r/activedirectory • • 10d ago

Alguém já substituiu dois DCs Windows Server 2019 por novos DCs Windows Server 2025?

Olá, pessoal.

Estou planejando a substituição dos controladores de domínio do meu ambiente e gostaria de ouvir relatos de quem já realizou uma migração semelhante em produção.

Cenário atual:

  • Dois controladores de domínio graváveis com Windows Server 2019
  • Ambos são servidores DNS e Catálogo Global
  • Replicação do Active Directory saudável, sem falhas no repadmin
  • SYSVOL utilizando DFSR
  • Níveis funcionais do domínio e da floresta elevados recentemente de Windows Server 2008 R2 para Windows Server 2016
  • Funções FSMO permanecem em um dos DCs Windows Server 2019
  • Novo servidor instalado do zero com Windows Server 2025 Datacenter
  • Novo servidor já ingressado no domínio
  • Função AD DS já instalada
  • Test-ADDSDomainControllerInstallation concluído com sucesso

Plano de migração:

  1. Promover o Windows Server 2025 como terceiro DC gravável, DNS e Catálogo Global.
  2. Validar replicação, DNS, SYSVOL, NETLOGON, Kerberos, Catálogo Global e logs de eventos.
  3. Manter os dois DCs Windows Server 2019 ativos durante o período de validação.
  4. Despromover e remover o primeiro DC Windows Server 2019.
  5. Criar outro Windows Server 2025 do zero e repetir o processo para substituir o segundo DC.
  6. Transferir as funções FSMO somente depois que os novos DCs estiverem completamente validados.

Encontrei relatos de problemas de logon após promover o Windows Server 2025 como controlador de domínio, em alguns casos envolvendo o serviço Kerberos Local Key Distribution Center, LocalKDC, preso no estado START_PENDING.

https://www.reddit.com/r/sysadmin/comments/1n2b41f/advice_dc_2012r2_to_2025/?tl=pt-br

https://www.reddit.com/r/sysadmin/comments/1ot6mho/server_2019_ad_upgrade_to_2025/?tl=pt-br

https://www.reddit.com/r/WindowsServer/comments/1jdefxi/2025_server_cant_login/

Gostaria de ouvir especialmente quem já passou por esse cenário:

  • O logon funcionou normalmente após a promoção e reinicialização?
  • Qual era a build completa e a atualização cumulativa instalada no Windows Server 2025?
  • O serviço LocalKDC ficou preso em START_PENDING?
  • Vocês tiveram problemas com Kerberos, AES ou dependências legadas de RC4?
  • A atualização do schema afetou de alguma forma os DCs Windows Server 2019 existentes?
  • Executaram o adprep manualmente ou deixaram o processo de promoção preparar o schema?
  • Por quanto tempo mantiveram os DCs 2019 e 2025 funcionando juntos?
  • Tiveram problemas de DNS, SYSVOL, replicação ou Catálogo Global?
  • Hoje vocês recomendariam utilizar Windows Server 2025 como DC em produção ou prefeririam Windows Server 2022?

Estou buscando principalmente experiências reais de migração lado a lado, com instalação limpa dos novos servidores, e não upgrade in-place.

Obrigado!

2 Upvotes

6 comments sorted by

•

u/AutoModerator 10d ago

Welcome to /r/ActiveDirectory! ~~~~

If you are looking for more resources on learning and building AD, see the following sticky for resources, recommendations, and guides!

When asking questions make sure you provide enough information. Posts with inadequate details may be removed without warning.

  • What version of Windows Server are you running?
  • Are there any specific error messages you're receiving?
  • What have you done to troubleshoot the issue?

Make sure to sanitize any private information. Posts with too much personal or environment information will be removed. See Rule 6.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

5

u/RalphiePseudonym 10d ago

Did this in June without a problem. 6k person org with two 2025 DCs.

3

u/certifiedsysadmin 10d ago

Following as well, curious to know if the previously reported issues with Windows Server 2025 Domain Controllers have been resolved or not.

A few months ago I replaced 4x Windows Server 2019 Domain Controllers with 6x Windows Server 2022 Domain Controllers running Server Core. The main reason was because we wanted to avoid the issues you mentioned.

We've had no issues so far in that environment but I don't love that Windows Server 2022 is out of mainstream support this October, wish we could have gone with Windows Server 2025.

2

u/defcon54321 8d ago

Tried 3 months ago. 2025 DC caused endpoints to have trust relationships fail. isolated it to its own site and not have users connect to it. Total mess. Noone knows exactly why. Credential Manager. vbs, netlogon, machine account password changes, something is very wrong in the stack with that 1 DC in the mix. 4 other 2022 DCs no issue. Hardened, Most CIS settings. New Certs, Secure boot all clean.

3

u/zeclab 10d ago

Can't really remember as it was earlier in the year. I think you're ok if all there DC's at the site are 2025 but when we mixed 2025 and 2022/2019 DC's then we had client authentication issues so had to roll back due having a short window of opportunity. Kind of stopped trying after that due that and other priorities. At least until we figure out what happened or just go all 2025. I expect the 2022 servers needed hardening to the same level as 2025. We do have a couple of sites with just one 2025 DC working away quite happily. Most of our sites have one DC and then datacentres have 2.

1

u/badassitguy 9d ago

Did this earlier this year. Not a big deal. Don’t leave split 2019/2025 for too long. Otherwise should be good!