{"id":65,"date":"2011-03-31T18:57:00","date_gmt":"2011-03-31T18:57:00","guid":{"rendered":"http:\/\/web03.partners.extranet.chrisse.com\/wordpress\/?p=65"},"modified":"2011-03-31T18:57:00","modified_gmt":"2011-03-31T18:57:00","slug":"upgrade-active-directory-from-ws03-to-ws08-r2","status":"publish","type":"post","link":"https:\/\/blog.chrisse.se\/?p=65","title":{"rendered":"Upgrade Active Directory from WS03 to WS08 R2"},"content":{"rendered":"<p>First of all thanks to everyone that attended my session &#8221; Upgrade Active Directory from WS03 to WS08 R2&#8243; at Microsoft Tech Days 2011 in Sweden. For those of you that couldn&#8217;t attend on site I did a session on upgrading a Windows Server 2003 Active Directory environment to Window Server 2008 R2 with a focus on automated processes. The scripts used in this session (also available for download at this blog) were developed by the Enfo Zipper \u2013 Directory Services Team and used in a real world scenario to upgrade an enterprise customer&#8217;s forest.<\/p>\n<p>FYI: The session will be available online later during the spring.<\/p>\n<p>&nbsp;<\/p>\n<p>Note: The steps below including the sample scripts is provided &#8220;AS-IS&#8221; with no warranties. Some of the sample scripts have a dependence that the Windows Support Tools for Windows Server 2003 \u2013 Service Pack 2 are installed on all Domain Controllers.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"margin-left: 48pt;\"><span style=\"font-family: Franklin Gothic Demi; font-size: 10pt;\">Table\u00a01.1\u00a0Upgrade Active Directory from WS03 to WS08 R2 Sample Scripts <\/span><\/p>\n<p>&nbsp;<\/p>\n<div style=\"margin-left: 52pt;\">\n<table style=\"border-collapse: collapse;\" border=\"0\">\n<colgroup>\n<col style=\"width: 308px;\" \/><\/colgroup>\n<colgroup>\n<col style=\"width: 308px;\" \/><\/colgroup>\n<tbody valign=\"top\">\n<tr style=\"background: #d9d9d9;\">\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: gray 1.5pt solid; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Demi Cond; font-size: 9pt;\">Name<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: gray 1.5pt solid; border-right: gray 1.5pt solid;\">\n<p style=\"text-align: center;\"><span style=\"font-family: Franklin Gothic Demi Cond; font-size: 9pt;\">Description<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">CopyLogs.VBS<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will backup all event logs and store them in C:migdata.<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">GetDHCPConfig.BAT<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will backup the DHCP database and the DHCP Server configuration and store them in C:migdata<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">GetDNSConfig.BAT<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will backup none-Active Directory primary zones and store them in C:migdata<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">GetIASConfig.VBS<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script has a prerequisite that the iasmigreader.exe has been run (You can find this tool at your Windows Server 2008 R2 DVD at the following location: &#8220;sourcesdlmanifestsmicrosoft-windows-iasserver-migplugin&#8221; the script will move the config to C:migdata.<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">GetIPConfig.BAT<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will save the current IP-config and save it in a text file stored in C:migdata<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">GetPrefBH.VBS<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script can be used to locate preferred bridgehead servers that can use replication issues during domain controller replacement.<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">GetTombstone.VBS<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script can be used to determine the current tombstone life time, if less than 180 days, we recommend to set it to 180 days.<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">RetireDC.cmd<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will change the name of a demoted Windows Server 2003 domain controller to its current name __RET (retired) and configure it to acquire an IP address from DHCP. <\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">RunDcPromo.VBS<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script is a wrapper around DCPROMO to demote a Windows Server 2003 DC, It has a feature to work around the &#8220;NETLOGN timeout bug&#8221; <\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">SetDHCPConfig.BAT<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will read and restore the previous backed up the DHCP database and the DHCP Server configuration from C:restore<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">SetDNSConfig.BAT<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will read and the previous backed up none-Active Directory Integrated DNS Zones from C:restore<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">SetIASConfig.BAT<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">This script will read and import the previous backed up IAS config in C:restore to NPS<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">unattend_demote.txt<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; color: red; font-size: 9pt;\">This file contains environment specific parameters that need to be changed to reflect your environment. <\/span><br \/>\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">The file is used to demote Windows Server 2003 DCs<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">unattend_first.txt<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; color: red; font-size: 9pt;\">This file contains environment specific parameters that need to be changed to reflect your environment. <\/span><br \/>\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">The file is used to promote the first Windows Server 2008 R2 DC<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 1.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">unattend_promote.txt<\/span><\/td>\n<td style=\"border-bottom: gray 1.