Checks to Add Win2019 DC with 2012

create share 646 Reputation points
2021-11-12T22:45:24.147+00:00

Hi,

We need to add a 2019 DC to our domain and then remove the 2012 DC. What checks should be performed before doing it? We have already migrated FRS to DFSR. 2012 DC is also a DHCP Server.

Thanks.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,990 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426.2K Reputation points MVP
    2021-11-13T00:07:59.753+00:00

    That's possible. You could follow-up with this one.
    https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041

    as far as adding the new domain controller I don't see this as an issue.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


8 additional answers

Sort by: Most helpful
  1. Dave Patrick 426.2K Reputation points MVP
    2021-11-12T23:16:49.317+00:00

    I'd check dcdiag reports no errors, and that replication is successful. This tool can be helpful
    https://www.microsoft.com/en-us/download/details.aspx?id=30005

    also check the event logs are clear of new errors since last boot.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  2. create share 646 Reputation points
    2021-11-12T23:30:36.203+00:00

    All tests passed with no errors except the below shown by dcdiag. I believe it is related to a security update?

            The Key Distribution Center (KDC) encountered a ticket that did not
    

    contain information about the account that requested the ticket while processing a request for another ticket. This prevented security checks from running and could open security vulnerabilities. See https://go.microsoft.com/fwlink/?linkid=
    2173051 to learn more.

    0 comments No comments

  3. Dave Patrick 426.2K Reputation points MVP
    2021-11-12T23:33:32.313+00:00

    The event log should provide more details about the issue. Also some info here.
    https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041

    as to adding the new DC if this is all there was it should be fine to proceed.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  4. create share 646 Reputation points
    2021-11-12T23:38:58.28+00:00

    This is shown for many domain users in DC event log.

    The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket. This prevented security checks from running and could open security vulnerabilities. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more.

    Ticket PAC constructed by: DC1
    Client: domain.com\domainuser
    Ticket for: krbtgt