Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Windows 2008 and 2003 AD problem

Posted on 2011-09-13
13
Medium Priority
?
448 Views
Last Modified: 2012-05-12
Hello,

My environment:

- 1 Windows Server 2008 SP2 DC, DNS, DHCP, holding  4 MSFO roles (all but infrastructure)
- 1 Windows Server 2003 SP2 DC DEFINITIVELY OFFLINE (holding only infrastructure role FSMO)

Problems:
I cannot transfer the Infrastructure FSMO role to the 2008 server (since the 2003 DC server is definitely offline)
1 want to do a clean delete of the 2003 DC from AD. It still appears in “sites and services” in AD DSA, in “domains and approbations”, ect….since it has never been demoted with DCPROMO

Of course I have AD replication errors in the event log, trying to replicate AD with the 2003 offline DC, I have also NTFRS errors, trying replications with the 2003 Offline DC, ect….

Questions:
- If I delete the 2003 Server from “sites and services” (in the 2008 DC) will it be enough to solve the FSMO missing role? If not how can I transfert this role to the 2008 DC ?
- Deleting the 2003 Server from “sites and services” will be enough to clean all AD from the 2003 DC?
- Any suggested procedure ?

Thank you
0
Comment
Question by:gadsad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
  • 3
13 Comments
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532042
Use NTDSUTIL to delete the failed DC from AD - a full guide can be followed here:

http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Once it is gone - remove it from AD Sites and Services and then run DCDIAG and see how it is.
0
 

Author Comment

by:gadsad
ID: 36532117
and how do I transfert the Infrastructure FSMO role that is still in the offline server ?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532130
When you remove the failed DC via NTDSUTIL - it should seize the roles for you automatically.

If that doesn't work (which would be odd), then you can seize them yourself:

http://support.microsoft.com/kb/255504
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532188
Questions:
- If I delete the 2003 Server from “sites and services” (in the 2008 DC) will it be enough to solve the FSMO missing role?
No, You need to seize the infrastructure role.

If not how can I transfert this role to the 2008 DC ?  
No, you can not as its offline, you need to seize it.
Seizing FSMO Roles- http://www.petri.co.il/seizing_fsmo_roles.htm

- Deleting the 2003 Server from “sites and services” will be enough to clean all AD from the 2003 DC?
Deleting the 2003 Server from “sites and services” will not be enough, You will need to perform complete metadata cleanup steps along with deleting failed DC from AD sites, AD Users and computers and its DNS records.

Metadata cleanup:
http://msmvps.com/blogs/ad/archive/2008/12/17/how-to-remove-a-failed-or-offline-dc.aspx.
http://usefulglyphs.wordpress.com/2010/02/10/how-to-delete-a-failed-domain-controller-from-active-directory/

0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532290
@ alanhardisty: Yes, I know the EE rules, not any difference in my comments, I had no any intention to post duplicate comments my mistake but I was preparing for comments and at the same time you posted your comments.  
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532319
It took you 22 minutes to come up with an answer since my first post?

If it takes you that long to Google for suitable links, may I suggest you hit the refresh button before posting.
0
 

Author Comment

by:gadsad
ID: 36532337
So if I understood well
1) NTDSUTIL and it will delete the failed DC and should also seize the infrastructure role
2) If the infrastructure role has not been automatically seized, I do it manually
3) I delete the failed DC from AD sites

Right ?
Do I have to reboot the DC in all this procedure ?

Thanks
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 2000 total points
ID: 36532348
You understand well!

No reboot required.
0
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36532352
Thank you for suggestion, I was on call so unable to calculate that 22 minutes.    
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532376
I know the feeling only too well :)  Please be careful in future though.  EE is fast-paced, especially so in the Exchange Zone and if you get distracted between opening the Question and posting - you may find a similar situation happening.
0
 

Author Closing Comment

by:gadsad
ID: 36532478
thank you
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36532489
You are welcome - if you get stuck anywhere - please post a follow-up comment.

Thanks for the points.

Alan
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question