Categories: Windows ServerTags: Active Directory Migration, IP Address Stealing, SRV records, SRV Recovs, Windows Server 2025After decommissioning the old domain controllers, one final polish step can make your migration airtight: reassigning the IP addresses of your legacy DCs to the new ones. This isn’t required for Active Directory to function correctly, but it can eliminate surprises from hardcoded references to old DC IPs in firewalls, scripts, monitoring tools, or the […](Read more...)
After decommissioning the old domain controllers, one final polish step can make your migration airtight: reassigning the IP addresses of your legacy DCs to the new ones. This isn’t required for Active Directory to function correctly, but it can eliminate surprises from hardcoded references to old DC IPs in firewalls, scripts, monitoring tools, or the memory of seasoned admins.

Planning IP Reassignment
Assume:
We now want to give DC2025-1 the 192.0.2.10 IP and DC2025-2 the 192.0.2.11 IP. Before doing so, ensure the old DCs are shut down to avoid IP conflicts.
Executing the IP Change
1. Prepare for Change
Downtime is usually unnecessary, especially with multiple DCs in place. Still, a maintenance window is helpful.
2. Change IP on DC2025-1
3. Update DNS Records
4. Repeat for DC2025-2
5. Reverse DNS Update
6. Notify Network Team
Testing After Reassignment
Ping Domain and DNS Test
Log Review
Admin Tip
Changing the IP triggers NetLogon and DNS updates. Clients querying DC info will receive new IPs quickly. Cached info clears naturally over time, providing graceful fallback for clients or services not yet updated.
Optional: Hostname Reuse (Not Recommended)
We avoided reusing hostnames. While technically possible, it introduces complexity:
If necessary, add CNAME records and register old names as SPNs. Otherwise, focus on IP reuse.
Real-World Insight
In one case, IP reassignment solved a firewall routing issue. Remote clients were only allowed to reach the old DC IPs. When the new DCs took over those IPs, everything began functioning as expected.
Wrapping Up
Your new DCs are now indistinguishable from the old ones—they have the same roles, IPs, and cleaner environments. We’ve set the stage for a fully transitioned AD. Next, we configure proper NTP settings on the new PDC Emulator to ensure time sync stability.
Onward to Part 8: NTP Configuration and Time Service Alignment!
Cristal Kawula, Checkyourlogs.net