{"id":1586,"date":"2017-09-01T16:58:35","date_gmt":"2017-09-01T23:58:35","guid":{"rendered":"http:\/\/jim-zimmerman.com\/?p=1586"},"modified":"2017-09-01T16:58:35","modified_gmt":"2017-09-01T23:58:35","slug":"windows-2012-r2-seize-roles-from-failed-domain-controller","status":"publish","type":"post","link":"https:\/\/jim-zimmerman.com\/?p=1586","title":{"rendered":"Windows 2012 R2 &#8211; seize roles from failed domain controller."},"content":{"rendered":"<p>I had to deal with a really neglected domain, and found that all the FSMO roles were on a domain controller that no longer functioned or existed.  I had to get the roles on the working server.  Using convental methods in the UI or the ntdsutil to transfer the roles succeeded.  I had no choice, but to seize all the roles from the missing server.  All of these tasks were completed on the domain controller I wanted the roles on as the domain\\Administrator.<\/p>\n<p>Check the current roles holders:<\/p>\n<blockquote><p>C:\\><strong>netdom query fsmo<\/strong><br \/>\nSchema master               MYOLDDC1.mydomain.local<br \/>\nDomain naming master        MYOLDDC1.mydomain.local<br \/>\nPDC                         MYOLDDC1.mydomain.local<br \/>\nRID pool manager            MYOLDDC1.mydomain.local<br \/>\nInfrastructure master       MYOLDDC1.mydomain.local<br \/>\nThe command completed successfully.<\/p><\/blockquote>\n<p>Enter the ntdsutil utility by entering ntdsutil:<\/p>\n<blockquote><p>C:\\><strong>ntdsutil<\/strong><\/p><\/blockquote>\n<p>And then roles:<\/p>\n<blockquote><p>ntdsutil: <strong>roles<\/strong><\/p><\/blockquote>\n<p>You see the options by entering a question mark at the &#8220;fsmo maintenance&#8221; prompt.  Obviously, this where you also transfer the roles if possible (not so in my case):<\/p>\n<blockquote><p>fsmo maintenance: <strong>?<\/strong><\/p>\n<p> ?                             &#8211; Show this help information<br \/>\n Connections                   &#8211; Connect to a specific AD DC\/LDS instance<br \/>\n Help                          &#8211; Show this help information<br \/>\n Quit                          &#8211; Return to the prior menu<br \/>\n Seize infrastructure master   &#8211; Overwrite infrastructure role on connected server<br \/>\n Seize naming master           &#8211; Overwrite Naming Master role on connected server<br \/>\n Seize PDC                     &#8211; Overwrite PDC role on connected server<br \/>\n Seize RID master              &#8211; Overwrite RID role on connected server<br \/>\n Seize schema master           &#8211; Overwrite schema role on connected server<br \/>\n Select operation target       &#8211; Select sites, servers, domains, roles and<br \/>\n                                 naming contexts<br \/>\n Transfer infrastructure master &#8211; Make connected server the infrastructure master<br \/>\n Transfer naming master        &#8211; Make connected server the naming master<br \/>\n Transfer PDC                  &#8211; Make connected server the PDC<br \/>\n Transfer RID master           &#8211; Make connected server the RID master<br \/>\n Transfer schema master        &#8211; Make connected server the schema master<\/p><\/blockquote>\n<p>Seize the roles one at a time.  Each takes a while to complete, but they do.:<\/p>\n<blockquote><p>fsmo maintenance: <strong>seize pdc<\/strong><br \/>\nAttempting safe transfer of PDC FSMO before seizure.<br \/>\nldap_modify_sW error 0x34(52 (Unavailable).<br \/>\nLdap extended error message is 000020AF: SvcErr: DSID-03210617, problem 5002 (UNAVAILABLE), data 1722<\/p>\n<p>Win32 error returned is 0x20af(The requested FSMO operation failed. The current FSMO holder could not be contacted.)<br \/>\n)<br \/>\nDepending on the error code this may indicate a connection,<br \/>\nldap, or role transfer error.<br \/>\nTransfer of PDC FSMO failed, proceeding with seizure &#8230;<br \/>\nServer &#8220;mydc01&#8221; knows about 5 roles<br \/>\nSchema &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nNaming Master &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nPDC &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nRID &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nInfrastructure &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nfsmo maintenance:<br \/>\nfsmo maintenance: <strong>seize naming master<\/strong><br \/>\nAttempting safe transfer of domain naming FSMO before seizure.<br \/>\nldap_modify_sW error 0x34(52 (Unavailable).<br \/>\nLdap extended error message is 000020AF: SvcErr: DSID-0321041F, problem 5002 (UNAVAILABLE), data 1722<\/p>\n<p>Win32 error returned is 0x20af(The requested FSMO operation failed. The current FSMO holder could not be contacted.)<br \/>\n)<br \/>\nDepending on the error code this may indicate a connection,ldap, or role transfer error.<br \/>\nTransfer of domain naming FSMO failed, proceeding with seizure &#8230;<br \/>\nServer &#8220;mydc01&#8221; knows about 5 roles<br \/>\nSchema &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nNaming Master &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nPDC &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nRID &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nInfrastructure &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nfsmo maintenance: <strong>seize rid master<\/strong><br \/>\nAttempting safe transfer of RID FSMO before seizure.<br \/>\nldap_modify_sW error 0x34(52 (Unavailable).<br \/>\nLdap extended error message is 000020AF: SvcErr: DSID-03210F70, problem 5002 (UNAVAILABLE), data 1722<\/p>\n<p>Win32 error returned is 0x20af(The requested FSMO operation failed. The current FSMO holder could not be contacted.)<br \/>\n)<br \/>\nDepending on the error code this may indicate a connection, ldap, or role transfer error.<br \/>\nTransfer of RID FSMO failed, proceeding with seizure &#8230;<br \/>\nSearching for highest rid pool in domain<br \/>\nServer &#8220;mydc01&#8221; knows about 5 roles<br \/>\nSchema &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nNaming Master &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nPDC &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nRID &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nInfrastructure &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nfsmo maintenance: s<strong>eize schema master<\/strong><br \/>\nAttempting safe transfer of schema FSMO before seizure.<br \/>\nldap_modify_sW error 0x34(52 (Unavailable).<br \/>\nLdap extended error message is 000020AF: SvcErr: DSID-0321041F, problem 5002 (UNAVAILABLE), data 1722<\/p>\n<p>Win32 error returned is 0x20af(The requested FSMO operation failed. The current FSMO holder could not be contacted.)<br \/>\n)<br \/>\nDepending on the error code this may indicate a connection, ldap, or role transfer error.<br \/>\nTransfer of schema FSMO failed, proceeding with seizure &#8230;<br \/>\nServer &#8220;mydc01&#8221; knows about 5 roles<br \/>\nSchema &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nNaming Master &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nPDC &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nRID &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nInfrastructure &#8211; CN=NTDS Settings,CN=MYOLDDC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nfsmo maintenance: <strong>seize infrastructure master<\/strong><br \/>\nAttempting safe transfer of infrastructure FSMO before seizure.<br \/>\nldap_modify_sW error 0x34(52 (Unavailable).<br \/>\nLdap extended error message is 000020AF: SvcErr: DSID-0321041F, problem 5002 (UNAVAILABLE), data 1722<\/p>\n<p>Win32 error returned is 0x20af(The requested FSMO operation failed. The current FSMO holder could not be contacted.)<br \/>\n)<br \/>\nDepending on the error code this may indicate a connection, ldap, or role transfer error.<br \/>\nTransfer of infrastructure FSMO failed, proceeding with seizure &#8230;<br \/>\nServer &#8220;mydc01&#8221; knows about 5 roles<br \/>\nSchema &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nNaming Master &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nPDC &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nRID &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nInfrastructure &#8211; CN=NTDS Settings,CN=MYDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=mydomain,DC=local<br \/>\nfsmo maintenance:<\/p><\/blockquote>\n<p>Check to role locations to verify using netdom again:<\/p>\n<blockquote><p>C:\\>netdom query fsmo<br \/>\nSchema master               MYDC01.mydomain.local<br \/>\nDomain naming master        MYDC01.mydomain.local<br \/>\nPDC                         MYDC01.mydomain.local<br \/>\nRID pool manager            MYDC01.mydomain.local<br \/>\nInfrastructure master       MYDC01.mydomain.local<br \/>\nThe command completed successfully.<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>I had to deal with a really neglected domain, and found that all the FSMO roles were on a domain controller that no longer functioned or existed. I had to get the roles on the working server. Using convental methods in the UI or the ntdsutil to transfer the roles succeeded. I had no choice, [&#038;hellip<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[221,138,457,36],"class_list":["post-1586","post","type-post","status-publish","format-standard","hentry","category-documentation","tag-domain-controller","tag-roles","tag-seize","tag-windows"],"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=\/wp\/v2\/posts\/1586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1586"}],"version-history":[{"count":1,"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=\/wp\/v2\/posts\/1586\/revisions"}],"predecessor-version":[{"id":1587,"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=\/wp\/v2\/posts\/1586\/revisions\/1587"}],"wp:attachment":[{"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jim-zimmerman.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}