Re: Making another DC the Primary



"Mark" <mark@xxxxxxxxxxxxx> wrote in message
news:u4lLGOFRFHA.2744@xxxxxxxxxxxxxxxxxxxxxxx
> > Mind you, I'm concerned about what this mean:
> >
> >> has two DCs. Actually, it now has three because I intend to demote the
> >> one.
> >
> >
> > Can you clarify??
>
>
> Hi Paul,
>
> Sorry for the confusion - my child domain had the original domain
controller
> (that's Primary) and a backup domain controller - that was my original
> configuration.

First of all they are both "just DCs".

The first one will (be default) hold the specical roles,
including the PDC Emulator but it isn't primary and there
are no Win2000+ Backup DCs.

> But I've been getting some bad vibes from the Primary and
> got nervous,

What sort of bad vibes? If you have a DNS or other replication
problem you will likely just move that problem around.

> ...so I promoted another server in my child domain.

That is a good idea -- especially if you are concerned about
hard drives, motherboards, power supplies, and other failures.

You should (practically) always have TWO DCs (or more)
PER DOMAIN if this is at all possible.

> Now I'd like to demote the original,

Why? You believed you needed an "extra" so what is better
about the new one over the old one?

What will you do with this server if your retire it as a DC?

Why can't it continue being another DC?

> but I didn't know what would happen to its role as
> Primary.

The (5 or 3) ROLES are SUPPOSED to transfer if you DCPromo
correctly -- I don't like to trust it and prefer to transfer them myself
using NTDSUtil (see below***).

> All three have global catalogs (needed at least one in the child
> domain for my Exchange server). I'm going to remove the GC from that
> Primary first.

Not necessary. A GC "leaving" is no big deal IF you
have another.

In general, single domains, and small forests with multiple
domains should have ever DC as a GC.

If you don't do that, the GC and infrastructure master should
not be on the same DC.

> When I was testing AD, prior to my migration from NT4, I had gone through
> the FSMO roles situation, but seemed to remember that a proper demotion
> using dcpromo moved those elsewhere? I guess my memory is failing me.
:-)

It is supposed to do that -- and it will IF the DNS and other
connectivity are CORRECT.

Most AD problems are really DNS problems though, so if
you DC is shaky, or untrustworthy, I wouldn't trust it to do that
either.

***NTDS roles

Search Google for:

[ NTDSutil "transfer roles" ]

Do NOT use "seize" unless the other DC is gone PERMANENTLY.

No need to add either site:microsoft.com OR microsoft:
since the NTDS and other terms make it Microsoft specific
by itself.

Key points to NOTE when working with NTDSUtil:

You CONNECT to a WORKING DC.

'Connect' (and 'Select') are technical terms in this context.


.



Relevant Pages

  • Re: FQDN - DNS resolution
    ... > that look like in the DNS console. ... > If you have multiple DCs in a single site this will be load-balanced, ... > the first is passed, then the second, etc. (from the server -the client ... when you ping the domain name you get a DC returned. ...
    (microsoft.public.win2000.active_directory)
  • Re: Group Policy Not Applied
    ... You may just have DNS data issues. ... Netdiag would give you better clue on that. ... make sure the DCs are pointing at correct ... Microsoft MVP (Windows Server System: ...
    (microsoft.public.windows.group_policy)
  • Re: Troubleshoot or reinstall Server 2000?
    ... functionality to the newer 2003 DC including FSMO roles, ... shouldn't have the IM on GC, unless all DCs on your site are also GCs. ... Are both DCs DNS server? ...
    (microsoft.public.win2000.active_directory)
  • Re: No client login when DC not available
    ... Ie. the client's logon server is not DC1, ... This implies the OTHER DCs are not properly registered in DNS ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Controller Stops Processing All Login Requests Randomly
    ... Randomly the server will stop responding to workstation ... They use split-brain DNS ... As long as NO client (including DCs) ... the clients have all four DNS entries listed in their NIC ...
    (microsoft.public.windows.server.dns)