Domain Services and Active Directory Roles Migration — Domain Controller Move to New Server
Domain Services and Active Directory Roles Migration transfers the typical functions of a domain controller, including DNS and DHCP, to a new server. This service may be necessary when migrating from an SBS server to a new server, or from an On-Premises solution to Microsoft 365 when you want to keep the Domain Controller in your network but need a new operating system or hardware.
What this engagement is
This service helps transfer typical Domain Controller functions, including DNS and DHCP, to a new server. IT Partner responsibilities include Domain Controller preparation and promotion, transfer of Domain Controller roles, transfer of group policy, groups, and users, DNS server transfer, and DHCP server transfer. The plan may include verification of work and demotion of the old DC.
Success criteria
What you receive
How the work unfolds
Confirm the environment details, roles to transfer, schedule, access, and points of contact.
Prepare the new server and promote it to a Domain Controller in the existing domain.
Transfer Domain Controller roles, group policy, groups and users, DNS, and DHCP to the new server in stages.
Verify that the new Domain Controller performs all required functions, including authentication, GPO application, DNS, and DHCP.
Demote the old Domain Controller once the new server is verified, so it can be safely turned off.
Perform final verification across users and services and fix issues found within scope.
Prerequisites
Who does what
IT Partner
- Domain Controller preparation and promotion
- Transfer of Domain Controller roles
- Transfer of group policy, groups, and users
- DNS server transfer
- DHCP server transfer
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Coordinate any outside vendor resources and schedules
- Provide administrative access to the Active Directory domain and servers
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
What's not included
Limitations & technical notes
Frequently asked questions
What is included in the Domain Services and Active Directory Roles Migration service?
The Domain Services and Active Directory Roles Migration service includes preparing and promoting a new Domain Controller, transferring Domain Controller roles, transferring group policy, groups, and users, and transferring DNS and DHCP services. The engagement is designed to move the typical functions of an existing domain controller to a new server while preserving the required Active Directory, DNS, DHCP, and GPO functionality.
When would a business need this Active Directory domain controller migration service?
This service is typically needed when replacing an older domain controller, moving away from an SBS server, or keeping an on-premises Domain Controller while moving other services to Microsoft 365. It is also appropriate when the organization needs new server hardware or a newer operating system for its Domain Controller.
How long does the Domain Services and Active Directory Roles Migration take?
The listed service duration is 3 days. Actual timing depends on your environment and is confirmed with IT Partner during the kickoff meeting.
How is the service priced?
The service is priced at a fixed $900 per project, quoted in writing before work begins — you pay after you approve delivery. Work outside the stated scope — such as operating system installation on the new server or migration to Entra ID — is quoted separately.
What are the prerequisites before the migration can start?
Before the engagement starts, the operating system for the new Domain Controller must already be installed, and all devices should be configured to use a DHCP server. These prerequisites matter because the service scope does not include remote Windows OS installation on the server or support for devices with static network settings.
Does this service include installing Windows Server on the new domain controller?
No, remote installation of the Microsoft Windows operating system on the server is not included in this service. This exclusion applies, for example, when using a virtual machine or remote server management technologies such as iLO, so the new server OS should be installed before the migration begins.
Does this service include migration to Microsoft Entra ID?
No, migration to Microsoft Entra ID is not included in the Domain Services and Active Directory Roles Migration service. The service is focused on transferring on-premises Domain Controller functions, including DNS and DHCP, to a new server.
What happens during the Active Directory migration engagement?
The engagement typically starts with a kickoff meeting, followed by preparation of the new server, staged transfer of roles and data, verification of work, demotion of the old Domain Controller, and final verification with issue fixing if needed. This staged approach helps confirm that the new Domain Controller can perform the required functions before the old one is turned off.
Will Group Policy settings be preserved during the migration?
Yes, preserving Group Policy settings is part of the stated success criteria for this service. IT Partner’s responsibilities include transferring group policy, groups, and users, so GPO settings are included in the migration scope.
What happens to the old Domain Controller after the migration?
The implementation plan may include demotion of the old Domain Controller after the new Domain Controller is verified. A stated success criterion is that the old Domain Controller is demoted and can be turned off.
Are devices with static IP or static network settings supported by this service?
No, support of devices with static network settings is not included in this service. The prerequisites state that all devices should be configured to use a DHCP server, so any static-device remediation should be handled separately or discussed with IT Partner before the engagement.
How is completion of the migration verified?
Completion is verified against criteria such as the new Domain Controller being available to users, users being able to log in, GPO settings being saved, DHCP working with settings preserved, and the old Domain Controller being demoted and ready to turn off. The implementation plan also includes verification of work and fixing issues if any are found within the engagement scope.