Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Promote Additional Domain controller to Primary Domain Controller

814 views
Skip to first unread message

Noel Pereira

unread,
Feb 2, 2008, 7:04:00 AM2/2/08
to
Dear Sir,
Our Domain "SevenSeasgroup.co.ae" had two domain controller .one
is Primary domain controller and other one is additional domain controller. A
week before primary domain controller was down(Operating System corrupted)
and it is inactive.Now we are managing all the users and computers with
additional domain controller and facing lot of problems without primary
domain controller. Please tell me the procedures to promote this additional
domain controller to Primary Domain controller.

Regards

Abdul Rahuman.M

Meinolf Weber

unread,
Feb 2, 2008, 7:28:05 AM2/2/08
to
Hello Noel,

If it NEVER comes back, you have to seize the FSMO roles:
http://support.microsoft.com/kb/255504/en-us

Also make it a Global catalog server and DNS server, if not already done
before.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

Marcin

unread,
Feb 2, 2008, 7:40:36 AM2/2/08
to
Start by seizing the FSMO roles that were assigned to the failed DC
(http://support.microsoft.com/kb/255504), configuring the remaining DC as
Global Catalog and DNS server (this will likely require repointing your
clients to it as their primary), and cleaning up any invalid metadata
(http://support.microsoft.com/kb/216498)...

hth
Marcin

Noel Pereira

unread,
Feb 2, 2008, 8:26:01 AM2/2/08
to
Dear Meinolf,

Following error is appearing while seizing the roles.
"
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8

Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.) "

Please note that Primary Domain controller is no more Available and all the
systems are managing by Additional Domain Controller only. Please advise .


Regards

Abdul Rahuman.M

Noel Pereira

unread,
Feb 2, 2008, 8:28:00 AM2/2/08
to
Dear Marcin,

Following are the error when attempting to seize the roles.


Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8

Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.)

Please advice.

Regards

Abdul Rahuman.M

Meinolf Weber

unread,
Feb 2, 2008, 8:36:58 AM2/2/08
to
Hello Noel,

Srcoll down in the document to the part SEIZE the FSMO roles.

Meinolf Weber

unread,
Feb 2, 2008, 9:01:21 AM2/2/08
to
Hello Noel,

Here is an article about it with more details what is shown during the seizing:
http://www.petri.co.il/seizing_fsmo_roles.htm

s

unread,
Feb 2, 2008, 12:15:00 PM2/2/08
to
How are you trying to move the FSMO roles ?

Noel Pereira

unread,
Feb 5, 2008, 5:17:00 AM2/5/08
to
Dear Marcin,

According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO roles to
the BackupDomain Controller. Please tell me , how can i check the roles are
assigned to the Backup controller. And also please advice me , how to make
backup domain controller as global catalog server.


Regards

Abdul Rahuman.M

Meinolf Weber

unread,
Feb 5, 2008, 5:46:42 AM2/5/08
to
Hello Noel,

The document also contains the Global catalog part.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> Dear Marcin,

Noel Pereira

unread,
Feb 5, 2008, 6:44:02 AM2/5/08
to
Ok. I have assigned FSMO roles to Backup Domain Controller. Please tell me ,
where can i go and check these roles were assigned properly.

Noel Pereira

unread,
Feb 6, 2008, 7:08:01 AM2/6/08
to
Hello Meinolf,

Thanks for your king Cooperation. I have promoted Backup Domain
controller to PDC by seizing all five roles. Now while working on users and
computers ,When i attmept to display members of any security group , i got
the following error.

" A global catalog cannot be located to retrieve the icons
for the member list"

Then i configure this new PDC as global catalog server.After
that i am not getting any error when working on the "Active Directory users
and computers" Kindly advice me, is there any problem configuring 'global
catalog server' and 'infrastructure master' on the same Domain Controller ?.
what are the impacts will happen ? and please advice me how to solve this
issue ?


Regards

Abdul Rahuman

Meinolf Weber

unread,
Feb 6, 2008, 7:27:56 AM2/6/08
to
Hello Noel,

No impact, if you have a single forest, single domain environment like you
have.

Noel Pereira

unread,
Feb 6, 2008, 7:59:02 AM2/6/08
to
Hello Meinolf,

Thanks for your advice. Now i have promoted a Backup
Domain Controller for this new PDC . After this operation, i cant able to
open anything in Active Directory on BDC.I am getting the following error
when i open "Active Directory Users and Computers" in BDC.

" Naming Information cannot be located because: The
Specified domain either does not exist or could not be contacted. ".

Please help me to make new Backup domain Controller in operational.


Regards

Abdul Rahuman.M
Tel:8033-306

Meinolf Weber

unread,
Feb 6, 2008, 8:06:31 AM2/6/08
to
Hello Noel,

Just one note before. Since windows 2000 there are no longer the terms PDC/BDC,
all Dc's are the same, the differences are in the FSMO roles.

Did you run dcdiag and netdiag before starting with the new server on the
old machine to see that everything is ok and without errors?

Please describe the steps you have taken to promote the new machine. Also
post an ipconfig /all from both machines.

Noel Pereira

unread,
Feb 13, 2008, 7:26:04 AM2/13/08
to
Hello Meinolf,

Backup Domain Controller is done and i can open the
Active Directory. The Problem now is , What ever the modification i m doing
in the Primary Domain controller is not replicating in Backup Domain
Controller. So i planned to demote the BDC and Promote Again. When i start
Demoting , i could see a error message
" A Domain Controller could not be contacted for the domain
SevenSeasgroup.co.ae that contained an account for this Computer".

Please let me know what is this error ? Why the modification is not
replicating?

Regards

Abdul rahuman.M

Meinolf Weber

unread,
Feb 13, 2008, 7:54:58 AM2/13/08
to
Hello Noel,

Do not demote in the moment. let's try to find your problem. As ia sked BEFORE:

0 new messages