Article ID: 232070 - Last Review: September 11, 2009 - Revision: 7.0 When you run Dcpromo.exe to create a replica domain controller, you receive the "Failed to modify the necessary properties for the machine account. Access is denied" error messageThis article was previously published under Q232070 SYMPTOMSWhen you run Dcpromo.exe to create a replica domain controller, you receive one of the following error messages in Dcpromo.exe: Error message 1 Failed to modify the necessary properties for the machine account. Access is denied. Error message 2 Error - The Active Directory Installation Wizard was unable to convert the computer account <Computer Name>$ to a domain controller account. (5) Examination of the Dcpromoui.log file indicates that the initial part of the promotion was successful (this is also verified because the computer becomes a member server in the domain), but that the promotion to domain controller did not succeed because Dcpromo.exe could not modify the machine account. CAUSE This problem can occur if the account that is used for the promotion operation has not been assigned the "Delegation Privilege" right. Or, if this right has been assigned, the policy has not propagated yet, possibly because of replication latency. By default, only members in the Administrators group have the "Delegation Privilege" right. RESOLUTION To resolve this problem, use an account in the Administrators group, or add the appropriate account to the Administrators group. To grant this right to another user or group, set the delegation privilege on the Group Policy object:
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. MORE INFORMATION The Dcpromoui.log file reports an error similar to the one shown below. In the following example, a replica/backup domain controller is attempting to be installed: dcpromoui t:0x490 00685 Exit doProgressLoop dcpromoui t:0x490 00686 Exit DS::CreateReplica dcpromoui t:0x490 00687 Exception caught dcpromoui t:0x490 00688 catch completed dcpromoui t:0x490 00689 handling exception dcpromoui t:0x490 00690 Active Directory Installation Failed dcpromoui t:0x490 00691 Enter GetErrorMessage 80070005 dcpromoui t:0x490 00692 Exit GetErrorMessage 80070005 dcpromoui t:0x490 00693 Access is denied. Failed to modify the necessary properties for the machine account MYDC$ "Access is denied. " 09/12 09:33:14 [INFO] Error - The Active Directory Installation Wizard was unable to convert the computer account <machinename>$ to a domain controller account. (5) 09/12 09:33:15 [INFO] NtdsInstall for <domainname> returned 5 09/12 09:33:15 [INFO] DsRolepInstallDs returned 5 09/12 09:33:15 [ERROR] Failed to install to Directory Service (5) APPLIES TO
| Article Translations
|
Back to the top
