Solved

how to demote DC and joining it on a remote DC

Posted on 2010-11-17
23
613 Views
Last Modified: 2012-05-10

 Hi Experts,

 How to demote DC and join it on a remote DC with different subnet?
 I need a step by step guide please. many thanks
0
Comment
Question by:ragot
  • 12
  • 8
  • 3
23 Comments
 
LVL 5

Accepted Solution

by:
logideepak earned 500 total points
ID: 34162156
For Demoting a DC,
goto start--> Run and type dcpromo

It will provide you with a web based wizard for demtoting the current dc and bringing the machine in the workgroup.

After that you need to set up the TCP / IP Settings of the workgroup so that it can find the ad from other sub net.

Once the IP settings are complete, you can add the computer in the remote dc.
0
 

Author Comment

by:ragot
ID: 34162239
thanks logideepak! do i need to run dcpromo again after i add the pc in the remote dc?
0
 
LVL 5

Expert Comment

by:logideepak
ID: 34162257
No, DCPromo is used to either create an AD structure in the server to promote the machine as a domain controller.
Once the machine is promoted to a domain controller, if you run the dcpromo again, it will demote the machine back to the workgroup.

however, after adding the PC to the remote DC, you dont need to run the dcpromo command.
0
 

Author Comment

by:ragot
ID: 34162283
thanks but i want that DC to be part of the remote DC.
0
 
LVL 5

Expert Comment

by:logideepak
ID: 34162298
Have you installed your DC as a part of the existing Forest of the Remote DC?
0
 

Author Comment

by:ragot
ID: 34162320
i think not yet, can you tell me how to install?
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34163312
ragot
To give you an accurate answer we will need to know your topology.

Do you have a seperate AD forest at this remote site you want this DC to be a part of?
Is this DC just moving to a seperate subnet within your company and will still be apart of the same forest?

Here is a link on how to run DCPromo, but it may not fit your senerio.

http://www.petri.co.il/how_to_install_active_directory_on_windows_2003.htm
0
 

Author Comment

by:ragot
ID: 34170030
Do you have a seperate AD forest at this remote site you want this DC to be a part of? - this is the one.
i already joined the dc into another AD forest. i can logon administrator with the same domain on different subnet. problem is i cannot login my new created user account from AD. i got the error message " The local policy of this system does not permit you to logon interactively "
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34170043
Are you trying to login to a Domain Controller with a user account you created? or it is juts a server?

If it is a server make sure that user is at least in the Remote Desktop User group. If it is the Domain Controller the user will need to be in the domain admins group.
0
 

Author Comment

by:ragot
ID: 34170096

 wow it works now after setting it as a member of remote desktop user group.
 will there be no problem if i created a user account and logon to client machine?
 and is there any DNS forwarding that needs to be setup on the instructions above? ( please refer to logideepak's first reply )

 thanks!
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34170105
If you need to get name resolution for the other domain you can setup conditional forwaders in each domain. See link below

You should be able to login into client computers with new accounts on the same domain.



http://msmvps.com/blogs/ad/archive/2008/09/05/how-to-configure-conditional-forwarders-in-windows-server-2008.aspx
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:ragot
ID: 34170155
thanks KenMcF, how will i know if i need to get name resolution for the other domain?
do you have link for server 2003? thanks
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34170182
That link has a screen shot from 2003. It is labled old way.

If you do not need to access any resources on the other domain then you should not need to configure the forwarders.
0
 

Author Comment

by:ragot
ID: 34170224
oh i see. we need to access files on both domain. can you help me how to do the configuration for forwarders? many thanks
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34170275
Look at this link for setting up conditional forwaders.

You would just put the domain name in for the remote domain and the IP of the DNS server.

http://www.windowsnetworking.com/articles_tutorials/DNS_Conditional_Forwarding_in_Windows_Server_2003.html
0
 

Author Comment

by:ragot
ID: 34170285

 scenario
 DC1 - " other DC "
 DC2 - demoted and join " other DC "

 you mean i will input the DNS of DC2 into forwarder settings? am i correct?
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34170314
You have two forests now. So call them forest1 and forest2

forest1 = domain1.local

forest2 = domain2.dns

in forest1 create a conditional forwader for domain2.dns and points to a DNS server in domain2.dns

in forest2 create a conditional forwader for domain1.local and points to a DNS server in domain1.local
0
 

Author Comment

by:ragot
ID: 34184989

 thanks KenMcF! if i demote the DC, do i need to reconfigure the DHCP server after joining it to other domain?
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34185064
You will need to authorize the DHCP server in the new domain and I would verify the settings are correct like the DNS servers.
0
 

Author Comment

by:ragot
ID: 34185122

 thanks. how about the files?, they will not be deleted right? i just have to reassign access rights to them?
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 34185157
Files will not be deleted. Since it is a new domain you will need to reassign permissions.
0
 

Author Comment

by:ragot
ID: 34185271

 thanks. no need to create another AD on forest2 right? i will just use the forest1 AD ( which is the one i joined to ) or it better to create?
0
 

Author Closing Comment

by:ragot
ID: 34288590
awesome! thanks
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Palo Alto Networks Global Protect 2 104
Event ID: 7023 / Source: Service Control Manager 4 92
Backup DHCP Server 8 94
By pass website on ASA for Websense 4 52
Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now