Home
%3CLINGO-SUB%20id%3D%22lingo-sub-1113853%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Server%202008%20End%20of%20Support%20-%20Active%20Directory%20and%20DNS%20Migration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1113853%22%20slang%3D%22en-US%22%3EThe%20hyperlink%20at%20the%20end%20of%20the%20article%20is%20bad%3B%20it's%20linking%20to%20just%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%3C%2FA%3E%20not%20the%20full%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fws2008ADMigration%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2Fws2008ADMigration%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1106757%22%20slang%3D%22en-US%22%3EWindows%20Server%202008%20End%20of%20Support%20-%20Active%20Directory%20and%20DNS%20Migration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1106757%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EJanuary%2014th%202020%20has%20come%20and%20gone%20which%20means%20unless%20you%20have%20either%20migrated%20your%202008%20servers%20and%20their%20workloads%20to%20Azure%20(to%20get%20free%20security%20updates)%20or%20you%20have%20purchased%20an%20extended%20support%20agreement%20-%20you%20now%20have%20the%20situation%20of%20having%20to%20keep%20unsupported%20servers%20running%20key%20workloads%20in%20your%20environment.%26nbsp%3B%20Even%20if%20you%20DID%20take%20advantage%20of%20one%20of%20these%20options%20-%20lets%20be%20honest%20and%20say%20it's%20not%20Optimal%20and%20is%20a%20temporary%20fix%20at%20best.%26nbsp%3B%20They%20were%20designed%20to%20give%20YOU%20MORE%20TIME%20to%20migrate%20existing%20workloads%20OFF%20the%20unsupported%20operating%20system%20%22as%20is%22%20OR%20to%20buy%20you%20more%20time%20to%20rearchitect%20the%20workload.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E...but%20what%20about%20workloads%20that%20can't%20be%20migrated%20or%20rearchitected%3F%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EYesterday%20we%20talked%20about%20a%20workhorse%20of%20a%20workload%20running%20on%20Windows%20Server%202008%20%2F%202008%20R2%20-%20The%20File%20Server...%20Todays%20post%20is%20about%20a%20workload%20that%20I%20personally%20find%20WAY%20more%20critical%20to%20the%20everyday%20operation%20of%20your%20environment.%20It's%20the%20workload%20that%20in%20my%20opinion%26nbsp%3Bis%20probably%20your%20MOST%20important%20workload%20because%20it%20is%20the%20single%20source%20for%20the%20security%20representing%20the%20digital%20personification%20of%20your%20ENTIRE%20user%20base%20right%20down%20to%20your%20CEO%3A%20Active%20Directory.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EI%20have%20been%20designing%20and%20updating%20Active%20Directory%20Designs%20since%20it%20came%20out%20-%20it%20was%20my%20specialty%20when%20I%20was%20in%20consulting.%26nbsp%3B%20But%20now%20that%20I%20work%20at%20Microsoft%20-%20why%20not%20go%20to%20the%20source%3F%20Who%20better%20to%20ask%20then%20Mr.%20%22AskDS%22%20himself%20-%20Ned%20Pyle%2C%20Principal%20Program%20Manager%20from%20the%20Windows%20Server%20Team%20to%20talk%20shop%20about%20the%20%232%20Workload%20for%20servers%3A%20%22Active%20Directory%20Domain%20Controllers%22.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3C%2FP%3E%3CDIV%20class%3D%22video-embed-center%20video-embed%22%3E%3CIFRAME%20class%3D%22embedly-embed%22%20src%3D%22https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Fsrc%3Dhttps%253A%252F%252Fwww.youtube.com%252Fembed%252F01zqmQ7sCbI%253Ffeature%253Doembed%26amp%3Burl%3Dhttps%253A%252F%252Fwww.youtube.com%252Fwatch%253Fv%253D01zqmQ7sCbI%26amp%3Bimage%3Dhttps%253A%252F%252Fi.ytimg.com%252Fvi%252F01zqmQ7sCbI%252Fhqdefault.jpg%26amp%3Bkey%3Db0d40caa4f094c68be7c29880b16f56e%26amp%3Btype%3Dtext%252Fhtml%26amp%3Bschema%3Dyoutube%22%20width%3D%22200%22%20height%3D%22112%22%20scrolling%3D%22no%22%20frameborder%3D%220%22%20allow%3D%22autoplay%3B%20fullscreen%22%20allowfullscreen%3D%22true%22%20title%3D%22Video%22%3E%3C%2FIFRAME%3E%3C%2FDIV%3E%3CP%3E%3C%2FP%3E%0A%3CP%3EThere%20are%20a%20lot%20of%20manual%20and%20time%20sensitive%20steps%20that%20Ned%20goes%20through%20in%20this%20demo%20-%20but%20trust%20me%2C%20it's%20not%20that%20bad%20when%20you%20actually%20get%20started.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAt%20a%20high%20level%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3E%3CSTRONG%3ELeave%3C%2FSTRONG%3E%20your%20existing%20Windows%20Server%20domain%20controller%20%3CSTRONG%3Eas%20is%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3ESetup%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20your%20new%20Windows%20Server%20domain%20controller%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3ESynchronize%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20the%20new%20Windows%20Server%20domain%20controller%20with%20the%20old%20one%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3EPromote%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20the%20new%20domain%20controller%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3ETransfer%3C%2FSTRONG%3E%20%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3EFSMO%3C%2FSTRONG%3E%20%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3Eroles%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20and%20Leverage%20new%20capabilities%20(RODC%2C%20RecycleBin%20and%20more)%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3EDemote%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20the%20old%20domain%20controller%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3ERepeat%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20this%20at%20each%20site%20where%20DCs%20exist%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3ERaise%20%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3Efunctional%20levels%20of%20AD%20and%20leverage%20new%20tech%20like%20AD%20Recycle%20bin%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3EThe%20main%20thing%20to%20remember%20is%20replication%20between%20sites%20and%20allowing%20your%20changes%20to%20replicate%20(or%20forcing%20it%20to%20speed%20up).%20The%20best%20part%20about%20this%20approach%20with%20integrating%20another%20DC%20into%20existing%20sites%20is%20that%20you%20will%20be%20introducing%20very%20little%20disruption%20to%20your%20end%20users%20in%20these%20sites%20-%20due%20to%20the%20multi-master%20architecture%20in%20use%20for%20Active%20Directory.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAll%20the%20detailed%20information%20including%20a%20variety%20of%20caveats%20that%20could%20come%20up%20are%20documented%20over%20on%20Docs%20which%20can%20be%20reached%20at%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fws2008ADMigration%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2Fws2008ADMigration%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20hope%20you%20have%20enjoyed%20these%20Windows%20Server%202008%20%2F%202008%20R2%20migration%20series%20episodes%20so%20far.%20Did%20we%20miss%20anything%20yet%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1106757%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EJanuary%2014th%202020%20has%20come%20and%20gone%20which%20means%20unless%20you%20have%20either%20migrated%20your%202008%20servers%20and%20their%20workloads%20to%20Azure%20(to%20get%20free%20security%20updates)%20or%20you%20have%20purchased%20an%20extended%20support%20agreement%20-%20you%20now%20have%20the%20situation%20of%20having%20to%20keep%20unsupported%20servers%20running%20key%20workloads%20in%20your%20environment.%20This%20post%20tackles%20one%20of%20THE%20MOST%20important%20workloads%20to%20update%3A%20Active%20Directory.%20I%20tracked%20down%20Mr.%20AskDS%20himself%20-%20Ned%20Pyle%2C%20Principal%20Program%20Manager%20from%20the%20Windows%20Server%20Team%20to%20talk%20shop%20about%20the%20%232%20Workload%20for%20servers%3A%20%22Active%20Directory%20Domain%20Controllers%22.%3CBR%20%2F%3E%26nbsp%3B%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F165424i9CB4503F02E477C7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Windows_Server_2008_End_of_Support_Ned_Pyle_Active_Directory_AD_DNS.png%22%20title%3D%22Windows_Server_2008_End_of_Support_Ned_Pyle_Active_Directory_AD_DNS.png%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EWindows_Server_2008_End_of_Support_Ned_Pyle_Active_Directory_AD_DNS%3C%2FSPAN%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1106757%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ened%20pyle%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ERick%20Claus%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1113858%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Server%202008%20End%20of%20Support%20-%20Active%20Directory%20and%20DNS%20Migration%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1113858%22%20slang%3D%22en-US%22%3E%3CP%3EDOH!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F521813%22%20target%3D%22_blank%22%3E%40oohgodyeah%3C%2FA%3E%26nbsp%3Bfor%20that%20catch.%20fixed.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

