Hi,
I'm conduction a domain transformation from a Windows Server 2008R2 Domain Controller infrastructure to Windows Server 2016 Domain Controllers.
At a very, very, high level the process will be
1. Build new Win Svr 2016 servers, add them to the domain, and promote them to DC's
2. Transfer the FSMO roles from the 2008R2 DC's to the 2016 DC's
3. Demote the 2008R2 DC's
4. Raise the Domain/Forrest Functional Level to Server 2016
One of our stake holders has asked
- How this will this impact Kerberos keytab files?
- How will Kerberos be impacted?
- Will there be any impact to live services using Kerberos keytab files to authenticate?
- Will the Kerberos keytab files still be valid after decommissioning the 2008R2 DC's?
I'm struggling to find any documentation, that covers my scenario, to help me answer this.
Can anyone please advise?
Thanks,