adding a 2nd domain controller to existing domain


Recommended Posts

I have a question (probably stupid but it's not mentioned anywhere). We have just purchased a new server. When adding a 2nd controller to my existing tree (using dcpromo), does the new server have to be part of the domain first or can I just add it as a domain controller and it would know to add it the domain?

 

 

 

you don't need to add it to the domain first, if you add dns server first and have it be a secondary dns server you can then add it as a second domain controller. It will save a reboot doing it this way.

  • Like 2
  On 22/07/2014 at 15:53, sc302 said:

you don't need to add it to the domain first, if you add dns server first and have it be a secondary dns server you can then add it as a second domain controller. It will save a reboot doing it this way.

Isnt that very insecure? Doesnt the pc need to be a member of the domain first? If not couldnt anybody just add a rougue dns server to the domain? I thought you have to make the pc a member of the domain first before adding any roles to it. Usually it throws up an error message stating so.

No.. You would have to give permission to that server to be a dns server..It isn't like you can just simply add a dns server nilly willy to the domain

 

Here are the steps:

1st, give the new server a static ip address with the dns servers the current dns servers in the ipv4 properties

2nd go to a dns server and open up the zone that you want to add a secondary dns server to, go to the properties of the domain and the _msdcs and allow zone transfers to the ip of the new server

3rd go to the new server and setup the ad zones in the dns (you will need to install the dns server role on the server)

4th change the dns on the nic of the new server to be itself

5th run dcpromo and add server as a secondary domain controller. 

 

Once completed you can take the zone transfers out. 

 

 

This saves on a reboot, takes me less time to do this than it does to do a reboot.  All about saving time when you don't have a lot of time to do this. 

  On 22/07/2014 at 18:49, hagjohn said:

Thanks. I've never added a 2nd controller to a windows domain. I assume I add a user to the domain, to get it fully on the domain and then promote it, correct?

 

You can do it the way sc302 mentioned or just do it via System - change the workgroup business and add the domain. Once you click ok it will ask you for a username for an authorized account (admin account) to add the server the domain, same way how you add a non-server to a domain.

 

Once that's all done you just have to promo it and follow the wizard which will mention the other DC and that you are a 2nd controller in the main forest.

  • 4 months later...

I have always done it the traditional way, when adding a new server, patch it up with service packs/fixes, join to domain, then add roles to the server (inc DC role) after being joined.

 

a reboot save isn't valid if its not yet a part of the domain/DC cluster.

  On 22/07/2014 at 19:18, sc302 said:

No.. You would have to give permission to that server to be a dns server..

 

Once completed you can take the zone transfers out. 

 

This saves on a reboot, takes me less time to do this than it does to do a reboot.  All about saving time when you don't have a lot of time to do this. 

 

Sounds like a recipe for disaster and I cannot believe it to be much faster than a join, reboot then promote. Kudos if that's what works for you but to me it seems a bit overly complicated.

Depends, have you ever waited 5-10 minutes for a server reboot to scan through raid/scsi cards or that dell lifecycle controller? 

 

Not a recipe for disaster, there is nothing that would cause an issue.  Tell me what is going to screw up so bad by doing it the way I describe?  DNS?  no you are copying information not over writing.  The process of adding a server?  maybe, if you don't add the dns entries in the tcp/ip properties properly after you have copied the dns info over.

 

 

  On 10/12/2014 at 12:52, Mando said:

I have always done it the traditional way, when adding a new server, patch it up with service packs/fixes, join to domain, then add roles to the server (inc DC role) after being joined.

 

a reboot save isn't valid if its not yet a part of the domain/DC cluster.

btw, with my method the system does not need to be a domain member prior to dcpromo. 

  On 10/12/2014 at 14:05, sc302 said:

Depends, have you ever waited 5-10 minutes for a server reboot to scan through raid/scsi cards or that dell lifecycle controller? 

 

Yes, I call that time "coffee" time or "me" time :)

 

Again kudos to you, and if it works for you go for it.

  • 1 month later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • That's not Pinocchio. That's a twink boy with a robot arm. Even the puppet is a lie in Lies of P!
    • I have a question on W11. Do VLC Player ( not the Store version ) and QBitorrent work with W11?
    • Splitgate 2 gets a surprise battle royale mode just as the free-to-play game releases by Pulasthi Ariyasinghe The highly anticipated arena shooter with portals, Splitgate 2, has just been released across PC and consoles as a free-to-play experience. At the same time, the studio head appeared on the Summer Game Fest showcase's stage today with a surprise reveal, showing off a brand-new battle royale mode that is a part of the game and is also launching today for free. Watch the action-packed trailer above. The sci-fi shooter franchise by 1047 Games has not breached the battle royale space before, but it seems the studio has been working secretly on the project all this time for this surprise reveal and launch. The Splitgate 2 battle royale mode features 60-player showdowns, letting 15 teams, each with four players, compete with each other to be the last squad standing. The map is touted as being an interconnected, gigantic colosseum with five biomes, and players will have to go through massive World Portals to reach each of them and hopefully take down anyone on the other side. "Choose where to drop in across Drought’s scorching desert, Glacier’s slick snowscape, Inferno’s active volcano, or Fracture’s cluster of asteroids," explains the developer. "After landing, players who stay in the match long enough will gain access to a fifth biome – the central area of Sanctum’s foreboding ruins, which offers special, powerful loot for those who can survive sparring to get it." Being a battle royale, there are chests to loot for better armaments, fast-paced action, map events to change up the atmosphere, and plenty of quick action to jump into. Aside from the new mode, with the Splitgate 2 full launch, the studio has delivered four new maps to the arena mode, a fresh map-creating template, as well as the Gravitas Shotgun as a brand-new weapon. It is also working on implementing a ranked mode, even more maps, map reskins, and more content as part of its post-launch support plans. Splitgate 2 is now available on PC (Steam and Epic Games Store), Xbox Series X|S, Xbox One, PlayStation 5, and PlayStation 4.
    • I hate that they have removed settings that we once had, and had them for what feels like forever. Until now.   My desktop icon font are too thin, and too small now in Windows 11 since the last Windows Update. I have been using Winareo Tweaker to set the icon font to bold, and to change the size to a size larger. Now I have to do it twice, loggin out and back in each time, before it finally takes effect on the third time. But wait.... it gets worse. Once the system is shutdown, and turned back on the next day, all of those icon settings are reset to thin, and small.   I see no reason for the previous font customization options we always had now being removed. SO upsetting.   Boo Microsoft. Updates are suppose to be 'better', not removing options we had previously. This is horrible.
  • Recent Achievements

    • Week One Done
      daelos earned a badge
      Week One Done
    • One Month Later
      daelos earned a badge
      One Month Later
    • Mentor
      Karlston went up a rank
      Mentor
    • One Month Later
      EdwardFranciscoVilla earned a badge
      One Month Later
    • One Month Later
      MoyaM earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      492
    2. 2
      snowy owl
      256
    3. 3
      +FloatingFatMan
      252
    4. 4
      ATLien_0
      212
    5. 5
      Xenon
      150
  • Tell a friend

    Love Neowin? Tell a friend!