Avatar of Selma D
Selma D
Flag for Canada asked on

Unable to promote Win2012r2 server to a DC and add to existing domain

I have a 2008 domain and I'm trying to add another DC to it, which is running Windows Server 2012r2
When I try to promote to a DC, it fails on prerequisite check with the following error:

Verification of prerequisites for Active Directory preparation failed. Unable to verify whether schema master has completed a replication cycle after last reboot.
Exception: Unavailable Critical Extension. Server extended error: 8366. Server extended message: 000020AE: SvcErr: DSID-03210384, problem 5010 (UNAVAIL_EXTENSION), data 8610
.
Adprep failed to verify whether schema master has completed a replication cycle after last reboot.
[Status/Consequence]
The schema is not upgraded.
[User Action]
Check the log file ADPrep.log in the C:\Windows\debug\adprep\logs\20151010161101-test directory for possible cause of failure.

I ran adprep manually on my 2008 DC and it said: Domain-wide information has already been updated.
[Status/Consequence]
Adprep did not attempt to rerun this operation.
Windows Server 2012Active Directory

Avatar of undefined
Last Comment
David Paris Vicente

8/22/2022 - Mon
David Paris Vicente

Hi Selmaa,

Can you give us more details about your domain.
How many domain controllers do you have with windows 2008?
Windows 2008 version?
Level of your forest in 2008?

Thank you.

D.
Selma D

ASKER
Hi David,

I have 2 DCs  and they're both Win 2008 R2.  Functional level is 2008
SOLUTION
David Paris Vicente

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
David Paris Vicente

Thanks for your prompt response.

Can you check with the tools mentioned on my last post for replication problems?
Are your DNS working properly?
Both servers are turned on?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
rindi

You can't promote a server that already is a DC to another domain. First make sure it is not a DC and not a member of any domain. Then add the server to the domain, and after that promote it to a DC.
Selma D

ASKER
David,
I ran the tool and it's come back with some errors.  But that's probably because the two DCs are currently separated by firewall, since one of them is at the Disaster Recovery site.
I need to change the firewall settings and I'll run it again, but it might be in 2-3 days when I have my next change window.
I will let you know.

Rindi,
I am not sure I've explained my problem properly, but the server I'm trying to promote to a DC is not a DC yet :)
ASKER CERTIFIED SOLUTION
David Paris Vicente

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Selma D

ASKER
David,
As it turns out, I couldn't fix the replication issues because the time last replication happened exceeded the tombstone lifetime.
So I decided to demote the DC that was dormant (DR site) and proceed with the new DC promotion (Win server 2012).  
Finally, it was promoted successfully.

Thanks for your help!!
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
David Paris Vicente

Hi Selma,

Thank you for your feedback.

That was my concern but I had hopes that we had time to force the replication. and get the DC outside of tombstone flag.

What counts now is that the problem is solved.

Cheers.

D.