Upgrading Domain Controllers from 2012R2 to 2022: What to Expect with Kerberos Changes?

0
1
Asked By TechieGamer99 On

I'm in the process of upgrading my environment from Windows Server 2012R2 to 2022. Most of the member servers are already migrated, but I have some concerns regarding changes to Kerberos on the domain controllers. I've heard that older systems might face authentication issues, and I don't want to run into any problems during this transition. I think I came across references to CVE-2025-26647 and CVE-2022-37967, but I can't recall the specifics. I'm hesitant to deploy 2022 DCs with the latest updates if it could impact the remaining 2012R2 servers. Can anyone clarify this situation for me?

4 Answers

Answered By ServerWhiz456 On

You'll be good to go! The real concern is the jump to 2025 for the DC OS, which can cause issues if you don't manage it carefully. You can keep your functional level lower for now if it helps.

CuriousCoder77 -

Got it! I’m definitely not pushing for 2025 just yet. Thanks for the heads-up!

OldSchoolAdmin03 -

Is it really the OS version that's the issue, rather than the domain functional level?

Answered By SecureNetworkGuy On

Just go ahead and install the 2022 servers, but avoid updating them beyond the last patch level of your 2012R2 servers for now. Migrate your Active Directory, and once that's done, fully patch the 2022 servers. Remember, it's not only Kerberos; DCOM changes could also create issues.

Answered By AdminExpert101 On

Make sure you test everything before fully migrating. I encountered some weird behaviors during my upgrade.

Answered By FutureReadyAdmin On

I migrated from 2012R2 to 2025 without any hiccups. If you're worried, consider setting up a 2016 or 2019 server as a middle step while you transition from 2012R2.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.