Windows Server 2008 Thread, Active Directory Wizard unable to set [computername]$ permissions in Technical; 2003SBS network.
I'm configuring a 2008Std server as a secondary DC, it's already running as a delegated DNS.
I've prep'd ...
-
11th November 2009, 10:34 PM #1 Active Directory Wizard unable to set [computername]$ permissions
2003SBS network.
I'm configuring a 2008Std server as a secondary DC, it's already running as a delegated DNS.
I've prep'd the AD on the SBS box with adprep /forestprep and everything completed OK there.
Then I ran the AD installation wizard on the 2008 box which started to run OK but then stopped and asked for credentials. It needs to access / modify / whatever, the <computername>$ account on the 2008 box. I'm using the network administrator account and I've amended the default domain policy on the 2003 box to trust the administrator account for delegation.
I've run gpupdate /force and I've logged off and back onto the 2008 box.
No joy at all. The wizard always stops at the same point with the error "Access Denied" to the <computername>$ account.
I'm stumped now, totally. What the hell else can I do to get around this?
-
-
12th November 2009, 09:03 AM #2 Oh dear.....
Looks like I'm on my own then 
Pete
-
-
12th November 2009, 09:13 AM #3 Network administrator account ? Is that the local admin account you created when you installed / setup the server - if not then try the servers local admin account maybe ? that or domain admin account ( which I am guessing the network administrator account is a part of )
Also am presuming that DNS is working 100% is forward and reverse lookup zones can resolve both ways ?
-
-
12th November 2009, 09:17 AM #4 If by SBS2003 you mean small business server i believe it is onky usable in a single DC enviroment - therfore it wont let you join the second DC - you would need to upgrade the first DC to be full server 2003 first.
Thanks
James
-
-
12th November 2009, 09:20 AM #5 
Originally Posted by
mac_shinobi
Network administrator account ? Is that the local admin account you created when you installed / setup the server - if not then try the servers local admin account maybe ? that or domain admin account ( which I am guessing the network administrator account is a part of )
Also am presuming that DNS is working 100% is forward and reverse lookup zones can resolve both ways ?
Tried the local account but it's insistent that it wants a domain account.
-
-
12th November 2009, 09:22 AM #6 Hi,
To confirm you can add a 2008 server as a dc to an existing 2003SBS domain. One of my customers runs with this setup.
Sorry Pete have not seen this error. Could try setting up another administrator user and try that. Is the SBS box fully service packed?
-
-
12th November 2009, 09:24 AM #7 
Originally Posted by
achedgy
Hi,
To confirm you can add a 2008 server as a dc to an existing 2003SBS domain. One of my customers runs with this setup.
Sorry Pete have not seen this error. Could try setting up another administrator user and try that. Is the SBS box fully service packed?
Tried setting up another account - failed in same way.
SBS box is right up to date, AD has been adprep'd, etc.
Pete
-
-
12th November 2009, 10:44 AM #8 Have now also added <computername>$ as a trusted account for delegation.
Also created a new Domain & Schema Admin account, trusted it for delegation and also added it to the local admins group on the 2008 box.
Still no luck.
It must be something deeper than a simple permissions error methinks.
Looking at the AD log on the 2008 box there are some warnings, which only crop up whilst I'm running dcpromo, something like "Internal Event, The Following Schema Class Has A Superclass That Is Not Valid" followed by some AD gobbledegook. These are warnings in the event log, not errors, do they matter?
Do I need to run adprep again? Or, God forbid, ADSIEdit?
Pete
-
-
12th November 2009, 11:07 AM #9 Is the account you ran adprep as a member of the scema admins group as you need to be for the schema upgrade to take place - make sure your admin account is a member of scema admins (its not by default) then on your sbs server run adprep (you have to run it on the server that holds the sceme FSMO role (if you only have one dc it must be that one)).
Then try dcpromo again.
Thanks
James
-
-
12th November 2009, 11:16 AM #10 
Originally Posted by
jamesreedersmith
Is the account you ran adprep as a member of the scema admins group as you need to be for the schema upgrade to take place - make sure your admin account is a member of scema admins (its not by default) then on your sbs server run adprep (you have to run it on the server that holds the sceme FSMO role (if you only have one dc it must be that one)).
Then try dcpromo again.
Thanks
James
Yep, ran adprep as Domain & Schema admin. Adprep ran and completed without errors.
Pete
-
-
12th November 2009, 02:37 PM #11 
Originally Posted by
jamesreedersmith
If by SBS2003 you mean small business server i believe it is onky usable in a single DC enviroment - therfore it wont let you join the second DC - you would need to upgrade the first DC to be full server 2003 first.
Thanks
James
Hi James
Sorry, I missed this post earlier.
No, that's not correct. You can only have one SBS box in a forest but you can have other DCs in the same forest so long as the SBS box has all the FSMO roles assigned to it.
Pete
-
SHARE:
Similar Threads
-
By SimpleSi in forum Windows
Replies: 4
Last Post: 1st February 2012, 12:42 PM
-
By steveo2000 in forum Mac
Replies: 0
Last Post: 6th April 2009, 11:26 PM
-
Replies: 7
Last Post: 31st January 2008, 01:17 PM
-
By marky2027 in forum Windows Vista
Replies: 16
Last Post: 13th November 2007, 09:57 AM
-
By meastaugh1 in forum Windows
Replies: 4
Last Post: 5th January 2007, 05:28 AM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules