Access Denied in creating Child Domain

J

JohnH

I am attempting to use dcpromo to create a child domain on
a new machine in my root domain.

Dcpromo fails with the message 'Access Denied' and 'don't
have sufficient rights'. However, I've used the ifmember
tool and it shows that I am Enterprise admin and Schema
admin.

I can't find other permissions that are off. I can re-add
the machine to the domain just fine (dcpromo works enough
to take the new server out of the root domain).
Is there a policy that I am missing? What could be denying
me access?

(I've checked DNS through and through as well. The new
machine has DNS for the new domain as standard primary,
secondary for the old domain. It accepts forwards from the
other DCs and they accept from it)

Here is where I fail according to dcpromoui.log:
dcpromoui t:0x870 00819 Calling
DsRoleGetDcOperationResults
dcpromoui t:0x870 00820 Error 0x0 (!0 => error)
dcpromoui t:0x870 00821 Operation results:
dcpromoui t:0x870 00822 OperationStatus : 0x5 !0 => error
dcpromoui t:0x870 00823 DisplayString : (null)
dcpromoui t:0x870 00824 ServerInstalledSite : (null)
dcpromoui t:0x870 00825 OperationResultsFlags: 0x0
dcpromoui t:0x870 00826 Exit DoProgressLoop
dcpromoui t:0x870 00827 Exit DS::CreateNewDomain
dcpromoui t:0x870 00828 Exception caught
dcpromoui t:0x870 00829 catch completed
dcpromoui t:0x870 00830 handling exception
dcpromoui t:0x870 00831 Active Directory Installation
Failed

I've also run dcdiag with positive results:
Testing server: Default-First-Site\BARTER
Starting test: Connectivity
.......................... BARTER passed test Connectivity
Doing primary tests
Testing server: Default-First-Site\BARTER
Starting test: Replications
.......................... BARTER passed test Replications
Starting test: NCSecDesc
.......................... BARTER passed test NCSecDesc
Starting test: NetLogons
.......................... BARTER passed test NetLogons
Starting test: Advertising
.......................... BARTER passed test Advertising
Starting test: KnowsOfRoleHolders
.......................... BARTER passed test
KnowsOfRoleHolders
Starting test: RidManager
.......................... BARTER passed test RidManager
Starting test: MachineAccount
.......................... BARTER passed test MachineAccount
Starting test: Services
.......................... BARTER passed test Services
Starting test: ObjectsReplicated
.......................... BARTER passed test
ObjectsReplicated
Starting test: frssysvol
.......................... BARTER passed test frssysvol
Starting test: kccevent
.......................... BARTER passed test kccevent
Starting test: systemlog
.......................... BARTER passed test systemlog
Running enterprise tests on : comcon.local
Starting test: Intersite
.......................... comcon.local passed test
Intersite
Starting test: FsmoCheck
.......................... comcon.local passed test
FsmoCheck
 
M

milt

I ran into this one time. I always use the Administrator
account for this task. If the Administrator password is
not the same on both machines/domains you will get this
error. It seems, if memory serves correctly, that the
admin password on the parent domain was different than the
one on the child domain. Not sure if this helps.
Hopefully, it will. milt
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

event 1265 ntds kcc - access denied 3
DCDiag error 4
DCDIAG Command Result 3
Re: DCDIAG errors 0
FSMO issues 4
DCDiag Sysvol Error 6
Windows 2000 Replication error 0
DCPROMO Failed 0

Top