Move Operations Master Role with NTDSUTIL
What would happen if we didn't either use dcpromo to demote the first domain controller before removing it from the domain or move each Operations Master role seperately before removing the computer?
We could use command line tool to assign the Operations Master roles to a new DC.
1. Log on to a member server or domain controller with an administrator account.
2. Click “Start”, click “run”, and enter “cmd“
3. Enter “ntdsutil“
4. Enter “roles“
5. Enter “connections“
6. Enter “connect to server [ServerName]“
7. Enter “quit“ to return to the roles level
8. Enter “seize [RoleName] “ (press ? to see all the roles)
9. Click “Yes“ on the confirmation dialog
10. Reboot Server
With out a proper operations master, you can no longer add new user accounts. Your domain is basically down.
SEIZE OPERATIONS MASTER ROLE
-------------------------------------------
1. Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Sites and Services.
2. Double-click Sites in the left pane, and then locate the appropriate site or click Default-first-site-name if no other sites are available.
3. Open the Servers folder, and then click the domain controller.
4. In the domain controller's folder, double-click NTDS Settings.
5. On the Action menu, click Properties.
6. On the General tab, view the Global Catalog check box to see if it is selected.

Recent comments
2 years 39 weeks ago
2 years 49 weeks ago
2 years 49 weeks ago
3 years 3 weeks ago
3 years 9 weeks ago
3 years 11 weeks ago
3 years 23 weeks ago
3 years 23 weeks ago
3 years 24 weeks ago
3 years 39 weeks ago