Unable to delete the computer from AD Users and Computers console

  • Thread starter Thread starter Dominik Rachwal
  • Start date Start date
D

Dominik Rachwal

Its been few days now for me trying to restore my domain. I have cleaned
done a lot of clean up as suggested by many of you. Current situation is as
follows I still ahve the computer showing under the computers console and
when trying to delete it I get an error message "THE DSA OBJECT CANNOT BE
DELETED" This computer used to be the first DC in the domain. I have managed
to seize all of the roles. Well at least I though so, till i got a following
error when creating a new user in the domain: "
Windows cannot validate the uniqueness of this proposed user name with
global catalog server because:
The server is not opertational.
Windows will create this user account, but the user can only log on after
the user name is verified to be unique. For further assistance, contact your
system administrator."

I feel I can see the light at the end of the tunnel, but I'm not quite there
yet. Hopefully some one shed some light :) on this for me. It was very
interesting for me so far as learing the in and outs (basic) of AD.

Regards,
Dom
 
Dominik

If you have the 2000 support tools installed you can run the following at a
command prompt and determine who owns all 5 of the FSMO roles:

netdom query fsmo

If any of the roles show the old sever as the owner, use ntdsutil to seize
the roles if the old server is not online and will not be coming back
online. See 255504 Using Ntdsutil.exe to Seize or Transfer FSMO Roles to a
Domain Controller
http://support.microsoft.com/?id=255504

If the computer object is giving you the error that you can not delete it,
run ntdsutil to make sure it is not listed in Active Directory, see 216498
HOW TO: Remove Data in Active Directory After an Unsuccessful Domain
http://support.microsoft.com/?id=216498

If the old server is not listed in AD, use ADSI Edit (part of the support
tools) to find the computer account, go to the computer account properties
and set the userAccountControl to 4096. Then you should be able to delete
all references to the old server in AD Sites and Services as well as in AD
Users and Computers.
 
Back
Top