What is the impact to AD CS when upgrading AD from 2012 to 2022?

Hii Sing Chung 21 Reputation points
2024-10-05T09:25:57.1066667+00:00

Currently I have 2 domain controllers on Windows 2012, there is one CA server also on Windows 2012. I am planning to upgrade the OS of domain controllers to Windows 2022. I have doubt on the AD CS, and I can't find any information on the Internet regarding impact on AD CS if Domain Controllers are upgraded to Windows 2022 but the CA is still on Windows 2012.

Can anyone provide some insights on this scenario?

Do I have to upgrade the CA OS also to 2022? What happen if I don't upgrade the CA's OS, for whatever reason?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,939 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marcin Policht 44,360 Reputation points MVP
    2024-10-05T11:05:11.27+00:00

    In short, you don't have to upgrade your Certificate Authority (CA) server to Windows Server 2022 if you're upgrading your domain controllers to Windows Server 2022. Active Directory Certificate Services (AD CS) on a Windows Server 2012 machine will still work and interact with domain controllers running Windows Server 2022.

    However, it is recommended to eventually upgrade the CA to ensure long-term support and security updates, as well as compatibility with newer features that may be introduced in Windows Server 2022, especially considering that Windows Server 2012 is no longer supported by Microsoft. Keeping the CA on an older, unsupported version might expose you to security risks and compatibility issues down the line, though there shouldn't be an immediate functional impact just from upgrading the domain controllers.

    In any case, you should consider testing the CA functionality in a non-production environment to ensure that the certificate issuance and revocation processes still work as expected after upgrading the domain controllers.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.