Migrating Kris Corporation to Windows Server 2012 Active Directory
This paper presents a comprehensive technical plan for migrating Kris Corporation's Active Directory infrastructure from Windows Server 2008 to Windows Server 2012. The organization operates across five locations — Atlanta, Baltimore, Chicago, Seattle, and San Diego — and faces challenges related to multi-domain management, disaster recovery, physical server space, and real-time procurement identity requirements from automobile manufacturers. The paper covers the rationale for migration, a step-by-step migration procedure, the transition from a multi-domain to a single-domain model, single sign-on configuration via AD DS, DNS security strategies, DHCP fault tolerance and address tracking, Hyper-V virtualization trade-offs and clustering, and network redesign for improved file sharing and security across all sites.
- Introduction to Active Directory for Kris Corporation: AD fundamentals, domain controllers, and Kris Corporation's topology
- Why and How to Migrate to Windows Server 2012 AD: Migration rationale, step-by-step procedure, and single-domain transition
- DNS: Placement and Security Strategies: DNS server placement and security measures against common attacks
- DHCP Fault Tolerance and Address Tracking: DHCP failover configuration and IP address tracking via IPAM
- Hyper-V: Evaluation, Clustering, and Features: Hyper-V pros, cons, clustering for disaster recovery, and key features
- Routing and Network Security for File Sharing: Network redesign for inter-site file sharing and security improvements
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Provides a concrete, numbered step-by-step migration procedure grounded in real Windows Server 2012 tooling, making the argument operational rather than purely theoretical.
- Consistently ties each technical recommendation back to Kris Corporation's specific business constraints — physical space limitations in Atlanta, disaster recovery concerns, and real-time procurement identity requirements — demonstrating applied rather than generic analysis.
- Balances breadth (covering AD, DNS, DHCP, Hyper-V, and routing) with sufficient depth in each section to give a complete infrastructure picture.
Key academic technique demonstrated
The paper employs applied problem-solution structuring: each major section identifies a specific organizational pain point and then proposes a technically grounded resolution. This approach keeps the analysis anchored to the client scenario rather than drifting into abstract exposition, which is a strong model for IT systems design papers at the undergraduate level.
Structure breakdown
The paper opens with a contextual introduction explaining Active Directory fundamentals and Kris Corporation's network topology. It then moves through five numbered technical domains — AD migration rationale and procedure, DNS, DHCP, Hyper-V, and routing/security — each organized around sub-questions that mirror a real systems design brief. The conclusion of each section feeds into the next, creating a coherent migration and infrastructure upgrade narrative. References follow APA formatting conventions.
Introduction to Active Directory for Kris Corporation
Kris Corporation's parent domain (kris.local) and child domain (corp.kris.local) for the organization's Active Directory (AD) infrastructure are running on Windows Server 2008. The company faces several AD-related concerns: it is concerned about managing multiple domains, and automobile manufacturers are asking Kris Corporation to use a single identity to procure orders in real time. The company operates across five locations — Atlanta (GA), Baltimore (MD), Chicago (IL), Seattle (WA), and San Diego (CA) — with manufacturing plants in Atlanta and Seattle. Disaster recovery is a major concern, physical server space is limited at the Atlanta location, most IT staff are based in Atlanta (the company headquarters), and file sharing among sites is difficult since all locations are independently connected to the internet.
Kris Corporation needs to migrate from Windows Server 2008 to Windows Server 2012 Active Directory to address most of its current issues and concerns. Active Directory is a database that enables Kris Corporation to track all user accounts and passwords. It allows passwords and user accounts to be stored and protected in a single location, enhancing the company's overall security. An Active Directory environment can comprise at least one domain, and every domain within it acts as a security boundary.
A domain controller (DC) is a server used to host each domain. The DC is responsible for managing all passwords and user accounts for a domain stored in one location. AD includes a feature that allows network administrators to set baseline password parameters — for instance, minimum length, password complexity, password change interval, maximum number of failed attempts, and lockout functionality. These controls enhance security and reduce the likelihood of successful attacks such as brute-force attacks.
Because Kris Corporation is a large organization, Active Directory enables its network administrators to simplify processes involved in maintaining a complex network. Updating a single AD object in one step performs an automatic update, eliminating the need for manual updates by the network administrator. Administrators can also grant or deny access to specific applications for end-users via network trees based on Active Directory. Large networks like Kris Corporation's can be maintained and organized through Active Directory, removing the need to perform every task through a single manual process.
Active Directory can be highly complex, as it supports distributed networks like Kris Corporation's; therefore, a knowledgeable network administrator is essential. Without AD, Kris Corporation would find it very difficult to effectively store data and information across its vast network. Each of the five company locations is connected on a domain, which stores all information in a central location (the DC) rather than on the hard drive of each individual computer. A global catalog (kris.local) controls each domain, tracking all registered network devices. It stores computer names, IP addresses, and user information, enabling the global administrator to monitor and manage everything occurring on the domain. Since everything is linked on the back end, all a user needs to locate any computer on the network is its name.
