Link to home
Start Free TrialLog in
Avatar of daveviolante
daveviolanteFlag for Netherlands

asked on

Cannot Demote Active Directory DC into member server

Hi,

Before I go to the question issue need to explain a bit of my Domain Network environment.

I recently virtualised all my domain network environment from phisical servers to virtual.

Now i am running almost everything virtually in robust and very powerfull server that runs VMware Server. There also a separate Phisical Root Domain Controller that need to be demoted to a member server and let the virtual Domain Controller become the only DC
I have 3 virtual machine:
1) Server Domain controller added as additional DC
2) Member Server that function as Exchange Server
3) Terminal Server in a member server

Eventually i will add another DC as additional DC.(Redundancy)

This is production environment with 50 user small office. Not alive still experimental we need to go alive 2009

Here we go:

I tried to demote the root DC to a member server, and if i remember correctely when this operation is done the role of Active Directory DC is automatically transfred to another available DC, (In this case should be the Virtual DC) but unfortunately this doesn't happen and i get an error message when i try to remove the DC role, first he ask me if there are other GC Server and indeed the Virtual server is also GC so I click next to continue, then the wizard ask me if this is the last DC in the Domain obviously isn't so i don't check the check box. Soon after i click next and i get the following error:

The box indicating that this is the last domain controller is unchecked, however no other domain controller can be contacted. Do you wish to proceed anyway?

Now, if i say yes the operation fails if i say no then the process is aborted.

I cannot understand the issue, it seems that Active Directory has something wrong.

I checked the DNS configuration and it's all ok, the virtual server is GC, also when i go to site and services i can see the two domain controller and if i go to ntds click property i can let the two server replicate each other. So.... Where the problem is? It seems that the additional DC that is virtual machine is a read only copy of Active Directory. I notice that if i switch the root phisical server off no body can authenticate also from the virtual server it is not possible open active directory anymore, and exchange doesn't work anymore i cannot logon to any virtual machine into the domain.

Please help i had a similar problem while ago but right i cannot figure out where the issue is.

ASKER CERTIFIED SOLUTION
Avatar of jmoisy
jmoisy

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of daveviolante

ASKER

Hi,
 already done that,

This is the problem i already done the main common troobleshooting steps.

I made the virtual server GC and transfered all the fsmo roles to it.

It still doesn't work, I'll try again riht now see if i made any mistake but i don't think i did, i do this things in regular basis i am an IT Guy and i know the most common task
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi,

As Ryan said before i did transfer all the 5 fsmo roles using AD. Now it seems that the virtual domain controller hold all the 5 roles plus is a DC. Issue still remain but i find out something guys and one of you it might help maybe. First of all I couldn't transfer the fsmo role using ntdsutil the command was failing when i supposed to connect to the server that was holding the fsmo role. this shouldn't happen. But as i said before i did it with active directory. After i run DC Diag and i can see there is a problem with fsmo role thta is not available please read the dc diag result below:
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Netherlands\SERVER1NL
      Starting test: Connectivity
         ......................... SERVER1NL passed test Connectivity

Doing primary tests

   Testing server: Netherlands\SERVER1NL
      Starting test: Replications
         ......................... SERVER1NL passed test Replications
      Starting test: NCSecDesc
         ......................... SERVER1NL passed test NCSecDesc
      Starting test: NetLogons
         ......................... SERVER1NL passed test NetLogons
      Starting test: Advertising
         Warning: SERVER1NL is not advertising as a time server.
         ......................... SERVER1NL failed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... SERVER1NL passed test KnowsOfRoleHo
      Starting test: RidManager
         ......................... SERVER1NL passed test RidManager
      Starting test: MachineAccount
         ......................... SERVER1NL passed test MachineAccoun
      Starting test: Services
         ......................... SERVER1NL passed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER1NL passed test ObjectsReplic
      Starting test: frssysvol
         ......................... SERVER1NL passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours af
         SYSVOL has been shared.  Failing SYSVOL replication problems
         Group Policy problems.
         ......................... SERVER1NL failed test frsevent
      Starting test: kccevent
         ......................... SERVER1NL passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0xC0001B77
            Time Generated: 10/07/2008   17:26:58
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC25A001D
            Time Generated: 10/07/2008   17:31:05
            (Event String could not be retrieved)
         ......................... SERVER1NL failed test systemlog
      Starting test: VerifyReferences
         ......................... SERVER1NL passed test VerifyReferen

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRef

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDR

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRef

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDR

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidati
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefV
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRe

   Running partition tests on : technopc
      Starting test: CrossRefValidation
         ......................... technopc passed test CrossRefValida
      Starting test: CheckSDRefDom
         ......................... technopc passed test CheckSDRefDom

   Running enterprise tests on : technopc.eu
      Starting test: Intersite
         ......................... technopc.eu passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed,
5
         A Good Time Server could not be located.
         ......................... technopc.eu failed test FsmoCheck

C:\Program Files\Support Tools>
A good time server?

What's that?
Hi Ryan,

Did you see the result from DC Diag?

Also i would like to do what you said, but if i shut the server down the root DC, no body can logon anymore nothing work anymore even the virtual server DC the Active directory are not available anymore. Basically the fsmo role cannot be transfered i just cannot understand why using active directory it seems to work(to be transfred), but is not in reality.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial