Exchange server-Removing a Domain Controller from the forest

Hi Guys,
I need some help on removing a faulty domain controller from the AD forest. Here is the scenario:
1. The FSMO roles have been seized to a new domain controller already.
2. The old one is non-functional and is down for ever.
I know the steps would be doing a meta-data cleanup And then remove some of the DNS entries related to the old server. But the real issue is:
> I have Exchange 2013 running in one of the machines configured in the Forest, which was migrated from the old Domain controller. I then set Exchange listening to the new domain controller.
So, my doubt is, if I delete the old domain controller and do a metadata cleanup, would it have any effect on the exchange server? The Exchange machine acts as an additional domain controller as well. Its a production environment and any
change that affects Exchange would cause a big loss. Looking forward for your valuable suggestions..
Regards,
Nash

Hi Ed,
I don't have issues with the AD on the Exchange server. Eventhough it is configured as an AD, Exchange is pointed to the main working domain controller, which is a different machine. I just want to remove the traces of an old domain controller from which
I transferred the FSMO roles to the new domain controller. The old  domain controller is completely down and hence I can't do a conventional 'dcpromo' on it. So just planning to do a 'metadata clean up' for removing the non-working DC from the forest. 
So, In essence, I just want to know that, if I do a metadata cleanup, would it affect the Exchange server in any way?
Regards,
Nash

Similar Messages

  • Exchange Server 2013 and Domain Controller

    Hello,
    I am planning to install domain controller and exchange server 2013 in same server hardware. Is that not recommended? If not, why is it no recommended?
    Thank you in advance,

    thanks for such a quick response.
    Just a small question about the link that you put. Does member server mean other server other than domain controller?
    Regards,
    Yes, Also the server on which you are installing Exchange should have exchange installed.
    Cheers,
    Gulab Prasad
    Technology Consultant
    Blog:
    http://www.exchangeranger.com    Twitter:
      LinkedIn:
       Check out CodeTwo’s tools for Exchange admins
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • What note when remove an Domain controller from Existing Domain!!!

    Dear everybody,
    My company has 3 Domain controllers at the moment.
    all of them have some functions: DHCP, DNS.
    Now, we have plan to remove an DC/
    So, What note we need to pay attention when remove one of them?
    Thanks for your help!!!

    1. Migrate DHCP first. Using below command
    netsh dhcp server export C:\dhcp.txt all       -old Server
    netsh dhcp server import C:\dhcp.txt all       -New Server.
    2. Enable DNS debug log & see which client still pointing the old DC.
    http://technet.microsoft.com/en-us/library/cc759581%28v=ws.10%29.aspx
    3. Change the DHCP Scope accordingly.
    HTH
    Biswajit
    Regards,
    Biswajit
    MCTS, MCP 2003,MCSA 2003, MCSA:M 2003, CCNA, Enterprise Admin, ITIL F 2011
    Blog:
      Script Gallary:
    LinkedIn:
    Note: Disclaimer: This posting is provided & with no warranties or guarantees and confers no rights..

