Uber22 Posted October 30, 2019 Posted October 30, 2019 hey all I recently moved my domain controller to a new host ever since i moved it i cant seem to join any new pcs to the domain, i get the following error . The following error occurred attempting to join the domain "Domain Name " Cannnot complete this function I cant really see that moving it would cause any issues. I can ping the dc, i can ping the fqdn , i can ping the full dc fqdn. i can also connect to \\dc\sysvol with the login details. I have tested with other pcs and they have the same issue. Thanks
ITGURU Posted October 30, 2019 Posted October 30, 2019 What steps did you carry out to 'move the domain controller to a new host' Is this a VM you have just moved via live migration?
Uber22 Posted October 30, 2019 Author Posted October 30, 2019 Hi, I used veeam first i replicated the machine across then done a fail over then a permanent fail over. once it had failed over i had to add the network card in as for some reason it didnt have it. Thanks
ITGURU Posted October 30, 2019 Posted October 30, 2019 Hi, I used veeam first i replicated the machine across then done a fail over then a permanent fail over. once it had failed over i had to add the network card in as for some reason it didnt have it. Thanks I'm assuming you have more than 1 DC? If you've had to re-add the network adapter due to differences in Host setups - then you'll need to check all services are using that Network connection, DNS in particular. Have all IP settings been reconfigured correctly and then reboot the DC again so everything initialises on the new network interfaces
Uber22 Posted October 30, 2019 Author Posted October 30, 2019 yes there an issue there, 6 months ago i lost the secondary dc due to hardware failure and no back, i will go over all the setting, i will be building a secondary dc in the next few weeks.
ITGURU Posted October 30, 2019 Posted October 30, 2019 yes there an issue there, 6 months ago i lost the secondary dc due to hardware failure and no back, i will go over all the setting, i will be building a secondary dc in the next few weeks. If the failed DC was going to be offline forever did you run the metadata cleanup in ntdsutil? Does your remaining DC hold all the FSMO roles?
kmount Posted October 30, 2019 Posted October 30, 2019 Hello, Being a single domain controller I think it's now caught in a vicious loop between DNS and AD not coming up. Please check in event viewer to see if you can see an ID "4013 - The DNS server was unable to load AD integrated DNS zones" https://support.microsoft.com/en-gb/help/2001093/troubleshoot-dns-event-id-4013-the-dns-server-was-unable-to-load-ad-in
Uber22 Posted October 30, 2019 Author Posted October 30, 2019 I have this as a warning, in the dns event viewer "The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical DNS data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the Internet Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed."
kmount Posted October 30, 2019 Posted October 30, 2019 Yep, look at the KB above (short version - add that registry entry and reboot) (usual caveat, take a backup first)
Uber22 Posted October 30, 2019 Author Posted October 30, 2019 think first job maybe to do clean up the old dc, then as you say follow the guide.
Uber22 Posted October 30, 2019 Author Posted October 30, 2019 stupid question but doesn't a domain controllers dns ip address ment to be set to loop back 127.0.0.1 and not its own ip ? Thanks
Guest Guest Posted October 30, 2019 Posted October 30, 2019 No, I queried that with Microsoft as the BPA says it should. It should point to its address eg 10.x.x.x the BPA words it badly
Uber22 Posted October 30, 2019 Author Posted October 30, 2019 I think my current dc does but no according to the event log with lots of errors in there. I did a qurrie and it says the FSMO roles are on the current dc Schema master MYDC.DOMAIN Domain naming master MYDC.DOMAIN PDC MYDC.DOMAIN RID pool manager MYDC.DOMAIN Infrastructure master MYDC.DOMAIN
HPlum78 Posted October 30, 2019 Posted October 30, 2019 Yep you have a number of issues here and as @Uber22 the first thing to get sorted is the DC that is missing, 2016 server running AD should clean up ok without the need to do the metadata clean up. If you are not able to add workstations to your Domain why do you think that adding a DC is going to be any different? Also knowing that you have replication/ AD issues trying to do operations against your AD infrastructure is interesting. Are you sure that this is only affecting joining workstations to the domain? Are you still able to create new accounts? Update password and the likes? I ask this as it seems like a RID Pool issue due to the FSMO problems you have posted above.
Uber22 Posted October 31, 2019 Author Posted October 31, 2019 You are correct I can't do any of that ekkk. So I think the plan is to decommission that old DC out of the picture, then transfer the fsmo roles , but when I run the command to check were the roles are it's says there on the current server. I have just had email saying couple of users that are in saying the workstation have lost trust relationship as well.
HPlum78 Posted October 31, 2019 Posted October 31, 2019 Thing is the current server knows of the missing DC and DC's insist on checking with their known partners who each other thinks is the FSMO role holder. You may well find that clearing up the missing DC resolves the knows of FSMO role holders issues you are seeing at the min. This depends on the state of the FSMO roles at the point the other DC went down mind.
HPlum78 Posted October 31, 2019 Posted October 31, 2019 Don't just go forceably grabbing FSMO roles until you get the missing DC out of the picture, get that cleaned up and boot the existing DC and see what state it comes back in. Also if you are using AAD connect or whatever we are calling it today you should probably stop the sync cycles....
HPlum78 Posted November 1, 2019 Posted November 1, 2019 (edited) @Uber22 how you getting on with resurrecting your AD services? Edited November 1, 2019 by HPlum78
Uber22 Posted November 4, 2019 Author Posted November 4, 2019 Hey Guys Well I braved it after some more research, So I ran some command to see what dc had the FSMO roles and it was my main dc witch was fully working, So I deleted the other dc from Ad then deleted it from sites and services. After a reboot I tested the domain joins and its back working, I can create user and change passwords. DNS errors are clear, directory services are all good as well. Thanks for the advice, last thing or maybe I will start a new discussion but should I have a second dc or AD, DNS, DHCP. Thanks
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now