PC Review


Reply
Thread Tools Rate Thread

can't demote DC

 
 
mike
Guest
Posts: n/a
 
      5th Nov 2004
I have 3 dc's, and want to demote one of them. Let's say
ser01, ser 02, and ser03. I want to keep 1 and 2, get rid
of 3. All FSMO's are on 1 and 2. When I run dcpromo on 3,
it fails with the following message; the operation failed
because;Active Directory could not configure the computer
account ser03$ on the remote domain controller
ser01.domain.com. "access is denied". I am using an
enterprise admin account to run dcpromo. What permissions
does the 2 and 3 dc need to be able to accept
authentication from ser03? I think it may be something in
the local policy, but have not found what it is.

I know I can force this out with ntdsutil, but would
rather fix this problem and do it cleanly.

Thanks in advance for any help.
 
Reply With Quote
 
 
 
 
Guest
Posts: n/a
 
      5th Nov 2004
never mind, I figured it out, thx
>-----Original Message-----
>I have 3 dc's, and want to demote one of them. Let's say
>ser01, ser 02, and ser03. I want to keep 1 and 2, get rid
>of 3. All FSMO's are on 1 and 2. When I run dcpromo on 3,
>it fails with the following message; the operation failed
>because;Active Directory could not configure the computer
>account ser03$ on the remote domain controller
>ser01.domain.com. "access is denied". I am using an
>enterprise admin account to run dcpromo. What permissions
>does the 2 and 3 dc need to be able to accept
>authentication from ser03? I think it may be something in
>the local policy, but have not found what it is.
>
>I know I can force this out with ntdsutil, but would
>rather fix this problem and do it cleanly.
>
>Thanks in advance for any help.
>.
>

 
Reply With Quote
 
Cary Shultz [A.D. MVP]
Guest
Posts: n/a
 
      5th Nov 2004
Was it the 'delegation' problem?

Cary

<(E-Mail Removed)> wrote in message
news:351501c4c344$b5335850$(E-Mail Removed)...
> never mind, I figured it out, thx
> >-----Original Message-----
> >I have 3 dc's, and want to demote one of them. Let's say
> >ser01, ser 02, and ser03. I want to keep 1 and 2, get rid
> >of 3. All FSMO's are on 1 and 2. When I run dcpromo on 3,
> >it fails with the following message; the operation failed
> >because;Active Directory could not configure the computer
> >account ser03$ on the remote domain controller
> >ser01.domain.com. "access is denied". I am using an
> >enterprise admin account to run dcpromo. What permissions
> >does the 2 and 3 dc need to be able to accept
> >authentication from ser03? I think it may be something in
> >the local policy, but have not found what it is.
> >
> >I know I can force this out with ntdsutil, but would
> >rather fix this problem and do it cleanly.
> >
> >Thanks in advance for any help.
> >.
> >



 
Reply With Quote
 
Hank Arnold
Guest
Posts: n/a
 
      7th Nov 2004
Netiquette says you should post how you resolved it. Others may have the
same problem and could benefit....

--
Regards,
Hank Arnold

<(E-Mail Removed)> wrote in message
news:351501c4c344$b5335850$(E-Mail Removed)...
> never mind, I figured it out, thx



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
can't demote Neil Jarman Microsoft Windows 2000 Advanced Server 4 8th Nov 2004 06:44 PM
can't demote Neil Jarman Microsoft Windows 2000 Active Directory 4 8th Nov 2004 06:44 PM
dc demote =?Utf-8?B?ZnJhbms=?= Microsoft Windows 2000 Active Directory 1 27th Oct 2004 07:17 PM
Demote DCs Miguel E. Alicea Microsoft Windows 2000 Active Directory 2 12th Nov 2003 10:04 PM
AD will not demote Richard Microsoft Windows 2000 Active Directory 1 22nd Sep 2003 03:56 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:18 PM.