DC Upgrade Methods
There are a few preferred methods to upgrading/replacing an organizations domain controller(s):
Build and Migrate
- Build and add the new DC(s) to the existing domain.
- Update all infrastructure to use the new DC(s) as their primary DNS server(s).
- Update all LDAP-enabled services to use the new DC(s).
- Migrate all FSMO roles to the new DC(s).
- Demote and remove the old DC(s).
Build and Swap Out
- Build and add the new DC(s) to the existing domain.
- Systematically shuffle the DC(s) IP addresses around so the new DC(s) end up inheriting the old DC(s) IP addresses.
- Update any remaining equipment that is LDAP-tied to the FQDN of the old DCs (rather than the IP address or the root FQDN (ex. ad.example.com).
- Migrate all FSMO roles to the new DC(s).
- Demote and remove the old DC(s).
Decommission and Replace
- Migrate FSMO roles, demote and decommission one DC.
- Build and add the new DC using the same IP address and possibly same hostname (if preferred).
- Migrate FSMO roles, demote and decommission the next DC.
- Build and add the new DC using the same IP address and possibly same hostname (if preferred).
- Rinse and repeat the above process.