Can not devote Server 2008 R2

Hi,

the question is asked for some times, but I dont find a 100% answer.

I have two 2008 R2 DCs (DC03 and DC04) and added two 2012 R2 DCs (DC05 and DC06).

The 5 master roles are transfered via ntdsutil to the DC05.

Under "CN=Infrastructure" - "fSMORoleOwner" on all servers in DomainDNSZones and DomainDNSZones is the following entry:

CN=NTDS Settings\0ADEL:57265bad-6bbc-49a1-b5e3-4e020869e718,CN=DC04\0ADEL:8e360e4a-b7c1-4618-9e3d-534056811d6a,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=%domain%,DC=local

I can not rename it.

errorcode: 0x20ae

What can I do?

I have tried to run the Fix-InvalidFsmo.ps1 script, he asks me after a DN.

What do I have to type here?

What can I do further?

Or must I force the DCs to remove?

Please help me

Thanks in advance

May 19th, 2015 2:09pm

Hi,

Have you try Transferring the role to new DC. Also if old DC is not removed can you remove forcefully and then do metadata clean-up followed by manual deletion of records from DNS.

Also can you share the link which you referring for PowerShell script and output of the script.

Free Windows Admin Tool Kit Click here and download it now
May 19th, 2015 3:08pm

Hello,

"\0ADEL" relates to an object in AD which is removed not correct from the AD database.

Before doing anything else check with the support tools for errors and solve them one by one including to remove not longer existings DCs with metadata cleanup.

http://blogs.msmvps.com/mweber/2010/05/16/active-directory-metadata-cleanup/

If you think we should check the output files please UPLOAD them:

ipconfig /all >c:\ipconfig.log [all DCs]
dcdiag /v /c /d /e /s:dcname >c:\dcdiag.log
repadmin /showrepl dc* /verbose /all /intersite >c:\repl.log  ["dc* is a place holder for the starting name of the DCs if they all begin the same (if more then one DC exists)]
dnslint /ad /s "DCipaddress" (http://support.microsoft.com/kb/321045)
ADREPLSTATUS: http://www.microsoft.com/en-us/download/details.aspx?id=30005 can also be exported to file.

As the output will become large,DON'T post them into the thread, please use Windows OneDrive(with open access!) https://onedrive.live.com and add the link from it here. Also the /e in dcdiag scans the complete forest, so better run it on COB.

May 20th, 2015 6:06am

See the last comment here: http://blogs.technet.com/b/the_9z_by_chris_davis/archive/2011/12/20/forestdnszones-or-domaindnszones-fsmo-says-the-role-owner-attribute-could-not-be-read.aspx

It describes the same issue.

Free Windows Admin Tool Kit Click here and download it now
May 20th, 2015 6:23am

Please find the blow.. The extract from what Mr.X told.

cscript fixfsmo.vbs dc=forestdnszones,dc=mydomain,dc=org
then for domain zone:
cscript fixfsmo.vbs dc=domaindnszones,dc=mydomain,dc=org

May 20th, 2015 9:38am

Hello,

Any updates on above?

Free Windows Admin Tool Kit Click here and download it now
May 21st, 2015 2:04am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics