Error during DC Promo


hi,

i receiving error when trying promote windows 2008 r2 or windows 2012 r2 server domain controller in existing windows 2003 (sp2) domain. have tried both 2008 r2 , 2012 r2 , receiving same error.

existing environment:

2 x windows 2003 sp2 domain controllers
several "external" trusts
windows server 2003 functional level
new windows 2008 r2 , windows server 2012 r2 servers (with dns pointing existing 2003 dc's dns servers)

the error:

the promotion errors following in adprep.log file.

adprep unable complete because call function failed.
[status/consequence]
error message: unable access computer "domaincontrollername.domain.com.au". access denied.
  (0x80070005).
[user action]
check log file adprep.log, in c:\windows\debug\adprep\logs\20140207153306 directory more information.

dsid info:
dsid: 0x1811132a
winerror = 0x1f
nt build: 9600
nt build: 16384

[2014/02/07:15:33:06.648]
adprep unable update forest information.

what have tried far?:

  • ensured account being used part of enterprise admins group, domain admins group , schema admins group. created new ad account belonged 3 groups.
  • disabled antivirus on source domain controller (the 1 referenced in error)
  • ensured windows firewall turned off on source , target dc's
  • ensured ad account being used part of administrators group in domain
  • ensured administrators had trusted delegation rights in domain controller policy
  • ran adprep /forestprep , /domainprep /gpprep using windows 2008 r2 media on existing 2003 dc (successful)
  • tried doing dcpromo (using server manager) on both windows 2008 r2 , windows 2012 r2 server. same error on both servers.
  • checked event logs obvious, nothing see.
  • searched net high , low go on can't find anything!!

hope can here! luckily cloned these servers , doing in test environment. (both 2003 dc's dns servers, 2008 r2 target dc, 2012 r2 target dc, exchange 2003 server , target exchange 2010 server happen after dcpromo).

i suggest download trial version of server 2008 or 2012 , extend schema that.  extension newer version won't hurt , out of issue in.  45 sounds updated schema somehow (a beta product?) , out of sync somehow.  not sure if resolve issue @ least schema version supported, if have call product support.

paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security, bs csci
2012, 2008, vista, 2003, 2000 (early achiever), nt4
twitter @pbbergs http://blogs.dirteam.com/blogs/paulbergson
please no e-mails, questions should posted in newsgroup.
posting provided no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...