P
Paul Clarke
I'm having problems seizing the domain naming master role.
I have two win2k domains in separate forests. The first
forest held the schema and the domain naming roles for
both forests. I have transferred all users, apps and
services to the new second domain running in native mode.
I had problems with the trust between the two domains and
could not transfer the roles so I tried seizing them. I
have managed to seize the schema role out of the old
forest into the new but when I try the domain name master
I get an "Insufficient access rights" message as shown
below.
fsmo maintenance: seize domain naming master
Attempting safe transfer of domain naming FSMO before
seizure.
ldap_modify_sW error 0x32(50 (Insufficient Rights).
Ldap extended error message is 00002098: SecErr: DSID-
031513C9, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
Win32 error returned is 0x2098(Insufficient access rights
to perform the operation.)
)
Depending on the error code this may indicate a connection,
ldap, or role transfer error.
Transfer of domain naming FSMO failed, proceeding with
seizure ...
ldap_modify of SD failed with 0x32(50 (Insufficient
Rights).
Ldap extended error message is 00002098: SecErr: DSID-
03151404, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
Win32 error returned is 0x2098(Insufficient access rights
to perform the operation.)
)
fsmo maintenance:
I am logged on as administrator and a member of the
Enterprise Admins group though this is only a global group
despite the fact that the new domain is in native mode.
Any ideas?
I have two win2k domains in separate forests. The first
forest held the schema and the domain naming roles for
both forests. I have transferred all users, apps and
services to the new second domain running in native mode.
I had problems with the trust between the two domains and
could not transfer the roles so I tried seizing them. I
have managed to seize the schema role out of the old
forest into the new but when I try the domain name master
I get an "Insufficient access rights" message as shown
below.
fsmo maintenance: seize domain naming master
Attempting safe transfer of domain naming FSMO before
seizure.
ldap_modify_sW error 0x32(50 (Insufficient Rights).
Ldap extended error message is 00002098: SecErr: DSID-
031513C9, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
Win32 error returned is 0x2098(Insufficient access rights
to perform the operation.)
)
Depending on the error code this may indicate a connection,
ldap, or role transfer error.
Transfer of domain naming FSMO failed, proceeding with
seizure ...
ldap_modify of SD failed with 0x32(50 (Insufficient
Rights).
Ldap extended error message is 00002098: SecErr: DSID-
03151404, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
Win32 error returned is 0x2098(Insufficient access rights
to perform the operation.)
)
fsmo maintenance:
I am logged on as administrator and a member of the
Enterprise Admins group though this is only a global group
despite the fact that the new domain is in native mode.
Any ideas?