For a hardware refresh that must preserve your Configuration Manager (ConfigMgr, formerly SCCM) site identity, do not build a second primary site and run the Migration Wizard. Use a passive site server for a supported CAS or child primary site; use backup and site recovery for a standalone primary site; choose a side-by-side hierarchy migration only when the hostname, site code, hierarchy, or design must change.
The correct method depends on where SQL Server, the content library, WSUS, and site-system roles run. Treat those as separate components, protect them independently, and test a rollback before cutting over.
Choose the method before touching the old server
| Situation | Recommended method | Identity result |
|---|---|---|
| CAS or child primary; planned hardware replacement | Site server high availability with a passive site server | Existing site identity is retained |
| Standalone primary, or passive mode is unavailable | Configuration Manager backup and site recovery | Retain the original site code, database name, hostname and FQDN |
| New hostname, site code, domain, or redesigned hierarchy | Side-by-side hierarchy migration | New hierarchy; clients and supported objects are migrated |
| Only the operating system changes on the same machine | Supported in-place Windows upgrade | Not a hardware migration; verify the exact support matrix |
Microsoft documents passive site servers for a central administration site (CAS) and child primary sites, not secondary sites. See site server high availability. Site recovery is documented at Recover a site.
Inventory the complete site, not just the server
Record the site code, site database name, SQL server and instance, server hostname/FQDN, installation paths, content-library path, WSUS/SUSDB location, certificates and private keys, service accounts, reporting configuration, boundaries and boundary groups, and every installed role. Identify whether SQL, the content library, management point, distribution point, software update point, reporting services point, service connection point, cloud management gateway integration, or other roles are local or remote.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Dell PowerEdge R730xd 24B SFF 2U Server
- 2x Intel Xeon E5-2690 v4 2.6Ghz 14-Core (28-cores Total)
- 128GB DDR4 RAM – 4x 1.2TB 10K SAS 2.5” 12Gb/s
- Dell H730P mini 2GB 12Gb/s RAID
- 2x 750W PSU - 2x 10Gb SFP+ 2x 1Gb (RJ45) NIC
- Protect the content library separately from the site database.
- Back up package and application source files, driver and operating-system image sources, custom reports, scripts, certificates, external databases, and WSUS data where applicable.
- Document firewall rules, SMB permissions, SQL logins, gMSA rights, PKI bindings, and the AD System Management container.
- Copy the active site’s
CD.Latestfolder outside the Configuration Manager installation directory. Recovery and passive-server setup must use source files matching the active site version; stale baseline media can cause a version mismatch.
Do not use a virtual-machine snapshot as your primary ConfigMgr backup or recovery method; Microsoft guidance warns that snapshots are not a supported substitute for site backup.
Method 1: add a passive site server and promote it
This is normally the lowest-risk planned hardware transition for a supported CAS or child primary. The passive server uses the existing site database and remote content library, and promotion changes which server owns the active site-server role. Promotion is manual; it is not automatic failover.
Rank #2
- Model: Dell OptiPlex 7050 Small Form Factor (SFF)
- Processor: Intel Core i7-7700 3.60 GHz
- Memory: 32GB DDR4 Ram
- Storage: 1TB Solid State Drive (SSD) Fast Boot + Storage
- Operating System: Windows 11 Pro (64-bit)
Prerequisites
- Both computers are joined to the same Active Directory domain.
- The new computer account is in the active site server’s local Administrators group and has equivalent rights on remote site systems and content sources.
- The new server meets the supported Windows Server and ConfigMgr prerequisites.
- No site-system roles are installed on the new server before passive installation.
- The content library is on a remote share with Full Control for both site-server computer accounts. Move a local library first; this is separate from moving SQL.
- Grant the new computer account the required SQL login and database permissions.
- Move the service connection point off either high-availability site server; Microsoft says it should not be hosted on those servers.
Install passive mode
- In the console, open Administration > Site Configuration > Sites.
- Select Create Site System Server in the ribbon.
