Relocating SYSVOL Manually
Applies To: Windows Server 2008, Windows Server 2008 R2
If you want to move all folders in the SYSVOL directory, you can relocate these folders manually. You must carefully copy all folders and retain the same level of security at the new location.
The recommended method for relocating SYSVOL is to remove Active Directory Domain Services (AD DS) and then reinstall AD DS with the new SYSVOL path. Because of the potential for error, we do not recommend relocating SYSVOL manually.
If you choose to move SYSVOL manually, you first copy the entire folder structure to a new location; then, you update the SYSVOL junction point and the parameters that are stored in the registry and in AD DS. As an option, you can relocate the staging areas subdirectory only. For information about relocating the staging areas subdirectory, see Relocating the SYSVOL Staging Area.
Before you relocate all or part of SYSVOL, be sure to inform domain administrators that you are doing so and that they should not make any changes in the SYSVOL directory until the move is complete.
Relocating SYSVOL can alter security settings if you do not use a copy method that retains file ownership and access control list (ACL) settings. The copy method that is described in this procedure retains security settings. After you move the SYSVOL tree, verify that the security settings on the relocated SYSVOL folders match the settings on the original SYSVOL folder structure. As an alternative, you can reapply security settings on the moved SYSVOL.
When you have completed SYSVOL relocation, force replication from the updated domain controller to a replication partner in the domain.
The following tools are required to perform the procedures for this task:
Active Directory Sites and Services
To prevent conflicts, use the updated version of Robocopy available in Microsoft Knowledge Base article 979808.
If you choose to reapply security settings manually, the following additional tools are required:
To complete this task, perform the following procedures:
You can use this procedure if you want to reapply the default security settings to the SYSVOL directory. However, if you use the Robocopy command that is specified in Copy SYSVOL to a New Location, file ownership and access control list (ACL) settings are retained on the copied SYSVOL folders and files, and reapplying security settings is not required.
After all these steps are complete and you verify replication succeeds, delete the original location of SYSVOL so only the new SYSVOL folder exists on the domain controller. By default, administrators are denied from deleting SYSVOL. You need to grant full control on all files, folders, and subfolders before you can complete the deletion.