RE: Can not create addition domain controller

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Kevin Bowersock (a-KBower_at_online.microsoft.com)
Date: 08/05/04


Date: Thu, 05 Aug 2004 21:53:07 GMT

A few more things to look at:

1. Make sure the existing DC is in the Domain Controllers OU.
2. check to make sure that you are not crossing arouter with an MTU packet
size of less than 1500
3.On the domain controllers, look at the files below and verify that they
are not set
to Read Only. If they are, remove the Read Only check mark from the
properties of
that object.

C:\WINNT\Security\Templates\Policies\gptXXXXX.dom
C:\WINNT\Security\Templates\Policies\gptXXXX1.inf
C:\WINNT\Security\Templates\Policies\tmpgptfl.inf

Having these files as Read-Only, or with too restrictive NTFS permissions,
can
prevent the Security Client-side extension (SceCli) from doing it's job in
applying
the security settings to the server.

4. Make sure you DC is not multi-homed and both NICS are being registered
in DNS

5. Configure Domain Controllers Group Policy
Computer Configuration \ Windows Settings \ Security Settings \ Local
Policies \
User Rights Assignment \ Enable computer and user accounts to be trusted
for
delegation.
Change policy setting to give right to administrators, run secedit to apply
policy.

a-Kbower@online.microsoft.com

This posting is provided "AS IS"
with no warranties, and confers no rights
--------------------
| Thread-Topic: Can not create addition domain controller
| thread-index: AcR6ekRa6CUKLv/tSbS0z/ldYvW/7w==
| X-WBNR-Posting-Host: 216.231.28.132
| From: =?Utf-8?B?TmV3Ymll?= <Newbie@discussions.microsoft.com>
| References: <DB1A2EA2-A0F1-41D7-A879-EC662C0829CE@microsoft.com>
<033801c47a75$95b22960$a501280a@phx.gbl>
| Subject: RE: Can not create addition domain controller
| Date: Wed, 4 Aug 2004 16:25:02 -0700
| Lines: 29
| Message-ID: <721A384C-04B6-4E26-99D5-25B49154E22A@microsoft.com>
| MIME-Version: 1.0
| Content-Type: text/plain;
| charset="Utf-8"
| Content-Transfer-Encoding: 7bit
| X-Newsreader: Microsoft CDO for Windows 2000
| Content-Class: urn:content-classes:message
| Importance: normal
| Priority: normal
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
| Newsgroups: microsoft.public.win2000.active_directory
| NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.1.29
| Path: cpmsftngxa06.phx.gbl!TK2MSFTNGXA03.phx.gbl
| Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.active_directory:83395
| X-Tomcat-NG: microsoft.public.win2000.active_directory
|
| Thanks
|
| but 250874 can not solve my problem
|
|
|
| "Alex Martinez" wrote:
|
| > Hi,
| > I just ran into this problem myself. Check out knowledge
| > base article 250874.
| >
| > Good Luck...!
| > >-----Original Message-----
| > >Hello,
| > >
| > >When I tried to create new addition domain controller, I
| > always get the
| > >following message:
| > >
| > >The operation failed because: Failed to modify the
| > necessary properties for
| > >the machine account %computername%$ "Access Denied".
| > >
| > >
| > >Thanks
| > >.
| > >
| >
|



Relevant Pages

  • Re: User Access to a DC
    ... Check the policies at the domain controllers OU for: ... Computer configuration, windows settings, security settings, local ...
    (microsoft.public.win2000.active_directory)
  • Re: User Access to a DC
    ... Check the policies at the domain controllers OU for: ... Computer configuration, windows settings, security settings, local policies, user rights assignment, "logon locally" ...
    (microsoft.public.win2000.active_directory)
  • Re: NT workstations cant see shares on Windows 2000 server
    ... Browse thru the security settings, ... I logon (using Domain administrator and domain user) I get the same error ... and issue the net use command to the share folder, and i got "The Password is ... > Windows 2000 domain controllers and make sure that they have the same ...
    (microsoft.public.win2000.security)
  • Re: delegate permissions to logon dc-servers
    ... The domain controllers of a domain share the same security settings. ... Anyway, for security reasons, the only people who should be able to write to the filesystem, modify services, or log on interactively to DCs should be domain admins and they should also all be enterprise admins. ... How can I do the same thing with a user that should only logon to one domain controller with a specific admin-account? ...
    (microsoft.public.win2000.active_directory)