  • Remove a domain controller when dcpromo bombs

    i'm trying to demote one server in a two server setup
    i start dcpromo , it gets part way through and then bombs with an "Access is denied" error
    which is b~@:!hit. Ive tied this 2 or 3 times with known good passwords(see dcpromoui.log below)
    So how can i fix that or delete the controller without using dcpromo
    cheers
    dave
    ============================
    dcpromoui E28.638 0466 13:58:28.218   Enter DS::DemoteDC
    dcpromoui E28.638 0467 13:58:28.218     Enter State::IsLastDCInDomain false
    dcpromoui E28.638 0468 13:58:28.218     Enter State::IsForcedDemotion false
    dcpromoui E28.638 0469 13:58:28.218     Enter State::GetAdminPassword
    dcpromoui E28.638 046A 13:58:28.218     Enter State::GetAppPartitionList
    dcpromoui E28.638 046B 13:58:28.218     Enter AllocateAppPartitionList
    dcpromoui E28.638 046C 13:58:28.218     Calling DsRoleDemoteDc
    dcpromoui E28.638 046D 13:58:28.218     lpServer               : (null)
    dcpromoui E28.638 046E 13:58:28.218     lpDnsDomainName        : (null)
    dcpromoui E28.638 046F 13:58:28.218     ServerRole             : DsRoleServerMember
    dcpromoui E28.638 0470 13:58:28.218     lpAccount              : (null)
    dcpromoui E28.638 0471 13:58:28.218     Options                : 0x80
    dcpromoui E28.638 0472 13:58:28.218     fLastDcInDomain        : false
    dcpromoui E28.638 0473 13:58:28.218     cRemoteNCs             : 0
    dcpromoui E28.638 0474 13:58:28.250     HRESULT = 0x00000000
    dcpromoui E28.638 0475 13:58:28.250     Enter DeallocateAppPartitionList
    dcpromoui E28.638 0476 13:58:28.250     Enter DoProgressLoop
    dcpromoui E28.638 0477 13:58:28.250       Enter State::GetOperation DEMOTE
    dcpromoui E28.638 0478 13:58:28.250       Enter ProgressDialog::UpdateButton
    dcpromoui E28.638 0479 13:58:29.765       Enter ProgressDialog::UpdateText Active Directory Domain Services successfully transferred the remaining data in directory partition DC=ForestDnsZones,DC=data-action,DC=co,DC=uk to Active Directory Domain Controller \\nasbox.data-action.co.uk.
    dcpromoui E28.638 047A 13:58:43.297       Enter ProgressDialog::UpdateText Stopping service NETLOGON
    dcpromoui E28.638 047B 13:58:44.797       Enter ProgressDialog::UpdateText Stopping service IsmServ
    dcpromoui E28.638 047C 13:58:47.797       Enter ProgressDialog::UpdateText Stopping service kdc
    dcpromoui E28.638 047D 13:58:49.297       Enter ProgressDialog::UpdateText Creating a new local security account manager (SAM) database...
    dcpromoui E28.638 047E 13:58:50.875       Enter ProgressDialog::UpdateText Removing Active Directory Domain Services objects that refer to the local Active Directory Domain Controller from the remote Active Directory Domain Controller nasbox.data-action.co.uk...
    dcpromoui E28.638 047F 13:59:02.875       Enter ProgressDialog::UpdateText Configuring service NTDS
    dcpromoui E28.638 0480 13:59:04.375       Enter ProgressDialog::UpdateText Configuring service NETLOGON
    dcpromoui E28.638 0481 13:59:05.875       Enter ProgressDialog::UpdateText Configuring service DFSR
    dcpromoui E28.638 0482 13:59:07.375       Enter ProgressDialog::UpdateText The attempted domain controller operation has completed
    dcpromoui E28.638 0483 13:59:07.375       Enter ProgressDialog::UpdateButton
    dcpromoui E28.638 0484 13:59:07.375       Progress loop complete.
    dcpromoui E28.638 0485 13:59:07.375       Calling DsRoleGetDcOperationResults
    dcpromoui E28.638 0486 13:59:07.375       Error 0x0 (!0 => error)
    dcpromoui E28.638 0487 13:59:07.375       Operation results:
    dcpromoui E28.638 0488 13:59:07.375       OperationStatus      : 0x5 !0 => error
    dcpromoui E28.638 0489 13:59:07.375       DisplayString        : The attempt at remote directory server nasbox.data-action.co.uk to remove directory server CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk was unsuccessful.
    dcpromoui E28.638 048A 13:59:07.375       ServerInstalledSite  : (null)
    dcpromoui E28.638 048B 13:59:07.375       OperationResultsFlags: 0x0
    dcpromoui E28.638 048C 13:59:07.375       Enter ProgressDialog::UpdateText The attempt at remote directory server nasbox.data-action.co.uk to remove directory server CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk was unsuccessful.
    dcpromoui E28.638 048D 13:59:07.375       Enter State::SetOperationResultsMessage The attempt at remote directory server nasbox.data-action.co.uk to remove directory server CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk was unsuccessful.
    dcpromoui E28.638 048E 13:59:07.375       Enter State::SetOperationResultsFlags 0x0
    dcpromoui E28.638 048F 13:59:07.375   Exception caught
    dcpromoui E28.638 0490 13:59:07.375   catch completed
    dcpromoui E28.638 0491 13:59:07.375   handling exception
    dcpromoui E28.638 0492 13:59:07.375   Enter State::ClearHiddenWhileUnattended
    dcpromoui E28.638 0493 13:59:07.375   Enter EnableConsoleLocking
    dcpromoui E28.638 0494 13:59:07.375     Enter RegistryKey::Create SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    dcpromoui E28.638 0495 13:59:07.375     Enter RegistryKey::SetValue-DWORD DisableLockWorkstation
    dcpromoui E28.638 0496 13:59:07.375   Enter State::SetOperationResults result FAILURE
    dcpromoui E28.638 0497 13:59:07.375   Enter ProgressDialog::UpdateText
    dcpromoui E28.638 0498 13:59:07.375   Enter State::IsOperationRetryAllowed
    dcpromoui E28.638 0499 13:59:07.375     true
    dcpromoui E28.638 049A 13:59:07.375   credentials were invalid, hr=0x80070005
    dcpromoui E28.638 049B 13:59:07.375   Enter GetErrorMessage 80070005
    dcpromoui E28.638 049C 13:59:07.375   Enter State::GetOperationResultsMessage The attempt at remote directory server nasbox.data-action.co.uk to remove directory server CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk was unsuccessful.
    dcpromoui E28.638 049D 13:59:07.375   Enter State::GetOperation DEMOTE
    dcpromoui E28.638 049E 13:59:07.375   Enter State::GetParentDomainDnsName
    dcpromoui E28.638 049F 13:59:44.469   credential retry canceled
    dcpromoui E28.638 04A0 13:59:44.469   Enter ComposeFailureMessage
    dcpromoui E28.638 04A1 13:59:44.469     Enter State::GetOperationResultsMessage The attempt at remote directory server nasbox.data-action.co.uk to remove directory server CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk was unsuccessful.
    dcpromoui E28.638 04A2 13:59:44.469     Enter State::GetOperationResultsFlags 0x0
    dcpromoui E28.638 04A3 13:59:44.469     Enter State::GetOperationResultsFlags 0x0
    dcpromoui E28.638 04A4 13:59:44.469     Enter State::SetFailureMessage The operation failed because:
    The attempt at remote directory server nasbox.data-action.co.uk to remove directory server CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk was unsuccessful.
    "Access is denied."
    dcpromoui E28.638 04A5 13:59:44.469   posting message to progress window
    dcpromoui E28.318 04A6 13:59:44.469               Enter ProgressDialog::UpdateText Operation Stopped
    dcpromoui E28.318 04A7 13:59:44.485               Enter ProgressDialog::OnDestroy
    dcpromoui E28.318 04A8 13:59:44.485             OPERATION FAILED
    dcpromoui E28.318 04A9 13:59:44.485           Enter State::GetNeedsReboot false
    dcpromoui E28.318 04AA 13:59:44.485           Enter State::IsOperationRetryAllowed
    dcpromoui E28.318 04AB 13:59:44.485             true
    dcpromoui E28.318 04AC 13:59:44.485           Enter Wizard::SetNextPageID id = 156
    dcpromoui E28.318 04AD 13:59:44.485             push 142
    dcpromoui E28.318 04AE 13:59:44.485         Enter FailurePage::OnInit
    dcpromoui E28.318 04AF 13:59:44.485           Enter MultiLineEditBoxThatForwardsEnterKey::Init
    dcpromoui E28.318 04B0 13:59:44.485             Enter ControlSubclasser::Init
    dcpromoui E28.318 04B1 13:59:44.485         Enter FailurePage::OnSetActive
    dcpromoui E28.318 04B2 13:59:44.485           Enter State::GetOperationResultsCode FAILURE
    dcpromoui E28.318 04B3 13:59:44.485           Enter State::GetNeedsReboot false
    dcpromoui E28.318 04B4 13:59:44.485           Enter State::GetFailureMessage The operation failed because:
    The attempt at remote directory server nasbox.data-action.co.uk to remove directory server CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk was unsuccessful.
    "Access is denied."
    dcpromoui E28.318 04B5 13:59:47.876         Enter DCPromoWizardPage::OnWizNext
    dcpromoui E28.318 04B6 13:59:47.876           Enter FailurePage::Validate
    dcpromoui E28.318 04B7 13:59:47.876           Enter Wizard::SetNextPageID id = 154
    dcpromoui E28.318 04B8 13:59:47.876             push 156
    dcpromoui E28.318 04B9 13:59:47.876         Enter FinishPage::OnInit
    dcpromoui E28.318 04BA 13:59:47.876           Enter MultiLineEditBoxThatForwardsEnterKey::Init
    dcpromoui E28.318 04BB 13:59:47.876             Enter ControlSubclasser::Init
    dcpromoui E28.318 04BC 13:59:47.876         Enter FinishPage::OnSetActive
    dcpromoui E28.318 04BD 13:59:47.876           Enter State::GetNeedsReboot false
    dcpromoui E28.318 04BE 13:59:47.876           Enter getCompletionMessage
    dcpromoui E28.318 04BF 13:59:47.876             Enter State::GetOperation DEMOTE
    dcpromoui E28.318 04C0 13:59:47.876             Enter State::GetOperationResultsCode FAILURE
    dcpromoui E28.318 04C1 13:59:47.876             Enter NeedDsBinaryWarning
    dcpromoui E28.318 04C2 13:59:47.876               Enter Computer::RemoveLeadingBackslashes
    dcpromoui E28.318 04C3 13:59:47.876               Enter GetProductTypeFromRegistry
    dcpromoui E28.318 04C4 13:59:47.876                 Enter RegistryKey::Open System\CurrentControlSet\Control\ProductOptions
    dcpromoui E28.318 04C5 13:59:47.876                 Enter RegistryKey::GetValue-String ProductType
    dcpromoui E28.318 04C6 13:59:47.876                 LanmanNT
    dcpromoui E28.318 04C7 13:59:47.876                 prodtype : 0x2
    dcpromoui E28.318 04C8 13:59:47.876             Enter State::GetFinishMessages
    dcpromoui E28.318 04C9 13:59:59.751         Enter FinishPage::OnWizFinish
    dcpromoui E28.318 04CA 13:59:59.766         Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04CB 13:59:59.766         Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04CC 13:59:59.766         Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04CD 13:59:59.766       Enter State::GetNeedsReboot false
    dcpromoui E28.318 04CE 13:59:59.766       Enter State::GetUserCancelled false
    dcpromoui E28.318 04CF 13:59:59.766       Enter State::GetOperationResultsCode FAILURE
    dcpromoui E28.318 04D0 13:59:59.766       Enter State::GetHadNonCriticalFailures
    dcpromoui E28.318 04D1 13:59:59.766         bHadNonCriticalFailures = false
    dcpromoui E28.318 04D2 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04D3 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04D4 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04D5 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04D6 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04D7 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04D8 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04D9 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04DA 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04DB 13:59:59.766       Enter ControlSubclasser::UnhookWindowProc
    dcpromoui E28.318 04DC 13:59:59.766     exitCode = 54
    dcpromoui E28.318 04DD 13:59:59.766   Enter State::UnbindFromReplicationPartnetDC
    dcpromoui E28.318 04DE 13:59:59.766 closing log