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; color: red; font-size: 9pt;\">This file contains environment specific parameters that need to be changed to reflect your environment. <\/span><br \/>\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">The file is sued to promote additional Windows Server 2008 R2 DCs using IFM.<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>&nbsp;<\/p>\n<div style=\"margin-left: 52pt;\"><\/div>\n<p>&nbsp;<\/p>\n<div style=\"margin-left: 52pt;\"><strong><a href=\"http:\/\/blogs.chrisse.se\/files\/folders\/session\/entry66.aspx\">Download the Sample Scripts<\/a><\/strong><\/div>\n<p>&nbsp;<\/p>\n<p>In addition to the presentation slide&#8217;s I will also share some additional information about compatibility between a forest\/domain running Windows Server 2003 DCs compared to running Windows Server 2008 R2 and how this can effect LOB apps, services and your business.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 14pt;\"><br \/>\nPrepare a new Windows Server 2008 R2 Domain Controller <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong><br \/>\nOperating System Configuration <\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">We generally recommend that customers apply its standard Windows Server 2008 R2 Standard Edition image as long as your desired &#8220;Domain Controller Configuration&#8221; (Disk layout, Unnecessary agents are uninstalled) is applied.<br \/>\nNote: If you&#8217;re going to reuse the name that the previous Windows Server 2003 DC you&#8217;re replacing had, assign a temporary name. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">The following hotfixes should be installed to prevent known issues when introducing Windows Server 2008 R2 Domain Controllers: <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><br \/>\nNote: The listed hotfixes has to be installed before the machine is promoted to domain controller (Or Windows Server 2008 R2 Service Pack 1). <\/span><\/p>\n<p>&nbsp;<\/p>\n<p style=\"margin-left: 48pt;\"><span style=\"font-family: Franklin Gothic Demi; font-size: 10pt;\">Table\u00a03.2\u00a0\u00a0\u00a0Required Domain Controller Hotfixes before promotion <\/span><\/p>\n<p>&nbsp;<\/p>\n<div style=\"margin-left: 52pt;\">\n<table style=\"border-collapse: collapse;\" border=\"0\">\n<colgroup>\n<col style=\"width: 308px;\" \/><\/colgroup>\n<colgroup>\n<col style=\"width: 308px;\" \/><\/colgroup>\n<tbody valign=\"top\">\n<tr style=\"background: #d9d9d9;\">\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: gray 1.5pt solid; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Demi Cond; font-size: 9pt;\">Microsoft KB<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: gray 1.5pt solid; border-right: gray 1.5pt solid;\">\n<p style=\"text-align: center;\"><span style=\"font-family: Franklin Gothic Demi Cond; font-size: 9pt;\">Description<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">977158 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=178225)<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Windows Server 2008 R2 Dynamic DNS updates to BIND servers log NETLOGON event 5774 with error status 9502<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">974639 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=165961)<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Event ID 1202 logged with status 0x534 if security policy modified<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">2001086 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=178226)<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">TimeZoneKeyName registry entry name is corrupt on 64-bit upgrades<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">2005074 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=185205)<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Event ID 1988 Logged in Directory Service Log after Schema Update<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">832223 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=186576)<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Windows Server 2008 R2 DNS servers that use root hints are unable to resolve some DNS queries.<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">978055 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=185219)<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Windows Server 2008 R2 domain controllers fail to authenticate DES-enabled clients.<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 1.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">977073 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=186934)<\/span><\/td>\n<td style=\"border-bottom: gray 1.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Digest authentication fails on a Windows XP or Windows Server 2003 member server when authenticating against a Windows Server 2008 R2 domain controller<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">We recommend that in addition to those hotfixes, the customer should ensure that the machine has reached the desired\/approved patch level within the organization. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li>\n<div><span style=\"font-family: Arial; font-size: 14pt;\">Replace an existing Windows Server 2003 Domain Controller <\/span><\/div>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>DHCP Service <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">If the particular domain controller also acting as a DHCP Server, Logon using Domain Admin or DHCP Administrator credentials (the later also requires the logon locally right). <\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Use the following steps to backup the DHCP database: <\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type cmd in the Open box, and then click OK. <\/span><\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>md C:migdata<\/strong> and then press <strong>enter<\/strong>. <\/span><\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; <\/span><\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li>Type CD scripts and press enter.<\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>GetDHCPConfig.BAT -export<\/strong> and press enter.