Problem in Adding a DC access denied

  • Thread starter Thread starter Nwtest
  • Start date Start date
N

Nwtest

I'm running out of idea on this issue can somebody assist.

I'm trying to add a DC in my AD child domain setup. I have
already 3 DCs and all working fine. When I promote and run
DCpromo in a member server I got this error
"The Operation Failed: Failed to modify the necessary
properties for the machine account my.computer$
Access Denied."

I tried all work arounds like:
- rename server put it in Workgroup run DCpromo again same!
- Ensure that my DNS and Zone copy is installed in the
server to be promoted
- Check all TCP/IP settings connectivity, comunications
channel etc no luck!
-Verify Default Domain controllers Policy and ensure
Administrators are in access to this computer; Esnure
Admins are member of Enable trusted this computer for
delegation(according to Microsoft) NO LUCK Still.

Can somebody provide an Idea to fix this problem.
thanks
 
After you make the change to the default domain policy you will have to
force a sync of the policy to the domain controllers or reboot there
servers. Type this at the command line: secedit /refreshpolicy
machine_policy
do this on all DC's and try promtion again.

HTH

Paul McGuire
 
Back
Top