Stéphane Thirion
  • Home
  • Consulting – Raidho
  • homelab
3K
0
0
0
Stéphane Thirion
Stéphane Thirion
  • Home
  • Consulting – Raidho
  • homelab
  • Windows 2016
  • Windows 2019

Migration farm ADFS operating system Windows server 2016 to Windows server 2019

  • January 6, 2021
  • Rodolphe Herpeux
Total
1
Shares
0
0
1
0
0
0
0

Context

This document describes how to migrate farm ADFS install in Windows 2016 server operating system to Windows 2019 server operating system.

Environment

ADFS Farm

  • The ADFS farm is composed by:
    • Two ADFS servers:
      • ADFS01
      • ADFS02
    • One server WAP
    • One MS SQL server 2016

Requirements

To realize these operations, we need to have an account with enterprise admin privileges. Ensure ADFS service account has the administrative permissions on the SQL server and each server in the ADFS farm.We recommend to backup your environment with the official Microsoft tools before start this migration. Minimum 20 Go free space on system drive.

Migration plan

Upgrade operating system

In this first step, we upgrade operating system with upgrade in place mode. In this mode we just upgrade the operating system in place with new operating system server.

Comments Captures
Insert DVD of Windows server 2019 in the drive of the server
Double click on DVD drive to explore the content
Double click on setupe.exe file to launch upgrade

Select in the panel “Not right now”

Click on “Next” button

Add license key

Click on “Next” button

Select “GUI” installation mode

Click on “Next” button

Accept license terms
Select “Keep personal files and apps”

Click on “Next” button

Click on button “Confirm” to validate we need to setting AD FS service after upgrade
Click on button “Install”
The upgrade start

The progress of the installation take 30 minutes

Setup AD FS service

Comments Captures
After the update is completed, open a session on the server with an account with privileges Enterprise admin
In server manager console, launch “configure the federation service on this server”
Select “add a federation server to a federation server farm”

Click on “Next” button

Select the account with the enterprise admin privileges

Click on “Next” button

Select “Specify the database location for an existing farm using SQL Server”

Add “Database Host Name” and “Database instance”

Click on “Next” button

Select in drop menu the good communication certificate

Click on “Next” button

Add the account service for AD FS service and password

Click on “Next” button

Click on “Next” button
Verify if no issues

Click on “Configure” button

Click on “Close” button

Check AD FS service

To check if the service is started, retrieve event ID 100 in event viewer console

Check in AD FS mmc if you are connected to the service and verify if you retrieve all relaying party truts

Check the connection to the database

Deploy new DB on MS SQL Server

Export script to creation

Execute the following command:
Export-AdfsDeploymentSQLScript -DestinationFolder c:temp -ServiceAccountName "adsvc-adfs"
This command export two scripts with all command lines to create the new DB in V4.

Raise level of the farm

Ensure ADFS service account has the administrative permissions on the SQL server and each server in the ADFS farm.

From an ADFS server run Powershell in administrator mode and execute this command:
$creds = Get-Credential

Invoke-AdfsFarmBehaviorLevelRaise -Credential $creds

Take the database V3 offline

Set permission on database

Copy/paste the content of the second file “Setpermissions.sql” in MS SQL Management studio

Get current version of ADFS Farm

Upgrade the Configuration Version of existing WAP servers

Run the same action describes in chapter “Upgrade operating system”

Verify web application proxy configuration

Get-WebApplicationProxyConfiguration

Remove old database V3

Connect on MS SQL Server and open administration server SQL console.
Select the database name “ADFSConfigurationV3”, click right on the database and select “Delete”

Select “Close existing connections” and press on button “OK”

Go to explorer and brows path to the database file and log

Select files “ADFSConfigurationV3”, click right on them

Select in the dropdown menu “Delete”

Clean old installation of Windows server 2016

After upgrade operating system, a folder is created with the old OS. We need to delete this folder if the OS upgrade is validating.
To delete this folder, please execute these steps:

 

Total
1
Shares
Tweet 0
Share 0
Share 1
Share 0
Share 0
Share 0
Share 0
Related Topics
  • ADFS
  • Migration
  • Operating System
Rodolphe Herpeux

Previous Article
  • Windows 2016

Migrate ADFS configuration Database from WID to MS-SQL

  • January 5, 2021
  • Rodolphe Herpeux
View Post
Next Article
  • RDS
  • Security
  • Windows 2016