\n<p><strong>Note:<\/strong> While the export command runs, DHCP server is stopped and does not respond to clients seeking new leases or lease renewals. (Verify if there is another DHCP server with overlapping scopes in the same site and\/or service interruption is approved) <\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>DNS Service<\/strong> <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">If the particular domain controller also acting as a DNS Server and hosting additional none Active Directory Integrated Zones. (Active Directory Integrated Zones are stored in Active Directory and will be replicated to the destination domain controller) <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">Logon using Domain Admins or DNS Admins (the later also requires the logon locally right).Use the following steps to backup none Active Directory Integrated Zones: <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type cmd in the Open box, and then click OK. <\/span><\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>md C:migdata<\/strong> and then press enter (if not already created in a previous step) <\/span><\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; (if not already created in a previous step) <\/span><\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<ul>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type CD scripts and press enter. <\/span><\/li>\n<\/ul>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul>\n<li>\n<div><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>GetDNSConfig.BAT<\/strong> and press <strong>enter.<\/strong> <\/span><\/div>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><br \/>\n<strong>Note: <\/strong>While the export command runs, The DNS Services is stopped and started. <\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Event Logs<\/strong> <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">We recommend to backup the event logs of the domain controller prior to the replacement since it can help with troubleshooting. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type cmd in the Open box, and then click OK. <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type md <strong>C:migdata<\/strong> and then press enter (if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; (if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type CD scripts and press enter. <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>script copyLogs.vbs<\/strong> and press enter (make sure the logs where successfully backed up) <\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>TCP\/IP Settings <\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">Save the TCP\/IP Settings configuration so those can be applied to the destination domain controller. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type cmd in the Open box, and then click OK <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>md C:migdata<\/strong> and then press <strong>enter <\/strong>(if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; (if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type CD scripts and press enter. <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li>\n<div><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>GetIPConfig.bat<\/strong> and press <strong>enter<\/strong> <\/span><\/div>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>System State Backup <\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">Ensure there is enough and health system backups before proceeding to next step. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><br \/>\nBackup the captured configuration in previous step by taking the following steps: <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: <a href=\"file:\/\/server\/projectshare\">\\serverprojectshare<\/a> <span style=\"color: red;\">&lt;TBD&gt;<\/span> <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>xcopy C:migdata X:DCs%computername% \/E<\/strong> and then press <strong>enter<\/strong>. <\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Directory Services <\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">This is the final step and enters the critical point of no return where the Windows Server 2003 Domain Controller is going to be demoted to a member server and will no longer acting as a Directory Service Agent (DSA) or a replica (Replication Partner) and won&#8217;t keep an instance of the Directory Services Database. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">Enfo Zipper recommends to run the demotion process unattended and automated to avoid mistakes and errors. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type cmd in the Open box, and then click OK. <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; (if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type CD scripts and press enter. <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>cscript RunDCPromo.VBS<\/strong> . (The demotion process should now start, please wait while the Windows Server 2003 Domain Controller being demoted and restarts) <\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Decommissioning <\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Arial; font-size: 10pt;\">Logon to the server as local administrator using the password specified in the unattended_demote.txt file above and either shutdown the server and\/or disconnect it from the network. For safety reasons we recommend that the server is renamed to something else before its shutdown and that the IP-address is changed from static to dynamic. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type <strong>cmd<\/strong> in the Open box, and then click <strong>OK<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>netdom renamecomputer %computername% \/NewName:%computername%_retired<\/strong> and press enter <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>netsh interface ip set address &#8220;Local Area Connection&#8221; dhcp<\/strong> and press <strong>enter<\/strong>.