Hi
I have a problem adding my Windows Server 2019 to the additional AD server, I try to promote my server, got that error message...
The operation failed because:
Active Directory Domain Services could not create the NTDS Settings object for this Active Directory Domain Controller CN=NTDS Settings,CN=XXX ,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=XXX,DC=LOCAL on the remote AD DC XXX.XXX.LOCAL. Ensure the provided network credentials have sufficient permissions.
"The Directory Service cannot perform the requested operation because a domain rename operation is in progress."
I have got that solution, without success :-(
Resolution
To resolve this issue, follow these steps:
- Verify that all the steps and conditions in the "Resolution" section of Knowledge Base article 2002413 are true for your environment.
- If domain controller promotion still fails even after you make sure that the user also has the SeEnableDelegationPrivilege permission, check ADSIEdit.msc to verify the user's effective permissions for the domain partition:
- Click Start, click Run, and then type adsiedit.msc.
- Expand Default naming context, right-click DC=domain,DC=com, and then click Properties.
- On the Security tab, click the Advanced button.
- On the Effective Access tab, enter the user or group name of the user who is performing the operation that's failing in DCPromo.
- Confirm whether the Add/remove replica in domain control access permission has been granted.
- If the Add/Remove Replica In Domain permission is missing for the user or group, add it by using ADSIEdit.msc:
- Click Start, click Run, and then type adsiedit.msc.
- Expand Default naming context, right-click DC=domain,DC=com, and then click Properties.
- On the Security tab, click the Advanced button.
- On the Permissions tab, add the Add/remove replica in domain control access permission for the desired user or group as follows:
- Type: Allow
- Applies to: This object only
Anyone with more ideas ??
Please help
--- Sokoban ----