Windows 10: Make Second Domain Controller Primary

Discus and support Make Second Domain Controller Primary in Windows 10 Software and Apps to solve the problem; I have 2 domain controllers, Primary is Windows Server 2012 and the secondary Domain Controller is Windows Server 2022. Primary successfully replicates... Discussion in 'Windows 10 Software and Apps' started by Harley_Rhodes, Feb 8, 2023.

  1. Make Second Domain Controller Primary


    I have 2 domain controllers, Primary is Windows Server 2012 and the secondary Domain Controller is Windows Server 2022. Primary successfully replicates to Secondary without issues and visa versa if I make changes in Secondary. I want to decommission the Primary DC, I followed the steps to transfer all 5 FSMO roles to secondary and now secondary is supposed to be Primary.All servers see the secondary DC and it is listed as a DNS in ipconfig/all. When I shutdown the old 2012 DC, I Could not access any of the servers with domain name only IP. I tried flushing DNS but that did not help. I turned o

    :)
     
    Harley_Rhodes, Feb 8, 2023
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Feb 8, 2023
    #2
  3. bdanmo Win User
    UnattendedJoin error: failed to find the domain data (0x6e)

    Thanks for the suggestion! I don't want to add a domain account, as this is a generic unattended install that will be used for all company machines. Do you think it's possible that the computer would join the domain if, instead of using UnattendedJoin in specialize, I used your steps but left out the specific account?

    The other thing I was thinking was to use a generic account to allow the domain join during the specialize step. I added a machine password in the UnattendedJoin component, and instead of getting the error listed above, I got an authentication error, which makes me think I could probably do a secure join instead of the unsecure join.

    Thoughts?
     
    bdanmo, Feb 8, 2023
    #3
  4. Make Second Domain Controller Primary

    BOINC for Windows Domain Controllers

    Long story short, BOINC stopped supporting domain controllers after version 5.10.45 and 5.10.45 broke because it's HTTPS security certificates are out of date. Requirements:
    • Windows Server 2003 R2 x64 Edition or newer (must be 64-bit)
    • Must have domain controller role installed.
    If neither of these requirements are met, just use the latest version from Berkeley.

    The solution:
    • Download this ZIP from TPU (thanks @Wizzard!)
    • Extract everything from the ZIP to the desktop or some place you can easily access it.
    • Run "boinc_5.10.45_windows_x86_64.exe" to install 5.10.45 as normal.
    • After it is installed, make sure BOINC is not running. If it is running as a service, you can stop it via Services. If it is running in the tray, right click on the tray icon and click on Exit.
    • Navigate to where BOINC is installed. This is usually C:\Program Files\BOINC. You should see a ca-bundle.crt file here (it'll have a different icon from the rest). If you do, you're in the right place.
    • Extract the contents of the "certificates" folder to the folder where BOINC is installed. You should be prompted to replace existing files. Do it. If you do not, you're likely in the wrong directory or copied the "certificates" folder instead of its contents. It is very important that the files inside of "certificates" overwrite the installed BOINC files.
    • Start BOINC again. If it is a service, go back into Services and start the BOINC service. If it is a tray application, run it from your start menu. You'll also need to start the BOINC Manager if you have it installed as a service for the next step.
    • Double click on the tray icon to open the BOINC Manager if it isn't already open. Click on the "Messages" tab and verify it is able to download tasks. If it is, you're good to go. If you see "SSL connect" errors lets us know by replying to the thread.
    The "certificates" are copied from 7.6.22.
     
    FordGT90Concept, Feb 8, 2023
    #4
Thema:

Make Second Domain Controller Primary

Loading...
  1. Make Second Domain Controller Primary - Similar Threads - Second Domain Controller

  2. need to block copilot using GPO policy . currently my Primary domain controller 2012...

    in Windows 10 Gaming
    need to block copilot using GPO policy . currently my Primary domain controller 2012...: I need to block Copilot using Group Policy. Currently, my primary domain controller is Windows Server 2012 Datacenter. Since the default option is not available in 2012 Datacenter, how should I proceed?...
  3. need to block copilot using GPO policy . currently my Primary domain controller 2012...

    in Windows 10 Software and Apps
    need to block copilot using GPO policy . currently my Primary domain controller 2012...: I need to block Copilot using Group Policy. Currently, my primary domain controller is Windows Server 2012 Datacenter. Since the default option is not available in 2012 Datacenter, how should I proceed?...
  4. I cant delete the email that is primary or make mine primary

    in Windows 10 Software and Apps
    I cant delete the email that is primary or make mine primary: Hi, I have been hacked recently, and even though we got rid of the hacker, they still left a big mess with my microsoft account. For examble they fully deleted my microsoft account and made a new one wich I cant log into. So here is the problem: I made a new account and was...
  5. Make Second Domain Controller Primary

    in Windows 10 Gaming
    Make Second Domain Controller Primary: I have 2 domain controllers, Primary is Windows Server 2012 and the secondary Domain Controller is Windows Server 2022. Primary successfully replicates to Secondary without issues and visa versa if I make changes in Secondary. I want to decommission the Primary DC, I followed...
  6. Domain controller is not replicating

    in Windows 10 Gaming
    Domain controller is not replicating: Hi Techies,We have run in kind of a situation here in our estate. We found out that one of DC is not replicating properly with rest of them . On some troubleshooting I did reset affected DC password using netdom but that did not help and now it is saying "The naming context...
  7. Domain controller is not replicating

    in Windows 10 Software and Apps
    Domain controller is not replicating: Hi Techies,We have run in kind of a situation here in our estate. We found out that one of DC is not replicating properly with rest of them . On some troubleshooting I did reset affected DC password using netdom but that did not help and now it is saying "The naming context...
  8. Client can't join primary domain controller but secondary domain controller is working normal?

    in Windows 10 Customization
    Client can't join primary domain controller but secondary domain controller is working normal?: Hi team,I have two domain controller primary and secondary domain controller on windows server 2016 Standard. Now i have some issue with my client any new client PC with windows 10 can't join primary domain controller but my secondary domain controller is working fine. I...
  9. Make secondary monitor primary from second display?

    in Windows 10 Ask Insider
    Make secondary monitor primary from second display?: So I'm using an egpu to play games on Windows 10. I can only see my external monitor however and my laptop screen is blank. I need to make my external monitor the primary display so I can use it, but I can't do it from the main display (laptop Screen) because it's blank....
  10. Adding a second SSD and making it the primary and boot drive

    in Windows 10 Network and Sharing
    Adding a second SSD and making it the primary and boot drive: Unsure if this is the best place but I am trying to figure out how to best configure my storage for my Laptop. It has 2 NVMe Slots. Originally came with 500GB drive Added my own 1TB WD drive to empty NVME Slot Very little data on the original drive, most are in one...