Can't install Exchange 2016 on prem.

cdshreve
cdshreve used Ask the Experts™
on
Back ground  - Exchange On prem.  Exchg. 2010 and 2016 already in the org.  our US servers are on 2010 and overseas ones on 2016.  we are looking to install new 2016 servers and migrate our US users over.  Now comes the fun.

Can't install Exchange 2016 on prem.  install errors out saying the install account doesn't have permissions, but it is in the proper permission groups. verified several times.

My service account is a member in both the Enterprise Admins and the Organization Management groups  as well as the local administrators group for the server.

We have verified the Schema is at the correct level and the Domain level is 2012R2.
Error listed below.  Any help would be appreciated.

____________________________________________________________________
Error:
You must be a member of the 'Organization Management' role group or a member of the 'Enterprise Admins' group to continue.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.GlobalServerInstall.aspx

Error:
You must use an account that's a member of the Organization Management role group to install or upgrade the first Mailbox server role in the topology.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.DelegatedBridgeheadFirstInstall.aspx

Error:
You must use an account that's a member of the Organization Management role group to install the first Client Access server role in the topology.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.DelegatedCafeFirstInstall.aspx

Error:
You must use an account that's a member of the Organization Management role group to install the first Client Access server role in the topology.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.DelegatedFrontendTransportFirstInstall.aspx

Error:
You must use an account that's a member of the Organization Management role group to install or upgrade the first Mailbox server role in the topology.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.DelegatedMailboxFirstInstall.aspx

Error:
You must use an account that's a member of the Organization Management role group to install or upgrade the first Client Access server role in the topology.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.DelegatedClientAccessFirstInstall.aspx

Error:
You must use an account that's a member of the Organization Management role group to install the first Mailbox server role in the topology.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.DelegatedUnifiedMessagingFirstInstall.aspx

Error:
Setup encountered a problem while validating the state of Active Directory: No domain controllers for the domain belcan and the site AW-Common-Global are available.  See the Exchange setup log for more information on this error.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.AdInitErrorRule.aspx

Error:
Either Active Directory doesn't exist, or it can't be contacted.
For more information, visit: http://technet.microsoft.com/library(EXCHG.150)/ms.exch.setupreadiness.CannotAccessAD.aspx
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Server engineer
Commented:
Make sure you are logged in to domain.

From CMD type - WHOAMI

It should reference below info. which means you are logged in not locally but in domain.

Domain.com/admin

Also run command: netdom query dc

If the output shows schema master on another DC, then probably you will have to move the schema master role of CDC(configuration domain controller) which exchange server is pointing to so that exchange setup goes smooth.

Normally this also happens in parent and child domain scenarios where schema master role is placed in parent domain and you are setting up exchange server in child domain. SEE IF THIS IS NOT THE CASE WITH YOUR ENVIRONMENT.

Author

Commented:
Whoami gives me my domain and the account properly.
and netdom query dc lists all of my DC's
Jose Gabriel Ortega CastroTop Rated Freelancer on MS Technologies
Awarded 2018
Distinguished Expert 2018

Commented:
1. Both servers on US and overseas are updated?
2. what is the schema and domain functional lvls on each site
3. are both sites connected over vpn?
4. Use administrator to run the installation (domain\administrator)
5. Check replication between AD on one site and the other (cross-site replication).
Success in ‘20 With a Profitable Pricing Strategy

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Edward van BiljonMessaging and Collaboration Technical Lead (Exchange MVP & MCT)

Commented:
Hi

Does the same error happen with another Admin that has Org, schema, enterprise and domain admin rights?

Is this one forest stretched across by VPN? Any Read only domain controllers (RODC)?
Rajkumar DuraisamyIT Service Manager
Top Expert 2012

Commented:
Exchange 2016 version that you are installing making some changes to schema it seems..

Add the user account into schema admins group and run the installation again.

Author

Commented:
We had all of the permissions correct.  Unfortunately another project going on had moved the network segment we were on to another AD Site!  GRRRRRR.   and I did not know that.  Once this was resolved the install went as planned.   I had a discussion with their managers and highlighted the change process and that it has a purpose!  

Thanks so much for the responses!!

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial