Solved

Cannot demote a DC using DCPROMO  - 'Logon failure: the target account name is invalid.

Posted on 2013-11-13
6
5,841 Views
Last Modified: 2013-11-18
Hi,

I have a urgent need to demote a 2003 DC server. The server was offline for over 60 days and it appears to have tombstoned. The server was offline and due to a network issue and now users are having issues logging in to their workstations, etc

The server has no roles attached to it and is not a GK server. I'm getting replication issues on my good DC.

The error I receive is - The operation failed because:


Managing the network session with  ****.local failed.

'Logon failure. The target account name is incorrect.


How do I demote this server?
0
Comment
Question by:APC_40
  • 3
  • 3
6 Comments
 
LVL 23

Accepted Solution

by:
Thomas Grassi earned 500 total points
Comment Utility
take a look at this

http://www.petri.co.il/delete_failed_dcs_from_ad.htm#

What errors are you getting? Post
0
 

Author Comment

by:APC_40
Comment Utility
On my good DC it says in event viewer under directory service -


Event ID  - 2042  -  

Source NTDS replication.

Description - It has neen too long since this machine last replicated with the named source machine. The time between replicatins with this source has excedded the tombstone lifetime. The source machine may still have copies of object that have been deleted.

On the 'bad' DC -


Error event ID  1864  -


The local domain controller has not recently received replication information from a number of domain controllers. The count of domain controllers is shown, divided in to the following intervals.

More thatn 24hrs
2
More thatn a week
2
More than a month
2
More than two months
2
More than a lifetime
2
Tombstone lifetime Days
60
0
 
LVL 23

Expert Comment

by:Thomas Grassi
Comment Utility
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 

Author Comment

by:APC_40
Comment Utility
Ok I've deleted the DC using the metadata cleanup and it's been removed from DNS. Only 2 DCs are now in AD. I did not DCPROMO /force, i deleted the server through meta data cleanup

Unfortunately I logged on to a few PCs and some allowed access but others did not as before.  I don't understand why sometimes I can logon to a PC but others i can't . The message when trying to logon states 'a domain controller could not be found, etc...'


There was still an issue that when a users password was changed in AD and they were forced to change it, it never asked for them to change it.

Any further guidance?
0
 
LVL 23

Expert Comment

by:Thomas Grassi
Comment Utility
Run this and post results

@echo off
echo "Starting NetDiag on SERVER" >>c:\util\dclogx.txt
netdiag >>dclogx.txt

echo "Starting DCDiag on SERVER" >>c:\util\dclogx.txt
dcdiag >>dclogx.txt
dcdiag /test:registerindns /dnsdomain:FQDN>>dclogx.txt
dcdiag /c /v >>dclogx.txt
dcdiag /test:dns >>dclogx.txt
browstat status -v our >>dclogx.txt

echo "Who owns FSMO Roles" >>dclogx.txt
NTDSUTIL roles Connections "Connect to server SERVER" Quit "select Operation Target" "List roles for connected server" Quit Quit Quit >>dclogx.txt

EXIT


Lets check your AD and DNS
0
 

Author Closing Comment

by:APC_40
Comment Utility
Cleared the DC using metadatacleanup - cheers all.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Suggested Solutions

Hallo! I guess almost every Windows Administrator must have got stumped with this question "Where does WINDOWS store a users cached credentials? Every user who had once logged onto a Server/Desktop while it was connected to the domain could sti…
Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now