Solved

Windows Server 2012 R2 Unable to Re-Join the Domain

Posted on 2016-07-19
12
80 Views
Last Modified: 2016-07-20
I have a Windows Server 2012 R2 machine that I have previously added to the domain for testing purposes.  I have since removed it from the domain.  I now need to rejoin it to the domain and I get the following error:

"An Active Directory Domain Controller (AD DC) for the domain "domain.com" could not be contacted.

Ensure that the domain name is typed correctly.

If the name is correct, click details for troubleshooting information.

Note: This information is intended for a network administrator.  If you are not your network's administrator, notify the administrator that you received this information, which has been recorded in the file C:\Windows\debug\dcdiag.txt.

DNS was successfully queried for the service location (SRV) resource record used to locate a domain controller for domain "domain.com":

The query was for the SRV record for _ldap._tcp.dc._msdcs.domain.com

The following domain controllers were identified by the query:
server1.domain.com
server2.domain.com

However no domain controllers could be contacted.

Common causes of this error include:

- Host (A) or (AAAA) records that map the names of the domain controllers to their IP addresses are missing or contain incorrect addresses.

- Domain controllers registered in DNS are not connected to the network or are not running."

I am however able to join and un-join the domain from a Windows 7 machine.  I have verified that AD and DNS are propagating correctly.  I have also viewed the computers in AD and enabled the computer account, I've tried resetting the account, as well as deleting the account with no luck.

When running ipconfig /all it lists the appropriate DNS servers.

I can also ping my ad/dns servers via host name.

When doing an nslookup on domain.com I get the results:

PS C:\Users\Administrator> nslookup domain.com
DNS request timed out.
    timeout was 2 seconds.
Server:  UnKnown
Address:  (server1's address)

DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
*** Request to UnKnown timed-out
PS C:\Users\Administrator>

When running nslookup from another computer or Windows 2012 R2 Server I get the results I should receive.

It appears as though it is a DNS issue but I'm not sure where to go next.

Thanks in advance.
0
Comment
Question by:ollybuba
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
  • 2
12 Comments
 
LVL 6

Expert Comment

by:Tim Phillips
ID: 41719750
Simple things first, do you have the DNS server entries on your NIC pointing to the correct DNS server (likely the domain controller)?
0
 

Author Comment

by:ollybuba
ID: 41719755
Yes, I can also ping my ad/dns servers by host name.
0
 
LVL 12

Expert Comment

by:Bryant Schaper
ID: 41719757
check DNS, or if on a separate subnet/vlan we may have to look at a couple things
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:ollybuba
ID: 41719760
What should I check with DNS?  Everything seems to be operating properly on every other computer.
0
 
LVL 6

Expert Comment

by:Tim Phillips
ID: 41719773
If you do an "ipconfig /flushdns" are you still able to resolve the domain controller after that?
0
 

Author Comment

by:ollybuba
ID: 41719777
Yes.
0
 
LVL 12

Accepted Solution

by:
Bryant Schaper earned 500 total points
ID: 41719781
you can ping the domain.com try the short name of the domain instead
0
 

Author Comment

by:ollybuba
ID: 41719784
That works as well.
0
 
LVL 12

Expert Comment

by:Bryant Schaper
ID: 41719802
joining by the short name works?
0
 

Author Comment

by:ollybuba
ID: 41719810
I was referring to pinging.  I was able to join the server to the domain via the short name.  Do you know why it wouldn't let me join via domain.com?
0
 
LVL 12

Expert Comment

by:Bryant Schaper
ID: 41719832
can you post ipconfig /all
0
 

Author Closing Comment

by:ollybuba
ID: 41721522
Solution was found by only entering the short name of the domain.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In-place Upgrading Dirsync to Azure AD Connect
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question