DC NetBIOS name impacting Group Policy

I'm having a problem with a recently promoted W2K Adv. server.  Details are as follows:

Host name = EIT-AD1 (note the hyphen)
Domain = EITNY.INT

This machine was DCPROMO'd as the first server in the domain/tree/forest. AD was installed in pre-W2K compatibility mode. This is the only server in the domain.

On reboot following the DCPROMO the Application log was full of Error # 1000, source=UsrEnv and Error # 1001, source=SceCli.  When I try to load a Group Policy I get the following error:

"Domain Controller not found for EITNY.INT

The Domain Controller for Group Policy operations is not available.  You may cancel this operation for this session or retry using one of the following domain controller choices..."

Trying any of the three options presented fails with the following error:

"Group Policy error

Failed to find a domain controller.  There may be a policy that prevents you from selecting another domain controller.

Details: A duplicate name exists on the network"

I ran DCDIAG.exe against the machine and found the following:

      Starting test: Advertising
         Warning: DsGetDcName returned information for \\eitad1.eitny.int, when we were trying to reach EIT-AD1.
         Server is not responding or is not considered suitable.

So my thought is that in bringing the machine up in Pre-W2K compatibility mode the hyphen was removed from the host name, causing the share for the GP files to be lost.  This seems to be supported by the following details from the 1001 errors in the App log:

Security policy cannot be propagated. Cannot access the template. Error code = 3.
     \\eitny.int\sysvol\eitny.int\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf.

I've checked the file system and the directories & files are present and correct.  As you'll note above, AD is looking for the hostname that does not have the hyphen.

So, what to do?  Due to the project schedule this domain is in production, so I don't have the luxury of blowing everything away and starting over.  I've thought about bringing up another DC in the domain, DCPROMO'ing the affected machine down, renaming it minus the hyphen, and bringing it back up, but I'm afraid the same problem might be propogated to the second domain controller.  I imagine there is some way to manually edit the error out of AD, but I think that is beyond what I'm capable of.  Any thoughts on how to resolve this?


Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

First, why are you running in Mixed Mode if this is the only server in the domain?  Mixed mode is only to support NT 4 domain controllers.

>> I've thought about bringing up another DC in the domain, DCPROMO'ing the affected machine down, renaming it minus the hyphen, and bringing it back up, but I'm afraid the same problem might be propogated to the second domain controller.

It will not be propogated, just be sure to clear any entries in DNS, WINS, flush DNS cache, and remove the server in AD.  Why would it propogate to second controller??

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
This is almost  certainly a DNS problem.

WIn2k AD requires that DNS be perfect !!

Please read up on DNS for win2k etc.

 These links will help you perform the upgrade from NT to win2k


I hope this helps !

You can change the DNS server to accept different naming conventions here:

Open Administrative Tools>DNS
Expand the server.
Right click the server name and select Properties.
On the Advanced Tab - 2/3 of the way down there is a Name Checking option.

Select a different option, either reboot or restart the DNS services and see if that cures your itch.

Let us know.
No comment has been added lately, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question is to:

Points split between MSGeek, SysExpert and Netman66

Please leave any comments here within the next seven days.


EE Cleanup Volunteer
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Operating Systems

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.