The domain controller governs permissions within AD, meaning the DC has already assigned permissions to every user in the domain. As a result, users in the Kris Corporation network can experience efficient digital communication, with information available and all network resources accessible.
The proposed single-domain topology connects the Baltimore, Seattle, Chicago, and San Diego locations to the Atlanta headquarters — which acts as the DC and Global Catalog Server — through the cloud, consolidating the company's AD infrastructure into a unified structure.
Why and How to Migrate to Windows Server 2012 AD
Why Should the Company Migrate to Windows Server 2012 AD?
Kris Corporation should migrate from Windows Server 2008 to Windows Server 2012 AD because the newer platform delivers a more advanced AD infrastructure. Windows Server 2012 includes features optimized for the cloud and provides a range of capabilities to help Kris Corporation deploy highly available applications stored in the cloud — directly addressing the Atlanta location's lack of physical server space. Hyper-V, PowerShell 3.0, SMB 3.0, and an improved virtualization hypervisor are among the features the company needs to exploit in order to overcome the challenges it faces across its five locations (Desmond, 2013).
PowerShell 3.0 introduces over 2,300 additional cmdlets, providing more granular control over the operating system. The company can enjoy broader data center control through commands executed remotely via PowerShell remoting. Virtualization capabilities are also significantly improved in Server 2012, with Hyper-V 3.0 supporting up to 64 processors and 1 TB of memory. The VHDX format offers a larger disk storage capacity along with greater resilience compared to Windows Server 2008. The Server Core feature, which provides command-line administration, is enhanced in Server 2012 for better performance. Unlike a full GUI (graphical user interface), Server Core offers greater security and supports administration from remote locations. By deploying a role, users of the Kris Corporation network can easily switch between the GUI Server Manager and Server Core views (Desmond, 2013).
Additional Windows Server 2012 features that will benefit Kris Corporation include easier replication, dynamic access control, access to better management tools, DHCP failover, AD Recycle Bin improvements, and an updated DNS system. Replication and DHCP failover are particularly valuable for disaster recovery, enabling the organization to maintain operations during and after a disaster. Databases across the different branches can be pointed to an alternative replication site for backup and data access. DHCP failover can continue IP management operations when the primary DHCP server goes offline, sustaining the network — making it equally valuable as a disaster recovery mechanism (Desmond, 2013).
How Should the Company Migrate to Windows Server 2012 AD?
By migrating to Windows Server 2012, Kris Corporation is taking a step toward adopting a cloud solution. Before the migration begins, the company must download Windows Server 2012 R2, perform a full backup of the existing Windows Server 2008, and verify the current AD DS Schema version by running the regedit command. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters and check the Schema's current version. To avoid failure of the new AD server, the organization should first create a test or simulation environment to validate the new setup. Running both the old and new AD servers in parallel for a period is also advisable to mitigate risk (parallel changeover). A clear fallback plan should be in place — the old server should remain on standby in case the new server fails to meet AD requirements (Desmond, 2013).
Once the newly installed Windows Server 2012 has been confirmed to work, the migration process can begin.
Step 1: Use the adprep Command to Prepare the Existing Forest
1. Open the Windows Server 2008 R2 AD DS DVD drive and insert the DVD containing Windows Server 2012.
2. Open the command prompt, type adprep /forestprep, and press Enter.
3. Using the procedure described above, verify the Schema's current AD DS version (Desmond, 2013).
Step 2: Promote the Windows Server 2012 Domain Controller
1. Open the Server Manager Console and select "Add roles and features."
2. Choose "Role-based or Feature-based Installation." Click "Next."
3. Under "Roles," select "Active Directory Domain Services."
4. Click "Add Features" to accept the required default features.
5. Click "Next" on the Features screen.
6. On the next window, check "Restart the destination server automatically if required." Click "Install" on the "Confirm Installation Selections" window.
7. Upon completion, click "Close" to exit the installation window.
8. A notification with a yellow exclamation mark appears on the dashboard. Click on it and select "Promote this server to a domain controller."
9. Under "Select a deployment operation," select "Add a domain controller into existing domain."
10. Select or type the target domain — in this case, kris.local.
11. Click "Change" to provide the network administrator's credentials. Click "Next."
12. Specify the domain controller capabilities: check "Domain Name System (DNS) server" and "Global Catalog." Select the DC site — Atlanta (GA), the company headquarters.
13. Type the Directory Services Restore Mode (DSRM) password and confirm it.
14. Click "Next."
15. On the "Additional Options" screen, choose to install the DC from media or select a replication source. The server will select the best location from which to replicate the AD database. Click "Next."
