My DC who was operations Master died, and cannot be revived. Getting SAM error on remaining DC

My DC that was Op Master died, and now I am getting a crazy amount of SAM errors on my remaining DC, saying I will be unable to create new accounts.  I cannot change the operations master to the other machine because I cannot get it revived - so it says it's "offline" when I go to the AD Scema snap in.  I had AD running on both machines when th op master died,and the AD seemed to be replicating fine, in that if I made a new account on the op master it showed up in users and computers on the second DC, so I thought it wouldn't be a big deal.  I get an error saying that "the account identifier failed to initialize properly..."blah, blah and I think that this has to do with the operations master roles not being transfered.  I cannot add users and everything is messed up.  I am an AD lightweight, so go easy on me please...Can anyone help?
LynniebobinnieAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Chris DentPowerShell DeveloperCommented:

Yep...

Ensure you have the DNS Service set up on your new Domain Controller.

Then here's how to force transfer the roles onto the new server:

Start
Run

Then start typing this lot in (at any time ? shows the lists of available commands):

ntdsutil
roles
connections
connect to domain <your domain>
connect to server <your server>
quit <quits to FSMO Maintenance>
seize PDC
seize Domain naming Master
seize RID Master
seize Schema Master
seize Infrastructure Master
quit <quits the program>

Confirm each of those is taken over correctly. It'll let you know after each one

Make your server a Global Catalog (right click on NTDS Settings for the Server in Active Directory Sites and Services).

Let me know if you run into any problems with that.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Chris DentPowerShell DeveloperCommented:

I should have added this point.

It's really really important that after Seizing those roles your Old Server **never** comes back onto the domain.

If you recover the hardware it must be rebuilt.
0
Chris DentPowerShell DeveloperCommented:

I assumed all roles were on the old server, obviously you won't need to seize roles if the server already runs them or another working server has it.

Sorry for all the additional comments, think I need a coffee.
0
Debsyl99Commented:
Hi
Just to check - you only need to seize the roles that are no longer available, so be careful -
How To Find Servers That Hold Flexible Single Master Operations Roles
http://support.microsoft.com/default.aspx?scid=kb;en-us;234790
Another way to locate a FSMO role holder.
http://www.jsiinc.com/SUBH/TIP3500/rh3509.htm
The following is th ms article that relates to Chris's post above:
Using Ntdsutil.exe to seize or transfer FSMO roles to a domain controller
http://support.microsoft.com/default.aspx?scid=kb;EN-US;255504

Once you've successfully seized roles you will then need to remove your extinct dc from active directory:
How to remove data in Active Directory after an unsuccessful domain controller demotion - be ultra careful with adsiedit if you use it.
How to remove data in Active Directory after an unsuccessful domain controller demotion
http://support.microsoft.com/default.aspx?kbid=216498&product=nts40

You may also need to look at establishing a new global catalog server if that was set on the old dc - will post on that if you need further instructions

Deb :))
0
LynniebobinnieAuthor Commented:
thakns, I'll give it a try and see what transpires...
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 2000

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.