Unable to promote or demote a DC

I have an account that is part of the Domain admins group, the Schema admins group, and the server operators group but I am unable to promote or demote a domain controller.  I am the one who installed and configured all of these servers. Our security guy implemented a bunch of GPO's that I am now in charge of but I can't find anything that would stop me from promoting a server.  Any Ideas?  The error I get  says that my account doesn't have access to change the account for z000tsm1$ to a domain controller.  I can get the exact words if someone needs them.
LVL 3
m-moloneyAsked:
Who is Participating?
 
JimboEfxConnect With a Mentor Commented:
was the message like this?

http://support.microsoft.com/kb/250874

note the reference to change to security policy...
0
 
JimboEfxCommented:
Get the exact words.
Get any errors in the event logs.
But most importantly, find out what your 'security guy' has changed - in detail.
0
 
ChiefITCommented:
Sometimes DCPromo gets stuck and you have to put the switch of DCPromo /f  from the command prompt. That /f forces DCpromo execution.

I have never run into a Access denied error when promoting or demoting a machine. Usually you are logged on as the Domain Administrator when trying to execute DCpromo. I also don't know of a GPO that will prevent you from removing the AD database.

If you look at your GPO's it must be a default domain policy, or a Group policy object on the whole domain to prevent the Domain Administrator from doing anything to the server's drive. Let me see if I can find the exact policy that would prevent this from happening.
0
 
m-moloneyAuthor Commented:
I checked the user rights assignment for delegating and it was configured but noone was added. DUH
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.