Re: Unable To Add DC

From: Adam (adam_at_email.com)
Date: 06/21/04


Date: Sun, 20 Jun 2004 22:30:17 -0700

Hi,

I found out in the end a way around it. I removed the
machine from the domain, then deleted the computer account
from active directory and then ran DCPROMO,

This worked and the machine is now working correctly as a
domain controller.

Thanks heaps for your help!

Cheers
Adam

>-----Original Message-----
>Hi Adam
>
>I'd suggest working through the following in order:
>
>http://support.microsoft.com/default.aspx?scid=KB;EN-
US;255504
>
>http://support.microsoft.com/default.aspx?scid=KB;EN-
US;216498
>
>After doing this, I'd move the problematic server to a
workgroup, delete the
>existing computer account for this machine from the
Active Directory, double
>check the steps in the previous knowledge base article
that I mentioned and
>then reboot the DC.
>
>Failing these steps, you can try examining the
dcpromo.log and dcpromoui.log
>files in %systemroot%\debug folder for any further
information. If you send
>me these logs directly, I can take a quick look. If I
don't find anything
>straight forward, you're probably best logging a support
incident with
>Microsoft to investigate in more detail.
>
>Kind regards
>--
>Mark Renoden [MSFT]
>Windows Platform Support Team
>Email: markreno@online.microsoft.com
>
>Please note you'll need to strip ".online" from my email
address to email
>me; I'll post a response back to the group.
>
>This posting is provided "AS IS" with no warranties, and
confers no rights.
>
>
>
>"Adam" <Adam@adam.com> wrote in message
>news:1c72601c4527a$a9970130$a401280a@phx.gbl...
>> Hi Mark,
>>
>> Thanks for writing back so quick.
>>
>> In my hast to try and get the server rebuild,
>> i forgot to DCPROMO it and take it off the domain.
>>
>> I have reloaded it with 2003 server again and given
>> it a different name and ip address.
>>
>> I have gone into active directory users and computers
then
>> into domain controllers and removed it from there, using
>> the option of the domain controller is no longer
>> physicially available.
>>
>> When i went into the sites and services i noticed that
>> it still had the old domain controller in there, so i
>> removed it the same way.
>>
>> I have gone through the MS KB Article and followed the
>> intructions. I'm already logging on as administrator,
>> however under the enable computer and user accounts to
be
>> trusted for delegation, there was no usernames. So i
have
>> added in the administrators group.
>>
>> Apon trying to run it again it still fails, this is the
>> exact error message:
>>
>> The operation failed because: The active directory
>> installation wizard was unable to convert the computer
>> account SERVERNAME$ to a domain controller
>> account. "Access is denied"
>>
>> Type a username and password of an account with
sufficient
>> privileges to create and additional domain controller
for
>> the domainname.domainname domain.
>>
>> Also please forgive my stupidness, but were would i find
>> the FSMO roles.
>>
>> Thanks
>> Adam
>>>-----Original Message-----
>>>Hi Adam
>>>
>>>It could be this:
>>>
>>>232070 When you run Dcpromo.exe to create a replica
>> domain controller, you
>>>http://support.microsoft.com/?id=232070
>>>
>>>Additionally:
>>>
>>>Did you demote the DC before formatting and starting
>> again?
>>>Did you rebuild using the same name?
>>>Did you move the FSMO roles to the remaining DC?
>>>
>>>Kind regards
>>>--
>>>Mark Renoden [MSFT]
>>>Windows Platform Support Team
>>>Email: markreno@online.microsoft.com
>>>
>>>Please note you'll need to strip ".online" from my email
>> address to email
>>>me; I'll post a response back to the group.
>>>
>>>This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>>>
>>>"Adam" <adam@nospam.com> wrote in message
>>>news:1c91401c45270$ba5f9ea0$a001280a@phx.gbl...
>>>> Hi All,
>>>>
>>>> We have a win2003 server network with 2 DC's.
>>>> Recently one of the DC's has been giving us alot of
>>>> weird problems, so last night i reloaded the OS on it.
>>>>
>>>> In doing so i have reloaded the OS and gone to make
>>>> the machine a DC again and i am now recieving an error
>>>> in doing so.
>>>>
>>>> The active directory wizard was unable to convert the
>>>> computer account to a domain controller "Access is
>> denied"
>>>>
>>>> I'm guessing this is a permissions error and proberbly
>>>> something to do with the permissions in active
>> directory.
>>>>
>>>> Does anyone know were i can find this and set it right
>>>> please
>>>>
>>>> PS I am logging on using the administrator account
>>>> so the account does have the right permissions
>>>>
>>>> Thanks
>>>> Adam
>>>
>>>
>>>.
>>>
>
>
>.
>



Relevant Pages

  • RE: NTDS.dit file is currupt
    ... "microsoft" wrote:> We are currently facing a serious problem with one our client server. ... > After rebooting the machine in directory services restore mode, I had> followed the steps below; ntdsutil neither defrag Active Directory Database> nor repair. ... Restart the domain controller. ... Check the integrity of the Active Directory database. ...
    (microsoft.public.win2000.active_directory)
  • Re: W2k3 Problems
    ... The other is our Exchange Server. ... > The DNS server has encountered a critical error from the Active Directory. ... > Replication Service while polling the Domain Controller dc01.restons.co.uk ... > NSPI Proxy failed to connect to Global Catalog dc01.restons.co.uk over ...
    (microsoft.public.windows.server.general)
  • RE: Event Id 4 Kerberos
    ... > If this is an additional domain controller, ... Remove Data in Active Directory After an Unsuccessful Domain ... > menu is used to connect to the specific server where the changes occur. ... > Server (DNS) host name, and the location of the server's computer account ...
    (microsoft.public.windows.server.sbs)
  • RE: Second Win200 server on network proper config.
    ... Step-by-Step Guide to Setting up Additional Domain Controllers - ... cannot have a domain without at least one domain controller. ... Active Directory allows Windows® 2000 domain controllers function as peers, ... The Windows NT Server domain system ...
    (microsoft.public.win2000.active_directory)
  • Re: Unable To Add DC
    ... After doing this, I'd move the problematic server to a workgroup, delete the ... existing computer account for this machine from the Active Directory, ... > it still had the old domain controller in there, ...
    (microsoft.public.windows.server.active_directory)