What is the best practice to maintain Certificate Authority Roles on Active Directory or Member Servers?

Sathishkumar Singh 486 Reputation points
2023-06-19T16:16:55.41+00:00

Screenshot 2023-06-19 214803

**

**
Now Primary Domain Controller **(Win2012)**TLS.LOCAL
Running with CA Roles, Print Server. is it good practice to running? CA and Print Servers in Primary domain Controllers?

What is recommended? Can i use member server for CA Roles and Print server to keep away from my primary domain controllers.

i am able to migrate OS from 2012 R2 To 2022 R2. But i would like to know the best practices to move CA Roles to new Server and Print Server.
Can you please send me the link with steps?****

Windows for business | Windows Server | User experience | Other
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 44,776 Reputation points
    2023-06-20T16:54:53.81+00:00

    Hello Sathishkumar,

    Thank you for your question and for reaching out with your question today.

    It is generally recommended to separate critical server roles like CA and Print Server from domain controllers, especially the primary domain controller, to enhance security, stability, and performance. By moving these roles to dedicated member servers, you can isolate potential issues and reduce the impact on domain controller functionality.

    To move the CA roles to a new server, you can follow the steps outlined in Microsoft's documentation for migrating a CA:

    For Windows Server 2012: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-certification-authority

    For Windows Server 2012 R2: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/upgrade-certification-authority

    For migrating the Print Server role, you can use the Print Management console to export and import the printer configuration to the new server. Microsoft provides documentation on migrating print servers:

    For Windows Server 2012: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj134150(v=ws.11)

    For Windows Server 2012 R2:

    https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj134150(v=ws.11)

    Please note that the links provided are based on the information available up until my knowledge cutoff in September 2021. It's always a good practice to refer to the official Microsoft documentation for the most up-to-date instructions.

    Before making any changes, ensure you have a backup of your CA and printer configurations, and thoroughly test the migration process in a non-production environment to mitigate any potential risks.

    I used AI provided by ChatGPT to formulate part of this response. I have verified that the information is accurate before sharing it with you.

    If the reply was helpful, please don’t forget to upvote or accept as answer.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.