Demote AD

  • Thread starter Thread starter tfrancis
  • Start date Start date
T

tfrancis

Hi all
I'm having some problems demoting a couple of servers from being AD domain
controllers to just being member servers.
both are Win2K sp4.

the situation is :
We have a domain with several child domains, each of the servers in question
is a domain controller (not PDC) in it's respective child domain, when
demoting we get an error that we nned an account with administrative
privledges in the forest no matter what the user name is we always get the
same error (local domain admin, domain / enterprise admin for parent domain)

in the dcpromo log file the error is
"[Info] Error - The attempt to configure the machine account {servername}$
on server "
"[Info] {PDCservername.domain.com}failed. (5) "
"[Info] NtdsDemote returned 5"
"[Info] DsRolepDemoteDs returned 5"
"[Error] Failed to demote the Directory Service (5)"

Thanx

Todd Francis
(e-mail address removed)
 
you need to make sure that user is trusted for delegation in the domain
security policy and the domain controller security policy. Take a look at
these policies and there will be a tab the says Enable users/computers to be
trusted for delehation. Add the users/group and then force policy to apply
to each DC. you do that by going to run and typing

SECEDIT /REFRESHPOLICY MACHINE_POLICY /ENFORCE

Do this on all DC's and then try demotion again

HTH

Paul McGuire
 
Back
Top