RDS access to applications with second authentication factor by smartcard

  • January 7, 2021
  • Rodolphe Herpeux
View Post
You May Also Like
View Post
  • RDS
  • Security
  • Windows 2016

RDS access to applications with second authentication factor by smartcard

  • Rodolphe Herpeux
  • January 7, 2021
View Post
  • Windows 2016

Migrate ADFS configuration Database from WID to MS-SQL

  • Rodolphe Herpeux
  • January 5, 2021
View Post
  • Citrix
  • Citrix Virtual Apps and Desktops
  • Microsoft
  • PowerShell
  • Scripting
  • Windows 2016
  • Windows 2019
  • XenApp
  • XenDesktop

Enable SSL on Citrix Virtual Apps and Desktops 1912(+) XML Service

  • Stephane Thirion
  • February 13, 2020
View Post
  • Microsoft
  • Windows 2019

Migrating FSMO roles Windows 2019 Server

  • Stephane Thirion
  • November 5, 2018
View Post
  • Azure
  • Azure
  • Citrix
  • Citrix Virtual Apps and Desktops
  • Cloud
  • Microsoft
  • Windows 2019
  • Windows Virtual Desktop

Microsoft, Citrix, 2019, 1808.2 etc…

  • Stephane Thirion
  • October 16, 2018
View Post
  • Experience
  • Microsoft
  • PowerShell
  • Scripting
  • Windows 2016
  • XenApp

XenApp Windows 2016 build report

  • Stephane Thirion
  • May 25, 2018
View Post
  • Microsoft
  • PowerShell
  • Uncategorized
  • Windows 2016

Hyper-V 2016 – Add-VMTPM issue

  • Rodolphe Herpeux
  • October 28, 2017
View Post
  • Microsoft
  • PowerShell
  • Windows 2012R2
  • Windows 2016

Active Directory Certificate Services [Part2]

  • Rodolphe Herpeux
  • October 5, 2017
vmware
Coinbase – Affiliated link
Blog Stats
  • 1,237,017 hits
Categories
  • Amazon (1)
  • Apple (20)
    • iOS (5)
    • Mac OSx (11)
  • ArchY.net Site (30)
  • Azure (8)
  • Certifications (3)
  • Citrix (207)
    • ADC (1)
    • Citrix Virtual Apps and Desktops (3)
    • NetScaler (12)
    • Password Manager (3)
    • Personal vDisk (5)
    • Power and Capacity Management (3)
    • Provisioning Services (22)
    • Receiver (29)
    • ShareFile (8)
    • Single Sign On (3)
    • SmartAuditor (2)
    • Storefront (12)
    • Synergy (25)
    • User Profile Management (2)
    • VDI (7)
    • WebInterface (21)
    • XenApp (84)
    • XenApp Plugin (3)
    • XenClient (10)
    • XenDesktop (55)
    • XenServer (42)
  • Cloud (12)
  • Crystal Ball (2)
  • CTP (13)
  • Docker (2)
  • Events (35)
    • E2E – PubForum (9)
    • Geek Speak (3)
  • Experience (53)
  • Kubernetes (2)
  • Licensing (3)
  • Linux (12)
  • Microsoft (145)
    • Azure (8)
    • Office365 (4)
    • PowerShell (18)
    • RDS (5)
    • Windows 10 (6)
    • Windows 2003 (21)
    • Windows 2008 (20)
    • Windows 2008 R2 (54)
    • Windows 2012 (13)
    • Windows 2012R2 (13)
    • Windows 2016 (18)
    • Windows 2019 (4)
    • Windows 2022 (1)
    • Windows 7 (27)
    • Windows 8 (19)
    • Windows Virtual Desktop (1)
    • Windows XP (11)
  • News (5)
  • Raidho (2)
  • Raspberry (3)
  • Scripting (13)
  • Security (4)
  • Slide Deck (1)
  • Thin Clients (3)
  • Twitter (1)
  • Ubiquiti (1)
  • Uncategorized (12)
  • VMware (27)
    • VMWare WorkStation (2)
    • vSphere (15)
Stéphane Thirion
Don't Follow the Trend

Input your search keywords and press Enter.

 

Loading Comments...