?
Solved

Cannot Demote Active Directory  DC into member server

Posted on 2008-10-07
10
Medium Priority
?
718 Views
Last Modified: 2012-08-13
Hi,

Before I go to the question issue need to explain a bit of my Domain Network environment.

I recently virtualised all my domain network environment from phisical servers to virtual.

Now i am running almost everything virtually in robust and very powerfull server that runs VMware Server. There also a separate Phisical Root Domain Controller that need to be demoted to a member server and let the virtual Domain Controller become the only DC
I have 3 virtual machine:
1) Server Domain controller added as additional DC
2) Member Server that function as Exchange Server
3) Terminal Server in a member server

Eventually i will add another DC as additional DC.(Redundancy)

This is production environment with 50 user small office. Not alive still experimental we need to go alive 2009

Here we go:

I tried to demote the root DC to a member server, and if i remember correctely when this operation is done the role of Active Directory DC is automatically transfred to another available DC, (In this case should be the Virtual DC) but unfortunately this doesn't happen and i get an error message when i try to remove the DC role, first he ask me if there are other GC Server and indeed the Virtual server is also GC so I click next to continue, then the wizard ask me if this is the last DC in the Domain obviously isn't so i don't check the check box. Soon after i click next and i get the following error:

The box indicating that this is the last domain controller is unchecked, however no other domain controller can be contacted. Do you wish to proceed anyway?

Now, if i say yes the operation fails if i say no then the process is aborted.

I cannot understand the issue, it seems that Active Directory has something wrong.

I checked the DNS configuration and it's all ok, the virtual server is GC, also when i go to site and services i can see the two domain controller and if i go to ntds click property i can let the two server replicate each other. So.... Where the problem is? It seems that the additional DC that is virtual machine is a read only copy of Active Directory. I notice that if i switch the root phisical server off no body can authenticate also from the virtual server it is not possible open active directory anymore, and exchange doesn't work anymore i cannot logon to any virtual machine into the domain.

Please help i had a similar problem while ago but right i cannot figure out where the issue is.

0
Comment
Question by:daveviolante
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 2

Accepted Solution

by:
jmoisy earned 450 total points
ID: 22660068
Hello,

you can try to use dcdiag.exe on each DC server to check for errors.

You can also use ntdsutil to try to transfer all fsmo roles to the virtual DC before demote the first server.

Unfortunately they are the only ideas I have for the moment on your problem. If I find something or that I have another idea I post.

Best regards,
0
 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 750 total points
ID: 22660179
Make the second machine a global catalog
transfer FSMO roles to second machine
then try and run a dcpromo
0
 

Author Comment

by:daveviolante
ID: 22660225
Hi,
 already done that,

This is the problem i already done the main common troobleshooting steps.

I made the virtual server GC and transfered all the fsmo roles to it.

It still doesn't work, I'll try again riht now see if i made any mistake but i don't think i did, i do this things in regular basis i am an IT Guy and i know the most common task
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 750 total points
ID: 22660576
If you can verify that the roles are with the VM and its a GC and you still cant demote it then power it off and remove it from AD using a metadata cleanup
http://technet.microsoft.com/en-us/library/cc736378.aspx
0
 

Author Comment

by:daveviolante
ID: 22660602
Hi,

As Ryan said before i did transfer all the 5 fsmo roles using AD. Now it seems that the virtual domain controller hold all the 5 roles plus is a DC. Issue still remain but i find out something guys and one of you it might help maybe. First of all I couldn't transfer the fsmo role using ntdsutil the command was failing when i supposed to connect to the server that was holding the fsmo role. this shouldn't happen. But as i said before i did it with active directory. After i run DC Diag and i can see there is a problem with fsmo role thta is not available please read the dc diag result below:
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Netherlands\SERVER1NL
      Starting test: Connectivity
         ......................... SERVER1NL passed test Connectivity

Doing primary tests

   Testing server: Netherlands\SERVER1NL
      Starting test: Replications
         ......................... SERVER1NL passed test Replications
      Starting test: NCSecDesc
         ......................... SERVER1NL passed test NCSecDesc
      Starting test: NetLogons
         ......................... SERVER1NL passed test NetLogons
      Starting test: Advertising
         Warning: SERVER1NL is not advertising as a time server.
         ......................... SERVER1NL failed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... SERVER1NL passed test KnowsOfRoleHo
      Starting test: RidManager
         ......................... SERVER1NL passed test RidManager
      Starting test: MachineAccount
         ......................... SERVER1NL passed test MachineAccoun
      Starting test: Services
         ......................... SERVER1NL passed test Services
      Starting test: ObjectsReplicated
         ......................... SERVER1NL passed test ObjectsReplic
      Starting test: frssysvol
         ......................... SERVER1NL passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours af
         SYSVOL has been shared.  Failing SYSVOL replication problems
         Group Policy problems.
         ......................... SERVER1NL failed test frsevent
      Starting test: kccevent
         ......................... SERVER1NL passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0xC0001B77
            Time Generated: 10/07/2008   17:26:58
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC25A001D
            Time Generated: 10/07/2008   17:31:05
            (Event String could not be retrieved)
         ......................... SERVER1NL failed test systemlog
      Starting test: VerifyReferences
         ......................... SERVER1NL passed test VerifyReferen

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRef

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDR

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRef

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDR

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidati
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefV
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRe

   Running partition tests on : technopc
      Starting test: CrossRefValidation
         ......................... technopc passed test CrossRefValida
      Starting test: CheckSDRefDom
         ......................... technopc passed test CheckSDRefDom

   Running enterprise tests on : technopc.eu
      Starting test: Intersite
         ......................... technopc.eu passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed,
5
         A Good Time Server could not be located.
         ......................... technopc.eu failed test FsmoCheck

C:\Program Files\Support Tools>
A good time server?

What's that?
0
 

Author Comment

by:daveviolante
ID: 22660663
Hi Ryan,

Did you see the result from DC Diag?

Also i would like to do what you said, but if i shut the server down the root DC, no body can logon anymore nothing work anymore even the virtual server DC the Active directory are not available anymore. Basically the fsmo role cannot be transfered i just cannot understand why using active directory it seems to work(to be transfred), but is not in reality.
0
 
LVL 2

Assisted Solution

by:jmoisy
jmoisy earned 450 total points
ID: 22660776
Hi,

Can you verify that the time is set correctly on the two server ?

If there is a difference correct it and try again to demote.

Regards,
0
 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 750 total points
ID: 22660790
OK no worries about the time server thats not a critical component at this point.
If you power down the machine then seize the fsmo roles
http://support.microsoft.com/kb/255504

After then you can run a metadata clean up and life should be good.
As always make sure you have good clean backups before doing anything...
0
 
LVL 16

Assisted Solution

by:robrandon
robrandon earned 150 total points
ID: 22661003
Are you running DNS on your virtual DC, or is it only running on your physical DC?  You will need DNS running when you shut down that physical box.
0
 
LVL 7

Assisted Solution

by:BogdanSUA
BogdanSUA earned 150 total points
ID: 22663540
When you virtualized your DCs, did you build them fresh and then do a DC promo, or did you do a P2V?
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
High user turnover can cause old/redundant user data to consume valuable space. UserResourceCleanup was developed to address this by automatically deleting user folders when the user account is deleted.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question