Answered by:
Migrarte DC WK 2008 R2 to WK 2019 question / Issue

Question
-
Hi,
I want to migrate my DC WK 2008 R2 which holding at the time all FSMOs roles to WK 2019 Server. Here are my Questions:
1) Can I transfers my FSMOs roles to WK 2019 during all Emplooyes are working in the Company?
2) If I try to run "dcpromo" on DC with WK 2008 R2, I get the messge that the certificate authority is runnig, I have to uninstall it. Can I bbackup my certificate authority and restore it to the other DC at the same time? I mean, Can I restore my certificate authority first on the other DC and then uninstall it on the DC with WK 2008 R2?
3) How can I be sure the new restored on the DC with WK 2019 Server certificate authority does works fine?
Regards
Nick
Sunday, July 19, 2020 4:38 PM
Answers
-
Again, you are the one that asked about it.
(please don't forget to mark helpful replies as answer)
Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows Server] Datacenter Management
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.- Marked as answer by mpng2008 Monday, July 20, 2020 2:25 PM
Monday, July 20, 2020 1:55 PM
All replies
-
You can follow along here to migrate the cert authority.
and ask follow-up question from subject matter experts in dedicated forum over here.
The two prerequisites to introducing the first 2019 domain controller are that domain functional level needs to be 2008 or higher and older sysvol FRS replication needs to have been migrated to DFSR
https://techcommunity.microsoft.com/t5/Storage-at-Microsoft/Streamlined-Migration-of-FRS-to-DFSR-SYSVOL/ba-p/425405I'd use dcdiag / repadmin tools to verify health correcting all errors found before starting. Then stand up the new 2019, patch it fully, license it, join existing domain, add active directory domain services, promote it also making it a GC (recommended), transfer FSMO roles over (optional), transfer pdc emulator role (optional), use dcdiag / repadmin tools to again verify health, when all is good you can decommission / demote old one.
Doing this during work hours is not a problem.
(please don't forget to mark helpful replies as answer)
Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows Server] Datacenter Management
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.- Proposed as answer by Hannah XiongMicrosoft contingent staff Monday, July 20, 2020 1:40 AM
Sunday, July 19, 2020 6:15 PM -
Hi,
Thanks for your replay. I dont understand your link you provide me. Why should I migrate sysvol FRS to DFSR?
I have 3 DCs with Windows 2019 Server at the time. On the FSMOs running at the time on Windows 2008 R2.
I think the WK 2019 Server has already DFSR. Or am I wrong?
Regards
Nick
Monday, July 20, 2020 6:28 AM -
Hello Nick,
Thank you for posting in our TechNet forum.
As Dave mentioned, the minimum requirement to add a Windows Server 2019 Domain Controller is a Windows Server 2008 functional level. The domain also has to use DFS-R as the engine to replicate SYSVOL.
For more information, we could refer to: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-functional-levels
We can check if the SYSVOL folder replication type is DFSR by viewing the following registry on the existing DC.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DFSR\Parameters\SysVols\Migrating Sysvols\LocalState registry subkey.
If this registry subkey exists and its value is set to 3 (ELIMINATED), DFSR is being used.
If the subkey does not exist, or if it has a different value, FRS is being used.
For any question, please feel free to contact us.
Best regards,
Hannah XiongPlease remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.Monday, July 20, 2020 7:53 AM -
Hi Hannah,
Thanks for your replay. As I mention my DC with WK which holding all FSMOs roles has domain function level WK 2008 R2
and Registry does show me
Therefore I am sure that what dave says, is not correct, because If I say that I have two DCs with WK 2019 , it means the Sysvoll is DFSR.
Again my question here:
1) can I transfer my FSMOs roles during the work to the WK 2019 DC? and demote the WK 2008 R2?
2) As I mention, I have my certificate authority at the time on the DC with WK 2008 R2, If I want to demote that DC, I have first uninstall certificate authority role.
Can I have at the same time two certificate authority on the two DCs?
3) What happens if I uninstall the certificate authority role first and install it on Dc with DC 2019 during that time with all certificates what I have for our Company?
Regards
Monday, July 20, 2020 10:21 AM -
If you find 48 then using DFSR, if null or 0, 16, 32 then FRS or some state of migration from FRS
I included the step because you did not mention this in your original post. Obviously if it has been done you can skip it and then assuming health is 100% proceed.
I'd use dcdiag / repadmin tools to verify health correcting all errors found before starting. Then stand up the new 2019, patch it fully, license it, join existing domain, add active directory domain services, promote it also making it a GC (recommended), transfer FSMO roles over (optional), transfer pdc emulator role (optional), use dcdiag / repadmin tools to again verify health, when all is good you can decommission / demote old one.
(please don't forget to mark helpful replies as answer)
Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows Server] Datacenter Management
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.Monday, July 20, 2020 12:33 PM -
Hi Dave,
Thanks again for your help. Yes the DFSR Flag is 48 on the both DCs WK 2008 R2 and WK 2019
Again my Windows 2019 Server is already a DC and I have only to transfer the FSMOs roles from WK 2008 R2 to the WK 2019 server.
What I would like to ask you is the schema master role. As I mention the schema master role is running on the Dc with WK 2008 R2 and has the Version 47 which is correct so. On the DC with WK 2019 is the schema master Version 88, that is correct so too.
If I transfer the schema master from WK 2008 R2 to the WK 2019 server, do I need to run the following command line before I transfer?
Regsvr32.exe C: \ windows \ system32 \ schmmgmt.dll
I dont think so because both version are correct. Am I right?
Thank you
Monday, July 20, 2020 12:54 PM -
There's no harm in doing it again. It just registers Schema Admin snap-in. By default this snap in is there on your drive but not registered.
- Open a new MMC Console (Start\Run\mmc)
- In the MMC Console, go to File\Add Remove Snap-in
- Add the Active Directory Schema snap-in
(please don't forget to mark helpful replies as answer)
Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows Server] Datacenter Management
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.Monday, July 20, 2020 1:43 PM -
also no need to do thatMonday, July 20, 2020 1:52 PM
-
Again, you are the one that asked about it.
(please don't forget to mark helpful replies as answer)
Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows Server] Datacenter Management
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.- Marked as answer by mpng2008 Monday, July 20, 2020 2:25 PM
Monday, July 20, 2020 1:55 PM