
Our present Domain Controller is 6 years old and is beginning to develop hardware faults. Also, the system partition is a meagre 8GB - which is not a lot when 2003 server is installed. While generally reliable, it is causing problems for our Active Directory installation and I think it best to install a second DC which will replace it. The second DC has a system partition of 140GB, runs RAID 1, and is rack mountable - much better than the noisy tower we have at present.

We will repair the old server once the new one is installed, but would ideally prefer to have two new DC's anyway :)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top