    this is what i decided to do. unfortunately the metadata cleanup did not complete
    Access is denied? - that sounds familiar
    the server is still listed in "AD Sites and Services" (and cannot be deleted by the management snapin)
    ===================================================
    select operation target:
    select operation target:
    select operation target:
    select operation target: select server 1
    Site - CN=Palatine,CN=Sites,CN=Configuration,DC=data-action,DC=co,DC=uk
    Domain - DC=data-action,DC=co,DC=uk
    Server - CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,CN=Configuration,DC=data-ac
    tion,DC=co,DC=uk
            DSA object - CN=NTDS Settings,CN=LPSERVER,CN=Servers,CN=Palatine,CN=Site
    s,CN=Configuration,DC=data-action,DC=co,DC=uk
            DNS host name - lpServer.data-action.co.uk
    No current Naming Context
    select operation target:
    select operation target: quit
    metadata cleanup:
    metadata cleanup:
    metadata cleanup: remove selected server
    Transferring / Seizing FSMO roles off the selected server.
    Removing FRS metadata for the selected server.
    Unable to find server reference on "CN=LPSERVER,CN=Servers,CN=Palatine,CN=Sites,
    CN=Configuration,DC=data-action,DC=co,DC=uk".
    LDAP error 0x5e(94 (No result present in message).
    The attempt to remove the FRS settings on CN=LPSERVER,CN=Servers,CN=Palatine,CN=
    Sites,CN=Configuration,DC=data-action,DC=co,DC=uk failed because "Element not fo
    und.";
    metadata cleanup is continuing.
    DsRemoveDsServerW error 0x5(Access is denied.)
    metadata cleanup:
    metadata cleanup:

  • Windows Server 2008 R2 Domain Controller NOT logging EventID 4740

    EventID 4740 (account lockout) is not being logged to the event viewer. When searching through the security log there are none to be found. Having accounts locked out and no logging is driving me nuts. Hope someone has run into this before. This is what
    i have checked thus far.
    >Windows Server 2008 R2 Domain Controller
    >Verified the following GPO settings are set and correct:
    >Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy\ all are set for Success & Failure
    >Computer Configuration\Windows Settings\Security Settings\Advanced Audit Configuration\Logon/Logoff) is set for Success and Failure
    >Powershell command Get-Eventlog -log Security -InstanceId 4740 returns no results which makes sense since there are no entries in the security log file.
    >No 4740 entries in the netlogon.log debug file
    AD and the LockoutStatus tool show the account is locked out but i still have nothing in the logs.
    Anyone have any ideas? From everything i can find online , it appears i have everything set properly.
    Thanks, Chico

    Hi Chico,
    I suggest you try to enable this group policy below:
    Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy\Audit account management
    More information for you:
    Missing 4740 EventID's
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/c9871d72-7439-46b5-98e6-a7fadfa6ff28/missing-4740-eventids?forum=winserversecurity
    If you have multiple Domain Controllers, check this event on other DCs, too.
    Please feel free to let us know if there are any further requirements.
    Best Regards,
    Amy Wang

  • Can I move a Virtual Domain Controller from one host(Win Server 2008 R2) to another (Win Server 2012 R2) ? Are there any issues?

