Upgrade the domain controller of Windows server 2012r2 version to Windows server 2016r2 version

Upgrade the domain controller of Windows server 2012r2 version to Windows server 2016r2 version

According to the needs of the upgrade, the original Windows server 2012r2 version domain controller must be upgraded to the Windows server 2016r2 version

Environment: the original windows server 2012 r2 service operating system server, and the newly built windows server 2016

 

The following steps to upgrade the domain controller:

  1. First check the domain's primary controller and FSOM role, as shown in the figure below, this domain name is aaa.com, primary domain controller: ADDC

 

  1. First add the 2016 version to the domain, and upgrade it to an additional domain controller. This is the same as the previous operation

 

 

  1. Relocation: Relocate the domain of 2012 r2 to 2016 and let 2016 become the main domain controller. Steps

1. Check the primary domain controller in windows server 2016r2, as shown in the figure

2. Enter regsvr32 schmmgmt.dll in cmd, as shown in the figure, this is the preparation for transferring the primary domain controller

  1. Then enter the command: ntdsutil After entering: After entering roles, after entering, then enter connections

Then enter connect to domain aaa.com and enter quit as shown in the figure. This figure shows that it has been connected to this AD domain (windows server 2016 r2)

After that, it began to relocate the main domain, mainly relocating 5 roles: the first relocation

The second role: Schema master role: schema master, complete command: seize schema master click "Yes" as shown in the figure, execute

The third relocation is: domain naming master role; naming master, complete command: seize naming master

The fourth move is: RID master role, complete command: seize RID master

The fifth relocation is: PDC master role, complete command: seize PDC

After the relocation, enter quit twice to exit, verify: netdom query fsmo; Netdom query PDC, as shown in the figure

Then start the upgrade: the steps are as follows, open in the windows management tool of the windows server 2016 version à open in the AD domain and trust relationship, as shown in the figure

After opening as shown in the figure, right-click and click to increase the domain function level

When opened, the following picture will appear, that is because the original windows server 2012 r2 has not been downgraded to ordinary members, so this interface will appear

 

Start the downgrade steps:

Downgrade the main domain on windows server 2012r2, first check where the current master domain is controlled,

 

 

The above picture shows that the relocation has been completed, and now it is time to drop the domain. As shown in the picture below, the role and function are deleted. I have introduced it before, so I won’t introduce it.

After downgrading, go back to the windows server 2016r2 to upgrade. Although the system is the 2016 r2 version, the function of the domain was still the windows server 2012r2 version at the time, and it was still in the domain and trust relationship.

After opening, when the picture is still like this, the steps to eliminate the error

 

You can check the Domain controllers (domain controller container) and find that there is also a domain controller ADDC3 (this domain controller version is still server 2012 r2), so it cannot be upgraded. The reasons are as follows

Note: When upgrading the domain controller, after the master domain controller is relocated to a new server, the upgrade is performed on the relocated server. Note that everything in the past will be relocated, including the previous additional domain controllers . Therefore, it must be downgraded. If it is not downgraded, it will be impossible to upgrade. Additional controllers must be downgraded before they can be upgraded.

The extra domain begins to degrade: Identify the domain controller

Successful downgrade

After downgrading, go back to the windows server 2016 r2 version and start the upgrade. It is still in the AD domain and trust. After opening, right-click the domain name, as shown in the figure, you can upgrade the domain

After the upgrade is complete, you can right-click the domain name again, and you will find the image as shown in the figure.

The previous windows server 2012 r2 can no longer be a domain controller, but can become an ordinary member, as shown in the figure, when you try to join, it will become like this

Guess you like

Origin blog.csdn.net/weixin_47347190/article/details/107221782