Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 759
  • Last Modified:

Replication errors after AD 2003->2008 Schema upgrade

Hi EEr's

Have recently taken over a new client who have a small network with a couple of servers:
Previous IT guru attempted (and successfully?) upgraded their AD schema to 2008 (in preparation for their move to Exchange 2010 & new 2008 Servers), however one of their DCs failed the upgrade. Server was due to be decommissioned but was overlooked during the upgrade, has some serious OS issues that prevent communication to the network.

Should I manually remove it from the AD environment with NTDSutil (following steps identified here:http://www.petri.co.il/delete_failed_dcs_from_ad.htm) or am I better off trying to repair the OS and decommission via DCPromo?

Previous IT guy had attempted repairs, but AD replication errors & DNS resolution issues (due to non-replication of AD) that are piling up encouraged him to find greener pastures.

All FSMO roles, DHCP & DNS services have been transferred off the old server some time ago, and DCDiag doesn't report any issues with their primary DC (Secondary GC Servers are reporting replication warnings!).

Any advice?!

Regards
Mike

0
GTMike
Asked:
GTMike
  • 2
  • 2
1 Solution
 
snusgubbenCommented:
That's up to you if you chose to fix and demote, or run a MD Cleanup.

If you're in a hurry, a MD Cleanup will save you some time. Just remember to run dcpromo /forceremoval on it in case you do a MD Cleanup.
0
 
GTMikeAuthor Commented:
HI Snusgubben

Am considering trying to repair it (Was an old Win2000 that was upgraded to Win2003 by the look of it), but wondering if it'll even communicate properly once online given that its AD infrastructure missed the Schema upgrade?

Given that the old server won't even communicate with the domain in its present configuration (DCDiag fails to connect with a RPC error when run from the existing DC), should I just save time and do the MD cleanup?  DCPromo /forceremoval probably won't run given then RPC errors I'm seeing on the old server!

Regards
Mike
0
 
Mike KlineCommented:
When you say "successfully?" you can verify that  http://technet.microsoft.com/en-us/library/dd464018(WS.10).aspx#BKMK_VerifyForestPrep

See if your schema is at 44 for 2008 or 47 for 2008 R2.

I'd also go with the removal and metadata cleanup.

Thanks

Mike
0
 
snusgubbenCommented:
"dcpromo /forceremoval" will just uninstall AD from this old DC and place it in a workgroup. It will not replicate the "demotion" to its old replication partners. Thus you need to run the MD Cleanup.

You can compare the schema version on this DC and see if the schema extension has been replicated to the old DC. But I'd not hesitate. Force it out :)



0
 
GTMikeAuthor Commented:
Great advice for confirmation of a fix, thank you!
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now