after demoting DC, can't contact domain controller

Posted on 2008-11-17
Medium Priority
Last Modified: 2013-12-24
Computers on domain dont get connected to shares or printers automatically (can be mapped manually).
active directory is configured improperly somewhere and its not recognizing 2k3 DC "a" as the DC since the original 2k DC was demoted  (I swear I followed all appropriate steps  by transfering FSMO roles and seizing the them on the old DC).  The AD is visible and running.  However, it's not being acknowledged that 2k3 DC "a" as the primary DC.  I thought it might be because its 2k3, but its running in mixed mode which means it can play with 2k servers.  I checked the following:
-srv records on the dns server (which is not a DC) and appears that all the neccessary entries exist
-nslookup, set type=all,  Type _ldap._tcp.dc._msdcs.(Domain_Name) and responded with the right ip addresses
-ran netdiag and notice this error message: "the system volume has not been completely replicated to the local machine. this machine is not working properly as a dc".

Appears that the old 2k DC was holding on to something and it didn't properly transfer over.  I don't know what i missed; i thought all i had to do was transfer FSMO roles, seize the old one, and demote..as soon as i demoted, "can't contact domain controller".  
Question by:eelmazovski
  • 4
  • 2
LVL 70

Expert Comment

ID: 22980891
I'm a bit confused since you talk of transfering the FSMO roles then seizing the them - if you did a clean transfer, then there is no need to seize.

Did yoi make the new server a Global Catalog Server ?  To make the new machine a global catalog server, go to Administrative Tools, Active Directory Sites and Services, Expand, Sites, Default first site and Servers. Right click on the new server and select properties and tick the Global Catalog checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

Did you install DNS on the new server and configure you clients to use the new server for their DNS server ?

Author Comment

ID: 22981130
Yes, I made the new server a GC following those steps.  I didn't make the new server the dns server. there's a 2k server that handles that for us.  As far as i know, that dns is running fine.
LVL 70

Expert Comment

ID: 22981187
Is there any special reason that you are not using AD integrated DNS on the domain controllers, it makes far more sence to use Active Directory Integrated DNS in most cases, its much more efficient, less troublesome and secure.

I assume the Old DC is not functioning anymore - did you do a DCPROMO on it to remove Active Directory from it?
A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.


Author Comment

ID: 22981326
thanks for the quick response. the dns has been setup on that server since the begininng of time and it wasn't changed by the previous admin..yes, i ran the dcpromo on the original dc and it apparently ran succesfully; the AD isn't no longer there on that server.  as soon as that was successful, computers are failing "to contact domain controller".  the 2k3 dc is not being picked up by the network and i'm worried that the domain settings were damaged during this demoting process. i can access shares by entering the paths whether by name or ip (it will prompt me for a user id and password), i can get on the web, i can print to network servers; so, dhcp is working, dns apparently is working; sysvol directory exists; ...i don't know, first time i encountered an AD issue on this level and it's very frustrating.

Author Comment

ID: 22984343
I tried setting up another server as a DC and receive the message: "An Active Directory domain controller for the domain my.domain could not be contacted.  Ensure that the DNS name is typed correctly.  if the domain is correct then click details for troubleshooting information."  i do that and it lists common causes:
-Host (A) records that map the domain controller to its IP addresses are missing or contain incorrect addresses.
-Domain controllers registered in DNS are not connected to the network or are not running.
It's definetly not the second cause because it's online; it can be accessed by other workstations including the server.  pls help

Accepted Solution

eelmazovski earned 0 total points
ID: 23035506
It's resolved...the sysvol and netlogon folders weren't shared.

kb290762 and 315457

thanks for your efforts KCTS

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This article will help to fix the below errors for MS Exchange Server 2016 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question