reinstall active directory remotely ?

Posted on 2013-12-26
Last Modified: 2013-12-27
hi experts
we have a 2003 remote domain controller that is showing "directory services cannot start" error 0xc00002e1. We are not able to load windows normally. We can remotely access it if someone on site selects safe mode. I have gone through ms kb article 258062 and I am at the point where the ms kb is recommending to reinstall AD. Problem is this server is a 7 hour drive and I want to do this remotely. Any suggestions, guides or recommendations before I run dcpromo ?
Question by:WAMSINC

Assisted Solution

by:Brad Held
Brad Held earned 250 total points
ID: 39741175
So I will assume that there is no system state backup of this server?

When you say safe mode, is that directory services restore mode? I have seen issues where antivirus interferes with lsass, so that may be something to disable before you rebuild.

If I was going down the path of getting the DC happy again, I would perform a metadata cleanup, and a complete wipe and reload of the server, unless you do have a system state backup then I would just reload and restore from backup.

Other than the reboots there should not be a reason that the dcpromo wouldn't work from RDP, its getting it to a state where you can run dcpromo that is going to suck. Does this server have an HP iLo or Dell iDrac card in it?
LVL 26

Accepted Solution

Leon Fester earned 250 total points
ID: 39741359
We can remotely access it if someone on site selects safe mode.
Does this mean that you do have a resource onsite?

It should be easy to do the necessary then.
Since you cannot remote to the server directly you won't be able to do everything yourself.

You will have to give the person at the remote site a domain admin account in order to do the necessary.

From your side you'll need to do the Meta data cleanup - this is needed to remove all references of the remote DC from AD.

From his side, he'd have to boot into safe mode and then run:
DCPROMO /forceremoval

After the server has been rebooted he'd have to run DCPROMO again on that DC and re-enter the domain admin account credentials.

Once the replication has completed you can should then change the password on the domain admin account if necessary.

Author Closing Comment

ID: 39742195
thanks for the replies guys, Im driving up there saturday with a new server. We are just going to go ahead and do an in place upgrade and refresh the hardware and upgrade from 2k3 to 2k8 while we're at. To answer the question I thought I had a system state back up via DPM but that failed to recover. Because they need to be open for business Friday and Saturday we are just going to let it ride until the weekend. Big problem with not having a tested DR solution.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
heat agent push through GPO 2 56
Dentrix G4 1 59
how to check the account lockout counter? 6 64
Win 7 OS unable to install Win updates 3 164
INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question