Problem solve Get help with specific problems with your technologies, process and projects.

Our DC is not allowing us to add an ADC to our domain

Our Windows 2000 server is configured as a DC with DNS and DHCPserver. I tried to add an ADC to our domain but DC is not allowing me to do this. An "Access Denied" error always shows up. I tried all the articles on the knowledge base but am still having the problem. I didn't have the system state data backup. Now I am planning to implement a new Windows 2000 server with the same domain name and server name with DNS and DHCP. I want to migrate all the users, groups, ou and ACl, SID to the new server. I tried using the ADMT tool but it is not allowing me to copy this information to the same domain name. Please help me out.
You will not be able to copy the user from the old to the new domain since the domain names are the same. However, you are likely to still be able to repair the problem with the existing domain. It is highly likely that the problem with the existing domain is one of the following:

  1. The fully qualified domain name of the machine does not match the domain name. That is, if you run IPCONFIG /ALL on the DC you will see a FQDN of server.company.com, and if you look at the domain name in Active Directory User and Computers you will see MYcompany.com. Thus, the machine is unable to find itself. Since this is a Windows 2000 domain (likely upgraded from a Windows NT 4.0 domain) you are in pretty bad shape. You might consider upgrading to Windows 2003 and then using the domain rename tool to rename the server's FQDN. Alternatively, if you have a backup of the NT 4.0 domain (if that is where this all originated) you can restore that, fix the FQDN and then upgrade to Windows 2000 again.
  2. You have a DNS issue. That's right, if the DNS is unable to locate all of the SRV (server records) you can get odd results. Run the DCDIAG.exe on the server and see what the results are.
  3. Someone has put a second domain with the same name on the same network. This will lead to all sorts of confusion for the client systems, and any system that is attempting to locate the server. DCDIAG.exe should offer a clue as to whether this is the case.

Dig Deeper on Windows administration tools

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.