Old deleted server still in Active directory and prevents dcpromo


i trying demote server because old , have new 1 installed , working.
executing dcpromo in old server produces error:

active directory domain services not transfer remaining data in directory partition dc=forestdnszones,dc=xxxxxx,dc=local activedirectory domain controller \\newserver.xxxxxx.local.
"the directory service missing mandatory configuration information, , unable determine ownership of floating single-master operation roles."

have queried active directory "netdom query fsmo" , fsmo roles in newserver.
looking "directory service log" of old server event viewer, see warning following description:

operations require contacting fsmo operation master fail until condition corrected.
fsmo role: cn=infrastructure,dc=forestdnszones,dc=xxxxxx,dc=local
fsmo server dn: cn=ntds
settings\0adel:38b2eef0-bfa3-438a-a337-52349d447c49,cn=svm\0adel:b4474016-1746-4988-af31-9f0d75909dbc,cn=servers\0adel:a2ea0c85-85c1-4424-8f98-2d9ad429cd8b,cn=site2\0adel:7883f732-28ef-4a0b-b2e4-f460df46b504,cn=sites,cn=configuration,dc=xxxxxx,dc=local

long time ago, server called "svm" crashed without possible recovery. server in a different site called "site2", , after crash, site , server deleted active directory.

seems server "svm" has been existing deleted object years , prevent tries of demoting old server.

"active directory users , computers" found there link "svm" server in "system > file replication service > domain system volume > svm". deleted replication "svm" server exists deleted object and continues preventing dcpromo.

playing around ldp.exe found deleted object "svm" have not found way delete object, attempts "delete ldp" , "remove-adobject" guid failed object not found.

it seems must wait moths until active directory delete "svm" server because not linked replication service, maybe linked internally other things don't know.

anyway need demote old server in few days, can not wait months. there anyway purge deleted object prevents me demote server?

thank help.

i trying demote server because old , have new 1 installed , working.
executing dcpromo in old server produces error:

active directory domain services not transfer remaining data in directory partition dc=forestdnszones,dc=xxxxxx,dc=local activedirectory domain controller \\newserver.xxxxxx.local.
"the directory service missing mandatory configuration information, , unable determine ownership of floating single-master operation roles."

have queried active directory "netdom query fsmo" , fsmo roles in newserver.
looking "directory service log" of old server event viewer, see warning following description:

operations require contacting fsmo operation master fail until condition corrected.
fsmo role: cn=infrastructure,dc=forestdnszones,dc=xxxxxx,dc=local
fsmo server dn: cn=ntds
settings\0adel:38b2eef0-bfa3-438a-a337-52349d447c49,cn=svm\0adel:b4474016-1746-4988-af31-9f0d75909dbc,cn=servers\0adel:a2ea0c85-85c1-4424-8f98-2d9ad429cd8b,cn=site2\0adel:7883f732-28ef-4a0b-b2e4-f460df46b504,cn=sites,cn=configuration,dc=xxxxxx,dc=local

long time ago, server called "svm" crashed without possible recovery. server in a different site called "site2", , after crash, site , server deleted active directory.

seems server "svm" has been existing deleted object years , prevent tries of demoting old server.

"active directory users , computers" found there link "svm" server in "system > file replication service > domain system volume > svm". deleted replication "svm" server exists deleted object and continues preventing dcpromo.

playing around ldp.exe found deleted object "svm" have not found way delete object, attempts "delete ldp" , "remove-adobject" guid failed object not found.

it seems must wait moths until active directory delete "svm" server because not linked replication service, maybe linked internally other things don't know.

anyway need demote old server in few days, can not wait months. there anyway purge deleted object prevents me demote server?

thank help.

you need set fsmorileowner attribute point valid domain controller infrastructure object in forestdnszones nc, that's indicated here:
fsmo role: cn=infrastructure,dc=forestdnszones,dc=xxxxxx,dc=local
fsmo server dn: cn=ntds
settings\0adel:38b2eef0-bfa3-438a-a337-52349d447c49,cn=svm\0adel:b4474016-1746-4988-af31-9f0d75909dbc,cn=servers\0adel:a2ea0c85-85c1-4424-8f98-2d9ad429cd8b,cn=site2\0adel:7883f732-28ef-4a0b-b2e4-f460df46b504,cn=sites,cn=configuration,dc=xxxxxx,dc=local

follow instructions here correct issue: http://social.technet.microsoft.com/forums/windowsserver/en-us/b77a7e5c-590e-4d23-a9cb-8c4c0f403baf/forestdnszones-and-domaindnszones-have-wrong-infrastructure-role-record?forum=winserverds


enfo zipper
christoffer andersson – principal advisor
http://blogs.chrisse.se - directory services blog



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS