Solved

Cannot demote dc - Last DNS server for zone

Posted on 2011-03-22
9
2,166 Views
Last Modified: 2012-05-11
Hi, having trouble demoting a domain controller (2008 integrated DNS)
I get an error complaining about this dc being the last dns for the following ad integrated zone.
This is a primary zone (not the same domain that the dc itself is on), ad integrated, accepting secure and non-secure updates.
thnks.
0
Comment
Question by:Nelesh_N
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
  • 2
9 Comments
 
LVL 74

Accepted Solution

by:
Glen Knight earned 334 total points
ID: 35187711
If you check the properties of the zone on the Dc you are trying to demote, under Type click Change and uncheck the box for Store in Active Directory.  Then restart the DNS services.
0
 
LVL 1

Author Comment

by:Nelesh_N
ID: 35187898
But I do need it to be stored in AD, I dont want anything ito the zone to change.
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35187915
You cannot have a DNS zone stored in AD if the DNS server is not a domain controller.

This is why you are receiving the error when trying to DCPROMO
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 9

Assisted Solution

by:Chev_PCN
Chev_PCN earned 166 total points
ID: 35188466
If the zone is AD-integrated, then it should be replicated to all other DC's.
Verify this on the other DC's and check replication.
One worst case scenario would be to use the DCPROMO / forceremoval & then do a metadata cleanup afterwards. How many DC's do you have in total?
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35188474
Why would you want to do a forceremoval, it's a failry simply fix!!
0
 
LVL 9

Expert Comment

by:Chev_PCN
ID: 35188495
As mentioned - worst case scenario only if the DC will not demote gracefully.
0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35188499
But the reason it will not demote gracefully is because it has a zone on it which is AD integrated, it's a simple fix.
0
 
LVL 1

Author Comment

by:Nelesh_N
ID: 35197098
It is AD integrated...
0
 
LVL 74

Assisted Solution

by:Glen Knight
Glen Knight earned 334 total points
ID: 35197102
So change it so that it isn't AD Integrated and you will then be able to demote the server.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
powershell mailbox move question 8 47
Distinguished username as email address 4 43
(Same as parent Folder) Host (A) IP: x.x.x.x 7 39
Matching variables and Compare-Object 24 54
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question