Demote AD

T

tfrancis

Hi all
I'm having some problems demoting a couple of servers from being AD domain
controllers to just being member servers.
both are Win2K sp4.

the situation is :
We have a domain with several child domains, each of the servers in question
is a domain controller (not PDC) in it's respective child domain, when
demoting we get an error that we nned an account with administrative
privledges in the forest no matter what the user name is we always get the
same error (local domain admin, domain / enterprise admin for parent domain)

in the dcpromo log file the error is
"[Info] Error - The attempt to configure the machine account {servername}$
on server "
"[Info] {PDCservername.domain.com}failed. (5) "
"[Info] NtdsDemote returned 5"
"[Info] DsRolepDemoteDs returned 5"
"[Error] Failed to demote the Directory Service (5)"

Thanx

Todd Francis
(e-mail address removed)
 
P

Paul McGuire

you need to make sure that user is trusted for delegation in the domain
security policy and the domain controller security policy. Take a look at
these policies and there will be a tab the says Enable users/computers to be
trusted for delehation. Add the users/group and then force policy to apply
to each DC. you do that by going to run and typing

SECEDIT /REFRESHPOLICY MACHINE_POLICY /ENFORCE

Do this on all DC's and then try demotion again

HTH

Paul McGuire
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top