Make Second Domain Controller Primary

Sam Rao 1 Reputation point
2023-02-08T22:42:08.76+00:00

I have 2 domain controllers, Primary is Windows Server 2012 and the secondary Domain Controller is Windows Server 2022. Primary successfully replicates to Secondary without issues and visa versa if I make changes in Secondary. I want to decommission the Primary DC, I followed the steps to transfer all 5 FSMO roles to secondary and now secondary is supposed to be Primary.

All servers see the secondary DC and it is listed as a DNS in ipconfig/all. When I shutdown the old 2012 DC, I Could not access any of the servers with domain name only IP. I tried flushing DNS but that did not help. I turned old server back on and was able to access my servers again but some servers had issues with RDP but are okay now.

Did I miss a step to make the 2022 server a Primary DC so old one can be decommissioned? do I have to make any changes on DNS Management?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,082 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,820 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Amit Singh 4,846 Reputation points
    2023-02-09T08:43:52.03+00:00

    No need to remove the domain controller. You can freely transfer roles as needed at any time.

    Step-By-Step: Migrating Active Directory FSMO Roles From Windows Server 2012 R2 to 2016

    1 person found this answer helpful.
    0 comments No comments

  2. Dave Patrick 426K Reputation points MVP
    2023-02-08T23:46:22.58+00:00

    Make sure you updated DHCP server to hand out new address, also check that all statically assigned members have DNS on connection properties updated with correct addresses. Also check the event logs for clues.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  3. Adam J. Marshall 8,546 Reputation points MVP
    2023-02-09T01:01:03.5833333+00:00

    Technically there is no primary or secondary/backup domain controllers since windows server 2000. All domain controllers are equal.

    Ensure :

    BOTH are global catalog servers

    Ensure DNS is set up correctly for all client systems and other servers and devices. What is correctly? That ONLY the new DC is listed for DNS.

    Ensure DNS servers are set up correctly. What does correctly mean? https://www.ajtek.ca/guides/domain-controller-dns-in-an-active-directory-environment/

    Yes... You need to set this up even though you are getting rid of one. After it is gone, you can then adjust the DNS on the one left standing.

    If your old DC is providing DHCP services (likely), you will need to ensure that your new DC is setup to supply DHCP, is enabled, and authorized in the domain to give addresses to clients. Then unauthorize the old server and wait or force all clients to reregister their IPs.

    0 comments No comments

  4. Sam Rao 1 Reputation point
    2023-02-09T02:40:56.44+00:00

    DHCP is handled by our Meraki Security Appliance and I have set the DC IPs on the appliance.

    0 comments No comments

  5. rr-4098 1,111 Reputation points
    2023-02-11T18:00:05.3433333+00:00

    Can you post the results of dcdiag /v /e and repladmin /replsummary

    0 comments No comments