Planning: Installation, roles, upgrades
Practice in VM + get accustomed to GUI (charms, how to logout, etc.), test software
Prepare hardware (map toolkit) > (Toolkit to test if your machine is good enough to migrate)
Min requirements (1,4 GHz 64-bit, 512MB RAM, 32GB)
A good time for hardware upgrades
Drivers > Mass storage > Unsigned
Pre-learn PS cmdlets you might need
Watch for removed/deprecated www.cbt.gg/MsccFZ Backup + have contingency
Roll out, in stages
Installing server core
Core:
Minimal attack surface
Small footprint
Highly reliable (90% updates -> GUI updates)
Easily managed
Winrs/winrm(enables you to remotely administer computers/servers), powershell, srv mgr, rsat.
Features on Demand
Reduce footprint by removing payload of unused items
Even if features are not enabled, these can be used by attackers, that is why removing the payload is always good practice.
Minimal server interface
Most attacks are done through a vulnerability in the UI.
Migrating roles (Example: Useful for migrating from 2003-2012)
Tools
Migrate from w2k3 sp2/r2, w2k8 full r2/Win 12 Full/Core (NOT w2k8 core)
Physical to virtual / Virtual to physical
Only to same UI languages
Admins on both machines
PS scripts
Migrate roles, features, system settings, shares, data,…