Join Server 2012 to Server 2008 Forest


i have scenario have run ebs 2008 migration script dismantle ebs separate roles.  have created 2 new server 2008 r2 domain controllers , have been in environment @ least 1 month , running fine (dc diag comes clean).  ready introduce server 2012 member servers environment replace ebs servers (migrate exchange exchange 2013, etc.) , receiving error when go join server domain.

when type in domain name , click apply, prompted enter credentials usual.  enter in credentials (domain admin, ent. admin , schema admin associated account)  receive error message shortly after entering credentials stating "the following error occurred attempting join domain "<domain name>": user not allowed log on workstation"

i have used both fqdn , netbios name domain , receive same message.  logged in local administrator account on server , have disabled uac not help.  have checked c:\windows\debug\netsetup.log , edit post once can copy log (slow internet keeping me posting @ moment).  netsetup.log shows connecting new non-ebs domain controller has of fsmo roles associated why posting here , not in ebs forum. 


jason apt, microsoft certified master | exchange 2010 blog

hi jason,

i'd inclined check 2 things:

  1. the account's "logon to" workstation list.
  2. that security log isn't full on domain controller(s).

for first point, launch ad users , computers on domain controller(s) or via rsat tools (if have installed on workstation) , check allowed workstation list isn't populated. if is, empty looks following:

logon list

for second point, again, logon onto domain controller(s), load event viewer, right-click security log , go it's properties, , ensure either circular logging enabled or increase space if required.

there command equivalents these tasks. let me know if have build domain controllers server core , require instead.

cheers,
lain



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS