I am getting ready to upgrade my Active Directory Domain Controllers from Server 2012 R2 to Server 2019. I have 25 domain controllers in this environment. 5 of them reside at our national data center and serve as our ‘Core Hub’, and hold the schema roles. The other 20 are paired across our other sites. The overall upgrade will include replacing/upgrading the hardware for all 25 domain controllers. With that being said, should I look at going virtual instead of physical.<\/p>\n
Advertisement
Thoughts, advantages, disadvantages… and GO!<\/p>","upvoteCount":61,"answerCount":77,"datePublished":"2022-02-09T15:35:53.000Z","author":{"@type":"Person","name":"austinswoape","url":"https://community.spiceworks.com/u/austinswoape"},"suggestedAnswer":[{"@type":"Answer","text":"
Advertisement
I am getting ready to upgrade my Active Directory Domain Controllers from Server 2012 R2 to Server 2019. I have 25 domain controllers in this environment. 5 of them reside at our national data center and serve as our ‘Core Hub’, and hold the schema roles. The other 20 are paired across our other sites. The overall upgrade will include replacing/upgrading the hardware for all 25 domain controllers. With that being said, should I look at going virtual instead of physical.<\/p>\n
Thoughts, advantages, disadvantages… and GO!<\/p>","upvoteCount":61,"datePublished":"2022-02-09T15:35:54.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/1","author":{"@type":"Person","name":"austinswoape","url":"https://community.spiceworks.com/u/austinswoape"}},{"@type":"Answer","text":"
Ancient Alien Astronaut Theorists say YES.<\/p>","upvoteCount":14,"datePublished":"2022-02-09T15:42:06.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/2","author":{"@type":"Person","name":"Denis-Kelley","url":"https://community.spiceworks.com/u/Denis-Kelley"}},{"@type":"Answer","text":"
LOL, that is the problem.<\/p>","upvoteCount":0,"datePublished":"2022-02-09T15:44:51.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/3","author":{"@type":"Person","name":"austinswoape","url":"https://community.spiceworks.com/u/austinswoape"}},{"@type":"Answer","text":"
Why not go to 2022 server?<\/p>","upvoteCount":0,"datePublished":"2022-02-09T15:57:21.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/4","author":{"@type":"Person","name":"WarKraft","url":"https://community.spiceworks.com/u/WarKraft"}},{"@type":"Answer","text":"
You’re Tackling the issue backwards.<\/p>\n
You start with the proposition a DC will be a virtual machine, and seek business or technical arguments or reasons against it.<\/p>","upvoteCount":26,"datePublished":"2022-02-09T15:59:47.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/5","author":{"@type":"Person","name":"semicolon","url":"https://community.spiceworks.com/u/semicolon"}},{"@type":"Answer","text":"
What is your virtualization platform? Actually it doesn’t matter. You can virtualize all DCs on any hypervisor, even Hyper-V.<\/p>\n
How reliable is the connectivity between the remote sites and the main data center? I ask because if connectivity is reliable (say dual ISP circuit at each site), then the remote sites may not even need a local DC.<\/p>\n
My remote sites used to have a local DC. Now those are just member servers. We have dual ISP circuits at each location. If WAN is down, then phones are down, as is ERP. Having a local DC doesn’t buy much. We also centralized DHCP and DNS to the data centers<\/p>","upvoteCount":19,"datePublished":"2022-02-09T16:03:42.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/6","author":{"@type":"Person","name":"kevinhsieh","url":"https://community.spiceworks.com/u/kevinhsieh"}},{"@type":"Answer","text":"
If at all possible, yes virtualize your DCs.<\/p>","upvoteCount":15,"datePublished":"2022-02-09T16:04:18.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/7","author":{"@type":"Person","name":"tb33t","url":"https://community.spiceworks.com/u/tb33t"}},{"@type":"Answer","text":"
Read through Kevin’s Post. Good advice, depending on setup, you may not need all those DCs.<\/p>\n
And yes to virtualize, if you can.<\/p>\n
EDIT: we have about a dozen locations, 2 DC’s at our main data center. they handle the load just fine. going to be building a third here soonish at our Disaster Recovery site. the only time that DC would be used is if the main site goes down and we roll to DR.<\/p>","upvoteCount":4,"datePublished":"2022-02-09T17:44:59.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/8","author":{"@type":"Person","name":"GDaddy","url":"https://community.spiceworks.com/u/GDaddy"}},{"@type":"Answer","text":"
I’ve seen good arguments for still keeping one physical DC around over the past 5 years or so, but for the most part I wouldn’t bother in a modern setup. I don’t have a physical DC in my homelab anymore (although my hosts aren’t members of my AD) and haven’t had any issues. If you still want to have a physical DC, I’d suggest picking up something like an Intel NUC and setting it up as a backup DC, but still virtualize all of the others.<\/p>","upvoteCount":8,"datePublished":"2022-02-09T17:54:16.000Z","url":"https://community.spiceworks.com/t/virtualize-domain-controllers-yes-or-no/824612/9","author":{"@type":"Person","name":"Jrx1216","url":"https://community.spiceworks.com/u/Jrx1216"}},{"@type":"Answer","text":"