No permissions on DC after promotion

A Windows 2012 R2 was promoted as a DC in an existing domain.  The domain is running functional level domain/forest of 2003.  There are other 2012 R2 machines already promoted and behaving.

After the promotion we can login with domain credentials but we can't run anything as Administrator - like Server Manager.  A popup indicates we may not have sufficient rights.  If I drill to c:\windows\system32\servermanager.exe and try to RunAs and enter domain credentials I get an access denied.

At this point I'd like to demote it as a DC, but can't open powershell or server manager as administrator.

Any ideas as to how I might troubleshoot this.  As a 2nd option is there a way to remotely demote the DC.

Bigmac
BigmacMcAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

AmitIT ArchitectCommented:
I assume you have some GPO, which is blocking access to your new DC's. Check what all GPO's are applied on DC's.

If you want to demote, you can delete them from AD and perform metadata cleanup and then promote again. However, until you find the cause, i don't see any reason of demoting them.
0
BigmacMcAuthor Commented:
There's only one DC I'm having a issue with.  We had promoted one the other day that appears to be working normally.  All the DC's are in the default Domain Controllers OU.  From what I can tell replication is occurring.

I've attached dcdiag.txt after running dcdiag.exe on the server.  Some of the errors may be because I can't open anything as Administrator
dcdiag.txt
0
AmitIT ArchitectCommented:
It is still replicating. DC promotion is not completed. Leave server for a day. Then check again.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

BigmacMcAuthor Commented:
I finally had to delete the dc out of AD and perform a meta-data cleanup.  Removed the server from the domain.  Reset all the DNS settings.  After that I successfully joined server to domain and promoted as a DC.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
AmitIT ArchitectCommented:
Thanks for the update
0
BigmacMcAuthor Commented:
Never really figured this out, it was just easier to remove and start over
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.