Cannot demote DC

P

Peter Lillington

I cannot demote domain controllers in our domain. The
dcpromo.log shows this:

11/19 16:44:32 [INFO] Removing Directory Service objects
referring to the local server from the remote server
xxx.xxx.xxx
11/19 16:44:33 [INFO] Error - The attempt to configure
the machine account GHOST$ on server xxx.xxx.xxx failed.
(5)
11/19 16:44:35 [INFO] NtdsDemote returned 5
11/19 16:44:35 [INFO] DsRolepDemoteDs returned 5
11/19 16:44:35 [ERROR] Failed to demote the directory
service (5)

The message onscreen also tells you 'access is denied',
and asks for an account with ent admin rights - which the
account used for demotion has.

This looks to be a problem with access permissions on the
computer object in AD. I checked the permissions on the
computer object, and changed them temporarily to give FC
for ent admins (it appeared to be set too restrictively -
the same permissions as found on the AdminSDHolder
object). However, this permission change did not help
and access to the object is still denied. Any ideas
anybody? Thanks,

Peter
 
G

Guest

Should anybody be interested, I resolved the problem by
adding admins to the "enable computer and user accts to
be trusted for delegation" right in the DDCP GPO. Seems
that was missing.

Peter
-----Original Message-----
I cannot demote domain controllers in our domain. The
dcpromo.log shows this:

11/19 16:44:32 [INFO] Removing Directory Service objects
referring to the local server from the remote server
xxx.xxx.xxx
11/19 16:44:33 [INFO] Error - The attempt to configure
the machine account GHOST$ on server xxx.xxx.xxx failed.
(5)
11/19 16:44:35 [INFO] NtdsDemote returned 5
11/19 16:44:35 [INFO] DsRolepDemoteDs returned 5
11/19 16:44:35 [ERROR] Failed to demote the directory
service (5)

The message onscreen also tells you 'access is denied',
and asks for an account with ent admin rights - which the
account used for demotion has.

This looks to be a problem with access permissions on the
computer object in AD. I checked the permissions on the
computer object, and changed them temporarily to give FC
for ent admins (it appeared to be set too restrictively -
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top