January 14th 2020 has come and gone which means unless you have either migrated your 2008 servers and their workloads to Azure (to get free security updates) or you have purchased an extended support agreement - you now have the situation of having to keep unsupported servers running key workloads in your environment.  Even if you DID take advantage of one of these options - lets be honest and say it's not Optimal and is a temporary fix at best.  They were designed to give YOU MORE TIME to migrate existing workloads OFF the unsupported operating system "as is" OR to buy you more time to rearchitect the workload.

 

...but what about workloads that can't be migrated or rearchitected? 

 

Yesterday we talked about a workhorse of a workload running on Windows Server 2008 / 2008 R2 - The File Server... Todays post is about a workload that I personally find WAY more critical to the everyday operation of your environment. It's the workload that in my opinion is probably your MOST important workload because it is the single source for the security representing the digital personification of your ENTIRE user base right down to your CEO: Active Directory. 

 

I have been designing and updating Active Directory Designs since it came out - it was my specialty when I was in consulting.  But now that I work at Microsoft - why not go to the source? Who better to ask then Mr. "AskDS" himself - Ned Pyle, Principal Program Manager from the Windows Server Team to talk shop about the #2 Workload for servers: "Active Directory Domain Controllers".

There are a lot of manual and time sensitive steps that Ned goes through in this demo - but trust me, it's not that bad when you actually get started.

 

At a high level:

  1. Leave your existing Windows Server domain controller as is
  2. Setup your new Windows Server domain controller
  3. Synchronize the new Windows Server domain controller with the old one
  4. Promote the new domain controller
  5. Transfer FSMO roles and Leverage new capabilities (RODC, RecycleBin and more)
  6. Demote the old domain controller
  7. Repeat this at each site where DCs exist
  8. Raise functional levels of AD and leverage new tech like AD Recycle bin

The main thing to remember is replication between sites and allowing your changes to replicate (or forcing it to speed up). The best part about this approach with integrating another DC into existing sites is that you will be introducing very little disruption to your end users in these sites - due to the multi-master architecture in use for Active Directory. 

 

All the detailed information including a variety of caveats that could come up are documented over on Docs which can be reached at https://aka.ms/ws2008ADMigration

 

I hope you have enjoyed these Windows Server 2008 / 2008 R2 migration series episodes so far. Did we miss anything yet?

 

2 Comments
Occasional Visitor
The hyperlink at the end of the article is bad; it's linking to just https://aka.ms not the full https://aka.ms/ws2008ADMigration
Microsoft

DOH!

 

Thanks @oohgodyeah for that catch. fixed.