?
Solved

Windows 2008 and 2003 AD problem

Posted on 2011-09-13
13
Medium Priority
?
446 Views
Last Modified: 2012-05-12
Hello,

My environment:

- 1 Windows Server 2008 SP2 DC, DNS, DHCP, holding  4 MSFO roles (all but infrastructure)
- 1 Windows Server 2003 SP2 DC DEFINITIVELY OFFLINE (holding only infrastructure role FSMO)

Problems:
I cannot transfer the Infrastructure FSMO role to the 2008 server (since the 2003 DC server is definitely offline)
1 want to do a clean delete of the 2003 DC from AD. It still appears in “sites and services” in AD DSA, in “domains and approbations”, ect….since it has never been demoted with DCPROMO

Of course I have AD replication errors in the event log, trying to replicate AD with the 2003 offline DC, I have also NTFRS errors, trying replications with the 2003 Offline DC, ect….

Questions:
- If I delete the 2003 Server from “sites and services” (in the 2008 DC) will it be enough to solve the FSMO missing role? If not how can I transfert this role to the 2008 DC ?
- Deleting the 2003 Server from “sites and services” will be enough to clean all AD from the 2003 DC?
- Any suggested procedure ?

Thank you
0
Comment
Question by:gadsad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
  • 3
13 Comments
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532042
Use NTDSUTIL to delete the failed DC from AD - a full guide can be followed here:

http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Once it is gone - remove it from AD Sites and Services and then run DCDIAG and see how it is.
0
 

Author Comment

by:gadsad
ID: 36532117
and how do I transfert the Infrastructure FSMO role that is still in the offline server ?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532130
When you remove the failed DC via NTDSUTIL - it should seize the roles for you automatically.

If that doesn't work (which would be odd), then you can seize them yourself:

http://support.microsoft.com/kb/255504
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532188
Questions:
- If I delete the 2003 Server from “sites and services” (in the 2008 DC) will it be enough to solve the FSMO missing role?
No, You need to seize the infrastructure role.

If not how can I transfert this role to the 2008 DC ?  
No, you can not as its offline, you need to seize it.
Seizing FSMO Roles- http://www.petri.co.il/seizing_fsmo_roles.htm

- Deleting the 2003 Server from “sites and services” will be enough to clean all AD from the 2003 DC?
Deleting the 2003 Server from “sites and services” will not be enough, You will need to perform complete metadata cleanup steps along with deleting failed DC from AD sites, AD Users and computers and its DNS records.

Metadata cleanup:
http://msmvps.com/blogs/ad/archive/2008/12/17/how-to-remove-a-failed-or-offline-dc.aspx.
http://usefulglyphs.wordpress.com/2010/02/10/how-to-delete-a-failed-domain-controller-from-active-directory/

0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532290
@ alanhardisty: Yes, I know the EE rules, not any difference in my comments, I had no any intention to post duplicate comments my mistake but I was preparing for comments and at the same time you posted your comments.  
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532319
It took you 22 minutes to come up with an answer since my first post?

If it takes you that long to Google for suitable links, may I suggest you hit the refresh button before posting.
0
 

Author Comment

by:gadsad
ID: 36532337
So if I understood well
1) NTDSUTIL and it will delete the failed DC and should also seize the infrastructure role
2) If the infrastructure role has not been automatically seized, I do it manually
3) I delete the failed DC from AD sites

Right ?
Do I have to reboot the DC in all this procedure ?

Thanks
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 36532348
You understand well!

No reboot required.
0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532352
Thank you for suggestion, I was on call so unable to calculate that 22 minutes.    
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532376
I know the feeling only too well :)  Please be careful in future though.  EE is fast-paced, especially so in the Exchange Zone and if you get distracted between opening the Question and posting - you may find a similar situation happening.
0
 

Author Closing Comment

by:gadsad
ID: 36532478
thank you
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532489
You are welcome - if you get stuck anywhere - please post a follow-up comment.

Thanks for the points.

Alan
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question