Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

sysvol and netlogon missing but i still have old domain controller

Posted on 2016-07-16
3
Medium Priority
?
49 Views
Last Modified: 2016-08-01
My scenario is this, I started with a network of two 2008 servers acting as domain controllers.  I added a 2012r2 server and then transferred the FSMO roles to it and set it as a global catalog server and then removed the two 2008 servers from being global catalog servers.  I then demoted the first of the two servers.  At this point I noticed the 2012r2 server did not have the sysvol and netlogon directory so I pointed DNS to it and had it assume FSMO roles.  Active directory is working on my network again, but I still have the 2012r2 server that is not working properly.  I have found articles about an authoritive and non-authoritive restore but I don't want to force this server into production if it isn't necessary.  I would rather do it via normal processes.

My question is this, can I simply demote it and promote it again and see if it will work properly on a second attempt?

can anyone explain the risks of using an authoritive or non-authoritive restore?
0
Comment
Question by:AdvNetSol
  • 2
3 Comments
 
LVL 74

Accepted Solution

by:
Jeffrey Kane - TechSoEasy earned 2000 total points
ID: 41714601
If you have a solid working Server 2008 DC and the 2012 is just not working right, yes, you can demote it and remove it from the domain and then re-do -- but if you do that I would fully reinstall as well to get new SIDs.

But... this has happened to me a couple of times and it's not too difficult to just do a non-authoritative synchronization to get it working correctly.   Instructions for that are here:

https://support.microsoft.com/en-us/kb/2218556
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 41714603
By the way... don't think of non-authoritative as being worse... it's actually the default directory services restore mode.  What it means is that data doesn't get overwritten -- whereas an Authoritative restore/sync will overwrite data even if that data is newer than what is being copied.
0
 

Author Closing Comment

by:AdvNetSol
ID: 41737951
I did end up demoting and repromoting the server but that didn't fix the problem.  the ultimate solution was to perform an authoritive restore and manually sharing the sysvol folder (it didn't work until the sysvol was manually shared at which point netlogon automatically shared...within seconds)  Very strange resolution but everything has been perfect on the domain since.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Transferring FSMO roles is done when an admin wants to split roles between certain Domain Controllers or the Domain Controller holding the Roles has been forcefully demoted using dcpromo / forceremoval
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question