cannot remove pc from domain... Major issues

  • Thread starter Thread starter Obviously Hosed...
  • Start date Start date
O

Obviously Hosed...

I just rebuild my Exchange server. First I built a
temporary server, installed exchange and all patches. I
then transferred the roles to the temporary server and
made it a global catalog. Once this was completed, I was
going to remove the AD from the original and then remove
it from the Domain. AD failed to remove, so I went to
Microsoft's website and found an article on how to
forcably remove the server (by the way... I don't
recommend you doing this if you have a similar
situation). Basically, the forced removal worked;
however when I went to put the newly build server back on
teh domain there were problems and I had to call Microsoft
and spend the cash to get it fixed. Anyway, now I have
the new server up and running but I cannot remove the temp
server from the domain (similar to the initial problem)
In addition, the new server fails to start Exchange or my
backup software unless I manually do it even though they
are automatic services. I figured it was all DNS but
everything has been checked, rechecked and then checked
again by someone else. The error that i get from the old
server while trying to remove it is: "The operation
failed because: The attempt to configure the machine
account MACHINENAME$ on server example.netlan.sam.fred.com
failed. "Access is denied. "" then it prompts me for an
enterprise account, password, and domain, which I give and
then it appears as though it is going to remove, but then
the process repeats and I am unable to remove the PC from
the domain. I think that something is not getting
replicated to the new server? But I have no idea what it
could be as the new server works fine as long as I start
the services manually. Any assistance in this matter
will be greatly appreciated.
 
You should check with the Exchange community for information concerning the
Exchange services not starting.

Regarding the AD information, I've successfully used Dcpromo /Forceremoval
(kb 332199) numerous times. The process removes AD from the local domain
controller but does not remove information about the forcefully demoted
machine from the existing domain. On a remaining DC in the domain , you
need to follow the steps in kb 216498 to remove any information about the
forcefully demoted DC from the domain and ensure it replicates successfully
to other DCs in the domain before rejoining a new machine with the same
name.

As long as the machine can find a dns server that is authoritative for the
domain it should successfully demote from the domain. If you're
encountering problems joining/unjoining from the domain then DNS needs to
be checked.

291382 Frequently Asked Questions About Windows 2000 DNS and Windows Server
http://support.microsoft.com/?id=291382

260371 Troubleshooting Common Active Directory Setup Issues in Windows 2000
http://support.microsoft.com/?id=260371

The error you encountered is listed in the following kb article:
232070 "Access Denied" During Domain Controller Promotion
http://support.microsoft.com/?id=232070

Also, when you promote a DC ensure that it is healthy by checking the steps
outlined below:
298143 How to Verify an Active Directory Installation
http://support.microsoft.com/?id=298143

David Pharr, (e-mail address removed)

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Back
Top