Solved

Replication errors after AD 2003->2008 Schema upgrade

Posted on 2011-03-07
5
745 Views
Last Modified: 2012-05-11
Hi EEr's

Have recently taken over a new client who have a small network with a couple of servers:
Previous IT guru attempted (and successfully?) upgraded their AD schema to 2008 (in preparation for their move to Exchange 2010 & new 2008 Servers), however one of their DCs failed the upgrade. Server was due to be decommissioned but was overlooked during the upgrade, has some serious OS issues that prevent communication to the network.

Should I manually remove it from the AD environment with NTDSutil (following steps identified here:http://www.petri.co.il/delete_failed_dcs_from_ad.htm) or am I better off trying to repair the OS and decommission via DCPromo?

Previous IT guy had attempted repairs, but AD replication errors & DNS resolution issues (due to non-replication of AD) that are piling up encouraged him to find greener pastures.

All FSMO roles, DHCP & DNS services have been transferred off the old server some time ago, and DCDiag doesn't report any issues with their primary DC (Secondary GC Servers are reporting replication warnings!).

Any advice?!

Regards
Mike

0
Comment
Question by:GTMike
  • 2
  • 2
5 Comments
 
LVL 21

Accepted Solution

by:
snusgubben earned 250 total points
Comment Utility
That's up to you if you chose to fix and demote, or run a MD Cleanup.

If you're in a hurry, a MD Cleanup will save you some time. Just remember to run dcpromo /forceremoval on it in case you do a MD Cleanup.
0
 

Author Comment

by:GTMike
Comment Utility
HI Snusgubben

Am considering trying to repair it (Was an old Win2000 that was upgraded to Win2003 by the look of it), but wondering if it'll even communicate properly once online given that its AD infrastructure missed the Schema upgrade?

Given that the old server won't even communicate with the domain in its present configuration (DCDiag fails to connect with a RPC error when run from the existing DC), should I just save time and do the MD cleanup?  DCPromo /forceremoval probably won't run given then RPC errors I'm seeing on the old server!

Regards
Mike
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
When you say "successfully?" you can verify that  http://technet.microsoft.com/en-us/library/dd464018(WS.10).aspx#BKMK_VerifyForestPrep

See if your schema is at 44 for 2008 or 47 for 2008 R2.

I'd also go with the removal and metadata cleanup.

Thanks

Mike
0
 
LVL 21

Expert Comment

by:snusgubben
Comment Utility
"dcpromo /forceremoval" will just uninstall AD from this old DC and place it in a workgroup. It will not replicate the "demotion" to its old replication partners. Thus you need to run the MD Cleanup.

You can compare the schema version on this DC and see if the schema extension has been replicated to the old DC. But I'd not hesitate. Force it out :)



0
 

Author Closing Comment

by:GTMike
Comment Utility
Great advice for confirmation of a fix, thank you!
0

Featured Post

Integrate social media with email signatures

Is your company active on social media? Do you also use email signatures? Including social media icons in your email signature is a great way to get fans for free. Let all your email users know you’re on social media quickly and easily, in a single click.

Join & Write a Comment

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Know what services you can and cannot, should and should not combine on your server.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now