Exchange 2010 referencing incorrect domain controller

I know similar questions were asked about this topic, but I couldn't seem to parse out the definitive answer as to how to correct this problem.

I have a 2010 Exchange server.  AD is running on 2 domain controllers: one is a 2003 SBS DC (which is getting ready to be removed) and a 2012 DC.  Replication between the 2 DC's is current and from what I can see, AD as well as DNS appears to be functioning properly.  Both DC's are Global Catalogs.

In preparation for removing the 2003 SBS as a domain controller (right now only the PDC role is on it; all other FSMO's are on the 2012 DC), during a reboot cycle of the 2003 DC, I wanted to make sure that Exchange 2010 was working properly.  While being rebooted, I couldn't log into OWA internally on that server (mailbox and account can't be found/unavailable) and also couldn't launch EMC (throws a Kerberos error).

Upon the 2003 DC coming back online, without doing anything on the Exchange server, OWA and EMC will work again.

I had already changed the Configuration Domain Controller in EMC from "Default" to specifically the 2012 DC.  In checking some other settings from the different articles I had found on this problem, the Exchange server is pointing to the 2003 DC (Get-ExchangeServer|fl shows OriginatingServer as 2003DC and Get-DomainController shows both DC's but each entry shows OriginatingServer as 2003 DC as well).

Get-ExchangeServer |fl also has no entries for StaticDomainControllers, StaticGlobalCatalogs, StaticConfigDomainController as well as CurrentDomainControllers, CurrentGlobalCatalogs and CurrentConfigDomainController.

During the reboot of the 2003 DC, there are a number of errors in the Event Log, all pointing to not being able to contact a domain controller.  One of the errors lists both domain controllers, but still says it can't contact a suitable domain controller.  I can certainly include some of the Event ID's if necessary.

How do I go about forcing the Exchange server to use the 2012 DC for it's services and connection to AD?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

MASEE Solution Guide - Technical Dept HeadCommented:
Change the DNS server address in NIC properties of Exchange server and please try to point your Exchange to use new DC using this command and try
Set-ADServerSettings -PreferredServer dc2.exchangeserverpro.local

Open in new window

tnisupportAuthor Commented:
From what I've read, that command is only for choosing a domain controller to use during an Exchange Management Shell session.
Adam BrownSr Solutions ArchitectCommented:
Do you have subnets assigned in your AD Sites and Services configuration? That gets overlooked very regularly and can cause problems with Exchange when it tries to find DCs and determine its own topology.
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

tnisupportAuthor Commented:
There was not a subnet configured in ADSS.  It has now been configured to match the local IP subnet and assigned to "Default-First-Site-Name" where both DC's exist (single location, single IP network structure).

Now that it's there, should it be tested during the 2003 DC reboot again?  Or do you believe there may be more to it than that?
Adam BrownSr Solutions ArchitectCommented:
Restart the Exchange topology service and it should assign itself to the site. From there it should be able to discover DCs a little easier, but the Exchange server should be able to pull domain controllers from DNS even without a site, so do make sure the 2003 DC is not set as the primary DNS server for the Exchange Server itself.
tnisupportAuthor Commented:
I have confirmed that the Exchange server is pointing to the 2012 DC for primary DNS and the 2003 DC for secondary DNS.

I did also see that the 2012 DC was pointing to the 2003 DC for primary DNS and for secondary DNS.  I will be changing that to point to itself (using the actual IP address) for Primary DNS and 2003 DC for secondary DNS.

I won't be able to make that change until after hours, along with the restart of the Topology service.  I'm in Central time zone.
Adam BrownSr Solutions ArchitectCommented:
That should be good. The DNS settings are actually fine that way, and it's a recommended practice to have DCs point to a different DC for their primary DNS, as it helps prevent DNS and AD Services race conditions at startup. If you only have or are moving toward a single DC, it's okay to keep itself for DNS.

That said, you'll also want to verify that both DCs have the same copy of the DNS zone for the domain. I recommend comparing differences and verifying that both servers are set to use the same type of Active Directory Integrated DNS zone (if one is set to use Distribute to DCs in this Domain, the other should be set the same, otherwise they can end up getting messed up and store and load different copies of the DNS database).
tnisupportAuthor Commented:
I changed the 2012 DC to point to itself for Primary DNS and the 2003 DC as Secondary.

Restarted the AD Topology service on Exchange 2010.  Tested OWA and email delivery in/out; OK.

Rebooted the 2003 DC and tried OWA again.  Same problems as before, no OWA and errors trying to run EMC and EMS.  Once 2003 DC was back up for a little while, no problems and all works fine without restarting or doing anything on the Exchange 2010 server.

MASEE Solution Guide - Technical Dept HeadCommented:
This is your DC issue/ replication issue.
You will have to fix your old DC and make it healthy then fix the new DC and make sure replication is happening and both DCs are healthy.

Exchange will try to connect to the next available DC if connected one goes down after 10-15 min. Time depends on your server performance.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
tnisupportAuthor Commented:
Please double-check my original question for specific details on the setup and operation as I know it to be.

As far as I'm aware and through the checking that I've done, I don't have a DC replication issue.  Both DC's replicate without errors.  I'm getting ready to remove the 2003 DC, which right now has the PDC role (since it is a 2003 SBS DC).  All other FSMO roles are already on the 2012 DC.

I may not have been as clear as I needed to on my last post.  When I try to test Exchange 2010 operation by rebooting the 2003 DC, during that reboot phase (which the server takes at least 10 minutes to boot) I can't get to Exchange 2010 via OWA internally as well as EMC/EMS.  Exchange 2010 is Primary DNS to 2012 DC and secondary to 2003 DC.
tnisupportAuthor Commented:
There was indeed a DC replication issue, where the new 2012 DC, although replication was showing as good, was not sharing the SYSVOL and NETLOGON.  Worked with MS to correct problem and after that was resolved, Exchange worked properly when the 2003 SBS DC was inaccessible.

Credit for the solution should go to -MAS- with his response ID of 41741821.
MASEE Solution Guide - Technical Dept HeadCommented:
As per the comment from the asker. Comment ID: 41826217
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.