daveviolante
asked on
Cannot Demote Active Directory DC into member server
Hi,
Before I go to the question issue need to explain a bit of my Domain Network environment.
I recently virtualised all my domain network environment from phisical servers to virtual.
Now i am running almost everything virtually in robust and very powerfull server that runs VMware Server. There also a separate Phisical Root Domain Controller that need to be demoted to a member server and let the virtual Domain Controller become the only DC
I have 3 virtual machine:
1) Server Domain controller added as additional DC
2) Member Server that function as Exchange Server
3) Terminal Server in a member server
Eventually i will add another DC as additional DC.(Redundancy)
This is production environment with 50 user small office. Not alive still experimental we need to go alive 2009
Here we go:
I tried to demote the root DC to a member server, and if i remember correctely when this operation is done the role of Active Directory DC is automatically transfred to another available DC, (In this case should be the Virtual DC) but unfortunately this doesn't happen and i get an error message when i try to remove the DC role, first he ask me if there are other GC Server and indeed the Virtual server is also GC so I click next to continue, then the wizard ask me if this is the last DC in the Domain obviously isn't so i don't check the check box. Soon after i click next and i get the following error:
The box indicating that this is the last domain controller is unchecked, however no other domain controller can be contacted. Do you wish to proceed anyway?
Now, if i say yes the operation fails if i say no then the process is aborted.
I cannot understand the issue, it seems that Active Directory has something wrong.
I checked the DNS configuration and it's all ok, the virtual server is GC, also when i go to site and services i can see the two domain controller and if i go to ntds click property i can let the two server replicate each other. So.... Where the problem is? It seems that the additional DC that is virtual machine is a read only copy of Active Directory. I notice that if i switch the root phisical server off no body can authenticate also from the virtual server it is not possible open active directory anymore, and exchange doesn't work anymore i cannot logon to any virtual machine into the domain.
Please help i had a similar problem while ago but right i cannot figure out where the issue is.
Before I go to the question issue need to explain a bit of my Domain Network environment.
I recently virtualised all my domain network environment from phisical servers to virtual.
Now i am running almost everything virtually in robust and very powerfull server that runs VMware Server. There also a separate Phisical Root Domain Controller that need to be demoted to a member server and let the virtual Domain Controller become the only DC
I have 3 virtual machine:
1) Server Domain controller added as additional DC
2) Member Server that function as Exchange Server
3) Terminal Server in a member server
Eventually i will add another DC as additional DC.(Redundancy)
This is production environment with 50 user small office. Not alive still experimental we need to go alive 2009
Here we go:
I tried to demote the root DC to a member server, and if i remember correctely when this operation is done the role of Active Directory DC is automatically transfred to another available DC, (In this case should be the Virtual DC) but unfortunately this doesn't happen and i get an error message when i try to remove the DC role, first he ask me if there are other GC Server and indeed the Virtual server is also GC so I click next to continue, then the wizard ask me if this is the last DC in the Domain obviously isn't so i don't check the check box. Soon after i click next and i get the following error:
The box indicating that this is the last domain controller is unchecked, however no other domain controller can be contacted. Do you wish to proceed anyway?
Now, if i say yes the operation fails if i say no then the process is aborted.
I cannot understand the issue, it seems that Active Directory has something wrong.
I checked the DNS configuration and it's all ok, the virtual server is GC, also when i go to site and services i can see the two domain controller and if i go to ntds click property i can let the two server replicate each other. So.... Where the problem is? It seems that the additional DC that is virtual machine is a read only copy of Active Directory. I notice that if i switch the root phisical server off no body can authenticate also from the virtual server it is not possible open active directory anymore, and exchange doesn't work anymore i cannot logon to any virtual machine into the domain.
Please help i had a similar problem while ago but right i cannot figure out where the issue is.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Hi,
As Ryan said before i did transfer all the 5 fsmo roles using AD. Now it seems that the virtual domain controller hold all the 5 roles plus is a DC. Issue still remain but i find out something guys and one of you it might help maybe. First of all I couldn't transfer the fsmo role using ntdsutil the command was failing when i supposed to connect to the server that was holding the fsmo role. this shouldn't happen. But as i said before i did it with active directory. After i run DC Diag and i can see there is a problem with fsmo role thta is not available please read the dc diag result below:
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Netherlands\SERVER1NL
Starting test: Connectivity
......................... SERVER1NL passed test Connectivity
Doing primary tests
Testing server: Netherlands\SERVER1NL
Starting test: Replications
......................... SERVER1NL passed test Replications
Starting test: NCSecDesc
......................... SERVER1NL passed test NCSecDesc
Starting test: NetLogons
......................... SERVER1NL passed test NetLogons
Starting test: Advertising
Warning: SERVER1NL is not advertising as a time server.
......................... SERVER1NL failed test Advertising
Starting test: KnowsOfRoleHolders
......................... SERVER1NL passed test KnowsOfRoleHo
Starting test: RidManager
......................... SERVER1NL passed test RidManager
Starting test: MachineAccount
......................... SERVER1NL passed test MachineAccoun
Starting test: Services
......................... SERVER1NL passed test Services
Starting test: ObjectsReplicated
......................... SERVER1NL passed test ObjectsReplic
Starting test: frssysvol
......................... SERVER1NL passed test frssysvol
Starting test: frsevent
There are warning or error events within the last 24 hours af
SYSVOL has been shared. Failing SYSVOL replication problems
Group Policy problems.
