Home › Deploying domain controllers › Step 4

Upgrading domain controllers to a newer Windows Server

Step 4 of 6 in Deploying domain controllers · video 3:34

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Moving a domain to a newer Windows Server release can be done in two ways: upgrade the operating system of the existing domain controllers in place, or add new domain controllers running the new version and retire the old ones. The lesson recommends the second route because it leaves a clean operating system and a clean AD DS database, and DNS records update so that clients find the new servers straight away. Before the domain functional level can be raised, every domain controller in the domain must run the new version. An in-place upgrade does not prepare the schema or the domain by itself, so adprep /forestprep and adprep /domainprep from the \support\adprep folder of the installation media must be run first. By contrast, promoting a new server into an existing domain while signed in as a member of Schema Admins and Enterprise Admins updates the schema automatically. The steps for both methods are listed, including pointing client DNS settings at the new domain controllers.

Good to know: the lesson was recorded for Windows Server 2016. An in-place upgrade of a domain controller to Windows Server 2016 is supported from Windows Server 2012 and 2012 R2 only. Newer releases add their own functional levels, and SYSVOL must replicate with DFS Replication, not FRS, before domain controllers running Windows Server 2019 or later can join.

Check yourself

Answer in your head first, then open each question to see the answer.

1. Which upgrade method does the lesson recommend, and why?

Adding new domain controllers on the new version and phasing out the old ones, because you end up with a clean operating system and a clean AD DS database instead of carrying old state forward.

2. What must you do before an in-place operating system upgrade of an existing domain controller?

Run adprep /forestprep and adprep /domainprep from the installation media, because an in-place upgrade does not prepare the schema and the domain on its own.

3. You promote a new server into the existing domain while signed in as a member of Schema Admins and Enterprise Admins. Do you need to run adprep first?

No. In this case the promotion updates the schema automatically, so a separate adprep run is not needed.

4. What happens if you try to raise the domain functional level while one domain controller still runs an older Windows Server version?

You cannot raise it. The domain functional level can go up only when every domain controller in the domain runs that version or later, so the old DC must be upgraded or removed first.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Active Directory: Domain Controllers, Operations Masters, GC

4.6★ · 9,297 students on Udemy

See the course on Udemy
← Installing a domain controller from media (IFM)Next: Cloning virtual domain controllers →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.