Upgrading a domain controller that is also running RMS

Upgrading a domain controller that is also running RMS

If you have installed RMS (either Windows RMS on Windows Server 2003 or the AD RMS server role of Windows Server 2008) and want to upgrade the operating system on the domain controller, you must move RMS to another server before performing the upgrade. That's because running RMS on a domain controller presents a number of problems (for example, RMS groups are created as domain groups instead of local groups) that are only made worse when you upgrade the operating system.

To move RMS to another server and upgrade the operating system at the same time, you perform what's called a "join upgrade." To do this, you perform the following tasks:

  1. Install the upgraded operating system (Windows Server 2008 or Windows Server 2008 R2) on a second server that is a member of the domain where RMS is deployed.
  2. On the second server, add the AD RMS role and join it to the existing RMS cluster by following the instructions at Install AD RMS and join computer to existing RMS cluster. This will upgrade the RMS cluster database to the new version.
  3. Uninstall Windows RMS or remove the AD RMS server role from the domain controller.
  4. Upgrade the operating system on the domain controller.
  5. If RMS is running on any other member servers, upgrade the operating system of the other RMS servers, and then perform the following steps:
    1. Log on to the server on which you want to upgrade to AD RMS.
    2. Open Server Manager. Click Start, point to Administrative Tools, and then click Server Manager.
    3. Expand Roles, and then click Active Directory Rights Management Services.

      Note: An error message might appear when you perform this step. This does not indicate a problem with the upgrade. Click OK to continue.

    4. In the results pane, click Complete Installation of Active Directory Rights Management Services, and then follow the steps in the upgrade wizard to AD RMS.

Microsoft strongly recommends that you do not run the AD RMS server role on a domain controller. AD RMS is designed to run as a server role on member servers only.

Leave a Comment
  • Please add 7 and 5 and type the answer here:
  • Post
Wiki - Revision Comment List(Revision Comment)
Sort by: Published Date | Most Recent | Most Useful
Comments
  • Maheshkumar S Tiwari edited Revision 1. Comment: Added Tag and minor edit

Page 1 of 1 (1 items)
Wikis - Comment List
Sort by: Published Date | Most Recent | Most Useful
Posting comments is temporarily disabled until 10:00am PST on Saturday, December 14th. Thank you for your patience.
Comments
  • Maheshkumar S Tiwari edited Revision 1. Comment: Added Tag and minor edit

Page 1 of 1 (1 items)