Solved

Cannot Demote Active Directory  DC into member server

Posted on 2008-10-07
10
701 Views
Last Modified: 2012-08-13
Hi,

Before I go to the question issue need to explain a bit of my Domain Network environment.

I recently virtualised all my domain network environment from phisical servers to virtual.

Now i am running almost everything virtually in robust and very powerfull server that runs VMware Server. There also a separate Phisical Root Domain Controller that need to be demoted to a member server and let the virtual Domain Controller become the only DC
I have 3 virtual machine:
1) Server Domain controller added as additional DC
2) Member Server that function as Exchange Server
3) Terminal Server in a member server

Eventually i will add another DC as additional DC.(Redundancy)

This is production environment with 50 user small office. Not alive still experimental we need to go alive 2009

Here we go:

I tried to demote the root DC to a member server, and if i remember correctely when this operation is done the role of Active Directory DC is automatically transfred to another available DC, (In this case should be the Virtual DC) but unfortunately this doesn't happen and i get an error message when i try to remove the DC role, first he ask me if there are other GC Server and indeed the Virtual server is also GC so I click next to continue, then the wizard ask me if this is the last DC in the Domain obviously isn't so i don't check the check box. Soon after i click next and i get the following error:

The box indicating that this is the last domain controller is unchecked, however no other domain controller can be contacted. Do you wish to proceed anyway?

Now, if i say yes the operation fails if i say no then the process is aborted.

I cannot understand the issue, it seems that Active Directory has something wrong.

I checked the DNS configuration and it's all ok, the virtual server is GC, also when i go to site and services i can see the two domain controller and if i go to ntds click property i can let the two server replicate each other. So.... Where the problem is? It seems that the additional DC that is virtual machine is a read only copy of Active Directory. I notice that if i switch the root phisical server off no body can authenticate also from the virtual server it is not possible open active directory anymore, and exchange doesn't work anymore i cannot logon to any virtual machine into the domain.

Please help i had a similar problem while ago but right i cannot figure out where the issue is.

0
Comment
Question by:daveviolante
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 2

Accepted Solution

by:
jmoisy earned 150 total points
ID: 22660068
Hello,

you can try to use dcdiag.exe on each DC server to check for errors.

You can also use ntdsutil to try to transfer all fsmo roles to the virtual DC before demote the first server.

Unfortunately they are the only ideas I have for the moment on your problem. If I find something or that I have another idea I post.

Best regards,
0
 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 250 total points
ID: 22660179
Make the second machine a global catalog
transfer FSMO roles to second machine
then try and run a dcpromo
0
 

Author Comment

by:daveviolante
ID: 22660225
Hi,
 already done that,

This is the problem i already done the main common troobleshooting steps.

I made the virtual server GC and transfered all the fsmo roles to it.

It still doesn't work, I'll try again riht now see if i made any mistake but i don't think i did, i do this things in regular basis i am an IT Guy and i know the most common task
0
 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 250 total points
ID: 22660576
If you can verify that the roles are with the VM and its a GC and you still cant demote it then power it off and remove it from AD using a metadata cleanup
http://technet.microsoft.com/en-us/library/cc736378.aspx
0
 

Author Comment

by:daveviolante
ID: 22660602
Hi,

As Ryan said before i did transfer all the 5 fsmo roles using AD. Now it seems that the virtual domain controller hold all the 5 roles plus is a DC. Issue still remain but i find out something guys and one of you it might help maybe. First of all I couldn't transfer the fsmo role using ntdsutil the command was failing when i supposed to connect to the server that was holding the fsmo role. this shouldn't happen. But as i said before i did it with active directory. After i run DC Diag and i can see there is a problem with fsmo role thta is not available please read the dc diag result below:
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Netherlands\SERVER1NL
      Starting test: Connectivity
         ......................... SERVER1NL passed test Connectivity

Doing primary tests

   Testing server: Netherlands\SERVER1NL
      Starting test: Replications
         ......................... SERVER1NL passed test Replications
      Starting test: NCSecDesc
         ......................... SERVER1NL passed test NCSecDesc
      Starting test: NetLogons
         ......................... SERVER1NL passed test NetLogons
      Starting test: Advertising
         Warning: SERVER1NL is not advertising as a time server.
         ......................... SERVER1NL failed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... SERVER1NL passed test KnowsOfRoleHo
      Starting test: RidManager
         ......................... SERVER1NL passed test RidManager
      Starting test: MachineAccount
         ......................... SERVER1NL passed test MachineAccoun
      Starting test: Services
         ......................... SERVER1NL passed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER1NL passed test ObjectsReplic
      Starting test: frssysvol
         ......................... SERVER1NL passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours af
         SYSVOL has been shared.  Failing SYSVOL replication problems
         Group Policy problems.
         ......................... SERVER1NL failed test frsevent
      Starting test: kccevent
         ......................... SERVER1NL passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0xC0001B77
            Time Generated: 10/07/2008   17:26:58
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC25A001D
            Time Generated: 10/07/2008   17:31:05
            (Event String could not be retrieved)
         ......................... SERVER1NL failed test systemlog
      Starting test: VerifyReferences
         ......................... SERVER1NL passed test VerifyReferen

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRef

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDR

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRef

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDR

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidati
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefV
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRe

   Running partition tests on : technopc
      Starting test: CrossRefValidation
         ......................... technopc passed test CrossRefValida
      Starting test: CheckSDRefDom
         ......................... technopc passed test CheckSDRefDom

   Running enterprise tests on : technopc.eu
      Starting test: Intersite
         ......................... technopc.eu passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed,
5
         A Good Time Server could not be located.
         ......................... technopc.eu failed test FsmoCheck

C:\Program Files\Support Tools>
A good time server?

What's that?
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 

Author Comment

by:daveviolante
ID: 22660663
Hi Ryan,

Did you see the result from DC Diag?

Also i would like to do what you said, but if i shut the server down the root DC, no body can logon anymore nothing work anymore even the virtual server DC the Active directory are not available anymore. Basically the fsmo role cannot be transfered i just cannot understand why using active directory it seems to work(to be transfred), but is not in reality.
0
 
LVL 2

Assisted Solution

by:jmoisy
jmoisy earned 150 total points
ID: 22660776
Hi,

Can you verify that the time is set correctly on the two server ?

If there is a difference correct it and try again to demote.

Regards,
0
 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 250 total points
ID: 22660790
OK no worries about the time server thats not a critical component at this point.
If you power down the machine then seize the fsmo roles
http://support.microsoft.com/kb/255504

After then you can run a metadata clean up and life should be good.
As always make sure you have good clean backups before doing anything...
0
 
LVL 16

Assisted Solution

by:robrandon
robrandon earned 50 total points
ID: 22661003
Are you running DNS on your virtual DC, or is it only running on your physical DC?  You will need DNS running when you shut down that physical box.
0
 
LVL 7

Assisted Solution

by:BogdanSUA
BogdanSUA earned 50 total points
ID: 22663540
When you virtualized your DCs, did you build them fresh and then do a DC promo, or did you do a P2V?
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

HOW TO: Install and Configure VMware vSphere Hypervisor 6.5 (ESXi 6.5), Step by Step Tutorial with screenshots. From Download, Checking Media, to Completed Installation.
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This Micro Tutorial steps you through the configuration steps to configure your ESXi host Management Network settings and test the management network, ensure the host is recognized by the DNS Server, configure a new password, and the troubleshooting…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now