{"id":9057,"date":"2008-05-29T16:23:00","date_gmt":"1999-11-29T20:00:00","guid":{"rendered":"https:\/\/aidanfinn.com\/?p=9057"},"modified":"2008-05-29T16:23:00","modified_gmt":"1999-11-29T20:00:00","slug":"introducing-a-windows-2008-domain-controller","status":"publish","type":"post","link":"https:\/\/aidanfinn.com\/?p=9057","title":{"rendered":"Introducing a Windows 2008 Domain Controller"},"content":{"rendered":"<p>I installed a new W2008 x64 DC at work in our W2003 native (single domain) forest.\u00a0 I&#8217;m happy to report that:<\/p>\n<ol>\n<li>It was <em>easy.<\/em>\n<\/li>\n<li>It went flawlessly.<\/li>\n<\/ol>\n<p>I&#8217;m planning on wiping out the W2003 presence on our DC&#8217;s to have a native W2008 domain.\u00a0 Right now, there&#8217;s <a href=\"http:\/\/blogs.technet.com\/momteam\/archive\/2008\/01\/09\/support-plans-for-opsmgr-2007-sce-and-mom-2005-running-on-windows-server-2008.aspx\" target=\"_blank\">no support<\/a> for monitoring it using SCOM 2007 so I&#8217;ll have to wait for a wee while for the management pack and agent support.\u00a0 I want to be able to monitor our AD so I&#8217;ll wait before completing this project.\n<\/p>\n<p>Here&#8217;s one way to introduce a W2008 DC to your existing W2003 AD.\n<\/p>\n<p>The first question is: to upgrade or do a lean install?\u00a0 MS are strongly recommending clean installs.\u00a0 In fact, they almost go as far as saying don&#8217;t upgrade.\u00a0 They do clearly say that a machine with only W2003 components can be upgraded fairly dependably but you&#8217;ll want to verify that the machine spec and configuration are good.\u00a0 Watch out for the desired 40GB C drive &#8211; you&#8217;ll need to buy 72GB drives if using HP like me.\u00a0 Things like dodgy AV (I mean you Muckafee and Sinmantec), well &#8230;. you&#8217;ll want to do a clean install there because, in my opinion, Sinmantec trash the TCP stack when they get their hands on it and the W2008 stack is a complete re-write.\n<\/p>\n<p>Next question: do you need a rollback plan for the required schema updates?\u00a0 Best practice is &quot;yes&quot;.\u00a0 The best plan here is to power down selected DC&#8217;s before the upgrade and leave them off until you&#8217;re sure everything is OK.\u00a0 Keep the holder of the Schema Master FSMO role turned on &#8211; we need it.\u00a0 If so, then just power on those DC&#8217;s and continue as normal.\n<\/p>\n<p>If something does go wrong with the schema updates then you power off the powered on DC&#8217;s and only then would you power on the standby DC&#8217;s.\u00a0 Seize the FSMO roles to one of the now powered on standby DC&#8217;s.\u00a0 Do a <a href=\"http:\/\/support.microsoft.com\/kb\/216498\" target=\"_blank\">metadata cleanup<\/a> to wipe away all traces of the powered off DC&#8217;s.\u00a0 The powered off DC&#8217;s would be disconnected from the network (to prevent AD replication), rebuilt, reattached to the network and DCPROMO&#8217;ed.\n<\/p>\n<p>We&#8217;re assuming everything is good.\u00a0 I&#8217;ve not heard of anyone having a schema corruption via a MS update but I&#8217;d always recommend being safe.\n<\/p>\n<p>Now you can follow the process that MS <a href=\"http:\/\/technet2.microsoft.com\/windowsserver2008\/en\/library\/dc4dfacc-7771-4a31-8113-6e57c090987b1033.mspx?mfr=true\" target=\"_blank\">describes<\/a>.\u00a0 It&#8217;s pretty simple:<\/p>\n<ul>\n<li>Copy the &quot;sourcesadprep&quot; folder from the W2008 media to a W2003 DC where you will run the schema updates.\u00a0 The best DC for this is the holder of the Schema Master FSMO role.\u00a0 The tools you&#8217;ll use are in this folder.\n<\/li>\n<li>Run <em>adprep \/forestprep<\/em> to prepare the forest..\n<\/li>\n<li>Run <em>adprep \/domainprep \/gpprep<\/em> to prepare the domain.\n<\/li>\n<li>MS says to only run <em>adprep \/rodcprep<\/em> if you want to run Read-Only DC&#8217;s.\u00a0 As <a href=\"http:\/\/web2.minasi.com\/forum\/topic.asp?TOPIC_ID=25724\" target=\"_blank\">discussed<\/a> on the Minasi forum, the W2008 version of Dcdiag.exe returns an error when it runs the NCSecDesc test if you don&#8217;t do this step.\u00a0 I did it anyway just to get clean results from DCDIAG.\n<\/li>\n<li>Now you should build your W2008 DC&#8217;s operating system and configure it as required.\u00a0 Install the AD services role.\u00a0 This will probably install DNS as well.\n<\/li>\n<li>You&#8217;re all ready to do your DCPROMO.\u00a0 It&#8217;s pretty much the same as before apart from an annoying DNS warning.\u00a0 At the end, I&#8217;d recommend saving the unattended answer file settings.\u00a0 You can use this when you plan to DCPROMO your next W2008 DC.<\/li>\n<\/ul>\n<p>Now, keep an eye on your network, e.g. DFS, FRS, Directory Services, System and Application logs.\u00a0 I finished off by moving the FSMO roles to my new W2008 DC.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I installed a new W2008 x64 DC at work in our W2003 native (single domain) forest.\u00a0 I&#8217;m happy to report that: It was easy. It went flawlessly. I&#8217;m planning on wiping out the W2003 presence on our DC&#8217;s to have a native W2008 domain.\u00a0 Right now, there&#8217;s no support for monitoring it using SCOM 2007 &hellip; <a href=\"https:\/\/aidanfinn.com\/?p=9057\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Introducing a Windows 2008 Domain Controller&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-9057","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"jetpack_featured_media_url":"","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/9057","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9057"}],"version-history":[{"count":0,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/9057\/revisions"}],"wp:attachment":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9057"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9057"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9057"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}