Active Directory Server 2003 Operations Master is down.

Experts,

I recently lost my operations master server. I have one additional server on site, ( I can create a user on it) and two others at a different site. All of the remaining servers are acting as DNS servers and global catalog servers. It looks like I have to transfer my PDC emulator to one of my working servers, as well as other roles.

I am concerned with which roles should go and the order they should be transferred in. Also, I am not clear on how to go through this process.
Please advise as soon as possible

Thank you in advance

Don
dwesolowiczAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Seth SimmonsSr. Systems AdministratorCommented:
from the other domain controller, open command prompt and run netdom query fsmo and you will see what roles are on which server to find out which server they reside on and see which one needs to be relocated

follow this article; go to the seize fsmo roles section

http://support.microsoft.com/kb/255504

doesn't matter which one you do first as long as you are able to relocate them - and be certain the old server isn't coming back or you might have issues with multiple servers having the same role
0
dwesolowiczAuthor Commented:
Thanks for the reply. Looks like the server that went down contains all the roles.

Schema owner                bretdc1fp.bretfordhq.local

Domain role owner           bretdc1fp.bretfordhq.local

PDC role                    bretdc1fp.bretfordhq.local

RID pool manager            bretdc1fp.bretfordhq.local

Infrastructure owner        bretdc1fp.bretfordhq.local

In this case, is it still ok to transfer all of these roles?

Thank you again for your reply
0
Seth SimmonsSr. Systems AdministratorCommented:
if the server is not coming back, then yes, transfer all the roles to another server

also want to consider later cleaning up what's leftover of that domain controller

http://technet.microsoft.com/en-us/library/cc736378%28v=ws.10%29.aspx
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

dwesolowiczAuthor Commented:
Is there any harm in not moving the roles for a few days? I would like to do some additional reading so I am clear on the process.
0
dwesolowiczAuthor Commented:
Looks like you can transfer roles via ad users and computers as well. Is command line the best way to go or can I use the snap in?
0
dwesolowiczAuthor Commented:
my apologies......in my case, I have to seize the roles since the server will no longer be in production or operational
0
Seth SimmonsSr. Systems AdministratorCommented:
yes you can transfer (not seize) using gui tools though it's easier from the command line since gui requires registering a dll and adding mmc snap-in manually - doable, just cumbersome

wouldn't recommend waiting very long to seize the roles since it could affect some services

the entire process would only take a couple minutes but a bit longer for it to replicate depending on how many other sites and domain controllers exist
0
SandeshdubeySenior Server EngineerCommented:
As the FSMO role holder server is down and cannot be brought back you need to seize the fsmo role transfer will not work.

Seize FSMO role:http://www.petri.co.il/seizing_fsmo_roles.htm

You need to seize the fsmo role on online DC,here order is not important you can seize the role in any order.http://sandeshdubey.wordpress.com/2011/10/07/how-to-transfer-or-seize-fsmo-roles/

You also need to perfrom metadata cleanup of offline DC.http://sandeshdubey.wordpress.com/2011/10/12/metadata-cleanup-of-a-domain-controller/

Dont foreget to configure authorative time server role on PDC role holder server:http://support.microsoft.com/kb/816042

You also need to change the dns setting of clients /server whcih may be pointing to offline DC for name resolution this may be in DHCP or TCP/IP setting.

Just for your info there's some info on FSMOs and what would happen if any specific FSMO is down for any length of time, permanently or termporarily.
 
Active Directory FSMO Roles Explained and What Happens When They Fail and Why you may not be able to keep a DC up once roles were seized.
http://msmvps.com/blogs/acefekay/archive/2011/01/16/active-directory-fsmo-roles-explained.aspx

Complete Step by Step Guideline to Remove an Orphaned Domain controller (including seizing FSMOs, running a metadata cleanup, and more)
http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx

Hope this helps
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
dwesolowiczAuthor Commented:
Thanks to all of you! I am going to give this a try now since it wont take to long.
I will let you know how things go.
0
dwesolowiczAuthor Commented:
Well I wen through the process, and I am having problems with users home directorys being mapped. Is this typical?
0
SandeshdubeySenior Server EngineerCommented:
How is the home drive configured can you elaborate by scripts,GPP,etc.Can you post the printscreen of home drive policy.

Check the sysvol folder too and ensure that polcies and script folder is replicated.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.