<br \/>\nNote: The name &#8220;Local Area Connection&#8221; may differ from server to server. <\/span><\/li>\n<\/ol>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>shutdown \u2013s \u2013t 00<\/strong> and press <strong>enter<\/strong>. <\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li>\n<div><span style=\"font-family: Arial; font-size: 14pt;\"><br \/>\nPromote a new Windows Server 2008 R2 Domain Controller <\/span><\/div>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Configure TCP\/IP Settings and Names <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Logon locally to the domain controller and take the following steps in order to restore the name and TCP\/IP Settings from the retired Windows Server 2003 Domain Controller that this domain controller is intend to replace: <\/span><\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type <strong>cmd<\/strong> in the Open box, and then click <strong>OK<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type CD scripts and press enter. <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type<strong> xcopy X:DCs&lt;NAME OF SOURCE DC&gt; C:restore \/E <\/strong><\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type<strong> netdom renamecomputer %computername% \/NewName:&lt;NAME&gt;<\/strong> and press enter (if you wish to re-use the same name) <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>netsh interface ip set dns &#8220;Local Area Connection&#8221; static &lt;IP_OF_WIN2K3DC&gt;<\/strong><br \/>\nNote: The name &#8220;Local Area Connection&#8221; may differ from server to server <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>netsh interface ip set dns &#8220;Local Area Connection&#8221; static &lt;IP_OF_NEARESTBYDC&gt;<\/strong><br \/>\nNote: The name &#8220;Local Area Connection&#8221; may differ from server to server <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>shutdown \u2013r \u2013t 00 <\/strong><\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Promote the server to a Domain Controller <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Logon locally to the domain controller and take the following steps in order to promote the server to Domain Controller, Enfo Zipper recommends to run the promotion process unattended and automated to avoid mistakes and errors. <\/span><\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click Start, click Run, type cmd in the Open box, and then click OK. <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; (if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>dcpromo \/answer: X:scriptsunattended_first.txt<\/strong> and press <strong>enter<\/strong>. (The promotion process should now start, please wait while the Windows Server 2008 R2 Domain Controller is being promoted and restarts) <\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Verify that the promotion to Doman Controller was successful <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Logon as Domain Admin to the domain controller and take the following steps in order to verify that the promotion of the Domain Controller completed successfully without errors <\/span><\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Once logged on back, Review the DCPROMO.txt log file. Click <strong>Start<\/strong>, Click run and type<strong> Notepad C:WindowsDebugdcpromo.log<\/strong> and press <strong>enter.<\/strong> Search the file for the word error using notepad, ensure there were no errors, close notepad. <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Quickly review the DCPROMOUI.log file. Click <strong>Start<\/strong>, Click run and type<strong> Notepad C:WindowsDebugdcpromoui.log<\/strong> and press <strong>enter. <\/strong>Close notepad. <\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>DNS Service <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Enfo Zipper recommends that full replication has taken place before you proceed with the following step, in order to ensure that please run the DNSConvergeCheck script between the local domain controller and one of the domain controllers in the hub site.<br \/>\nThe DNSConvergeCheck script can be found at: <a href=\"http:\/\/go.microsoft.com\/fwlink\/?LinkId=135502\">http:\/\/go.microsoft.com\/fwlink\/?LinkId=135502<\/a> <\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">If full replication has taken place, please proceed with the following commands in order to import DNS Zone data (None-Active Directory integrated Zones). <\/span><\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click <strong>Start<\/strong>, click <strong>Run<\/strong>, type <strong>cmd<\/strong> in the Open box, and then click <strong>OK<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; (if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type CD scripts and press enter. <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>SetDNSConfig.BAT<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">All DNS Zones should now successfully have been restored. <\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>DHCP Service <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Logon as Enterprise Admin and take the following steps to install the DHCP Server service and restore the database and settings for the Windows Server 2003 Domain Controller. <\/span><\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click <strong>Start<\/strong>, click <strong>Run<\/strong>, and click <strong>Administrative Tools<\/strong> and then Click <strong>PowerShell Modules<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>Add-WindowsFeature DHCP<\/strong> and press <strong>enter.