16. Select the storage location for the AD database, log files, and SYSVOL folders. Click "Next."
17. The Schema and Domain preparation performed earlier is automatically executed by the system at this step.
18. Click "Next" to review selected options on the "Review Options" screen. Click "View Script" to automate future installations via PowerShell script.
19. Click "Next" to proceed.
20. Upon successful prerequisite checks, click "Install" to begin DC installation. The server restarts automatically once the Windows Server 2012 DC is set up.
21. Update NIC properties on every server under the target domain to point to the new Windows Server 2012 DC. Open the DHCP management console, select option 006, and add the new DC's IP address as a DNS server in the server/scope options window.
22. Click "OK" (Desmond, 2013).
Step 3: Verify the Newly Installed Windows Server 2012 DC
1. Open "Active Directory Users and Computers," expand the Kris Corporation domain, and click on the DC to confirm the server is listed.
2. Open "DNS Manager" and right-click the Kris Corporation domain. Select "Properties," click the "Name Servers" tab, and confirm that the company's server appears in the Name Servers list.
3. Open "Active Directory Sites and Services" and under Default-First-Site-Name, confirm the company's server is listed under "Servers" (Desmond, 2013).
Step 4: Flexible Single Master Operations (FSMO) Role Transfer
1. Open the "Active Directory Users and Computers" console on the server running the newly installed Windows Server 2012.
2. Select and right-click Kris Corporation's domain. Under the sub-menu, select "Operations Masters."
3. Select the RID tab on the Operations Masters window.
4. Click "Change" to transfer the operations master role.
5. Click "Yes" when prompted to confirm.
6. Click "OK" upon successful transfer.
7. Verify that the Operations Master box reflects Kris Corporation's new Windows Server 2012.
8. Configure the PDC and Infrastructure tabs by repeating steps 4 through 6.
9. Click "Close" to exit the Operations Masters window.
10. Close the "Active Directory Users and Computers" window (Desmond, 2013).
Step 5: Windows Server 2008 R2 Domain Controller Removal
1. Click "Start," then "Run" on the Windows Server 2008 R2 computer and type dcpromo. Click "OK."
2. The "Welcome to the Active Directory Installation Wizard" opens. Uncheck the option "Delete the domain because this server is the last domain controller in the domain."
3. Enter the correct password on the "Administrator Password" page. Click "Next."
4. Click "Next" on the "Summary" page and wait for the process to complete. Click "Finish."
5. Click "Finish" on the "Completing the Active Directory Domain Services Installation Wizard" page.
6. Click "Restart Now" to restart the server.
7. After the reboot, remove the Windows Server 2008 R2 Server from the domain to a workgroup. In the "Active Directory Sites and Services" console, delete all unnecessary records (Desmond, 2013).
Should the Company Remain on the Multi-Domain Model or Migrate to Single Domain?
The company should migrate to a single domain, as outlined in the migration procedure above. Although multiple domains reduce the risk of organization-wide security compromise, they come with additional cost. Implementing a single domain alongside appropriate security controls can achieve the same functionality as a multi-domain model at lower cost. A single domain will also give Kris Corporation the unified identity that automobile manufacturers require to procure orders in real time (Desmond, 2013).
What Technology Can Provide Single Sign-On? How Will It Be Configured?
Active Directory Domain Services (AD DS) stores all information about network objects and ensures that both administrators and users can access this information. AD DS uses Domain Controllers to provide users access to permitted resources anywhere on the network through a single sign-on process. The installation of AD DS is covered above in Step 2 — Promoting the Windows Server 2012 Domain Controller (Desmond, 2013).
DNS: Placement and Security Strategies
Where Should DNS Servers Reside?
The target Domain Controller Server is configured as the primary DNS server, as described in Step 2 of promoting the Windows Server 2012 DC. DNS servers typically reside on the domain controller servers of each domain, configured to act as Domain Name Service servers (Minasi, 2014).
What DNS Security Measures Can the DNS Servers Leverage?
DNS servers are vulnerable to a range of security threats, including resource utilization and cache poisoning attacks, denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks from open DNS resolvers, and DNS amplification and reflection attacks. To mitigate these threats, Kris Corporation can implement the Berkeley Internet Name Domain (BIND), disable recursion, randomize the DNS transaction identifier, randomize UDP source ports in BIND, use DNS Security Extensions (DNSSEC), and segregate authoritative and recursive resolvers. Unicast Reverse Path Forwarding, IP source guard, and access control lists can help prevent DNS server spoofing. Firewalls can also be deployed to improve DNS security.
One of the most common attacks on DNS servers is the pharming attack — an attack that exploits outdated DNS server software to redirect traffic to a rogue DNS server in order to analyze traffic patterns and network structure for further exploitation. Anti-pharming configurations and prevention of remote code execution should be implemented on the DNS server to guard against this threat (Minasi, 2014).
Create your account
Always verify citation format against your institution’s current style guide requirements.