Solved

I need some help decommissioning a tombstoned Exchange server - getting all kinds of AD errors

Posted on 2014-01-15
7
574 Views
Last Modified: 2014-01-15
Hi all,

So I migrated from Exchange 2007 to Exchange 2013, and everything went well. I shut off the 07 server once everything was done to be sure there were no connections to the old server and test new server functionality on its own.

I left the old server off for quite awhile, about 3 months.
Today I booted it up to remove Exchange 07 and demote it from being a DC, etc.. and am getting all sorts of Active Directory errors - I think due to the tombstone time frame.

I need some help working through this to be sure AD stays in good shape, and safely decommission the old server. Anyone feel up to this?
0
Comment
Question by:CoSmismgr
  • 5
7 Comments
 
LVL 5

Author Comment

by:CoSmismgr
Comment Utility
When I attempt to open AD Users & Computers on the old server I get:
 "Naming information cannot be located because: The target principal name is incorrect."


When I attempt uninstall E2K7 (Remove Mailbox, Client Access, Hub Transport and Mgmt Tools) I get the following:

Summary: 3 item(s). 0 succeeded, 3 failed.
Elapsed time: 00:00:44


Mailbox Role Prerequisites
Failed

Error:
You must be a member of the 'Exchange Organization Administrators' or 'Enterprise Administrators' group to continue.
Recommended Action: http://go.microsoft.com/fwlink/?linkid=30939&l=en&v=ExBPA.12&id=1d750594-9222-44d7-8f80-45e522e889e6

Error:
Setup encountered a problem while validating the state of Active Directory: An Active Directory error 0x8007203B occurred while searching for domain controllers in domain ci.soldotna.ak.us.local: A local error has occurred.


Error:
The clustered mailbox server removal cannot continue: Unexpected error [0xCC55F834] while executing command 'set-ClusterPassiveNodeDefaults -InstallMode:uninstall -DomainController:'' -ActiveCmsUninstall:('false' -eq 'true') -whatif'.

Error:
Cannot find at least one global catalog server running Windows Server 2003 Service Pack 1 or later in the local Active Directory site.
Recommended Action: http://go.microsoft.com/fwlink/?linkid=30939&l=en&v=ExBPA.12&id=67aca4a0-bc3f-4f8f-8297-b13e0d347942

Elapsed Time: 00:00:39


Client Access Role Prerequisites
Failed

Error:
Setup encountered a problem while validating the state of Active Directory: An Active Directory error 0x8007203B occurred while searching for domain controllers in domain ci.soldotna.ak.us.local: A local error has occurred.


Error:
Cannot find at least one global catalog server running Windows Server 2003 Service Pack 1 or later in the local Active Directory site.
Recommended Action: http://go.microsoft.com/fwlink/?linkid=30939&l=en&v=ExBPA.12&id=67aca4a0-bc3f-4f8f-8297-b13e0d347942

Elapsed Time: 00:00:02


Hub Transport Role Prerequisites
Failed

Error:
Setup encountered a problem while validating the state of Active Directory: An Active Directory error 0x8007203B occurred while searching for domain controllers in domain ci.soldotna.ak.us.local: A local error has occurred.


Error:
Cannot find at least one global catalog server running Windows Server 2003 Service Pack 1 or later in the local Active Directory site.
Recommended Action: http://go.microsoft.com/fwlink/?linkid=30939&l=en&v=ExBPA.12&id=67aca4a0-bc3f-4f8f-8297-b13e0d347942

Elapsed Time: 00:00:02
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
Comment Utility
Did you remove Exchange before running DCPROMO on it?
As it was a domain controller you shouldn't have left it off for so long.

Rebooting other domain controllers and Exchange servers should go someway to sorting out the mess.
If Exchange wasn't removed, I would also do that as Exchange on a DC causes interesting problems with other Exchange servers.

Simon.
0
 
LVL 5

Author Comment

by:CoSmismgr
Comment Utility
I haven't run DCPROMO on it yet. I realize I shouldn't have left it off for so long, but nothing I can do about that now :/

I will reboot other domain controllers and the new exchange server this evening and report back tomorrow.
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
Comment Utility
I would recommend doing the following...
- Power off the old DC/Exchagne 2007 server

Is your FSMO holder a DC the is in a good clean state? if so proceed...

Run the following command on your Good working DC

netdom query fsmo
Make sure that the old DC (that has been powered off does not hold any FSMO roles)

If the above is true and the tombstoned DC does hold ANY FSMO roles make sure that you Seize the roles to a working DC.

Seize FSMO Roles

If your old DC does not hold any FSMO roles proceed below...
- Perform Metadata cleanup Metadata cleanup
- Open Sites and Services, Delete any Computer objects for this old DC
- Open DNS Manager under the _msdcs folder and delete any SRV records that are present in GC\DC\Kerberos\LDAP\etc

Exchange Part
Once your DC has been cleaned up you will need to use ADSIEdit to remove Exchange.

Remove Exchange 2007 using ADSIEdit.msc

Will.
0
 
LVL 5

Author Comment

by:CoSmismgr
Comment Utility
Will, I will do this since it can be done without waiting for the reboots. I will post back with any issues.
0
 
LVL 5

Author Comment

by:CoSmismgr
Comment Utility
Will, that was the perfect way to do it! Thank you so much
0
 
LVL 5

Author Closing Comment

by:CoSmismgr
Comment Utility
Very accurate, and precise directions. No problems at all performing what I needed to do.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now