AD Login Issues after DC demoted

Posted on 2014-12-04
Medium Priority
Last Modified: 2014-12-10
Here is my environment.  I had 1 2008 Domain Controller and 2 Server 2012 R2 DC's.  All of the roles are on DC1 (2012 R2 Server).  I just demoted the 2008  server and now login are taking forever, and users are having issues opening and saving documents to network drives.  I checked DNS and all "seems" well.  I run a repadmin /syncall and no errors are returned.

I saw errors in the event viewer regarding time... I then saw that the time server was the 2008 box.....  I configured the 2012 R2 box to get the time from an external source...  Now both of the DCs are syncing the time exactly the same....  I have also verified that the DHCP clients are poiinting to the correct DNS servers... both 2012 r2 boxes....

What am I missing.... please help!!
Question by:BSModlin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 35

Expert Comment

by:Seth Simmons
ID: 40481197
what does netdom query fsmo show on the 2012 servers?
if the roles are between those servers then the 2008 server was not the time server since clients get their time from the server with the PDC emulator role

Author Comment

ID: 40481201
All roles are on the 2012 R2 server DC1, as they should..... What else to check for the slow logins?
LVL 35

Expert Comment

by:Seth Simmons
ID: 40481276
are the 2012 servers global catalogs?
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 40481289
LVL 10

Expert Comment

by:Walter Padrón
ID: 40481554
Have you raised the functional level of the domain?

Also, restart the KDC (Kerberos Key Distribution Center) service on both DC's

Best regards
LVL 20

Expert Comment

ID: 40487801
have you run a dcdiag /v /e >c:dcdiag.txt

Are saving files to the network the only thing that is slow? how about user logins from their workstations?

Was your old server running WINS?

Accepted Solution

BSModlin earned 0 total points
ID: 40488903
Found the issue... It was my EMC SAN/NAS.... Had old DNS info in it, and user home directories where contributing to slow logon times..... thank you all!!

Author Comment

ID: 40488930
I've requested that this question be closed as follows:

Accepted answer: 0 points for BSModlin's comment #a40488903
Assisted answer: 167 points for Seth Simmons's comment #a40481197
Assisted answer: 167 points for Walter Padrón's comment #a40481554
Assisted answer: 166 points for compdigit44's comment #a40487801

for the following reason:

Found my own solution
LVL 35

Expert Comment

by:Seth Simmons
ID: 40488931
select your own comment as the solution
nobody else gets points since not all details were provided and none of us would have known your NAS was a contributing factor

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question