    Can I move a Virtual Domain Controller from one host(Win Server 2008 R2) to another (Win Server 2012 R2) ? Are there any issues?

    I also had this error: "Setup cannot continue. Your computer will now restart, and your previous version of Windows will be restored."
    trying to do a in-place upgrade of a Domain Controller Windows 2008 R2 to Windows 2012 R2.
    The problem was the separated System Reserved Partition. After I removed using this instructions:
    http://jacobackerman.blogspot.com/2012/12/how-to-remove-system-reserved-partition.html
    The upgrade ran ok, and now have my DC as Windows 2012 R2.
    Hope that helps!.

  • Exchange 2007 RTM support with Windows Server 2012 R2 Domain Controller

    Hi All,
    I have not found any TechNet Article which states about the Windows Server 2012 R2 Active Directory domain controller operating system support with Exchange 2007 RTM, can some one please let me know that does Exchange 2007 RTM supports Windows Server 2012
    R2 domain controller operating system, we are in the process of upgrading the domain controllers to 2012 R2 but not the forest and domain functional level to 2012 R2.
    thanks
    If answer is helpful, please hit the green arrow on the left, or mark as answer. Salahuddin | Blogs:http://salahuddinkhatri.wordpress.com | MCITP Microsoft Lync

    There are several likely reasons for this.  The most significant is that Exchange 2007 RTM is no longer supported (outside ot extended support, which is not going to include adding support for new operating systems): 
    http://support2.microsoft.com/lifecycle/default.aspx?LN=en-us&p1=10926
    You'll note from the following -
    http://technet.microsoft.com/library/ff728623(v=exchg.150).aspx - that only Exchange 2007 SP3 is currently supported in any environment.
    HTH ...

  • HT1277 How do I make Mail remove junk/deleted messages from the server? The only option tht works for me now is the "Remove from server" button at Account Info Messages on server.

    How do I make Mail remove junk/deleted messages from the server? The only option tht works for me now is the "Remove from server" button at Account Info > Messages on server. What am I doing wrong?

    Mail > Preferences… > Accounts > Advanced > Remove copy from server after retrieving a message

  • Domain name from the configuerd mail server

    HI,
    How to get the domain name from the mail server that i configure using java Mail..
    Properties props = new Properties();
    props.put("mail.smtp.host", mailServer);
    mailServer has my mailServer name like email.something.com
    in my application, from address is the one user sets.. if they forgot to set it and tries to send a mail then i need to send that mail with a default address like [email protected] where something.com must be the domain name.. so i juz want to know how to get the domain name.?
    hope it is clear. can any of u help me out?

    There's no well-defined way to do this. The
    simplest approach is to offer this as a configuration
    option.
    A more complicated approach would be to use
    the host name of the mail server and look up
    that name in DNS and try to find the DNS record
    that tells which mail server to use for that host
    name, perhaps stripping off elements of the name
    until you find something. (And no, I can't explain
    to you exactly how to do that.)

