The directory services is missing mandatory configuration information, and is unable to determine the ownership of floating single-master operation roles.
I doing migration of AD with DNS server 2008 R2 to windows server 2012. but after migration when I try to demote old DC of 2008 R2 it shows below error message.
"The operation failed because: Active Directory Domain Services could not transfer the remaining data in directory partition DC=ForestDnsZones,DC=domain-internal,DC=com to Active Direcotry Domain Controller \\RWC-DC2.domain-internal.com.
"The directory services is missing mandatory configuration information, and is unable to determine the ownership of floating single-master operation roles." dc-remove.jpg DNS.png
I have successfully transferred FSMO roles to migrated 2012 DC. after transfer FSMO I have run command netdom query fsmo and it shows successfully.here i have attached file fsmo.jpg
rigelnet
ASKER
My setup is as below
old server : win server 2008 r2 including Active Directory and DNS
plan for New server: win server 2012 with Active directory and DNS and used new hardware with upgraded one.
Here I have attached right screenshot of my test setup which shows all fsmo roles are transferred successfully. Though I have tried with seize FSMO but when i run this it shows transferred successfully no need to seize. fsmo-result.jpg
Further more I have checked dcdiag /q from 2012
repadmin /replsum from 2012 while put down old 2008 R2 DC. Than i will get test result as attached dcdiag-test.jpg
thomasclm
Can you make an entry in DNS of the missing GUID (see attacment). Without porper GUID, AD will never replicate.
It seems to be dns issue make sure below practice is followed
Every DNS server should Point to its own IP as a primary DNS and DNS located in remote site as a secondary DNS in TCP/IP properties
All the unused NIC's to be disabled
Valid DNS Ip from ISP to be configuered in DNS forwarders Do not configuere local DNS in forwarders
Public DNS IP's Should not be used at any NIC Card except Forwarders
Domain Controllers should not be multi-homed
Running VPN server and RRas server makes the DC multihomed refer http://support.microsoft.com/default.aspx?scid=kb;en-us;272294
If anything above is incorrect please correct it and run "ipconfig /flushdns & ipconfig /registerdns " and restart DNS service using "net stop dns & net start dns"
The dcdiag output you posted in #38742912 shows an event in the System log indicating that your servers' clocks are not synchronized. Is that only happening in your test environment? If it's happening in production, it needs to be addressed, as too much clock skew (>5 minutes by default) causes Kerberos authentication failures.
rigelnet
ASKER
Thanks for your quick reply. But now i got error in Group policy. DNS name resolution and all working fine now. But group policy is not implemented as I configure in 2008 r2 AD. the policy folders and all are migrated but not in effect. here I have attached screenshot.
when i reset any password fron this 2012 new AD it will give effect on client end. but i can not get my old configured Group policy. gp.jpg group-policy-error.jpg
DrDave242
Run the "net share" command on both DCs to verify that the SYSVOL and NETLOGON folders are shared.
I have run "net share" command on both DCs to verify but in 2008 R2 I can find NETLOGON folder which shows shared. but in windows server 2012 AD server i could not find NETLOGON folder shared. event i can not find. can you give me detail path? or what configuration should be done?
http://greigmitchell.co.uk/guide-migrating-server-2008-r2-domain-controllers-to-server-2012/
Try this
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/847644e7-aee5-4d20-8bf8-497c359268fc
http://social.technet.microsoft.com/Forums/en/winserverDS/thread/2b5269f3-8b45-4e2b-aa10-c78493bbb547