<\/strong> (if asked to\/promoted to restart the server, please follow the instructions given) <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">If a restart was required, Logon back as Enterprise Admin, Click <strong>Start<\/strong>, click <strong>Run<\/strong>, type <strong>cmd<\/strong> in the Open box, and then click <strong>OK<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type net use X: \\serverprojectshare &lt;TBD&gt; (if not already created in a previous step) <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type CD scripts and press enter. <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>sc config dhcpserver start= auto<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type<strong> SetDHCPConfig.BAT -import<\/strong> <\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Post-Operating System Configuration <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">The following hotfixes should be installed to prevent known issues when introducing Windows Server 2008 R2 Domain Controllers: <\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\"><br \/>\nNote: The listed hotfixes has to be installed after the machine is promoted to domain controller (Or Windows Server 2008 R2 Service Pack 1) <\/span><\/p>\n<p style=\"margin-left: 48pt;\"><span style=\"font-family: Franklin Gothic Demi; font-size: 10pt;\">Table\u00a03.6\u00a0\u00a0\u00a0Required Domain Controller Hotfixes after promotion <\/span><\/p>\n<div style=\"margin-left: 52pt;\">\n<table style=\"border-collapse: collapse;\" border=\"0\">\n<colgroup>\n<col style=\"width: 308px;\" \/><\/colgroup>\n<colgroup>\n<col style=\"width: 308px;\" \/><\/colgroup>\n<tbody valign=\"top\">\n<tr style=\"background: #d9d9d9;\">\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: gray 1.5pt solid; border-right: gray 0.5pt solid;\">\n<p style=\"text-align: center;\"><span style=\"font-family: Franklin Gothic Demi Cond; font-size: 9pt;\">Microsoft KB<\/span><\/p>\n<\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: gray 1.5pt solid; border-right: gray 1.5pt solid;\">\n<p style=\"text-align: center;\"><span style=\"font-family: Franklin Gothic Demi Cond; font-size: 9pt;\">Description<\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">978387 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=184915):<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Dcdiag fails with error code 0x621<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">978277 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=184911):<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">The specified account does not exist<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">978516 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=185190)<\/span><\/td>\n<td style=\"border-bottom: gray 0.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Significant delays when you read the same set of files several times<\/span><\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: gray 1.5pt solid; border-left: gray 1.5pt solid; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 0.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">978837 (http:\/\/go.microsoft.com\/fwlink\/?LinkId=185191)<\/span><\/td>\n<td style=\"border-bottom: gray 1.5pt solid; border-left: medium none; padding-left: 7px; padding-right: 7px; border-top: medium none; border-right: gray 1.5pt solid;\">\n<span style=\"font-family: Franklin Gothic Medium Cond; font-size: 9pt;\">Group Policy Management Editor window crashes when you apply some changes for NRPT policy settings<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Disable EDNS <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Disable EDNS to avoid issues with global DNS servers that doesn&#8217;t support EDNS, (Not needed if forwarders is configured to handle external DNS queries outside the forest and to the internet) <\/span><\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click <strong>Start<\/strong>, click <strong>Run<\/strong>, type <strong>cmd<\/strong> in the Open box, and then click <strong>OK<\/strong> <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Type <strong>dnscmd \/config \/EnableEDNSProbes 0<\/strong> and press <strong>enter<\/strong>. <\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Configure Kerberos supported encryption types <\/strong><\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\">Note this step is only required if the domain contains service accounts and\/or computer accounts that are configured to use DES-only encryption. <\/span><\/p>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">In the Group Policy Management Console (GPMC), locate the following location: <strong>Computer Configuration Windows Settings Security Settings Local Policies Security Options<br \/>\n<\/strong><\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click to select the <strong>Network security: Configure encryption types allowed for Kerberos<\/strong> option.<br \/>\n<\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<ol>\n<li><span style=\"font-family: Arial; font-size: 10pt;\">Click to select <strong>Define these policy settings<\/strong> and all the six check boxes for the encryption types<br \/>\n. <\/span><\/li>\n<\/ol>\n<\/ol>\n<ol>\n<li>\n<div><span style=\"font-family: Arial; font-size: 10pt;\">Click <strong>OK<\/strong>. Close the GPMC. <\/span><\/div>\n<\/li>\n<\/ol>\n<p><span style=\"font-family: Arial; font-size: 10pt;\"><strong>Note:<\/strong> The policy sets the <strong>SupportedEncryptionTypes<\/strong> registry entry to a value of <strong>0x7FFFFFFF<\/strong>. The <strong>SupportedEncryptionTypes<\/strong> registry entry is at the following location: <\/span><br \/>\n<span style=\"font-family: Arial; font-size: 10pt;\"><strong>HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemKerberosparameters <\/strong><\/span><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>First of all thanks to everyone that attended my session &#8221; Upgrade Active Directory from WS03 to WS08 R2&#8243; at Microsoft Tech Days 2011 in Sweden. For those of you that couldn&#8217;t attend on site I did a session on upgrading a Windows Server 2003 Active Directory environment to Window Server 2008 R2 with a &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.chrisse.se\/?p=65\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Upgrade Active Directory from WS03 to WS08 R2&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[6],"class_list":["post-65","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-active-directory"],"_links":{"self":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/posts\/65","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=65"}],"version-history":[{"count":0,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/posts\/65\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=65"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=65"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=65"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}