  • Upgrade to Server 2012 R2 domain controllers from 2003

    I am at a loss as to what I did wrong here. Everything seems to be working fine except for one subnet (which is behind a hardware firewall).
    We had two Server 2003 domain controllers and one of them was failing.  I raised the forest functional level of our old primary domain controllers to 2003.  I built the first replacement Server 2012 R2 domain controller.  Added the AD DS roles
    and promoted it as a domain controller.  I let it sit for a couple days.  The FSMO roles were currently being handled by our other 2003 domain controller.  Once this had been sitting for a while (don't recall how long) I ran dcpromo on the failing
    server and demoted it.  Once demoted I shut it down and pulled it out of the rack.  I then built our second 2012 R2 server and gave it the same IP as the failing one.  Installed the AD DS roles and integrated DNS as prompted by the wizard. 
    I then made it the operations master for Schema master, Domain naming master, PDC, RID pool manager, and Infrastructure master.  Then I ran dcpromo on the second 2003 domain controller to demote it and removed it from the network.  I then demoted
    the first new controller (DC03) changed the hostname and IP to the name and IP of the second 2003 controller and promoted it again.  I'm not sure at what point things broke, but everything works from the same subnet that the domain controllers are in,
    just not a second subnet that is through a hardware firewall.  I don't see anything getting blocked while watching firewall logs so I don't think the firewall is the issue.
    Here is the dcdiag and ipconfig from the first controller (which has all 5 FSMO roles).
    Microsoft Windows [Version 6.3.9600]
    (c) 2013 Microsoft Corporation. All rights reserved.
    C:\Users\username>dcdiag /v /test:dns
    Directory Server Diagnosis
    Performing initial setup:
       Trying to find home server...
       * Verifying that the local machine WGDDC01, is a Directory Server.
       Home Server = WGDDC01
       * Connecting to directory service on server WGDDC01.
       * Identified AD Forest.
       Collecting AD specific global data
       * Collecting site info.
       Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=wgd,DC=inet,LD
    AP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
       The previous call succeeded
       Iterating through the sites
       Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name
    ,CN=Sites,CN=Configuration,DC=wgd,DC=inet
       Getting ISTG and options for the site
       * Identifying all servers.
       Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=wgd,DC=inet,LD
    AP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
       The previous call succeeded....
       The previous call succeeded
       Iterating through the list of servers
       Getting information for the server CN=NTDS Settings,CN=WGDDC01,CN=Servers,CN=
    Default-First-Site-Name,CN=Sites,CN=Configuration,DC=wgd,DC=inet
       objectGuid obtained
       InvocationID obtained
       dnsHostname obtained
       site info obtained
       All the info for the server collected
       Getting information for the server CN=NTDS Settings,CN=WGDDC02,CN=Servers,CN=
    Default-First-Site-Name,CN=Sites,CN=Configuration,DC=wgd,DC=inet
       objectGuid obtained
       InvocationID obtained
       dnsHostname obtained
       site info obtained
       All the info for the server collected
       * Identifying all NC cross-refs.
       * Found 2 DC(s). Testing 1 of them.
       Done gathering initial info.
    Doing initial required tests
       Testing server: Default-First-Site-Name\WGDDC01
          Starting test: Connectivity
             * Active Directory LDAP Services Check
             Determining IP4 connectivity
             * Active Directory RPC Services Check
             ......................... WGDDC01 passed test Connectivity
    Doing primary tests
       Testing server: Default-First-Site-Name\WGDDC01
          Test omitted by user request: Advertising
          Test omitted by user request: CheckSecurityError
          Test omitted by user request: CutoffServers
          Test omitted by user request: FrsEvent
          Test omitted by user request: DFSREvent
          Test omitted by user request: SysVolCheck
          Test omitted by user request: KccEvent
          Test omitted by user request: KnowsOfRoleHolders
          Test omitted by user request: MachineAccount
          Test omitted by user request: NCSecDesc
          Test omitted by user request: NetLogons
          Test omitted by user request: ObjectsReplicated
          Test omitted by user request: OutboundSecureChannels
          Test omitted by user request: Replications
          Test omitted by user request: RidManager
          Test omitted by user request: Services
          Test omitted by user request: SystemLog
          Test omitted by user request: Topology
          Test omitted by user request: VerifyEnterpriseReferences
          Test omitted by user request: VerifyReferences
          Test omitted by user request: VerifyReplicas
          Starting test: DNS
             DNS Tests are running and not hung. Please wait a few minutes...
             See DNS test in enterprise tests section for results
             ......................... WGDDC01 failed test DNS
       Running partition tests on : DomainDnsZones
          Test omitted by user request: CheckSDRefDom
          Test omitted by user request: CrossRefValidation
       Running partition tests on : ForestDnsZones
          Test omitted by user request: CheckSDRefDom
          Test omitted by user request: CrossRefValidation
       Running partition tests on : Schema
          Test omitted by user request: CheckSDRefDom
          Test omitted by user request: CrossRefValidation
       Running partition tests on : Configuration
          Test omitted by user request: CheckSDRefDom
          Test omitted by user request: CrossRefValidation
       Running partition tests on : wgd
          Test omitted by user request: CheckSDRefDom
          Test omitted by user request: CrossRefValidation
       Running enterprise tests on : wgd.inet
          Starting test: DNS
             Test results for domain controllers:
                DC: WGDDC01.wgd.inet
                Domain: wgd.inet
                   TEST: Authentication (Auth)
                      Authentication test: Successfully completed
                   TEST: Basic (Basc)
                      The OS
                      Microsoft Windows Server 2012 R2 Standard (Service Pack level:
     0.0)
                      is supported.
                      NETLOGON service is running
                      kdc service is running
                      DNSCACHE service is running
                      DNS service is running
                      DC is a DNS server
                      Network adapters information:
                      Adapter [00000010] Broadcom NetXtreme Gigabit Ethernet:
                         MAC address is B0:83:FE:C1:98:07
                         IP Address is static
                         IP address: 10.240.1.23
                         DNS servers:
                            10.240.1.23 (WGDDC01) [Valid]
                            10.240.1.24 (WGDDC02) [Valid]
                            127.0.0.1 (WGDDC01) [Valid]
                      The A host record(s) for this DC was found
                      The SOA record for the Active Directory zone was found
                      Warning: no DNS RPC connectivity (error or non Microsoft DNS s
    erver is running)
                      [Error details: 5 (Type: Win32 - Description: Access is denied
             Summary of test results for DNS servers used by the above domain
             controllers:
                DNS server: 10.240.1.23 (WGDDC01)
                   All tests passed on this DNS server
                   Name resolution is functional._ldap._tcp SRV record for the fores
    t root domain is registered
                DNS server: 10.240.1.24 (WGDDC02)
                   All tests passed on this DNS server
                   Name resolution is functional._ldap._tcp SRV record for the fores
    t root domain is registered
             Summary of DNS test results:
    Auth Basc Forw Del  Dyn  RReg Ext
                Domain: wgd.inet
                   WGDDC01                      PASS WARN n/a  n/a  n/a 
    n/a  n/a
             ......................... wgd.inet passed test DNS
          Test omitted by user request: LocatorCheck
          Test omitted by user request: Intersite
    C:\Users\dsmythe>ipconfig /all
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : WGDDC01
       Primary Dns Suffix  . . . . . . . : wgd.inet
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : wgd.inet
    Ethernet adapter WGD_INET:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
       Physical Address. . . . . . . . . : B0-83-FE-C1-98-07
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 10.240.1.23(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 10.240.1.1
       DNS Servers . . . . . . . . . . . : 10.240.1.23
                                           10.240.1.24
                                           127.0.0.1
       NetBIOS over Tcpip. . . . . . . . : Enabled
    Tunnel adapter isatap.{2C28B0FA-6BF8-4201-A6DA-081AED63B496}:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    When I try to bind a machine to the domain I get an error message that says "
    The following error occurred when DNS was queried for the service location (SRV) resource record used to locate an Active Directory Domain Controller (AD DC) for domain "wgd.inet":
    The error was: "This operation returned because the timeout period expired."
    (error code 0x000005B4 ERROR_TIMEOUT)
    The query was for the SRV record for _ldap._tcp.dc._msdcs.wgd.inet
    The DNS servers used by this computer for name resolution are not responding. This computer is configured to use DNS servers with the following IP addresses:
    10.240.1.24
    10.240.1.23
    Verify that this computer is connected to the network, that these are the correct DNS server IP addresses, and that at least one of the DNS servers is running.
    Please let me know if I'm missing something or if there are other things I can check.
    Thanks!
    I forgot to mention that after the 2003 domain controllers were out of the environment, I raised the domain and forest functional level to 2012 R2.  All clients in the environment are Windows XP Pro or above.  The XP Pro boxes will be going away as
    soon as our vendor supports their software to run on Windows 7.

