richtree
asked on
Why domain controller is not available?
I have two domain controllers running Windows 2003 server (dc1, dc2).
Both are up and running.
There is no network connectivity issue.
When I login as domain admin and try to open Group Policy Object from both dc1 and dc2, it ends up with error: Failed to open Group Policy Object. You may not have appropriate rights.
Note: Net Logon is started.
Q#1. How to turn it on manually?
Q#2. Why all of sudden the domain controllers are unavailable?
Q#3. What common services are required to start as dc?
Thanks a lot.
Both are up and running.
There is no network connectivity issue.
When I login as domain admin and try to open Group Policy Object from both dc1 and dc2, it ends up with error: Failed to open Group Policy Object. You may not have appropriate rights.
Note: Net Logon is started.
Q#1. How to turn it on manually?
Q#2. Why all of sudden the domain controllers are unavailable?
Q#3. What common services are required to start as dc?
Thanks a lot.
ASKER
on dc1, I open Active Directory Users and Computers, right click my domains, I see three tabs: RID, PDC, Infrastructure.
RID:
Operations master: dc1
PDC:
Operations master: ERROR
The current operations master is offline. The role cannot be transferred.
Infrastructure:
Operations master: ERROR
The current operations master is offline. The role cannot be transferred.
I get the same result on dc2.
Q#5. How to assume PDC and Infrastructure operation master? Any side effect of this operation?
Thanks.
RID:
Operations master: dc1
PDC:
Operations master: ERROR
The current operations master is offline. The role cannot be transferred.
Infrastructure:
Operations master: ERROR
The current operations master is offline. The role cannot be transferred.
I get the same result on dc2.
Q#5. How to assume PDC and Infrastructure operation master? Any side effect of this operation?
Thanks.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
One more detail:
There were dc1 and dc3 only when everything is fine.
dc3 failed due to power supply failure.
because dc3 hardware is old and I decided to retire it without further repair.
I thought dc3 did not assume any master roles, so I install dc2 and run dcpromo on it.
Now dc3 is runnable. I turn it on (without connecting to network) and found out it assumes the PDC and Infrastructure master role.
I still want to retire dc3 due to hardware issue in the end.
Two options here:
Option#:1 Let dc1 seize the master role without dc3 ever connecting back to the network again
Option#2: connect dc3 temporarily back to the network, transfer the roles off dc3 to dc1, then disconnect dc3 from the network.
Q#6. Which option is better?
Q#7. Please give detail steps of your recommendation. (including steps for dc1/2/3 if any).
Thanks a lot.
There were dc1 and dc3 only when everything is fine.
dc3 failed due to power supply failure.
because dc3 hardware is old and I decided to retire it without further repair.
I thought dc3 did not assume any master roles, so I install dc2 and run dcpromo on it.
Now dc3 is runnable. I turn it on (without connecting to network) and found out it assumes the PDC and Infrastructure master role.
I still want to retire dc3 due to hardware issue in the end.
Two options here:
Option#:1 Let dc1 seize the master role without dc3 ever connecting back to the network again
Option#2: connect dc3 temporarily back to the network, transfer the roles off dc3 to dc1, then disconnect dc3 from the network.
Q#6. Which option is better?
Q#7. Please give detail steps of your recommendation. (including steps for dc1/2/3 if any).
Thanks a lot.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
DC3 is not officially retired yet. It went offline due to hardware problem.
Not sure if dc1 is copied from dc3, but dc2 is copied from dc1 after dc3 went offline.
Can someone if any one of my options mentioned above will work?
Thanks.
Not sure if dc1 is copied from dc3, but dc2 is copied from dc1 after dc3 went offline.
Can someone if any one of my options mentioned above will work?
Thanks.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
There is no other data on dc3 to transfer. dc3 is just a domain controller. dc3 went offline (unexpected shutdown) due to power supply problem, so no data loss except possible AD data out-of-synch issue.
Given this,
Q#8 Is my option#2 easier than option#1?
Q#9. If option#2 chosen, I imagine the steps like the following. Are these steps correct?
9.1 shut down dc1
9.2 turn on dc3
9.3 turn on dc1
Q#10 What will happen between dc1 and dc3?
9.4 transfer master roles from dc3 to dc1
9.5 shutdown dc3
9.6 turn on dc2
Q#11 What will happen between dc1 and dc2?
Please advise. Thanks.
Given this,
Q#8 Is my option#2 easier than option#1?
Q#9. If option#2 chosen, I imagine the steps like the following. Are these steps correct?
9.1 shut down dc1
9.2 turn on dc3
9.3 turn on dc1
Q#10 What will happen between dc1 and dc3?
9.4 transfer master roles from dc3 to dc1
9.5 shutdown dc3
9.6 turn on dc2
Q#11 What will happen between dc1 and dc2?
Please advise. Thanks.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Hi ChiefIT,
Thanks a lot for your ideas. Now more questions with my option#2.
I did not have any problems with dc3 before it went down.
There is really not much change after dc3 went down. The only change is some AD users.
Given this,
Q#12. is option#2 still ok?
Q#13. Do I HAVE to demote dc3 after transfer roles to dc1? Can I simply shut dc3 off and put aside? Or is there any fundamental change to dc1/dc2 by demoting dc3?
My goal is to transfer all AD info/roles into dc1/dc2 properly. As long as this is done, I do not care what's left to dc3. I can simply wipe it out if just to prevent future interference.
Please let me know. Thanks again.
Thanks a lot for your ideas. Now more questions with my option#2.
I did not have any problems with dc3 before it went down.
There is really not much change after dc3 went down. The only change is some AD users.
Given this,
Q#12. is option#2 still ok?
Q#13. Do I HAVE to demote dc3 after transfer roles to dc1? Can I simply shut dc3 off and put aside? Or is there any fundamental change to dc1/dc2 by demoting dc3?
My goal is to transfer all AD info/roles into dc1/dc2 properly. As long as this is done, I do not care what's left to dc3. I can simply wipe it out if just to prevent future interference.
Please let me know. Thanks again.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
dc1 is able to transfer the pdc role from dc3 successfully.
because dc1 is a global catalog server, so dc1 warns against taking over Infrastructure role from dc3.
so I let dc2 try to take the Infrastructure role over. it sees dc3 is Infrastructure master but it says unable to contact it when trying to take it over. it suggests 'force transfer' and I select it. it shows successful.
now dc1 and dc2 see each other correctly.
but dc3 still thinks he is the Infractructure master. (I already disconnect dc3 from the network).
Q#14 is this an issue?
because dc1 is a global catalog server, so dc1 warns against taking over Infrastructure role from dc3.
so I let dc2 try to take the Infrastructure role over. it sees dc3 is Infrastructure master but it says unable to contact it when trying to take it over. it suggests 'force transfer' and I select it. it shows successful.
now dc1 and dc2 see each other correctly.
but dc3 still thinks he is the Infractructure master. (I already disconnect dc3 from the network).
Q#14 is this an issue?
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thank you both. I will post new questions to continue from here.
ASKER
on dc1, I open Active Directory Domains and Trusts and see my domain, but nothing shows when expanding my domain. Right click my domain and choose properties, it shows error message: You cannot modify domain or trust information because a Primary Domain Controller (PDC) emulator cannot be contacted.
Q#4. How to make a dc as PDC emulator?