I'll make this long story as concise as possible:
I had Essentials Business Server 2008 until MS dropped it. MS produced a "make it right" migration kit which stripped out the EBS features, leaving the servers as separate products. So after deploying the migration kit I had a windows 2008 DC, an exchange 2007 server (also on 2008) and an SQL server. The exchange server was also a DC as part of the default configuration of EBS.
The domain has been working fine in this configuration for almost 3 years. Now, I have a new vSphere server and am migrating the old physical servers over to VM servers. I have 2 x new DCs one of which has all of the FSMO roles. I have a new exchange server - all services are migrated and around half of the mailboxes (so far).
According to the document that MS released with the migration kit, I needed to remove ADCS from the old DC prior to demoting it. So I followed the instructions telling me to backup the ADCS config etc and removed the role. Then I demoted the server to a member server and rebooted.
On starting up again, the print spooler failed but began working again on a stop/start. Then users complained that they could not scan from a network MFP to a share on that server. I checked the permissions on the share and I could see GUIDs of users but no names. Also when I add a user to the ACL I cannot browse the domain - only the local server shows up. So I rebooted again and everything was working as expected - scanning resumed and I could add domain users to shares etc. - but after about 15 minutes it all went bad again.
Also every 48 hours or so, users that still have their mailboxes on the old exchange server lose access. At this point when I logon to the old exchange server, I am denied access. The server prompts that the credentials are incorrect. I have to restart the exchange server which will be good for another 48 hours before falling over again.
I believe this is down to the abrupt removal of the ADCS. I have discovered that the correct procedure should have been to decommission it according to http://support.microsoft.com/kb/889250
So I'm in a world of trouble until I can fully complete the migration process for the remaining servers plus all of their 6TB of data.
- Re-promote that server and restore ADCS then decommission it properly?
- Somehow broadcast that ADCS no longer available?
- Install ADCS on one of the new DCs and get it going that way?