    We now have 2 2012 R2 DCs. The 2003 DCs are gone. Metadata from the old DCs is all cleaned up. DNS seems to be working fine in 3 out of 4 subnets. The 4th is behind a hardware firewall and I can see the IP address of the machine I am trying to bind to the
    domain connecting to the two new domain controllers but the client machine that is trying to bind gives an error.  An Active Directory Domain Controller for the domain wgd.inet could not be contacted.  It seems that this is just a DNS issue for one
    particular subnet (10.240.2.0/24).  This subnet is setup in AD Sites and Services\Sites\Subnets\10.240.2.0/24 (Site: Default-First-Site-Name).
    When trying to do anything with nslookup from the 10.240.2.0/24 subnet it times out.  The route is there and I can watch it connect through our hardware firewall over port 53.
    DC01
    Microsoft Windows [Version 6.3.9600]
    (c) 2013 Microsoft Corporation. All rights reserved.
    C:\Users\dsmythe>netdom query fsmo
    Schema master               WGDDC01.wgd.inet
    Domain naming master        WGDDC01.wgd.inet
    PDC                         WGDDC01.wgd.inet
    RID pool manager            WGDDC01.wgd.inet
    Infrastructure master       WGDDC01.wgd.inet
    The command completed successfully.
    C:\Users\dsmythe>ipconfig /all
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : WGDDC01
       Primary Dns Suffix  . . . . . . . : wgd.inet
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : wgd.inet
    Ethernet adapter WGD_INET:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
       Physical Address. . . . . . . . . : B0-83-FE-C1-98-07
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 10.240.1.23(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 10.240.1.1
       DNS Servers . . . . . . . . . . . : 10.240.1.23
                                           10.240.1.24
       NetBIOS over Tcpip. . . . . . . . : Enabled
    Tunnel adapter isatap.{2C28B0FA-6BF8-4201-A6DA-081AED63B496}:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    C:\Users\dsmythe>
    DC02
    Microsoft Windows [Version 6.3.9600]
    (c) 2013 Microsoft Corporation. All rights reserved.
    C:\Users\dsmythe>netdom query fsmo
    Schema master               WGDDC01.wgd.inet
    Domain naming master        WGDDC01.wgd.inet
    PDC                         WGDDC01.wgd.inet
    RID pool manager            WGDDC01.wgd.inet
    Infrastructure master       WGDDC01.wgd.inet
    The command completed successfully.
    C:\Users\dsmythe>ipconfig /all
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : WGDDC02
       Primary Dns Suffix  . . . . . . . : wgd.inet
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : wgd.inet
    Ethernet adapter NIC1:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
       Physical Address. . . . . . . . . : B0-83-FE-C1-9F-74
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 10.240.1.24(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : 10.240.1.1
       DNS Servers . . . . . . . . . . . : 10.240.1.24
                                           10.240.1.23
       NetBIOS over Tcpip. . . . . . . . : Enabled
    Tunnel adapter isatap.{4F45E51E-FC2F-49ED-85CF-0750A9EEECF5}:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    C:\Users\dsmythe>

  • The box indicating that this domain controller is the last controller for the domain is unchecked. However, no other Active Directory domain controllers for that domain can be contacted

    I have 2 domain controllers running 2003 server, server1 and server2. I ran dcpromo on server1 and removed AD and removed him from the domain and disconnected from network. I then added a 2012 server
    with the same name and IP address server1 with no problem. Replication from sites and services work fine on both controllers.
    The new 2012 server1 is GC. I transferred all FSMO roles to server1. Again no problem and replicating using sites and services. AD on server1 is populated correctly.
    Now what I had intended on doing was a dcpromo to remove server2 from the domain so I can then add another 2012 server. That is when I get the: "The box indicating that this domain controller is the last controller for the domain
     is unchecked. However, no other Active Directory domain controllers for that domain can be contacted.
    I have DNS installed on both servers and both look good with replicating there. Strange thing is when on the 2012 server within DNS if I right click and connect to another DNS server I can add server2 just fine but from server2 adding server1 it tells me it
    is not available.
    Help please!

    Hi,
    As there is server 2012 DC (SERVER1) DC is operational in a domain then "This domain controller is the last controller for the domain" should be remain unchecked when you demote SERVER2 DC. 
    If you are getting error "Active Directory domain controllers for that domain can be contacted" while demoting SERVER2 DC then check the DNS pointing on both as per below article, disable windows firewall on all DC, less possiblities but worth to check if both
    are different site then check the ports are open on firewall. 
    http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/
    http://technet.microsoft.com/en-us/library/cc766337(v=ws.10).aspx
    http://social.technet.microsoft.com/wiki/contents/articles/584.active-directory-replication-over-firewalls.aspx
    run “ipconfig /flushdns & ipconfig /registerdns“, restart DNS server and NETLOGON service on each DC and try to demote server2 DC.
    If issue reoccurs, post dcdiag /q result.
    NOTE: If initial replication was completed between both DC (new 2012 and old DC) then you may remove the server2 DC from Active Directory forcefully (DCPROMO /FORCEREMOVAL) and perform metadata cleanup.
    Active Directory Metadata Cleanup
    http://abhijitw.wordpress.com/2012/03/03/active-directory-metadata-cleanup/
    Best regards,
    Abhijit Waikar.
    MCSA | MCSA:Messaging | MCITP:SA | MCC:2012
    Blog: http://abhijitw.wordpress.com
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees and confers no rights.

  • Adding a Server 2008 R2 Domain Controller at a remote site

    Hello. I have been trying to set up a hot site at a remote location.  The story is long and involved but a few weeks ago it seemed to be finally working.  Our setup is two mirrored 2008 R2 servers at main site, mirrored with Double Take. 
    The hot site is the same except that so far I only had one server working.  The two sites connected via site to site VPN.
    About a week later our primary server basically crashed.  At first it worked but very slowly.  I was on vacation at the time and so I am not sure of the sequence of events, or exactly what errors were presented, but my associate first tried rebooting. 
    It took over 20 minutes to boot and then it said something to the effect that no domain controllers were available (not sure about this message).  He then discovered that the server at the remote site had some fsmo roles assigned to it.  He transferred
    the roles to the primary at the main site and then demoted the remote server to a workstation (but still a domain member).
    After that, rebooting the primary was much faster and everything at the primary site is working again. Now I want to set the remote site up again, but avoid the problem.  The way I originally set up the remote server was to use an IFM file, generated
    from our primary.  This should have made the remote server a catalog server, with DNS (which it did), but as far as I know should not have transferred any fsmo roles.
    The remote server(s) are wanted to be in the same domain as the primary.  They will also be mirrored from the primary (with Double Take).  If we had total failure at the main site, we wish to be able to immediately begin operations at the hot site
    (after a fail over).  I freely admit that I am swimming out of my depth here.  I am not sure that I have selected the correct architecture or used the correct options in setting up the remote servers.  I am looking for information about what
    went wrong, and whether some other setup is more desirable.
    Thanks for any help, Russ
    Russ

    Philippe, thank you for you answers.  I do not understand everything you said but I will address each point as best I can:
    1. "In the remote site do you simply do a dcpromo / add the ADDS's role to make the server a active Domain Controller ?"  Yes, but I use the method described at
    http://technet.microsoft.com/en-us/library/cc753720(v=ws.10).aspx, The GUI method.  At step #8 I specified to use advanced mode so I could use the IFM file.
    2. "In your AD' Site and Service MMC, do you configured the remote site ?"  R do not know what you mean by this. How does one configure the site as 'remote'?
    3. "Do you added that remote server as a Global catalogue ?".  Yes, when I built the IFM file I specified to add the global catalog.
    4. "Do you added the PC in site 1, the IP of those DNS server in them ? (last of course) So the computer in the main site will talk to the remote server in case of a crash."  I am not sure I understand this item.  After the remote server
    was added, all of the members of both domain servers automatically appeared in the DNS of all servers in the domain.  I do not recall if the new items were last, but I expect that they would be.
    I have since reviewed the happenings with my associate and have a little more information.  The order of the problems and the actions taken are:
    1. Our primary (production) system was still working but extremely slow, and he observed that the slowness was caused by a lot of traffic with the remote site.  Rebooting the production server took over 25 minutes and the server to came up saying
    that domain information was not available.  After another 30 minutes or so he discovered that the domain data was now available and the server worked, but still slow.
    2. He did not check to verify that roles were held by the remote server, but he transferred all roles from the remote to the production server using ntdsutil.  I would expect that if the role was not held by the remote, the transfer command would have
    shown that fact.
    3. He then tried to demote the remote server but had an error that it could not be demoted because "the active directory service is missing mandatory configuration information".
    4. He forcefully demoted the remote server.
    5. After rebooting the production server again performance was slightly better but still slow (and the rebood was still very slow).
    6. After some research he removed the remote domain controller's meta data from the production server and then rebooted the production server again.
    At that point reboot was fast (under 5 minutes) and the production system was working at normal speed again.
    All of the above leads me to believe that somehow the FSMO roles got added to, or moved to the remote site when I used the IFM file to create the new domain controller.  However nothing I have read says that this should happen.  I hope someone
    here can give me a better answer as to what caused the problem, as I do not wish to interrupt our production system like this again.
    Thank you, Russ
    PS: Sorry for the delay in getting back to this but some other priorities took me away from it for a week.
    Russ

  • How do I remove my iWeb pages from the Home folder so I can publish to a new host?

    I have moved my MobileMe site to a new service (GoDaddy).  The basic transfer went very smoothly.  With one tiny hitch:  the new URL text.
    IWeb places web  pages in folders, each folder being a  "site." The name of the root folder automatically becomes a "pointer" to the web site -- and part of the URL text.
    My current root folder  is named DavidChartrand -- me.  So..... when I published everything over to GoDaddy the text "DavidChartrand" was attached to my URL. 
    Instead of seeing www.davidchartrand.com in the URL bar, visitors  see:   www.davidchartrand.com.com/DavidChartrand
    GoDaddy staff says this is simply a quirk in iWeb's design.  Fine, but it's annoying.  Is there anyway I can keep using iWeb but somehow remove the root folder.....that is, remove my site pages from the root folder and and then re-publish? GoDaddy tech support swears it  has many former MobileMe/iWeb users who have done this successfully but offered had no idea how.
    David

    The way iWeb publishes its websites, in its own folder, the normal URL is http://www.domain_name.com/Site_name/Page_name.html.  This is a normal URL for any web host.
    If you want to get rid of the site name you will need to publish your website to a folder on your hard drive and upload only the contents of the website folder to your server with a 3rd party FTP client like YummyLite, Transmit or Cyberduck.  That will get rid of the site name in the URL. 
    Of course remove the existing website foldr from the server beforehand.
    I believe the folder you publish to on GoDaddy is named public_html.  You might try renaming your website to "public_html" and publish to GoDaddy.  In theory iWeb will see the website's folder already on the server and publish the website file into it. 
    It works that way with HostExcellence.com which names the home folder the same as the domain name associated with it. This tutorial explains more about it: iW16 - Using HostExcellence.com with iWeb
    OT

  • Exchange Server CCR 2007 unable to see the File Share Witness resulting in mailbox failover ?

