DCPROMO promotion of a Windows Server 2008 or Windows Server 2008 R2 member computer to a replica DC fails with the following error:
Title: Windows Security
Message Text: Network Credentials
The operation failed because: The Active Directory Domain Services Installation Wizard was unable to convert the computer account <hostname>$ to an Active Directory Domain Controller account. "Access is denied"
DCPROMO Demotion can fail with the same error:
Title: Windows Security
Message Text: Network Credentials
The operation failed because: Active Directory Domain Services could not configure the computer account <hostname>$ to the remote Active Directory Domain Controller account <fully qualified name of helper DC>. "Access is denied"
The user account used to execute DCPROMO has not been granted the “Enable computer and user accounts to be trusted for delegation” user right
DCPROMO.LOG and DCPROMOUI.LOG from promotion
The DCPROMO.LOG contains the following
[INFO] Creating the NTDS Settings object for this Active Directory Domain Controller on the remote AD DC <helperDC>.contoso.com...
[INFO] Replicating the schema directory partition
…
[INFO] Replicated the schema container.
[INFO] Active Directory Domain Services updated the schema cache.
[INFO] Replicating the configuration directory partition
…
[INFO] Replicated the configuration container.
[INFO] Error - The Active Directory Domain Services Installation Wizard was unable to convert the computer account <DC being promoted>$ to an Active Directory Domain Controller account. (5)
[INFO] EVENTLOG (Error): NTDS General / Internal Processing : 1168
Internal error: An Active Directory Domain Services error has occurred.
Additional Data
Error value (decimal):
-1073741823
Error value (hex):
c0000001
Internal ID:
300162a
[INFO] EVENTLOG (Informational): NTDS General / Service Control : 1004
Active Directory Domain Services was shut down successfully.
[INFO] NtdsInstall for a.com returned 5
[INFO] DsRolepInstallDs returned 5
[ERROR] Failed to install to Directory Service (5)
[INFO] Starting service NETLOGON
[INFO] Configuring service NETLOGON to 2 returned 0
[INFO] The attempted domain controller operation has completed
[INFO] DsRolepSetOperationDone returned 0
The DCPROMOUI.LOG contains the following
Calling DsRoleGetDcOperationResults
Error 0x0 (!0 => error)
Operation results:
OperationStatus : 0x5 !0 => error
DisplayString : The Active Directory Domain Services Installation Wizard was unable to convert the computer account <DC being promoted>$ to an Active Directory Domain Controller account.
ServerInstalledSite : (null)
OperationResultsFlags: 0x0
Enter ProgressDialog::UpdateText The Active Directory Domain Services Installation Wizard was unable to convert the computer account <dc being promoted>$ to an Active Directory Domain Controller account.
Enter State::SetOperationResultsMessage The Active Directory Domain Services Installation Wizard was unable to convert the computer account <dc being promoted>$ to an Active Directory Domain Controller account.
Enter State::SetOperationResultsFlags 0x0
Exception caught
catch completed
handling exception
Enter State::ClearHiddenWhileUnattended
Enter EnableConsoleLocking
Enter RegistryKey::Create SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Enter RegistryKey::SetValue-DWORD DisableLockWorkstation
Enter State::SetOperationResults result FAILURE
Enter ProgressDialog::UpdateText
Enter State::IsOperationRetryAllowed
true
credentials were invalid, hr=0x80070005
Enter GetErrorMessage 80070005
Enter State::GetOperationResultsMessage The Active Directory Domain Services Installation Wizard was unable to convert the computer account <dc being promoted>$ to an Active Directory Domain Controller account.
Enter State::GetOperation REPLICA
Enter State::GetReplicaDomainDNSName <target dns domain name>
DCPROMO.LOG and DCPROMOUI.LOGS from Demotion
DCPROMO.LOG text is similar to:
[INFO] Uninstalling the Directory Service
[INFO] Invoking NtdsDemote
…
[INFO] Removing Active Directory Domain Services objects that refer to the local Active Directory Domain Controller from the remote Active Directory Domain Controller <DNS domain>...
[INFO] Error - Active Directory Domain Services could not configure the computer account <dc being demoted>$ on the remote Active Directory Domain Controller <helper DC>.<DNS domain>. (5)
[INFO] NtdsDemote returned 5
[INFO] DsRolepDemoteDs returned 5
[ERROR] Failed to demote the directory service (5)
….
DCPROMOUI.LOG text is similar to:
….
OperationStatus : 0x5 !0 => error
DisplayString : Active Directory Domain Services could not configure the computer account <dc name>$ on the remote Active Directory Domain Controller <helper DC>.<dns domain>.
ServerInstalledSite : (null)
OperationResultsFlags: 0x0
Enter ProgressDialog::UpdateText Active Directory Domain Services could not configure the computer account <dc name>$ on the remote Active Directory Domain Controller VM1-W7.a.com.
Enter State::SetOperationResultsMessage Active Directory Domain Services could not configure the computer account <dc name>$ on the remote Active Directory Domain Controller <helper DC>.<DNS domain>.
Enter State::SetOperationResultsFlags 0x0
…
credentials were invalid, hr=0x80070005
Enter GetErrorMessage 80070005
Enter State::GetOperationResultsMessage Active Directory Domain Services could not configure the computer account <dc name>$ on the remote Active Directory Domain Controller <helper DC>.<DNS domain>.
Enter State::GetOperation DEMOTE
Enter State::GetParentDomainDnsName
Note This is a "FAST PUBLISH" article created directly from within the Microsoft support organization. The information contained herein is provided as-is in response to emerging issues. As a result of the speed in making it available, the materials may include typographical errors and may be revised at any time without notice. See
Terms of Use
(http://go.microsoft.com/fwlink/?LinkId=151500)
for other considerations.
Article ID: 2002413 - Last Review: October 26, 2012 - Revision: 6.0
Applies to
- Microsoft Windows 2000 Server
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003 R2 Standard Edition (32-bit x86)
- Windows Server 2008 Standard
- Windows Server 2008 R2 Standard