Unable to Demote Domain Controller: DCPromo Error

Posted on 2010-01-06
Last Modified: 2012-05-08

I'm getting the following error when trying to demote a DC
"The box indicating that this is the last domain controller for the domain <domain> is unchecked.  However, no other Active Directory domain controllers for that domain can be contacted."

I have transfered the 5 fsmo roles to the from the OLDDC to the NEWDC and checked this using the Netdom Query fsmo tool to ensure that the roles have moved to the NEWDC.

Now if I shut down the OLDDC then the NEWDC cannot access the Domain Security Policy - Access denied or computer unavailable, and also cannot access the Domain Controller Security Policy - access denied or computer unavailable

I also cannot access the \\domain\sysvol share if the OLDDC is not available.  

Somehow the OLDDC is still the "Default" if I can call it that and the NEWDC cannot access the GroupPolicies.   I have check all replication and settings but I'm at a loss

Any assistance will be greatly appreciated.  Hope there is enough info above


Question by:mekhet30
    LVL 13

    Expert Comment

    Run Dcdiag and post result here

    you change your new DC as global catlog server?
    LVL 13

    Expert Comment


    configure a domain controller as a global catalog server
    LVL 5

    Accepted Solution


    Thanks - managed to sort it out.

    The problem was with the sysvol and netlogon shares on the newdc that kept going unavailable.  The is a registry key to fix this issue.



    As soon as I did that I was able to reshare the sysvol and netlogon and set the NEWDC DLS to active.

    LVL 37

    Expert Comment

    have the oldDC and the NEWDC had a chance to sync yet? If the sysvol is not accessible yet it may be the case that they have not.
    LVL 13

    Expert Comment

    Good Luck

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Suggested Solutions

    Title # Comments Views Activity
    Blocking GP Policy when authentication to a remote site 23 68
    Screen Mirroring 7 26
    exchange 8 34
    exchange 2007 2 23
    I know all systems administrator at some time or another has had to create a script to copy file from a server share to a desktop. Well now there is an easy way to do this in Group Policy. Using Group policy preferences is not hard. The first thing …
    ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
    This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    25 Experts available now in Live!

    Get 1:1 Help Now