Windows Server 2026 DCPromo to Windows 2012 R2 AD

R Feld 0 Reputation points
2026-09-29T12:59:44.0633333+00:00

We have a Windows 2012 R2 AD infrastructure and finally were able to purchase a new server to replace the current infrastructure. The 2012 server is not only the FSMO roles but also the file and print server. When we tried to promote the new DC to a DC within the 2012 R2 infrastructure I was told that the forest and domain need to be promoted to at least 2015. The process being replace all the 2012 servers with 2015 and raise the level and this cannot happen. Is there any other way to get this level higher than 2012R2?

Then I thought build a new AD forest and domain, transfer the computers, users and resources to the new infrastructure and then dismantle the old 2012 R2 AD and server. Does this make sense? Any suggestions to modify?

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
0 comments No comments

2 answers

Sort by: Oldest
  1. Tracy Le 13,130 Reputation points Independent Advisor
    2026-09-29T13:58:06.0366667+00:00

    Hello R Feld,

    The requirement you encountered relates to the Forest and Domain Functional Levels rather than having an intermediate server build. Windows Server 2025 and 2026 domain controllers require a minimum Functional Level of Windows Server 2016. Because a Functional Level cannot exceed the operating system version of any existing domain controller in the domain, your current Windows Server 2012 R2 domain controller physically prevents raising the domain to the 2016 level while it hosts active DC services.

    Instead of rebuilding a completely new forest and migrating all users and devices, the cleanest in-place upgrade path is introducing an intermediate Windows Server 2016 or 2019/2022 instance into your current domain. Promote this temporary server to a secondary domain controller, transfer the five FSMO roles using Move-ADDirectoryServerOperationMasterRole, migrate your file shares and print queues, and gracefully demote the old 2012 R2 machine using Server Manager or Uninstall-ADDSDomainController. Once the 2012 R2 server is decommissioned, raise your forest and domain functional levels to Windows Server 2016 via Set-ADForestMode and Set-ADDomainMode, which immediately unblocks adding your new 2026 server as a domain controller. If this migration strategy clarifies your path forward, please feel free to accept the answer.

    Tracy Le.

    Was this answer helpful?

    0 comments No comments

  2. Allan Solomon Mejia 10,225 Reputation points
    2026-09-29T13:58:38.5033333+00:00

    Hi @R Feld

    Assuming “Windows Server 2026” means Windows Server 2025, the error is expected. Windows Server 2015 isn't a functional level. The required level is Windows Server 2016.

    You can't add a Windows Server 2025 domain controller while the domain and forest remain at the Windows Server 2012 R2 functional level. However, Windows Server 2016, 2019, or 2022 domain controllers can operate at the 2012 R2 functional level.

    The least disruptive migration path is:

    1. Add a temporary Windows Server 2022 member server to the existing domain.
    2. Install AD DS and DNS, then promote it as an additional domain controller.
    3. Verify DNS, replication, SYSVOL, Global Catalog, and AD backups.
    4. Transfer all FSMO roles to the Server 2022 DC.
    5. Demote and remove the Windows Server 2012 R2 DC.
    6. Raise the domain functional level first, then the forest functional level, to Windows Server 2016.
    7. Join and promote the new Windows Server 2025 server.
    8. Transfer the FSMO roles to the final server, verify AD health, and then retire the temporary Server 2022 DC if it isn’t required.

    Microsoft documents the process of adding a newer DC, transferring FSMO roles, verifying the role holders, demoting the older DC, and then raising the functional levels.

    Building a separate forest isn’t necessary unless you intentionally want a new security boundary and are prepared to migrate identities, computers, profiles, permissions, and applications. For a straightforward hardware and operating-system replacement, preserving the existing domain is normally much simpler.

    Windows Server 2012 R2 can also be upgraded directly to Windows Server 2025 under Microsoft’s current supported upgrade matrix. However, because this server holds AD DS, FSMO, file, and print services, I’d favor the side-by-side route above instead of upgrading the only multifunction domain controller in place. Microsoft requires verified backups and checking role compatibility before any upgrade or migration.

    References:

    AD DS functional levels

    Upgrade domain controllers

    Identify the functional-level upgrade path

    Plan a Windows Server upgrade


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.