question

Racheal-6539 avatar image
0 Votes"
Racheal-6539 asked Racheal-6539 answered

How to Seize schema master

HI ,

I need to change FSMO role owner of my AD LDS instance

I have created replication between old servers (a/B) and new servers (c/d)

C is having FSMO role ownwe as A . How can i change it?

when i tried Move-ADDirectoryServerOperationMasterRole command it throws error

Move-ADDirectoryServerOperationMasterRole : Cannot find directory server with identity: 'xx-xx-xx'.

Any help to change FSMO roles will be much appreciated.

Thanks in advance

windows-server-2016
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered Racheal-6539 edited

You can follow along here to seize roles to another healthy domain controller.
https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds

--please don't forget to Accept as answer if the reply is helpful--


· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HI @DSPatrick ,

Thanks for the reply!

Yes am following that page but I'm facing below issue .

83791-fsmo.png

need to change FSMO roles in schema as attached from 9002000xxxx to SOK-24-xxxx

S C:\windows\system32> Move-ADDirectoryServerOperationMasterRole -Identity SOK-24-xxxx$Uxxxxxx -OperationMas
erRole domainnamingmaster -Force
ove-ADDirectoryServerOperationMasterRole : Unable to find a default server with Active Directory Web Services running.
t line:1 char:1
Move-ADDirectoryServerOperationMasterRole -Identity SOK-24-xxxx$Uxxxxxx ...
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ResourceUnavailable: (SOK-24-34-15:ADDirectoryServer) [Move-ADDirector...ationMasterRole
], ADServerDownException
+ FullyQualifiedErrorId : ActiveDirectoryServer:1355,Microsoft.ActiveDirectory.Management.Commands.MoveADDirectory
ServerOperationMasterRole


0 Votes 0 ·
fsmo.png (100.7 KiB)
DSPatrick avatar image
0 Votes"
DSPatrick answered Racheal-6539 commented

I'd check this one.
https://theitbros.com/unable-to-find-a-default-server-with-active-directory-web-services-running/

--please don't forget to Accept as answer if the reply is helpful--





· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HI @DSPatrick ,

Thanks for the link.

I tried those commands

PS C:\windows\system32> Import-Module ActiveDirectory
PS C:\windows\system32>
Err occur from below command only


PS C:\windows\system32> Move-ADDirectoryServerOperationMasterRole -Identity SOK-24-xxxx$Uxxxxxx -OperationMasterRole
schemaMaster -Server SOK-24-xxxx:50000
Move-ADDirectoryServerOperationMasterRole : Cannot find directory server with identity: 'SOK-24-xxxx'.
At line:1 char:1
+ Move-ADDirectoryServerOperationMasterRole -Identity SOK-24-xxxx$Uxxx ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (SOK-24-xxxx:ADDirectoryServer) [Move-ADDirector...ationMasterRole], ADIdentityNotFoundException
+ FullyQualifiedErrorId : ActiveDirectoryCmdlet:Microsoft.ActiveDirectory.Management.ADIdentityNotFoundException,Microsoft.ActiveDirectory.Management.
Commands.MoveADDirectoryServerOperationMasterRole






0 Votes 0 ·
FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered Racheal-6539 edited

Hi,

Welcome to share here!

Did you tried to use the Ntdsutil to seize or transfer roles?
Still any errors?
If there are any progresses ,welcome to share here!
Best Regards,

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

hi @FanFan-MSFT

Yes i tried but i get below message so i tried powershell method.

C:\Windows\System32>Ntdsutil
'Ntdsutil' is not recognized as an internal or external command,
operable program or batch file.

My issue is my AD LDS instance schema still referring to old server even after replication is stopped.



Thanks

0 Votes 0 ·
DSPatrick avatar image
0 Votes"
DSPatrick answered Racheal-6539 commented

'Ntdsutil' is not recognized as an internal or external command,

Are you trying from another healthy domain controller?

84243-image.png



image.png (132.6 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @DSPatrick ,

ntdsutil.exe is missing.
84632-ntds.png



Are you trying from another healthy domain controller? Am trying in new server C.

because C has the schema from A and when i check replication between C & D

C default web site shows A

C:\>repadmin /showrepl localhost:50000
Default-First-Site-Name*Server-A$instance1*
DSA Options: (none)
Site Options: (none)

Thanks in advance.

0 Votes 0 ·
ntds.png (94.0 KiB)
DSPatrick avatar image
0 Votes"
DSPatrick answered Racheal-6539 commented

Please run (old servers);

Dcdiag /v /c /d /e /s:%computername% >c:\dcdiag.log
repadmin /showrepl >C:\repl.txt
ipconfig /all > C:\dc1.txt
ipconfig /all > C:\dc2.txt

then put unzipped text files up on OneDrive and share a link.





· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @DSPatrick ,

There are some DC issue between old and new server as discussed here

As per Infra team, old servers has some vulnerability protocol and that has been disabled in new server so connectivity fails.
so I have done the below steps in new server

  1. deleted replica instance

  2. created new AD LDS instance

  3. took backup of data file from old server and pasted in new server

  4. created replication between new server C & D

  5. checked replication in Server C & D but server C still has dafault first site mapped to old server A

  6. checked Schema master for FSMO roles from ADSI EDIT but it has FSMOroleOwner as old server A
    7.while trying to seize the schema roles am getting this issue

Here is the one drive link


Thanks.

0 Votes 0 ·
DSPatrick avatar image
0 Votes"
DSPatrick answered DSPatrick edited

Ok, I just now realized this is the same issue with the same problems (multi-homed domain controllers, unknown DNS being used) as the thread here.
https://docs.microsoft.com/en-us/answers/questions/327802/the-attempt-to-establish-a-replication-link-for-th.html





· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @DSPatrick ,

Yeah linked to same issue.

But currently am not connecting to old server from new server am just executing the command
Move-ADDirectoryServerOperationMasterRole in new server and getting issues with powershell command itself .

eg:
PS C:\> Get-ADDomain
Get-ADDomain : Unable to find a default server with Active Directory Web Services running.

when i check the services its running.

What am i missing here?

Thanks

0 Votes 0 ·
DSPatrick avatar image
0 Votes"
DSPatrick answered FanFan-MSFT commented

Still have multi-homed domain controllers, unknown DNS being used




· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
Welcome to share your current situation if there are any updates.
Please feel free to let us know if you need further assistance.
 
Best Regards,

0 Votes 0 ·

If the information was helpful, you can accept it as answer to end this thread.
Best Regards,

0 Votes 0 ·
Racheal-6539 avatar image
0 Votes"
Racheal-6539 answered
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.