- On System Role Selection, select only Site server in passive mode.
- On Site Server In Passive Mode, select matching installation files, preferably the active server’s
CD.Latestsource, and specify the local ConfigMgr installation path. - Complete the wizard and monitor Monitoring > Site Server Status until both servers show OK.
Keep the old server available while the passive server is installed and validated. Confirm site and component health, database connectivity, content replication, and secondary-site replication before scheduling promotion.
Promote during a controlled window
- Stop or avoid starting new content-distribution jobs and other disruptive maintenance.
- In Administration > Site Configuration > Sites, select the site and open the Nodes tab.
- Select the passive server, choose Promote to active, and confirm.
- Monitor promotion until the new server is active and the old server is passive.
- Check distribution and database replication before resuming normal changes.
Promotion during active file or database replication can leave the new server without complete content and may require redistribution or secondary-site reinitialization. Clients can generally continue using client-facing roles, but administration is unavailable during portions of a transition, so test rather than promise zero downtime. Distribution-point certificates may need reimporting, and some non-PKI operating-system media may need to be recreated. Details are in Microsoft’s high-availability guidance.
Rank #3
- MODEL P86811-005: HPE ProLiant MicroServer Gen11 preconfigured with Intel Xeon 6315P 2.80GHz 4-core processor, ideal for small business IT, edge workloads, and on-premise compute
- WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
- READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), dedicated iLO-M.2 port kit, embedded Intel VROC SATA controller for Gen11 servers, 180w external power adapter and 1/1/1 year warranty for dependable plug-and-play server operation
- EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance
- INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0, enabling secure, remote administration through browser, command line, or API with shared port access
Method 2: recover a standalone primary site on replacement hardware
Use site recovery when the existing primary site’s identity must remain and passive mode is not available. The replacement computer may use a newer supported operating system, but the recovered site server must use the original hostname and FQDN, with the same site code and site database name. A required new hostname is not a normal recovery; use passive mode or a side-by-side migration instead.
Prepare the backup and cutover
- Enable and run the Backup Site Server maintenance task and verify a successful completion.
- Preserve the backup files, matching
CD.Latestsource, content library, source shares, certificates, SQL configuration, credentials, and external databases. - Record the database, WSUS, reporting, role, boundary, and certificate dependencies.
- According to the approved change plan, shut down or remove the old server from the network and DNS so its original name is no longer active.
- Build the replacement with the original hostname and FQDN, join it to the domain, and reconnect supported SQL and storage dependencies.
Run the recovery wizard
- Launch Setup from the copied
CD.Latestfiles located outside the ConfigMgr installation folder. The Recover a site option is unavailable when Setup is launched from the existing server’s Start menu. - Select Recover a site, then choose recovery of the site server from the existing backup.
- Choose the appropriate database option: restore the ConfigMgr backup, use a manually restored database, or skip database recovery when a healthy separate database remains available.
- Complete Setup, then restore or reconnect content and external databases.
- Reinstall or reconfigure roles and certificates that were not included in site-server recovery.
A standalone primary can lose site changes made after the last database backup. In a hierarchy, some changes can be retrieved from the CAS. The default SQL change-tracking retention period cited by Microsoft is five days. Newer SQL Server versions can be supported only when the exact ConfigMgr release, SQL version, edition, and operating system combination is supported; the recovery guidance does not support changing SQL edition as part of this operation. See Microsoft’s recovery documentation.
Rank #4
- MODEL P74439-005: Compact and affordable HPE ProLiant MicroServer Gen11 powered by Intel Pentium Gold G7400 3.7GHz processor, ideal for file sharing, NAS, and basic business workloads
- READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), one 1TB SATA 6G Business Critical HDD, embedded Intel VROC SATA, dedicated iLO-M.2 port kit, 180w external power adapter and 1/1/1 warranty for dependable plug-and-play server operation
- WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
- INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0 for secure, license-free remote server administration through shared port access
- EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance
Method 3: build a side-by-side hierarchy and migrate
Choose this path when a new hostname or site code is mandatory, the domain or hierarchy is changing, or the old installation is unhealthy or obsolete. Install and configure the destination hierarchy, then migrate supported objects and clients in controlled phases. The Migration Wizard moves selected data between hierarchies; it is not a site-server replacement shortcut. Most infrastructure, including the primary site itself and many site-system roles, does not migrate wholesale.
