ConfigMgr Current Branch - Real World Migration from ConfigMgr 2012R2
ConfigMgr Current Branch 1606 was released to General Availability in July 2016 and there has been a lot of excitement about the in-place upgrade to the latest version. I've done quite a number of upgrades from ConfigMgr 2012R2 to Current Branch so I thought that this would be a good time to describe some of the real world issues associated with this operation. Many of the ConfigMgr 2012R2 implementations we encounter are installed on Windows 2008R2 servers. This was ok at the time. However if we want to configure Windows 10 servicing we now require Windows Server 2012R2 on the Primary Site Server and Software Update Points.
In this blog I'll describe the steps required to upgrade from ConfigMgr 2012R2 (installed on Windows Server 2008R2) to Current Branch 1606 (installed on Windows Server 2012R2).
(ConfigMgr 1602 supports the in-place upgrade of the Operating System from Windows Server 2008R2 to Windows 2012R2. However some customers don't like in-place upgrades of the operating system and would like to start off with a freshly installed OS).
To achieve this we must back up the site and restore it to a new Windows 2012R2 server. I've listed the high level steps to carry out this operation below.
1. In this blog I'm referring to the 2008R2 server as "old" and the 2012R2 server as "new"
2. These steps are based on migrating a standalone Primary Site server configured as a Software Update Point.
- If you are using VMs take a snapshot of old
- Back up the existing environment - I like to back up all the SQL databases with a SQL maintenance plan. It's also easy to back up the ConfigMgr site on old using the native ConfigMgr Site Backup maintenance task. Restart the SMS_Site_Backup component to start the backup immediately and monitor progress in the smsbkup.log file.
- Deploy new Windows 2012R2 server, fully patch and join domain - use any name for now but use the same drive configuration as old.
- Install Windows ADK 10 - you can still use version 1511. A new ADK version 1607 has just been been released. However official ConfigMgr support for ADK 1607 has not been announced at time of writing.
- Install ConfigMgr 2012 pre-requisites on new as normal (roles and features)
- Copy source content, content library, WSUS metadata share from old to new while retaining permissions - if you are using VMs it's easier to detach the VHDs from old and attach them to new.
- Turn off old.
- Rename new box to original Primary Site Server name
- ptionally re-use the static IP address on new. It shouldn't matter as ConfigMgr uses DNS. However it can be useful to avoid recreating firewall rules.
- Re-delegate permissions on System Management container
- Install a supported SQL server version
- Install WSUS (use SQL database) and carry out the initial WSUS metadata share configuration (use a different share name than previously, do not configure WSUS)
- Stop WSUS services and detach WSUSDB
- Rename SUSDB.mdf and SUSDB.ldf
- Restore SUSDB database from old with overwrite option selected
- Copy WSUS metadata from old share location to new share location
- Start WSUS services
- Install WSUS hotfix KB3095113
- Install ConfigMgr 2012R2 and choose the recover site option, finish the wizard (we can only restore to the same ConfigMgr version)
- Carry out the ConfigMgr 2012R2 post-recovery tasks as directed - eg update account passwords
- Re-configure the Software Update Point to use port 8530/8531 instead of 80/443 - examine WCM.log for success
- Verify ConfigMgr site and component status
- Test ConfigMgr functionality
- Run TestDBUpgrade for ConfigMgr Current Branch 1511
- Perform in-place upgrade to ConfigMgr Current Branch 1511
- Back up Configuration.mof (it will be overwritten by the upgrade)
- Perform in-console upgrade to ConfigMgr Current Branch 1602 or 1606
- Optionally install MDT and re-configure integration
- Upgrade ConfigMgr clients to 1602/1606
I encountered a number of issues during the process (mostly WSUS Issues).
- If there is an existing WSUS GPO you must change the port from 80 to 8530
- You may have to additionally open port 8530 between VLANs
- I was unable to open the WSUS console. The following error appeared in the event log "The WSUS administration console has encountered an unexpected error. Index was outside the bounds of the array". This was solved by adding the HTTP Activation feature (I'd forgotten that one).
- WSUS broke after installing the KB3159706 update. This was solved by opening an elevated Command Prompt window, and then running "C:\Program Files\Update Services\Tools\wsusutil.exe postinstall /servicing"
- Reporting was broken - there were duplicates of all reports preceded by an underscore. This was solved by removing and re-adding the reporting point
I hope some of the information here will be helpful for you.