Solved

Windows 2008 and 2003 AD problem

Posted on 2011-09-13
13
443 Views
Last Modified: 2012-05-12
Hello,

My environment:

- 1 Windows Server 2008 SP2 DC, DNS, DHCP, holding  4 MSFO roles (all but infrastructure)
- 1 Windows Server 2003 SP2 DC DEFINITIVELY OFFLINE (holding only infrastructure role FSMO)

Problems:
I cannot transfer the Infrastructure FSMO role to the 2008 server (since the 2003 DC server is definitely offline)
1 want to do a clean delete of the 2003 DC from AD. It still appears in “sites and services” in AD DSA, in “domains and approbations”, ect….since it has never been demoted with DCPROMO

Of course I have AD replication errors in the event log, trying to replicate AD with the 2003 offline DC, I have also NTFRS errors, trying replications with the 2003 Offline DC, ect….

Questions:
- If I delete the 2003 Server from “sites and services” (in the 2008 DC) will it be enough to solve the FSMO missing role? If not how can I transfert this role to the 2008 DC ?
- Deleting the 2003 Server from “sites and services” will be enough to clean all AD from the 2003 DC?
- Any suggested procedure ?

Thank you
0
Comment
Question by:gadsad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
  • 3
13 Comments
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532042
Use NTDSUTIL to delete the failed DC from AD - a full guide can be followed here:

http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Once it is gone - remove it from AD Sites and Services and then run DCDIAG and see how it is.
0
 

Author Comment

by:gadsad
ID: 36532117
and how do I transfert the Infrastructure FSMO role that is still in the offline server ?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532130
When you remove the failed DC via NTDSUTIL - it should seize the roles for you automatically.

If that doesn't work (which would be odd), then you can seize them yourself:

http://support.microsoft.com/kb/255504
0
Get Actionable Data from Your Monitoring Solution

Your communication platform is only as good as the relevance of the information you send. Ensure your alerts get to the right people every time with actionable responses. Create escalation rules that ensure everyone follows the process and nothing is left to chance.

 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532188
Questions:
- If I delete the 2003 Server from “sites and services” (in the 2008 DC) will it be enough to solve the FSMO missing role?
No, You need to seize the infrastructure role.

If not how can I transfert this role to the 2008 DC ?  
No, you can not as its offline, you need to seize it.
Seizing FSMO Roles- http://www.petri.co.il/seizing_fsmo_roles.htm

- Deleting the 2003 Server from “sites and services” will be enough to clean all AD from the 2003 DC?
Deleting the 2003 Server from “sites and services” will not be enough, You will need to perform complete metadata cleanup steps along with deleting failed DC from AD sites, AD Users and computers and its DNS records.

Metadata cleanup:
http://msmvps.com/blogs/ad/archive/2008/12/17/how-to-remove-a-failed-or-offline-dc.aspx.
http://usefulglyphs.wordpress.com/2010/02/10/how-to-delete-a-failed-domain-controller-from-active-directory/

0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532290
@ alanhardisty: Yes, I know the EE rules, not any difference in my comments, I had no any intention to post duplicate comments my mistake but I was preparing for comments and at the same time you posted your comments.  
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532319
It took you 22 minutes to come up with an answer since my first post?

If it takes you that long to Google for suitable links, may I suggest you hit the refresh button before posting.
0
 

Author Comment

by:gadsad
ID: 36532337
So if I understood well
1) NTDSUTIL and it will delete the failed DC and should also seize the infrastructure role
2) If the infrastructure role has not been automatically seized, I do it manually
3) I delete the failed DC from AD sites

Right ?
Do I have to reboot the DC in all this procedure ?

Thanks
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 500 total points
ID: 36532348
You understand well!

No reboot required.
0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532352
Thank you for suggestion, I was on call so unable to calculate that 22 minutes.    
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532376
I know the feeling only too well :)  Please be careful in future though.  EE is fast-paced, especially so in the Exchange Zone and if you get distracted between opening the Question and posting - you may find a similar situation happening.
0
 

Author Closing Comment

by:gadsad
ID: 36532478
thank you
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532489
You are welcome - if you get stuck anywhere - please post a follow-up comment.

Thanks for the points.

Alan
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
A procedure for exporting installed hotfix details of remote computers using powershell
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question