Backup plan for FFL/DFL raise

Biswajeet Kumar 116 Reputation points
2021-02-02T06:08:34.807+00:00

Hi,

We have 80 DCs in our domain in different sites. Recently we upgraded from 2012r2 to 2019 server OS. Now we need to raise the FFL/DFL. As we cannot roll back the change, So we are looking for a backup plan?

After researching we found that the only way is to recover the forest/domain using system state backup of 1 DC and recreate all the other DCs. But for 80 DCs that seems very difficult.

Please suggest the process.

Thanks.

Windows Server Backup
Windows Server Backup
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Backup: A duplicate copy of a program, a disk, or data, made either for archiving purposes or for safeguarding valuable files from loss should the active copy be damaged or destroyed.
464 questions
{count} votes

Accepted answer
  1. Daisy Zhou 20,791 Reputation points Microsoft Vendor
    2021-02-02T09:07:15.257+00:00

    Hello @Biswajeet Kumar ,

    Thank you for posting here.

    Generally, we recommend backing up all domain controllers regularly using Windows server built-in Windows backup tool .

    Before we do any change in AD, we had better do related backups.

    For your request, after the discussion between my colleague and I, we think either we raise the FFL/DFL successfully, or we will not raise the FFL/DFL successfully (keep the current FFL/DFL) due to some reason.

    Assuming that DFL/FFL cannot be upgraded, we need to look for the reason.

    Meanwhile, I have done a test in my lab as below, raise FFL and DFL.

    62874-ddl.png

    And I can downgrade the FFL and DFL.
    62869-ddl1.png

    Before you raise FFL and DFL, I suggest we can check the information below.
    1.Ensure every DC works fine itself by running Dcdiag /v on each DC.
    2.Ensure AD replication works fine in the entire forest by running commands below on PDC(there is no any error in the command result).
    repadmin /showrepl
    repadmin /replsum
    repadmin /showrepl * /csv >c:\repsum.csv

    3.We can update gpo on all DCs by running gpupdate /force.
    4.Netlogon and SYSVOL are shared on all DCs.
    5.SYSVOL replication works fine between all DCs.

    If all above is OK, FFL and DFL should be raised successfully.

    Reference
    Understanding Active Directory Domain Services (AD DS) Functional Levels
    https://video2.skills-academy.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc754918(v=ws.10)?redirectedfrom=MSDN

    Hope the information above is helpful. If anything is unclear, please feel free to let us know.

    Best Regards,
    Daisy Zhou


0 additional answers

Sort by: Most helpful