Solved

Some PCs unable to login to a 2003 domain. One server may have tombstoned?

Posted on 2013-11-13
4
218 Views
Last Modified: 2013-11-18
Hi,

I have three domain controlers all running 2003

Some PCs are able to login without an issue but some cannot.

One DC was offline for over 60 days so I think it has now tombstoned. This DC has no roles and is not hosting any critial applications. I have NTDS replication in the event viewer (one is event ID 2042)

I'm tempted to demote the problematic DC in the short term to get the users back online as soon as possible. Would this sort this issue?

Is it as easy as DCPROMO and follow the wizard or is there anything else I can try? And can I demote a dc via remote desktop?. The DC in question is a virtual server on ESXI.
0
Comment
Question by:APC_40
  • 2
  • 2
4 Comments
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 500 total points
ID: 39646953
Event ID 2042 indicates server has has not replicated with its partner for longer than a tombstone lifetime.Demote/promote should fix the issue.

You cannot demote the faulty DC gracefully you need to do forcefull removal.You need to ran dcpromo/force removal and then run matadata cleanup on other DC(healthy) to remove the instance of faulty DC from AD database and DNS.If faulty DC is fsmo role holder server the you need to seize the FSMO role on other DC.

Once done you can promote the Server back as ADC.Also configure authorative time server role on PDC role holder server.

Reference link
Forcefull removal of DC: http://support.microsoft.com/kb/332199
Metadata cleanup: http://www.petri.co.il/delete_failed_dcs_from_ad.htm
Seize FSMO role: http://www.petri.co.il/seizing_fsmo_roles.htm
Authorative time server: http://support.microsoft.com/kb/816042
0
 

Author Comment

by:APC_40
ID: 39647231
I went straght to metadatacleanupp and did not use the force removal - will this cause issues? The DC appears to be gone though.

I have two DCs  - do I have to run metadatacleanup twice from each DC to cleanup the bad DC?
0
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 39647282
You have to run metadata cleanup only once to remove the instances of faulty server the other DC will replicate and remove the instances of faulty server no need to run on all DC.

On the faulty server excute dcpromo/force  to remove the AD.
0
 

Author Closing Comment

by:APC_40
ID: 39656058
Excellent answer - thanks
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Hallo! I guess almost every Windows Administrator must have got stumped with this question "Where does WINDOWS store a users cached credentials? Every user who had once logged onto a Server/Desktop while it was connected to the domain could sti…
The way I use Experts Exchange to assist me in analyzing and diagnosing a problem is I first enter a Verbose Question at Experts Exchange like: Office 2007 will hang when opening and saving files I then launch WordPad (any text editor will do) an…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now