Jump to content

Recommended Posts

Posted

We have just ghosted our Windows Server 2003 DC onto bigger hard drives. All work fine, RAID ok, etc...

... until I go to add our new Year 7 users.

 

Active Directory just will not let me add a single user.

It comes up with the message "Windows cannot create the object because the Directory Service was unable to allocate a relative identifier"

 

I have been here: http://www.netpro.com/forum/messageview.cfm?catid=7&threadid=201

 

...and here: http://support.microsoft.com/kb/839879/en-us

 

and tried the suggestions but I STILL can't add any users.

 

Any suggestions? :?

Posted
Is it the only DC? Are there any errors in the logs from NTDS? Ghosting and moving VM DCs is not supported and I have had one become out of sync with the other DC.
  • 1 year later...
Posted

Ihave a little problem similar to above.

 

One of our domain controllers wouldnt boot in to windows after christmas so i quickly reinstalled it and recreated all the shares.

 

I gave the server the same name as it was before and executed dcpromo.

thios all seemed to work fine until now.

 

I cant seem to create any users in active directory on that server anymore

 

I am also having problems replication problems on that server now

 

Has anyone had any similar problems like this and know any work arounds.

 

Any help will be appreciated.

 

Thanks

Posted

MM, when you rebuilt it did you first remove all mentions of that DC from Active Directory? If not I suspect you're going to be hitting a lot of problems.

 

It'd also be worth checking where your AD believes the FSMO roles to be held at the moment.

Posted

i removed the server 3 in active directory just by right clicking the server and pressing delete. i thought that this should be sufficient.

 

whats the best way on checking where the Fsmo role are?

Posted

Check in Active Directory Sites and Services I believe.

 

I suspect you'll end up needing to remove the DC fully, then rebuild it as a brand new DC with a different name. You can get away with reintroducing it as the same one when you're restoring from a backup, not so much with a reinstall.

  • Thanks 1
Posted

Based on what you've posted, it seems you've lost at the very least your RID Master FSMO role, which means you're in for a jolly old time! To put it into perspective, and without trying to frighten you, you will need to make repairs to the heart of AD now. As ever with major AD changes, do ensure you use NTBackup to make system state backups of all your DC's before attempting this. That way you have an escape route in place!

 

It IS possible to recover FSMO roles, but to do so you need to ensure there isn't a server on the network now with the same name as any DC that held any of the lost FSMO roles.

 

Also remember: NEVER seize FSMO roles unless you truly have no other choice. It is always a last-option scenario.

 

Having said that, you can find some decent information on FSMO roles and how to deal with them here: Determining FSMO Role Holders

 

At the end of the very detailed article there are more links to articles that teach you about seizing FSMO roles.

 

Good luck!

  • Thanks 1
Posted
what if i demote the server and rename it to something else then promote it again, do think that could cure this? i might give that a go first if that fails then it will have to be a fresh install.
Posted

I'm a little baffled - if you performed a disk image, it should of created an exact copy of your original drive.

 

Realistically there are two solutions to your problem. Firstly check the FSMO roles. Either put your original drive back in and transfer server roles to another DC on your network, in addition to the Global Catalog. More than likely DNS is AD integrated (hopefully), so you just have DHCP to transfer too.

 

Alternatively, perform a System State restore on your new drive from either a file or backup tape. This should (in theory) work.

Posted
I'm a little baffled - if you performed a disk image, it should of created an exact copy of your original drive.

 

If you look at MManjra's post rather than the OP's then you'll see that he performed a reinstall rather than an image. The thread's gone a little adrift from the original topic. :)

Posted
Ahh thanks Jamesb, makes more sense now. If MManjra's re-installed Server 2003 from new, you just need to give it the same computer name and IP address, then perform a System Restore along with the System State (very important), reboot and the server should be back online.
Posted
Ahh thanks Jamesb, makes more sense now. If MManjra's re-installed Server 2003 from new, you just need to give it the same computer name and IP address, then perform a System Restore along with the System State (very important), reboot and the server should be back online.

 

I have the feeling that there's no system state backup, or other backup, otherwise I doubt a reinstall would be used.

 

Thing is that even if there is a backup it could well be corrupted, looking at the original error.

 

But yep, in any other case yours is by far and away the easiest fix. :)

Posted
Realistically then I see no other way but to re-create the domain from scratch which is a massive job!

 

Since they've got multiple domain controllers it should be possible to clear down all traces of the failed one, and after a full reinstall of Windows and new name promote it as a new one (this is not Microsoft best practice by the way, I believe they recommend that once a domain controller has been forcibly removed it will be useful only as a paperweight).

Posted
Realistically then I see no other way but to re-create the domain from scratch which is a massive job!

 

Provided there is a valid backup of AD somewhere, or at least one other DC there is no need whatsoever to rebuild the domain from scratch.

 

Even if there is no other DC and the backup is older than the tombstone date for AD it remains possible to recover AD from such a backup.

  • 6 years later...
Posted

I would never ever clone a DC. You should really have at least 2 domain controllers. This would mean you could have transferred the FSMO roles over, demoted the old DC, then upgraded drives as needed then reinstall Windows and promote as DC.

 

If a DC ever crashed, I would never restore from an image, I would cleanly remove it from the system then re-promote after reinstall.

Got 3 DC's in total so shouldn't be any risk from needing to restore from backup

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...