RE: I can not add any new object to my AD

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: S.J.Haribabu (sjhari_at_microsoft.com)
Date: 06/22/04


Date: Tue, 22 Jun 2004 21:06:15 GMT

Hi,

I did research and found some articles in Active directory troubleshooting.
The problem is

Cannot create objects in Active Directory.
===================================
Cause:
======
The relative ID master is not available. This may be caused by a network
connectivity problem. It may also be due to a failure of the computer
holding the relative ID master role.

Solution:
========
Resolve the network connectivity problem.
Or, repair or replace the computer holding the relative ID master role. It
may be necessary to seize the relative ID master role.

See also:
=========
Diagnose connections; Single master operations; Responding to operations
master failures; Transfer the relative ID master role; Seize the relative
ID master role

For more information look at
http://www.microsoft.com/windows2000/en/server/help/default.asp?url=/windows
2000/en/server/help/sag_ADtrouble_1.htm?id=370

Relative ID master failure
======================
Temporary loss of the relative identifier operations master is not visible
to network users. It will not be visible to network administrators either,
unless they are creating objects and the domain in which they are creating
the objects runs out of relative identifiers.

If the relative identifier master will be unavailable for an unacceptable
length of time, you can seize the role to the operations master. However,
seizing this role is a drastic step that you should take only when the
failure of the relative identifier master is permanent.

Important
============
A domain controller whose relative identifier master role has been seized
must never be brought back online.
For procedures on how to seize the relative identifier master role, see
Seize the relative ID master role

To seize the relative ID master role
================================
Click Start, click Run, and then type cmd.
At the command prompt, type ntdsutil.
At the ntdsutil prompt, type roles.
At the fsmo maintenance prompt, type connections.
At the server connections prompt, type connect to server, followed by the
fully qualified domain name.
At the server connections prompt, type quit.
At the fsmo maintenance prompt, type seize RID master.
At the fsmo maintenance prompt, type quit.
At the ntdsutil prompt, type quit.
 Caution

Seizing the relative ID master is a drastic step that should be considered
only if the current operations master will never be available again.
 Note

Before seizing the relative ID master, use Repadmin, in the Active
Directory support tools, to verify whether the new operations master has
received any updates performed by the previous role holder, and then remove
the current operations master from the network. For more information about
single master operations, and the Active Directory support tools, see
Related Topics.

Hope this will help you to solve your issue.

Thanks,

sjhari@online.microsoft.com

This posting is provided "AS IS" with no warranties, and confers no rights.

 



Relevant Pages

  • Re: errors after migration
    ... Do I need to downgrade the migration server, ... > infrastucture master role to a DC that hosts a GC. ... > The name of the current operations master appears under Operations master. ...
    (microsoft.public.windows.server.migration)
  • RE: Active Directory FSMO, GC and Exchange Proper Setup
    ... As its a Parent child domain structure then Schema master role and Domain ... naming master role will be only on 1 Domain controlelr in the Forest(Majorly ... All my app servers, exchange servers and users reside on DomainB. ...
    (microsoft.public.windows.server.active_directory)
  • RE: errors after migration
    ... infrastucture master role to a DC that hosts a GC. ... To determine which domain controller holds the domain naming master role, ... >>I transported the following FSMO from the migration server to our new ...
    (microsoft.public.windows.server.migration)
  • Re: cant access Windows2003 domain
    ... > master role DC has very strange problem, you can ping successfully to both ... > internal and Internet host from this DC, but I couldn't connect to it from ... I try to change the master ... > I guess there's something wrong with the DNS service on this DC, ...
    (microsoft.public.windows.server.active_directory)
  • Re: errors after migration
    ... When I use NTDSUTIL to check which roles are on my new server, ... >> infrastucture master role to a DC that hosts a GC. ... In the console tree, right-click Active Directory Users and Computers, ... >> The name of the current operations master appears under Operations ...
    (microsoft.public.windows.server.migration)