Solved

Windows Server 2012 Active directory and WSUS issues

Posted on 2015-01-14
5
64 Views
Last Modified: 2016-06-14
I have been struggling with this issue for a while now. I have 4 AD servers. One Windows 2003 server, which is the primary, and three Windows 2012 servers. The AD syncing seems to be fine between three of them. One of the Win2012's is not syncing at all, So I just usually leave the AD and its associated services as not running on this one box. This has been going on for quite a while so it's well past the tombstone period. This server is also a WSUS server and it can't communicate with any of its clients. This one problematic AD server is also a primary file server and has extensive permissions setup throughout all the shared file folders and subfolders. There are close to a million files on it. I eventually want to have this 2012 server has the primary since it has an SSD Raid 5 array and is a very fast machine.

My inclination is to try uninstalling AD and also perhaps unjoining and then rejoining this box to the domain. However I'm not sure if that will kill all the permissions I have setup on all those files and folders. Having to re-setup all those folder permissions would be a nightmare.

If I remove the AD server role from this machine and unjoin it and rejoin it to the domain, are the file permission going to be reset? Any other ideas?

Thanks!
0
Comment
Question by:crdixon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
5 Comments
 
LVL 35

Accepted Solution

by:
Seth Simmons earned 500 total points
ID: 40550348
I'm not sure if that will kill all the permissions I have setup on all those files and folders

it does not change permissions
at the file system level, it has the SID of the objects in the ACL
you are fine removing from the domain and adding again - though you should do a metadata cleanup before adding to the domain again due to the AD tombstone

Clean Up Server Metadata
http://technet.microsoft.com/en-us/library/cc816907(v=ws.10).aspx
0
 

Author Comment

by:crdixon
ID: 40608645
Going to try to do this over the holiday weekend...thanks!
0
 
LVL 35

Expert Comment

by:Seth Simmons
ID: 41651712
i answered the question and provided a technical reference that explained things in more detail
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
dpm 2012 r2 3 27
WSUS on Serve 2012R2 1 37
Services disabled 1 31
MSCS Cluster ignoring route add 1 14
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question