[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Active Directory Roles

Posted on 2011-05-13
11
Medium Priority
?
434 Views
Last Modified: 2012-05-11
Dears
I have three DCs in one forest and on Active Directory , before yesterday one DC failed so we use in another site NTDSUTIL and we seize the infrastructure and PDC now yesterday the server fixed and it,s working fine now i have the following Questions please help me :
1- now i have two server with duplicate roles it,s ok or what i have to do to remove roles from one of this server.
2- after we fixed the server the replication not working what i can do to fix it.

thank you ....
0
Comment
Question by:it-qatar
  • 4
  • 3
  • 2
  • +1
11 Comments
 
LVL 12

Expert Comment

by:serchlop
ID: 35753671
First, you can't have 2 server with the same fsmo, when you make the change to fsmo, the new server will host that role.

To solve your problem about replication maybe you would need to move the others fsmo to another server and then uninstall active directory from that server and then add again as a dc. If you have problems remove the dc failed maybe you need to force demotion for this domain with dcpromo and a parameter that i don't remember right now, but you can google for it.
0
 
LVL 24

Accepted Solution

by:
Radhakrishnan R earned 1000 total points
ID: 35753780
Yes..You have to demote the failed DC and need to perform the metadata cleanup and then you can promote as DC and you can transfer any roles if you want.

This article will show you how to clean up metadata http://www.petri.co.il/delete_failed_dcs_from_ad.htm

"Good Luck"
0
 
LVL 13

Expert Comment

by:5g6tdcv4
ID: 35754014
So what you have is the situation where your PDC and infrastructure master was offline.
You seized the roles while the server was down.
The server came back online and now is unaware that its roles were seized.
First you need to find out what roles your other domain domain controller think are held by other servers.
use this command: netdom query /domain:yourdomain /server:DCNAME fsmo
run this against every domain controller in your org. If all of your servers think that the machine that you recently seized the roles holds those roles then
You need to demote the failed domain controller that "came back"
using dcpromo /forceremoval and then do the metadata cleanup mentioned in the article above
Don't forget to clean up DNS as well, removing any reference to it
0
Fill in the form and get your FREE NFR key NOW!

Veeam is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

 

Author Comment

by:it-qatar
ID: 35762675

So now first i have to demote the failed DC then while its removing i have to seize the other roles to another DC then after removing the DC i have to install Active directory role again then teransfer the role i want from that DC ?
0
 
LVL 12

Expert Comment

by:serchlop
ID: 35762710
You first have to get sure that the fsmo are in a functional dc like say the expert, thenyou have to remove the failed dc with dcpromo /forceremoval and then verify that all the metadata for removed server was removed in functional dc, to allow configure it again as a dc and return fsmo to original server.
0
 

Author Comment

by:it-qatar
ID: 35762781
If i make a force removal for the failed DC no problem i mean my network will be ok and users can logon without any problem ,
0
 
LVL 24

Expert Comment

by:Radhakrishnan R
ID: 35762806
Have you checked which sever holding all the fsmo roles, If it is failed DC then you need to size those, If it is on other DC then no issues for users to authenticate.

"netdom query fsmo" will help you to identify.
0
 

Author Comment

by:it-qatar
ID: 35763003
Every thing OK i moved all roles to another server on another site , but now i tried to create test user ok it,s created and i joined PC to domain and ok but when i tried to login to this test user to the joined domain PC it,s give me error " there are curently no logon servers avliable to service the logon request" any idea what this ?
0
 
LVL 24

Expert Comment

by:Radhakrishnan R
ID: 35763601
I moved all roles to another server on another site - Is trust relationship configured for these 2 sites? Have you enabled Global Gatalog on this server?
0
 

Author Comment

by:it-qatar
ID: 35763657
Why trust relationship it,s in same forest and same domain ,,,, any way it,s working now can any one tell me how to test replications between sites and another thing in active directory sites the new server not configured under NTDS setting should i add it manualy . thx
0
 
LVL 13

Expert Comment

by:5g6tdcv4
ID: 35764048
repadmin
Just type the command at the prompt and it will show you all of the options.
   /showrepl Displays the replication status when specified domain controll
           last attempted to inbound replicate Active Directory partitions.

   /showutdvec displays the highest committed Update Sequence Number (USN)
           that the targeted DC's copy of Active Directory shows as
           committed for itself and its transitive partners.

   /syncall Synchronizes a specified domain controller with all replication
            partners.
0

Featured Post

Get quick recovery of individual SharePoint items

Free tool – Veeam Explorer for Microsoft SharePoint, enables fast, easy restores of SharePoint sites, documents, libraries and lists — all with no agents to manage and no additional licenses to buy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
Transferring FSMO roles is done when an admin wants to split roles between certain Domain Controllers or the Domain Controller holding the Roles has been forcefully demoted using dcpromo / forceremoval
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question