Got a problem that's driving me bonkers. Got a file server that's sitting on a different subnet that my main DC and firewall. I'd like to turn this file server into a DC to help with login traffic. However, when I run DCPROMO I'm running into a problem. I get all the way through, to the point to where it's configuring the AD, forces a time sync with the DC, but then when it attempts to configure the server account, I get a box saying the following:
The operation failed because: Failed to modify the necessary properties for the machine account MT2$
"Access is denied. "
It then asks me to type in an account with sufficient privledges to create another DC in my domain. I've used every password I know -- my own (which has administrator privledges for the domain), the domain administrator password, even the forest administrator password -- and none of them work. I've looked all over AD Users and Computers, group policy objects, etc., and I can't even find anything that would restrict the ability to create additional DCs in a domain.
Anyone got any ideas??? Me: We need a better backup system.
My boss's boss: Backup? We don't need no stinkin' backup!
The operation failed because: Failed to modify the necessary properties for the machine account MT2$
"Access is denied. "
It then asks me to type in an account with sufficient privledges to create another DC in my domain. I've used every password I know -- my own (which has administrator privledges for the domain), the domain administrator password, even the forest administrator password -- and none of them work. I've looked all over AD Users and Computers, group policy objects, etc., and I can't even find anything that would restrict the ability to create additional DCs in a domain.
Anyone got any ideas??? Me: We need a better backup system.
My boss's boss: Backup? We don't need no stinkin' backup!