Restore Active Driectory

J

JM

Need guidance.
We have a small Active Directory domain that currently
has 2 PDC replicating with one another.
PDC 2 has 3 roles while PDC 1 has schema and Domain Naming

I am trying to restore 1 of the PDC from tape to a test
LAB.
Restore went flawless in Directory services mode.
Seized all 5 Roles
SysVol did not share did Q316790 Fix registry edit
brought SysVol online
Then followed Q216498 and Deleted Sever PDC 2 with
NTDSUTIL. Deleted all referenec to PDC 2 in DNS as well.

2 issues remain. When run DCDIAG I get 2 errors one
related to RID Manager saying
Account-Identifier allocator failed to initialize properly
and
The Netlogon service could not create server share
c:\winnt\sysvol\sysvol\domainname\scripts.

Net share say sysvol is running. There is no Folder
Scripts.

Can you please post instruction on converting to a single
PDC environment for testing purposes.
Thank You
JM
 
M

Matjaz Ladava [MVP]

You must do a metadata cleanup on your restored DC in a lab, as it is
referencing another nonexistent DC
http://support.microsoft.com/default.aspx?scid=kb;en-us;216498
RID master won't come online if there are nonexistent DC's around. Next you
will have to seize other FSMO roles on the test server
http://support.microsoft.com/default.aspx?scid=kb;en-us;255504 . Use netdom
query fsmo to find out which server has FSMO roles.

--
Regards

Matjaz Ladava, MCSE, MCSA, MVP
Microsoft MVP - Active Directory
(e-mail address removed), (e-mail address removed)
http://ladava.com
 
E

Eric Fleischman [MSFT]

Matjaz is pretty much right on with this one.
To expand a bit.....
In W2K SP3 and W2K03 we added a safeguard refered to as the init sync
requirement. The idea here is that when you restore a dc with a critical
role (handing out rid's, schema mod's, etc) we don't let it do a fsmo-type
activity until after it has replicated with a partner. The idea here is that
while we were offline maybe the rid master role was seized, other schema
mod's were made, etc. and therefore we could be "out of date"

A metadata cleanup will do it, and believe it or not often times just
deleting the inbound connection objects that the dc you restored has will
make it happy as well.

~Eric


--
Eric Fleischman [MSFT]
Directory Services
This posting is provided "AS IS" with no warranties, and confers no rights.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top