I have been working on a domain controller migration from Server 2008 to Server 2012. I first added the new server as a domain controller then added the DHCP and DNS roles. Then over a few days I began migrating data, shares, etc over to the new server. Everything seemed to be going mostly OK. I ran BPA and fixed any problems that were noted. This morning I hoped to complete the migration by moving the FSMO roles using these instructions.
All went as expected and no errors were noted. However now I am having issues with GP management and the AD Adminstrative Center. The FSMO roles have been moved to the new server but the old server has not been demoted yet (I am afraid to completely remove it until the problems have been resolved)
Here is a summary:
1. When running Group policy Management - Error: The network name cannot be found
2. I can open the Group Policy editor and I see all my expected Group Policy Objects listed
3. I am able to check Policy settings and they are correct
4. However I cannot edit any Group Policy Objects - Error: The network name cannot be found,
5. I am able to create new users via Active Directory Users and Computers
6. Active Directory Administrative Center fails - Error: Cannot connect to any domain Error: Cannot find server running ADSW in domain
7. AD Domain Service and AD Web Service are both running. Both have also been restarted without generating any errors
8. SYSVOL and NETLOG are were not being shared on new DC. I have manually shared both
9. I noted an error in Windows log relating to file replication problems for Sysvol and Netlog which might explain why they weren't shared
From Windows Error Log:
Notification of policy change from LSA/SAM has been retried and failed. Error 4312 to save policy change for account S-1-5-83-0 in the default GPOs
Active Directory Web Services could not find a server certificate with the specified certificate name. A certificate is required to use SSL/TLS connections.
The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete (The
The File Replication Service is having trouble enabling replication from FS1 to DC for c:\windows\sysvol\domain using the DNS name FS1.glcssm.org. FRS will keep retrying. (FS1 is original server and DC is new server).
File Replication Service is scanning the data in the system volume. Computer DC cannot become a domain controller until this process is complete. The system volume will then be shared as SYSVOL
I would appreciate any advice on how to resolve these issues.