Link to home
Start Free TrialLog in
Avatar of Ruzindana Alain floribert
Ruzindana Alain floribertFlag for Rwanda

asked on

MR Alain Ruzindana

I had this question after viewing Adprep /forestprep fails.


trying to update schema from Windows server 2008R 2 to windows server 2012R2 but getting the below error,note that Admin account is member of domain admins, enterprise Admin and schema master.and Schema admin has a full permission into Schema and configuration:

Adprep was unable to update forest information.
[Status/Consequence]
Adprep requires access to existing forest-wide information from the schema master in order to complete this operation.


Avatar of Ruzindana Alain floribert
Ruzindana Alain floribert
Flag of Rwanda image

ASKER

LDF log is as follows

Importing directory from file "C:\WS 2012 Extracted\support\adprep\sch48.ldf"

Loading entries
1: CN=ms-DS-Members-Of-Resource-Property-List,CN=Schema,CN=Configuration,DC=SORAS,DC=LOCAL
Entry DN: CN=ms-DS-Members-Of-Resource-Property-List,CN=Schema,CN=Configuration,DC=SORAS,DC=LOCAL
Add error on entry starting on line 1: Unwilling To Perform

The server side error is: 0x20bb Schema update failed: duplicate OID.

The extended server error is:

000020BB: SvcErr: DSID-03170D8A, problem 5003 (WILL_NOT_PERFORM), data 0


0 entries modified successfully.

An error has occurred in the program
Avatar of Seth Simmons
are you running this on the server with the schema master role?

have you ran netdom query fsmo and verified the servers listed with the FSMO roles are correct? (does not reference a server that is no longer there)

what is the functional level of the forest/domain?  if it is 2000 you need to raise it first to at least 2003 to add a 2012 domain controller
Thanks Simons, the Functional level of the forest/domain  is  windows 2008 r2 ,
the server listed with the FSMO role is correct.

Thanks
have you tried doing it through the GUI?
adding the ADDS role and promoting to a domain controller will do the necessary schema changes automatically; no need to run adprep manually

Add a 2012 Domain Controller to a 2008 Domain

https://www.petenetlive.com/KB/Article/0000680
Hi Simmons,

that is the first solution have started with but i got the following error:


User generated image

ok...have you looked at the log file cited there?
it will give more details as to why it is failing
ldif.log.0ADPrep.log

Hi Simmons,

the attached is the log file with details,.


Connecting to "SANLAM01DC01.SORAS.LOCAL"

Logging in as current user using SSPI

Importing directory from file "C:\Windows\system32\adprep\sch48.ldf"

Loading entries
1: CN=ms-DS-Members-Of-Resource-Property-List,CN=Schema,CN=Configuration,DC=SORAS,DC=LOCAL
Entry DN: CN=ms-DS-Members-Of-Resource-Property-List,CN=Schema,CN=Configuration,DC=SORAS,DC=LOCAL
Add error on entry starting on line 1: Unwilling To Perform

The server side error is: 0x20bb Schema update failed: duplicate OID.

The extended server error is:

000020BB: SvcErr: DSID-03170D8A, problem 5003 (WILL_NOT_PERFORM), data 0


0 entries modified successfully.

An error has occurred in the program

Thanks
did you do anything custom in AD or possibly a different schema change before that failed?

try going through this thread; different product but same OID issue

https://social.technet.microsoft.com/Forums/ie/en-US/1056021b-6171-482c-8001-93d6662ea6ae/error-extending-2012-r2-ad-schema-for-exchange-2013-rtmcu6cu7-for-office-365-attributes?forum=exchangesvrgeneral
Hi Simmons,

there was no schema change before the change, as if we do add a new Additional AD in Windows server 2008R2 it got promoted without any issue. but we cannot upgrade schema to go beyond WIN 2008 R2.

Thanks
ok...still take a pass at the article and see if the selected answer there fixes it
is the user a member of rhea schema admin group?
Morning David,

yes offcourse, he is a member of schema Admin


Hi Simmons ,

hope you are well.

I have done as per your Link's advice but without success .the issue is still persisting.

Thanks
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.