......................... SERVER1NL failed test frsevent
Starting test: kccevent
......................... SERVER1NL passed test kccevent
Starting test: systemlog
An Error Event occured. EventID: 0xC0001B77
Time Generated: 10/07/2008 17:26:58
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC25A001D
Time Generated: 10/07/2008 17:31:05
(Event String could not be retrieved)
......................... SERVER1NL failed test systemlog
Starting test: VerifyReferences
......................... SERVER1NL passed test VerifyReferen
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRef
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDR
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRef
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDR
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidati
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefV
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRe
Running partition tests on : technopc
Starting test: CrossRefValidation
......................... technopc passed test CrossRefValida
Starting test: CheckSDRefDom
......................... technopc passed test CheckSDRefDom
Running enterprise tests on : technopc.eu
Starting test: Intersite
......................... technopc.eu passed test Intersite
Starting test: FsmoCheck
Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERV ER_PREFERR ED) call failed,
5
A Good Time Server could not be located.
......................... technopc.eu failed test FsmoCheck
C:\Program Files\Support Tools>
A good time server?
What's that?
As Ryan said before i did transfer all the 5 fsmo roles using AD. Now it seems that the virtual domain controller hold all the 5 roles plus is a DC. Issue still remain but i find out something guys and one of you it might help maybe. First of all I couldn't transfer the fsmo role using ntdsutil the command was failing when i supposed to connect to the server that was holding the fsmo role. this shouldn't happen. But as i said before i did it with active directory. After i run DC Diag and i can see there is a problem with fsmo role thta is not available please read the dc diag result below:
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Netherlands\SERVER1NL
Starting test: Connectivity
......................... SERVER1NL passed test Connectivity
Doing primary tests
Testing server: Netherlands\SERVER1NL
Starting test: Replications
......................... SERVER1NL passed test Replications
Starting test: NCSecDesc
......................... SERVER1NL passed test NCSecDesc
Starting test: NetLogons
......................... SERVER1NL passed test NetLogons
Starting test: Advertising
Warning: SERVER1NL is not advertising as a time server.
......................... SERVER1NL failed test Advertising
Starting test: KnowsOfRoleHolders
......................... SERVER1NL passed test KnowsOfRoleHo
Starting test: RidManager
......................... SERVER1NL passed test RidManager
Starting test: MachineAccount
......................... SERVER1NL passed test MachineAccoun
Starting test: Services
......................... SERVER1NL passed test Services
Starting test: ObjectsReplicated
......................... SERVER1NL passed test ObjectsReplic
Starting test: frssysvol
......................... SERVER1NL passed test frssysvol
Starting test: frsevent
There are warning or error events within the last 24 hours af
SYSVOL has been shared. Failing SYSVOL replication problems
Group Policy problems.
......................... SERVER1NL failed test frsevent
Starting test: kccevent
......................... SERVER1NL passed test kccevent
Starting test: systemlog
An Error Event occured. EventID: 0xC0001B77
Time Generated: 10/07/2008 17:26:58
(Event String could not be retrieved)
An Error Event occured. EventID: 0xC25A001D
Time Generated: 10/07/2008 17:31:05
(Event String could not be retrieved)
......................... SERVER1NL failed test systemlog
Starting test: VerifyReferences
......................... SERVER1NL passed test VerifyReferen
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRef
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDR
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRef
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDR
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidati
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefV
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRe
Running partition tests on : technopc
Starting test: CrossRefValidation
......................... technopc passed test CrossRefValida
Starting test: CheckSDRefDom
......................... technopc passed test CheckSDRefDom
Running enterprise tests on : technopc.eu
Starting test: Intersite
......................... technopc.eu passed test Intersite
Starting test: FsmoCheck
Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERV
5
A Good Time Server could not be located.
......................... technopc.eu failed test FsmoCheck
C:\Program Files\Support Tools>
A good time server?
What's that?
ASKER
Hi Ryan,
Did you see the result from DC Diag?
Also i would like to do what you said, but if i shut the server down the root DC, no body can logon anymore nothing work anymore even the virtual server DC the Active directory are not available anymore. Basically the fsmo role cannot be transfered i just cannot understand why using active directory it seems to work(to be transfred), but is not in reality.
Did you see the result from DC Diag?
Also i would like to do what you said, but if i shut the server down the root DC, no body can logon anymore nothing work anymore even the virtual server DC the Active directory are not available anymore. Basically the fsmo role cannot be transfered i just cannot understand why using active directory it seems to work(to be transfred), but is not in reality.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
already done that,
This is the problem i already done the main common troobleshooting steps.
I made the virtual server GC and transfered all the fsmo roles to it.
It still doesn't work, I'll try again riht now see if i made any mistake but i don't think i did, i do this things in regular basis i am an IT Guy and i know the most common task