PC Review


Reply
Thread Tools Rate Thread

Administrator has Insufficient Privaleges to Transfer FSMOs from PDC to Secondary DC

 
 
Don
Guest
Posts: n/a
 
      11th Feb 2006
I am trying to temporarily transfer a DC to another machine so we can
rebuild the first machine. Thanks to several folks in these newsgroups I
got the scoop on how to do this. So far, I managed to set up a second
domain controller on the network (this is a stand-alone network with about a
dozen machines in a lab). I was in the process of transferring the FSMOs to
the secondary machine when I ran into problems.

When I try to transfer the RID, PDC, Infrastructure, Schema, etc I get an
error for each which basically say:

The transfer of the operations master role cannot be performed because: The
requested FSMO operation failed. The current FSMO holder could not be
contacted.

(I say "basically the same" because in a couple cases it asks if I want to
try a forced transfer.) According to what I read, this is usually caused by
insufficient account privileges. Well, I was in the domain administrator
account which has about every permission I could find and a member of the
Domain Administrators group, schema group, etc, etc. I was also doing it
from the machine which is currently the DC.

From what I have read, this is the preferred way of performing the transfer.
There is a way to "pull" the FSMOs over to the secondary machine by logging
in to it and using command line commands. However, some of the reading
imply that doing a "pull" will render the old domain controller unable to
resume as DC. Yes, I know that ultimately I am putting a clean machine back
in, but there is some sensitivity to being able to return things to they way
they were if the rebuild does not work. (The rebuild is a hard drive swap,
so I will have the old drive with everything on it.) I am also concerned
that the "pull" approach only half works and I am stuck with the old DC
being lobotomized and the new, temporary DC with not enough smarts to do the
job.

Anyone have insight into why "The current FSMO holder could not be
contacted." and how to resolve the problem? Any other suggestions would be
greatly appreciated too!

Thanks!

Don






 
Reply With Quote
 
 
 
 
Lanwench [MVP - Exchange]
Guest
Posts: n/a
 
      24th Feb 2006


In news:(E-Mail Removed),
Don <(E-Mail Removed)> typed:
> I am trying to temporarily transfer a DC to another machine so we can
> rebuild the first machine. Thanks to several folks in these
> newsgroups I got the scoop on how to do this. So far, I managed to
> set up a second domain controller on the network (this is a
> stand-alone network with about a dozen machines in a lab). I was in
> the process of transferring the FSMOs to the secondary machine when I
> ran into problems.
>
> When I try to transfer the RID, PDC, Infrastructure, Schema, etc I
> get an error for each which basically say:
>
> The transfer of the operations master role cannot be performed
> because: The requested FSMO operation failed. The current FSMO
> holder could not be contacted.
>
> (I say "basically the same" because in a couple cases it asks if I
> want to try a forced transfer.) According to what I read, this is
> usually caused by insufficient account privileges. Well, I was in
> the domain administrator account which has about every permission I
> could find and a member of the Domain Administrators group, schema
> group, etc, etc. I was also doing it from the machine which is
> currently the DC.
>
> From what I have read, this is the preferred way of performing the
> transfer. There is a way to "pull" the FSMOs over to the secondary
> machine by logging in to it and using command line commands.
> However, some of the reading imply that doing a "pull" will render
> the old domain controller unable to resume as DC. Yes, I know that
> ultimately I am putting a clean machine back in, but there is some
> sensitivity to being able to return things to they way they were if
> the rebuild does not work. (The rebuild is a hard drive swap, so I
> will have the old drive with everything on it.) I am also concerned
> that the "pull" approach only half works and I am stuck with the old
> DC being lobotomized and the new, temporary DC with not enough smarts
> to do the job.
>
> Anyone have insight into why "The current FSMO holder could not be
> contacted." and how to resolve the problem? Any other suggestions
> would be greatly appreciated too!
>
> Thanks!
>
> Don


"Transferring" the FSMO roles is indeed better than "siezing" them....

1. Are you 100% sure this server is pointing at the right DNS server (your
internal DNS server, AD-integrated or no) ?
2. What happens if you use the built-in domain admin account?


 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
insufficient rights-administrator Toobi Won Kenobi Windows XP Security 4 19th Feb 2007 10:04 PM
How do I get Administrator privaleges? T5 Windows Vista General Discussion 11 11th Jul 2006 12:04 AM
Administrator has Insufficient Privaleges to Transfer FSMOs from PDC to Secondary DC Don Microsoft Windows 2000 4 13th Feb 2006 03:28 AM
Insufficient Administrator Permissions Simon Esland Windows XP Security 1 9th Jul 2004 08:47 AM
Insufficient Administrator privileges !!! =?Utf-8?B?UG9veWE=?= Microsoft Windows 2000 0 29th Dec 2003 12:06 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:26 AM.