Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problems joining a domain with dcpromo

Status
Not open for further replies.

WilliamUT

IS-IT--Management
Oct 8, 2002
182
0
0
US
Hi last night i was having problems demoting a server and now im having problems promoting that server back onto the dc. I got suspicious wondering if it was just that one server that was having problems so i loaded a test server and tried promoting it and i get the same problem. The error i get is :

The operation failed because: Failed to modify the necessary properties for the machine account IS-5-155$
"Access is denied. "

it then prompts me for a password asking for a user account that have sufficient rights to perform the action. I am using the domain administrative account and have tried 3 other administrator account and it still gives me the access denied error. I jumped on the dc console and went into my computer accounts ou and tried to trust my pc for delegation and it said i dont have suffiecient rights as administrator to perform this action...

something on my dc security is really messed up im thinking has anybody else had this problem or know of a way to resolve it? Thanks

Bill
 
WilliamUT

Check for a hijacker I had the same problem and checked for hijackers and found the firedaemon running in my services.

Go to there is a windows 2000 security alert bulliten that can assist










bob

"ZOINKS !!!!!"

Shaggy
 
that link is broken do you have a different or correct one?
thanks for the help
 
doesnt look like i have a hijacker on my server any other suggestions?
 
Make sure you have Enterprise administrator rights in the domain .........
 
all 3 administrator accounts have enterprise admin rights that was the first thing I checked.
 
I guess the next ting I would check for is to make sure that all the fsmo roles are still there on the remaining dc or dcs.... There should be 5, plus 1 global catalog server.
 
I agree with vbrocks, looks like one of the fsmo roles is not available.
 
All my FSMO Roles are accurate and am having the same problem. Did you figure out how to resolve this issue?

Any help would be appreciated.

Thanks,
J.Rose
 
I have the same Problem guys!and I almost try everything Even this two KBIDs frm Microsoft and

Any other idea.. Running out of idea.

In my configuration I have a child domain structure.

Do I need an enterprise admins rights to add DC in my Child domains? I dont thinks so this is the only thing I never tried yet!

Please advise for some ideas
 
The next thing I would check are the Group policies and security policies of the domain......
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top