Solved

Forced Primary Master Windows 2000 Standard Server

Posted on 2006-07-24
16
169 Views
Last Modified: 2010-04-13
I had two servers both Windows 2000 standard servers. One failed from hardware issues. I performed a force on the member server to make it the domain master. The second server will not be comming back into the scope. When I try to add a user it gives an error that It cannot update schema. How would I go about correcting this issue? I did the force admin under the recomendation instruction recieved from Experts exchange. Thier were five commands performed at the command promtp.
0
Comment
Question by:OneStopPCHelp
  • 10
  • 4
  • 2
16 Comments
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17167381
i take it the 5 commands were 5 role seizing commands within ntdsutil?

can you please confirm role placement
http://support.microsoft.com/default.aspx?scid=kb;en-us;255690
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17167384
also run netdiag for me and post any failings
0
 

Author Comment

by:OneStopPCHelp
ID: 17167410
will do
0
 
LVL 5

Expert Comment

by:DhammikaWee
ID: 17167416
I think as u told in the question the both of those servers are in Windows Domain, I continue with that knowledge.

It seems you have failed a server which is installed first in your domain (i.e. the first domain controller in your domain)

In windows domain there are 5 FSMO roles doing different tasks

The first server of your Forest/Domain gets all of those 5 roles into it seft, so that server will be the Master for all of the domain controllers.

A perticular FSMO role called "RID Master" (Relative ID master) is doing the issue of unique IDs which is required by the Active Directory when it creates new Objects on AD. the objects are for example Users, groups, Computers etc. If there are no enough IDs for creating new objects it fails giving the error mentioned by u.

You have to elect a new RID master which is the other server mannually using "NTDSUTIL" command line utility by seizing the old server.

use this link (how to do it)

http://technet2.microsoft.com/WindowsServer/en/library/e8b6ccc4-cae8-46ea-86ed-bf5f1899cdb81033.mspx?mfr=true

0
 

Author Comment

by:OneStopPCHelp
ID: 17167457
i'm remoted in and looks like it doesn'r reconise this command i will have to transfer it to the machine and run it what kind of switch did you wish for ? /q /v /l  ?
0
 

Author Comment

by:OneStopPCHelp
ID: 17167525
It ran but told me I was allready the rid master
0
 

Author Comment

by:OneStopPCHelp
ID: 17167559
here is exacly what error says

windows cannot validate the uniqueness of the proposed user name with global catalog server becuase:

the server is not operational. yata yata yata
0
 
LVL 5

Expert Comment

by:DhammikaWee
ID: 17167616
ok then go to the Active directory  Domains and Trusts
and
Select Defult site > Servers > your server >NTDS Settings

right click on NTDS Setting and select Properties and on Properties page select the Global Catelog Checkbox and select ok
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 

Author Comment

by:OneStopPCHelp
ID: 17167679
ahh but the appserver isn't listed thier
0
 
LVL 5

Expert Comment

by:DhammikaWee
ID: 17167780
OK on Select Defult site > Servers  right click and go to New > select server and type the name of the server and add it
0
 

Author Comment

by:OneStopPCHelp
ID: 17167943
I don't have the option to for new however i do have connect to domain controller and if i select this my appserver is listed. what i have is the domainname.local listed in the tree if i try to expand it nothing.
0
 

Author Comment

by:OneStopPCHelp
ID: 17167969
this isn't under domain and trust it is unser sites and services
0
 

Author Comment

by:OneStopPCHelp
ID: 17167975
so i added the global now we had a missunderstanding
0
 

Author Comment

by:OneStopPCHelp
ID: 17174795
still unable to add a user
0
 
LVL 5

Accepted Solution

by:
DhammikaWee earned 250 total points
ID: 17175174
ok after doing those have u getting the same problem .. or a different problem. ? Did u make it a Global Catelog ?
0
 

Author Comment

by:OneStopPCHelp
ID: 17175317
Yes same error when i tried yesterday. I went ahead and did a reboot this morning after after my post and now am able to add users again. Forgot MS must reboot for everything. Thank you
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
A Short Story about the Best File Recovery Software – Acronis True Image 2017
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now