Problem in Domain Controller sync and transfer role

Lanny HO 0 Reputation points
2023-03-23T03:17:35.18+00:00

Hi, our environment has a DC and OS version is 2008R2, I created a new VM server and promote to DC, but this is very weird that both seem cannot connect, when one PC join the domain, only old DC (2008r2) can find its computer object, also, I tried to update the DNS record in new DC, the old DC doesn't sync anything, vice versa, but 5 roles PDC,RID and others are in new DC, how can I transfer the roles to old DC? Or any other alternative way to fix the problem? Here is the current Role state in old DC (2008R2)

testdc-error-2023-Mar-23

And in new DC, the same name and shown cannot transfer

testdc02-error-2023-Mar-23

Running the "netdom query fsmo" in CMD and shows the result

netdomquery-2023-Mar-23

Please give me any ideas... many thanks!

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,205 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 43,966 Reputation points
    2023-03-23T16:34:35.08+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having query\issues related to DC sync and transfer.

    It looks there is issues with AD replication health due to AD configuration are not synced.

    1. At the command prompt, type the following commands, and then press ENTER

    dcdiag /v /c /d /e /s: > c:\dcdiag.txt

    repadmin /replsum

    dcdiag /test:dns /s: /dnsbasic

    repadmin /syncall /aped

    1. Please verify DNS settings and its ip preferred DNS ip should be pointed to one of your working DC.
    2. Disable any Antivirus program or Windows firewall you may have for temporary purpose.
    3. Verify date and time should be correct and synced.
    4. Run Active Directory Replication Status tool to check overall health of AD Replication : from https://www.microsoft.com/en-us/download/details.aspx?id=30005

    Reference :

    https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/troubleshoot/troubleshooting-active-directory-replication-problems

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/common-active-directory-replication-errors

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments