How to recover domain when the primary domain controller failes and there are member domain controllers
<!--[if gte mso 9]><xml>Many of us have probably dabbled in setting up our own domain and forest for development purposes. For me - a domain is a must - I have my development environment that is heavily used to model development projects for clents - and I have my family - me, my wife, and 7 children with their own computers.
So, we have a fairly detailed setup on the home front - but the following applies to ANY environment in which your primary domain controller gives up the ghost - and you do not have an image backup of the PDC.
Foremost - clarity: In an Active Directory forest, where you have several domain controllers, but one primary domain controller (PDC) - you may think that you must RESTORE or recover this PDC to salvage the domain. In other words, if the PDC fails - is all lost? Nope, not at all. Unless you do not have backup domain controllers. If you do not - then reading the rest of this is moot - but if you do, then read on.
When you promote additional servers on your domain, and make them member DC's in the same forest, then your domain details are available to you - and you simply need to transfer the Operation Master role to another DC - but before doing that - there are the FSMO's - yea, something hardly anyone knows about: FSMO = Flexible Single Master Operation - something your PDC or master of operations - manages. If a PDC - and Global Catalog for that matter - goes offline, a backup DC will generally pickup and juggle traffic for the PDC. But what happens if the PDC crashes altogether, and you need to basically assign a member backup DC the PDC role?
FSMO must be transferred to a backup DC before that DC can assume the Master of Operations role. This is done at the command-line level, and you must be careful before you make this call - ONLY do this if you are sure you cannot recover the original PDC because once you do this - you cannot laterr recover the PDC and bring it online. It cannot be added back into the forest at all.
So, the FSMO roles and how we transfer these. In a word, you cannot simply transfer the FSMO roles because the PDC is off line and not available to authorize the transfer. However, you 'can' SEIZE the FSMO roles from the original PDC - even with the machine offl line.
Caution: Using the Ntdsutil utility incorrectly may result in partial or complete loss of Active Directory functionality.
Open a CMD prompt on the backup DC you want to perform this on. At the command-line prompt, type Ntdsutil and press <Enter>.
Microsoft Windows [Version
5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.
C:\WINDOWS>ntdsutil
ntdsutil:
At this prompt, type roles and press <Enter>:
ntdsutil: roles
fsmo maintenance:
Now type connections and press <Enter>:
fsmo maintenance: connections
server connections:
Now type connect to servername <serverName> where <serverName> is the name of the backup DC you are working on, and press <Enter>:
server connections: connect to servername hamddc02
Connected to hamdc02 using
credentials of locally logged on user.
server connections:
At the server connections prompt type q and press <Enter>:
server connections: q
fsmo maintenance:
Now we are going to SEIZE the FSMO roles we want. NOTE: Out of the 5 FSMO roles, we are NOT going to seize the Infrastructure Master. We do not want to put the Infrastructure Master (IM) role on the same domain controller as the Global Catalog server. If the Infrastructure Master runs on a GC server it will stop updating object information because it does not contain any references to objects that it does not hold. This is because a GC server holds a partial replica of every object in the forest. For now, we'll seize the following:
Seize domain naming master
Seize PDC
Seize RID master
Seize schema master
We do this by typig the line shown above. For example, to seize the domain naming master, type seize domain naming master and press <Enter>
You will receive a Windows dialog prompting to confirm this move - click <Yes> and then you'll see the attempt to safely transfer the FSMO role, a failure message, and then it will seize the role, assigning it to the backup DC you specified when you connected to the server above.
Once you have completed this for the 4 roles, type Quit to exit the utility, then Exit to return to Windows.
From the Start menu, select Run and enter dsa.msc and press <Enter>.
On the domain that is displayed, right click and select Operations Masters. You should now see that this backup domain controller (HAMDC02 in this case) is not the Operations master.
From here you simply re-create the failed domain controller, and promote it - joining it to this existing forest.
Hopefully others will find this useful
Thanks for the informative article, it was a good read and I hope its ok that I share this with some facebook friends. Thanks.
My website is on Healthy diet plan.
Finally a person that puts some real work into a blog. I do like what you have done with the blog.
My blog is High protein diet plan.
I greatly appreciate all the info I’ve read here. I will spread the word about your blog to other people. Cheers.
My website is about Weight loss recipes.
Thanks on creating one of the most stylish blogs I have come across in a long time! It’s truly incredible how much you are able to take away from some thing simply because of how aesthetically gorgeous it is. Youve created a fantastic be site fantastic graphics , structure. site!
Welcome to my blog : Lower back pain relief
great issues altogether, you just received brand new reader. What could you recommend in regards to your post that you just made some days in the past? Any positive?
Welcome to my blog : Neck pain relief
Hey, I can’t view your site properly within Opera, I actually hope you look into fixing this.
My website is what causes acne
Lots of helpful information. I have bookmarked your site.
My blog is about what causes acne
You have showed great perseverance behind the blog. It’s been enriched since the beginning. I love to share to with my friends. Carry on.
Recipes for diabetics
love this site – it’s a great blog – may i suggest you get an rss feed.
Diet recipes for diabetics
Магазин обуви: обувь оптом мужская женская детская Liska (Лиска), скандия обувь женская Liska (Лиска), необычная женская обувь Liska (Лиска), женская осенняя обувь купить Liska (Лиска), женская мембранная обувь Liska (Лиска).
Магазин обуви: женская обувь статьи Liska (Лиска), женская обувь по низким ценам Liska (Лиска), dsquared2 обувь женская Liska (Лиска), женская обувь сапоги осенние Liska (Лиска), женская обувь j elisabeth Liska (Лиска).
Магазин обуви: женская обувь 42 Liska (Лиска), женская обувь осень 2010 2011 Liska (Лиска), интернет каталог женской обуви Liska (Лиска), clarks женская обувь Liska (Лиска), дешевая женская обувь Liska (Лиска).
Мы предлагаем: xrumer palladium, как пользоваться хрумером, прогон хрумером, xrumer 2.5 скачать, скачать xrumer 3. Программа XRumer (xrumer установка).
Магазин обуви: обувь женская 2011 Liska (Лиска), женская обувь больших размеров украина Liska (Лиска), женские туфли магазины обуви Liska (Лиска), женская обувь ara Liska (Лиска), женская резиновая обувь оптом Liska (Лиска). Сайт: http://zimnyayaobuv.ru/
Магазин обуви: каталог немецкая женская обувь Liska (Лиска), женская обувь для дома Liska (Лиска), женская обувь спартак Liska (Лиска), женская обувь маленькая Liska (Лиска), купить резиновая обувь женская Liska (Лиска). Сайт: http://zimnyayaobuv.ru/
Магазин обуви: женская обувь экко Liska (Лиска), таблица соответствия женской обуви Liska (Лиска), женская обувь найк Liska (Лиска), женская обувь на автозаводской Liska (Лиска), женская обувь may Liska (Лиска). Сайт: http://zimnyaya-obuv.ru/
Мы предлагаем: как пользоваться xrumer, xrumer 5.0 бесплатно, xrumer 7.0 elite скачать бесплатно, скачать xrumer 5.0 palladium, скачать xrumer 5.0. Программа XRumer (хрумер аналог). Сайт http://x-rumer.ru/
hi there www.octopuse.com blogger found your site via Google but it was hard to find and I see you could have more visitors because there are not so many comments yet. I have discovered website which offer to dramatically increase traffic to your blog http://xrumerservice.org they claim they managed to get close to 1000 visitors/day using their services you could also get lot more targeted traffic from search engines as you have now. I used their services and got significantly more visitors to my blog. Hope this helps
They offer most cost effective backlink service Take care. Jason
Магазин электронных сигарет: электронные сигареты ego отзывы, в контакте электронные сигареты, электронная сигарета slb, наполнитель для электронной сигареты, электронные сигареты наркотик.
Магазин электронных сигарет: электронные сигареты тн вэд, ереван плаза электронные сигареты, электронные сигареты салехард, продажа электронных сигарет барнаул, электронная сигарета totally wicked. Сайт http://elektronnyesigarety.tv/
Магазин электронных сигарет: электронные сигареты в астрахани, сколько можно курить электронную сигарету, электронные сигареты на ввц, электронные сигареты в минске купить, электронная сигарета denshi tabaco turbo. Сайт http://elektronnyesigarety.tv/
Obedient bye, sentimental alternative other
Lofty bye, considerate chum