    Hi people,
    Here's my Exchange Server 2007 SP3 in the ideal and normal situation:
    Mailbox Server (CCR – Stretched Cluster) Nodes
    PRODEXMBX01-VM (Active Mailbox, Quorum) – 10.1.1.53
    DREXMBX01-VM (Passive mailbox) – 192.168.1.88
    Hub Transport and Client Access Server Nodes
    PRODEXHTCAS02-VM – 10.1.1.54
    PRODEXHTCAS03-VM (FSW holder) – 10.1.1.55
    DREXHTCAS02-VM – 192.168.1.89
    Saturday early morning, for some unknown reason the Active Mailbox Server (PRODEXMBX01-VM)
    cannot access or see the FSW on the HT server PRODEXHTCAS03-VM, thus
    the mailbox gets failover to the DR Mailbox server (DREXMBX01-VM).
    Here’s the Events logged:
    Log
    Name:      System
    Source:        Microsoft-Windows-FailoverClustering
    Event ID:      1564
    Task Category: File Share Witness Resource
    Level:Critical
    User:          SYSTEM
    Computer:      PRODEXMBX01-VM.domain.com
    Description:
    File
    share witness resource 'File Share Witness (\\PRODEXHTCAS03-VM \FSM_DIR_ExMbxCluster01)'
    failed to arbitrate for the file share '\\ PRODEXHTCAS03-VM \FSM_DIR_ExMbxCluster01'.
    Please ensure that file share '\\ PRODEXHTCAS03-VM \FSM_DIR_ExMbxCluster01'
    exists and is accessible by the cluster.
    Log Name: System
    Source: Microsoft-Windows-FailoverClustering
    Event ID:      1177
    Task Category: None
    Level:       Critical
    User:     SYSTEM
    Computer:PRODEXMBX01-VM.domain.com
    Description:
    The Cluster service is shutting down because quorum was lost.
    This could be due to the loss of network connectivity between some or all nodes
    in the cluster, or a failover of the witness disk.
    Run
    the Validate a Configuration wizard to check your network configuration. If the
    condition persists, check for hardware or software errors related to the
    network adapter. Also check for failures in any other network components to
    which the node is connected such as hubs, switches, or bridges.
    So I had to perform manual failover back from DR to production so that both Active mailbox and the Quorum
    are held by the Production Mailbox server (PRODEXMBX01-VM).
    On Sunday Morning, the Event ID Critical 1564 occurred again thus causing only the quorum only to failover
    to the DR mailbox server (DREXMBX01-VM) but the Active mailbox role is still held by the Production Exchange server (PRODEXMBX01-VM). 
    So now the situation is like the following:
    Mailbox Server (CCR – Stretched Cluster) Nodes
    PRODEXMBX01-VM (Active Mailbox) – 10.1.1.53
    DREXMBX01-VM (Passive mailbox, Quorum) – 192.168.1.88
    Hub Transport and Client Access Server Nodes
    PRODEXHTCAS02-VM – 10.1.1.54
    PRODEXHTCAS03-VM (FSW holder) – 10.1.1.55
    DREXHTCAS02-VM – 192.168.1.89
    So what causing the mailbox servers unable to contact the File Share Witness?
    /* Server Support Specialist */

    Did you check the blog above? 
    The account used in the clustered machine should have access to
    \\PRODEXHTCAS03-VM\FSM_DIR_ExMbxCluster01. Please check the permissions. Try giving full permission to admins as well (just to try)
    MAS
    I've followed this (http://technet.microsoft.com/en-us/library/bb124922(v=exchg.80).aspx) instruction and there is no mentioning other than the Cluster Service Account. 
    /* Server Support Specialist */

  • An attempt to resolve the DNS name of a domain controller in the domain being joined has failed.

    "An attempt to resolve the DNS name of a domain controller in the domain being joined has failed." 
    This is the error message I get whenever I try to connect to my servers domain which I just set up earlier today. I have read through a bunch of other threads on the same error message
    but each of them has had different solutions and none of them have helped me. 
    The one thing that I suspect is related to my problem is that I can't ping my domain on the W7 computer I'm trying to connect. I can ping the server, but not the domain. the domain
    i'm using is set up like "domain.local" . 
    Other things that might be relevant. 
    I'v already set up user accounts and a computer under the Server 2012 active domain administrator settings. 
    I'v port forwarded ports 80 and 443 on the server. 
    The server has a static IPv4 IP adress. I haven't done anything with IPv6 
    The W7 computer has a dynamic IP adress, but I don't think it changes. I believe my router is set up to keep it constant, not 100% sure though. 
    Thanks for any help with this, I'm pretty much out of ideas on this. 

    Hi ZachPrinz,
    Firstly, would you please let us know the outputs of ipconfig /all both of the clients and the DC.
    Also, if you run nslookup FQDN of your DC from your clients, what will you receive?
    Meanwhile, regarding the issue, we can refer to
    the similar thread and see how it works.
    More information:
    Troubleshooting Domain Join Error Messages (en-US)
    Hope this helps.
    Jeremy Wu
    TechNet Community Support

Maybe you are looking for

  • How to get folders from your server using IMAP and push, 3G.

    After looking all over this forum looking for an answer, I found out on my own. here's how: Step 1: Login to your email server. - If you can, log into your email server via webmail. This ensures that you are in fact connected to your email server and

  • Question Re video and Ipad +apple tv

    I rented a SD video from Itunes videos this weekend. I downloaded to Ipad2 and wanted to project through apple TV as I have doen many many times. The sound came through, and the video showed the progress bar and icon of the movie but no visual, why i

  • I deleted an item in my purchases, how do i get it back?

    I deleted an item in my purchases, how do i get it back?

  • Video Asset Management

    Looking for suggestions. We are a small business with 2-3 people editing on FCPX in the same room all on separate computers with separate versions of FCPX working on generally separate projects. We are all plugged into the same hard drive storage to

  • To find table field ,given its description

    i was give only the description of the field , how to find out in which table it is. eg : 'payment terms'