I just got to this place and learning the infra as the last guy left with very very little documentation. The setup was this. 2 W2k12 Domain controllers that held all the FSMO roles between them, and were DNS servers. Then he had a W2k19 server on another subnet which for some reason was the only place that can make GPO changes. The DFSR SYSVOL was created on all of them. Through a dfsrmig /getmigrationstate, I saw all the DCs were migrated. I raised both domain and forest levels to 2012, and proceed to introduce 2 W2k22 servers which are now Domain controllers and DNS servers. My mindset and sorry I havent done a migration in a while, was to intro the new DCs,(done) configured DNS on the new servers to make them the primary and secondary(done), transfer the FMSO roles to the two new servers(done) and then slowly decom the old DC, raise the functionality to 2016 and business as usual. But during the standing up of the new DCs, which are already done, I find out there are two more DCs in the infra on hyper V, which according to the last guy, they can be decom.
Now, I would do this, but I have a gut feeling that things will break as they are running DNS also and are GCs. So lately I have been getting replication errors and DNS issues. I am getting some 5014 Error for DFSR and some 4013 Msft-Windows DNS errors in the event log. The new DCs, I run net share and the original SYSVOL is there, but the other DCs have SYSVOL_DFSR. I have a funny feeling its a DNS issues, but cannot put my finger on it. I configured the new DNS severs to use their IP as primary and one of the old DC DNS as the secondary.
Any suggestions. I already ran dcdiag on the new DCs and it passed everything except DFSREvent, KccEvent. The existing servers all passed with the exception of the DFSREvent, Which I am thinking of attributing to DNS, but cannot put my finger on it.
Thanks in advance