Link to home
Start Free TrialLog in
Avatar of richtree
richtree

asked on

Why domain controller is not available?

I have two domain controllers running Windows 2003 server (dc1, dc2).
Both are up and running.
There is no network connectivity issue.
When I login as domain admin and try to open Group Policy Object from both dc1 and dc2, it ends up with error: Failed to open Group Policy Object. You may not have appropriate rights.
Note: Net Logon is started.
Q#1. How to turn it on manually?
Q#2. Why all of sudden the domain controllers are unavailable?
Q#3. What common services are required to start as dc?

Thanks a lot.
Avatar of richtree
richtree

ASKER

on dc1, I am able to open Active Directory Users and Computers and see the domain. Right click it and connect to domain controller and is able to see both domain controller dc1 and dc2; if clicking dc1, able to see all users; if clicking dc2, able to all users too.
on dc1, I open Active Directory Domains and Trusts and see my domain, but nothing shows when expanding my domain. Right click my domain and choose properties, it shows error message: You cannot modify domain or trust information because a Primary Domain Controller (PDC) emulator cannot be contacted.
Q#4. How to make a dc as PDC emulator?
on dc1, I open Active Directory Users and Computers, right click my domains, I see three tabs: RID, PDC, Infrastructure.
RID:
  Operations master: dc1
PDC:
  Operations master: ERROR
  The current operations master is offline. The role cannot be transferred.
Infrastructure:
  Operations master: ERROR
  The current operations master is offline. The role cannot be transferred.

I get the same result on dc2.

Q#5. How to assume PDC and Infrastructure operation master? Any side effect of this operation?

Thanks.
SOLUTION
Avatar of kind4me
kind4me
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
One more detail:
There were dc1 and dc3 only when everything is fine.
dc3 failed due to power supply failure.
because dc3 hardware is old and I decided to retire it without further repair.
I thought dc3 did not assume any master roles, so I install dc2 and run dcpromo on it.

Now dc3 is runnable. I turn it on (without connecting to network) and found out it assumes the PDC and Infrastructure master role.

I still want to retire dc3 due to hardware issue in the end.

Two options here:
 Option#:1 Let dc1 seize the master role without dc3 ever connecting back to the network again
 Option#2: connect dc3 temporarily back to the network, transfer the roles off dc3 to dc1, then disconnect dc3 from the network.

Q#6. Which option is better?
Q#7. Please give detail steps of your recommendation. (including steps for dc1/2/3 if any).

Thanks a lot.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
DC3 is not officially retired yet. It went offline due to hardware problem.
Not sure if dc1 is copied from dc3, but dc2 is copied from dc1 after dc3 went offline.
Can someone if any one of my options mentioned above will work?
Thanks.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
There is no other data on dc3 to transfer. dc3 is just a domain controller. dc3 went offline (unexpected shutdown) due to power supply problem, so no data loss except possible AD data out-of-synch issue.
Given this,
Q#8 Is my option#2 easier than option#1?
Q#9. If option#2 chosen, I imagine the steps like the following. Are these steps correct?
9.1 shut down dc1
9.2 turn on dc3
9.3 turn on dc1
Q#10 What will happen between dc1 and dc3?
9.4 transfer master roles from dc3 to dc1
9.5 shutdown dc3
9.6 turn on dc2
Q#11 What will happen between dc1 and dc2?
Please advise. Thanks.

SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi ChiefIT,

Thanks a lot for your ideas. Now more questions with my option#2.
I did not have any problems with dc3 before it went down.
There is really not much change after dc3 went down. The only change is some AD users.

Given this,
Q#12. is option#2 still ok?
Q#13. Do I HAVE to demote dc3 after transfer roles to dc1? Can I simply shut dc3 off and put aside? Or is there any fundamental change to dc1/dc2 by demoting dc3?
My goal is to transfer all AD info/roles into dc1/dc2 properly. As long as this is done, I do not care what's left to dc3. I can simply wipe it out if just to prevent future interference.

Please let me know. Thanks again.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
dc1 is able to transfer the pdc role from dc3 successfully.
because dc1 is a global catalog server, so dc1 warns against taking over Infrastructure role from dc3.
so I let dc2 try to take the Infrastructure role over. it sees dc3 is Infrastructure master but it says unable to contact it when trying to take it over. it suggests 'force transfer' and I select it. it shows successful.
now dc1 and dc2 see each other correctly.
but dc3 still thinks he is the Infractructure master. (I already disconnect dc3 from the network).
Q#14 is this an issue?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thank you both. I will post new questions to continue from here.