Domain Controller Cross Forest migration Part 2
Mohammed Hamada 4:35 AM Active Directory , Windows Migration , Windows Server
Current environment on the LAB.com DC
- Additional DC2
- SCVMM SQL
- SCMM SQL
AD 2012 R2 (LAB.com) to (Contoso.com) 2012 R2.
In the second part of this series (DC cross forest migration) I will demonstrate some major required steps for the migration from the old DC (lab.com) to the new DC (Contoso.com)
SQL Servers and their applications can’t be migrated due to SQL permissions and Schema mismatch.
Requirements are :
Destination DC Forest Function and domain function level must be set to at least 2008 R2 for ADMT3.2 to work
And a health check must be performed on the FSMO roles to make sure everything is functioning properly on the Source DC.. PDC, SchemaMaster..etc
The checks I will perform are
- Check replication (In case there’s more than one DC In the source forest).
- DC health (DCDiag tool)
- Check the reachability of the PDC.
Netdom query FSMO ( this command will show you which DC in the source forest holds the roles exactly)
1- For Checking replication you can use the repadmin command line which checks replication between sites, DCS and reports any errors in between. in case you have one server in pace the following outcome should be printed for you.
Repadmin.exe helps administrators diagnose Active Directory replication problems between domain controllers running Microsoft Windows operating systems.
2- Check DC health using DCDIAG tool
Analyzes the state of domain controllers in a forest or enterprise and reports any problems to help in troubleshooting
as they are multiple types of tests that can be applied with dcdiag depending on the parameter used. I will start with the DNS.
If the DNS is healthy then it should show as following. and we can continue to the next test.
For an extensive test, you can use the parameter /v along with this sign >c:\dcdiag.txt to export the test to a file and look at it line by line.
If everything sounds good and healthy we shall move on to the next step which is DNS configuration
- DNS replication between both domains
- Installing Windows 2008 R2 for ADMT 3.2
- Setting up domain trust between forests.
- DNS replication between the source and target domain
In order for the trust to be created between both forests, you either have to create a conditional forwarders that will copy the source zones to the destination DNS server and vice versa or you can create a secondary forwarder zone in destination DC for the source DC and vice versa.
In my case I will go for creating a secondary zone and to do this I will go to each DNS server and allow Zone to be transferred.
You can include only the IPs of the Source and Destination servers in the zone transfer and any additional DNS servers.
Now I a have created a secondary zone DNS and trying to resolve FQDNs from the source server as in the below snapshot.
Same will be done on the destination server.
Checking Name Resolution for both domains:
Once the nslookup works as expected from both servers then we’ll ahead with creating forest trust between both DCs.
Creating Forest trust between Source and Destination Domain.
In order for the trust to be created between both source and destination domains the PDC on the Destination Domain must be available.
1. Open the Active Directory Domains and Trusts, right click on the domain and click properties.
We will have to validate trust after creating it to make sure that trust in both ways are validated.
Now since trust is created and already validated both ways, we’ll have to add a GPO policy to update all clients with the new Domain name in the DNS suffix search list to resolve netbios names.
Updating DNS Suffix Search list:
DNS suffix search list:
In order to add the source and destination domains suffix to the dns suffix search list we will have to open GPO on the destination Domain (Contoso.com)
On the target domain (contoso.com) we’ll have to open GPO .
Right Click on default domain policy / Edit
Go to (Computer Configuration \ Policies \ Administrative Templates \ Network \ DNS client
Double click on the DNS Suffix Search list to open it and enable it.
Click ok and apply the police and see how it should show in the report.
Once this is done and policy is applied among all clients you should have no problem and it should show first on the DC where you applied the policy.