PC Review


Reply
Thread Tools Rate Thread

DCPROMO demote failed (Acess Denied)

 
 
jvaldry@gmail.com
Guest
Posts: n/a
 
      22nd Oct 2004
Hello,

I have a problem with Demoting a Windows 2000 server in a Windows 2003
Active Directory Domain. There error message I receive when running
dcpromo.exe is:
"The Operation Failed: Failed to modify the necessary properties for
the machine account MICHELANGELO$(my server name) Access Denied."


While searching for an answer I searched through Google Groups and
found references to this problem and two solutions in the MS KB.


http://support.microsoft.com/?kbid=232070
http://support.microsoft.com/?kbid=250874


I have tried both of these solutions and neither works.

The dcpromo.log file contains the following error messages:

--snip--
10/16 13:08:27 [INFO] Removing Directory Service objects referring to
the local server from the remote server vasari.arts.uci.edu
10/16 13:08:27 [INFO] Error - The attempt to configure the machine
account MICHELANGELO$ on server vasari.arts.uci.edu failed. (5)
10/16 13:08:28 [INFO] NtdsDemote returned 5
10/16 13:08:28 [INFO] DsRolepDemoteDs returned 5
10/16 13:08:28 [ERROR] Failed to demote the directory service (5)
--snip--



Other messages on Google Groups suggest using "dcpromo /forceremoval"
to solve the problem. However I hesitate to do this because I when
promoted a development W2K3 server and attempted to demote it, that
server also now exhibits the EXACT same error. Does anyone have any
suggestions on how to resolve this problem?
Thank you for reading and giving my problem your time.

-Jason Valdry

 
Reply With Quote
 
 
 
 
Matt Anderson
Guest
Posts: n/a
 
      22nd Oct 2004

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hello,
>
> I have a problem with Demoting a Windows 2000 server in a Windows 2003
> Active Directory Domain.


What happens if you log on as enterprise admin?

Matt


 
Reply With Quote
 
Jason Valdry
Guest
Posts: n/a
 
      22nd Oct 2004
I am logging in with an Enterprise Admin account for all actions.
-Jason

 
Reply With Quote
 
=?Utf-8?B?R2xlbm4gTA==?=
Guest
Posts: n/a
 
      23rd Oct 2004
Well, You could spend the time to troubleshoot this.
Or you could just use the /forceremoval switch to force remove it. Then do
the metadata cleanup. If the box holds FSMOs then you could sieze them to
another DC.

If your really interested in which attribute it is failing on (probably
useraccountcontrol), then you need to do a network trace. The ldap modify
calls will show you what attribute it is failing on.
Once you know the attribute, then fix the security on it.


"Jason Valdry" wrote:

> I am logging in with an Enterprise Admin account for all actions.
> -Jason
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DCPROMO demote failed (Acess Denied) jvaldry@gmail.com Microsoft Windows 2000 Active Directory 1 25th Oct 2004 04:09 PM
Can Not Demote DC with DCPROMO =?Utf-8?B?RGF2aWQgV3JpZ2h0?= Microsoft Windows 2000 Active Directory 3 29th May 2004 02:14 PM
DCpromo failed! Access Denied nwtest Microsoft Windows 2000 Active Directory 3 5th Apr 2004 01:05 PM
Cannot demote with dcpromo.exe Max Microsoft Windows 2000 Active Directory 5 10th Oct 2003 06:56 PM
Can't demote DC with dcpromo Rob Miles Microsoft Windows 2000 Active Directory 5 22nd Aug 2003 09:31 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:15 AM.