- Design and install the destination primary site and its roles.
- Configure boundaries and boundary groups carefully so clients do not move unexpectedly.
- Configure software-update infrastructure and synchronize updates.
- Set the old hierarchy as a migration source and gather data.
- Create migration jobs for supported collections, applications, packages, deployments, task sequences, and other required objects.
- Migrate clients in batches and monitor assignment, policy, content location, inventory, compliance, and software updates.
- Re-create objects that are not migratable and allow hardware/software inventory and applicable compliance data to repopulate after clients report to the destination.
- Stop data gathering and clean up migration data only after rollback criteria expire; decommission the old hierarchy last.
Microsoft’s planning references are migration planning checklists and data-migration scope.
Best Value
- HP Z4 G4 Workstation Tower
- Intel Xeon W-2133 6-Core 3.6GHz (3.9GHz Turbo)
- 64GB DDR4 Memory - Nvidia Quadro P400 2GB
- 512GB NVMe M.2 SSD (boot) + 2TB HDD (storage)
- Windows 11 Pro 64-bit
Validate every dependency after the move
Site, SQL, and roles
- Site status, component status, SMS Executive, SMS Site Component Manager, SMS Provider, and database connectivity.
- Hierarchy replication, management point, distribution point, software update point/WSUS synchronization, reporting services point, service connection point, CMG, co-management, endpoint protection, Asset Intelligence, and data warehouse integrations where used.
- SQL logins, encryption, availability-group configuration, backups, and maintenance jobs.
Content and security
- Content-library share and NTFS access, package/application sources, driver packages, boot images, operating-system images, task-sequence references, update packages, scripts, and network-access-account permissions.
- Site-server, management-point, distribution-point, SQL, and HTTPS certificates; private keys, trust chain, firewall rules, SMB permissions, service accounts, and gMSA rights.
Client test matrix
Test representative LAN, VPN, internet/CMG, remote-office, HTTPS/PKI, co-managed, PXE, and multiple operating-system clients. Verify site assignment, management-point location, machine policy, application and package deployment, update scan/install, inventory upload, compliance reporting, content download from the intended distribution point, PXE/task sequences, client push, and client repair.
Rollback and decommissioning
Keep the old server, backups, content, certificates, and DNS procedure recoverable until the agreed validation and business-observation period ends. For a passive transition, the old server can remain passive and available for a controlled reversal. For recovery, reverse the hostname cutover only under the approved plan and after checking database and content consistency. If replication or content is incomplete, stop new changes, restore the last known-good state, redistribute content, or reinitialize affected secondary sites.
Remove the old server from the console, DNS, SQL, storage, and monitoring only after clients, PXE, updates, reporting, CMG, and co-management pass validation and rollback is no longer required.
Quick Recap
Common failure points
- Recovery option missing: Setup was started from the existing server’s Start menu rather than external
CD.Latestmedia. - Version mismatch: installation files do not match the active site’s updated version.
- SQL connection failure: the new computer account lacks the documented SQL login/database permissions, or firewall and encryption settings differ.
- Passive prerequisite failure: the topology is unsupported, the content library is local, roles already exist on the new server, or remote-share permissions are incomplete.
- Clients inactive: management-point, boundary, DNS, PKI, firewall, or client-location settings were not validated.
- PXE or updates fail: distribution-point certificates, boot media, WDS/PXE settings, WSUS/SUSDB, or software-update synchronization require reconfiguration.
- Reporting breaks: reporting services point, data sources, credentials, or certificates were not restored.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →




