DC Demotion

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi,

I'm trying to demote a DC in our 2003 domain, I've run dcpromo, which gets
1/2 way through, but then pops up with this error:

The operation failed because: Active Directory could not configure the
computer account SERVER2$ on the remote domain controller
server1.domain.com. "Access is denied."

The event viewer on Server1 has the security error below. Can anyone suggest
anything? I'd rather not just blat the machine, as it causes other problems
with AD!

Cheers

Ben

Event Type: Failure Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 577
Date: 25/05/2005
Time: 14:28:49
User: DOMAIN\Administrator
Computer: SERVER01
Description:
Privileged Service Called:
Server: Security Account Manager
Service: Security Account Manager
Primary User Name: SERVER01$
Primary Domain: DOMAIN
Primary Logon ID: (0x0,0x3E7)
Client User Name: Adminstrator
Client Domain: DOMAIN
Client Logon ID: (0x0,0x5AB1DA88)
Privileges: SeEnableDelegationPrivilege


.



Relevant Pages

  • is my machine hacked?
    ... Event Type: Success Audit ... Caller User Name: GARNET$ ... Object Server: Security Account Manager ... Client User Name: GARNET$ ...
    (microsoft.public.win2000.security)
  • Re: win98 logon refused
    ... > I found that protocols installed are as below:> server1: tcp/ip, ... > I installed netbeiu in server2, then the client can login no matter server2> is online or not. ...
    (microsoft.public.win2000.active_directory)
  • Re: win98 logon refused
    ... I installed netbeiu in server2, then the client can login no matter server2 ... I deleted netbeui in the client, then the client can't login any time. ... > what error message. ...
    (microsoft.public.win2000.active_directory)
  • Re: Errors 2070 and 2102 on Exchange server 2000
    ... configured your client access licenses in your domain. ... > Type gebeurtenis: Informatie ... > Bron van gebeurtenis: MSExchangeDSAccess ... > Computer: SERVER2 ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Re: Listeners
    ... beleive you can then initiate an outgoing connection on it. ... or connected to a listening port. ... The client would listen on port1 for incoming data from ... and then process the data and pass it on to server2 through port2. ...
    (microsoft.public.dotnet.framework)