Unable to seize FSMO Roles

R

Rashid

Hi,

I am encountering problems associated with seizing the
Domain Master and Schema Master Roles.

The background to thi sproblem is as follows.
I have created a test area consisting of a Domain with 2
Directory Controllers. I have simulated a situation where
by the Domain controller with the main operations roles
has crashed and is off line permanently, and leaving an
alternate Domain Controller to work on its own. In order
to seize roles I have done the following.

So far I have run the NTDSUTil metadata cleanup and
deleted all other instances of previous domain controllers
and attempted seizure of all roles.
I managed to take all roles exxcept for Domain naming and
schema master.
I have already enabled this one as the Global catalog,
removed previous FRS settiungs for any other domain
controllers using ADSI Edit.

I managed to take all roles except the Domain Naming
Master and Schema master roles

When I try to seize them using ntdsutil I get the
following:

fsmo maintenance: seize schema master
Attempting safe transfer of schema FSMO before seizure.
ldap_modify_sW error 0x32(50 (Insufficient Rights).
Ldap extended error message is 00002098: SecErr: DSID-
031513C9, problem 4003 (IN SUFF_ACCESS_RIGHTS), data 0
Win32 error returned is 0x2098(Insufficient access rights
to perform the operation.)


And

fsmo maintenance: seize domain naming master
Attempting safe transfer of domain naming FSMO before
seizure.
ldap_modify_sW error 0x35(53 (Unwilling To Perform).
Ldap extended error message is 0000214B: SvcErr: DSID-
03210792, problem 5003 (WILL_NOT_PERFORM), data 0

Win32 error returned is 0x214b(Only DSAs configured to be
Global Catalog servers should be allowed to hold the
Domain Naming Master FSMO role.)

Is there any other utilities I need to run or procedures
to follow to get round this problem of seizing roles?
 
N

Neil Ruston

1. You need to be a member of the schema admins group to
seize / transfer the schema masster role.

2. The domain naming role can only be moved to a GC.
Ensure the DC to which the role is being moved to is also
a GC.

HTH,
Neil
 
R

Rashid

Thanks very much for the pointers.

Regarding the 1. The account (administrator) is already
part of Schema Admins).

re:2, I have already selected Global Catolog in Active
directory Sites and Services.

As consequence under AD Domains and trusts, under Domain
Naming operations master thereis an error, indicating the
main master is offline.
Is there away of forcing it besides the Roles utility in
NTDSUTIL?
are there any other procedures I need to follow in this
case?

Appreciate your help.

Regards
 
L

Laura A. Robinson

circa Fri, 24 Oct 2003 07:52:01 -0700, in
microsoft.public.win2000.active_directory, Rashid
([email protected]) said,
Hi,

I am encountering problems associated with seizing the
Domain Master and Schema Master Roles.

Are you performing this task as an Enterprise Admin?

Laura
 
R

Rashid

Hi Laura,

Thanks for the response, the account is indeed part of
Enterprise Admins.

Regards
 
L

Laura A. Robinson

circa Mon, 27 Oct 2003 07:11:46 -0800, in
microsoft.public.win2000.active_directory, Rashid
([email protected]) said,
Hi Laura,

Thanks for the response, the account is indeed part of
Enterprise Admins.
Okay, next question- are you positive that DNS is clean?

Laura
 
R

Rashid

As its a test environment created from a live domain (now
separated from this environment), there had been a number
of stale records that i have now deleted.

Please note this isnt a live environment, I have merely
constructed it to simulate the complete loss of an Active
Direcory Controller possessing all roles being taken out.
 
L

Laura A. Robinson

circa Tue, 28 Oct 2003 02:22:50 -0800, in
microsoft.public.win2000.active_directory, Rashid
([email protected]) said,
As its a test environment created from a live domain (now
separated from this environment), there had been a number
of stale records that i have now deleted.

Please note this isnt a live environment, I have merely
constructed it to simulate the complete loss of an Active
Direcory Controller possessing all roles being taken out.
I think you need to get DNS back together again. It sounds like some
of those "stale" records were needed. :)

Laura
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top