In our environment we have 6 read / write domain controllers and many read only domain controllers. Recently I have noticed that every time we demote a server the demotion process hangs. It looks to have removed the read only domain controller but the promotion
always seems to hang at this point.
Any insight to what could be causing this would be appreciated.
The following logs may help identify the problem.
DCPROMO.txt
10/03/2014 09:54:41 [INFO] Request for demotion of domain controller
10/03/2014 09:54:41 [INFO] DnsDomainName (NULL)
10/03/2014 09:54:41 [INFO] ServerRole 1
10/03/2014 09:54:41 [INFO] Account (NULL) 10/03/2014 09:54:41 [INFO]Options 128
10/03/2014 09:54:41 [INFO] LastDcInDomain FALSE
10/03/2014 09:54:41 [INFO] Forced Demote FALSE
10/03/2014 09:54:41 [INFO] Stage 2 only FALSE
10/03/2014 09:54:41 [INFO] Start the worker task
10/03/2014 09:54:41 [INFO] Request for demotion returning 0
10/03/2014 09:54:41 [INFO] Reading domain policy from the local machine
10/03/2014 09:54:41 [INFO] Searching for a domain controller for the domain DPI.NSW.GOV.AU
10/03/2014 09:54:41 [INFO] Searching for a domain controller for the domain DPI.NSW.GOV.AU that contains the account WGONFP1$
10/03/2014 09:54:41 [INFO] Located domain controller ORANDC1.DPI.NSW.GOV.AU for domain DPI.NSW.GOV.AU
10/03/2014 09:54:41 [INFO] Support Dc in DPI.NSW.GOV.AU is ORANDC1.DPI.NSW.GOV.AU
10/03/2014 09:54:41 [INFO] Located domain controller ORANDC1.DPI.NSW.GOV.AU for domain DPI.NSW.GOV.AU
10/03/2014 09:54:43 [INFO] Preparing the directory service for demotion
10/03/2014 09:54:47 [INFO] Started system volume demotion on enterprise
10/03/2014 09:54:47 [INFO] Read the LSA policy information from the local machine
10/03/2014 09:54:47 [INFO] Informed NETLOGON to deregister records
10/03/2014 09:54:47 [INFO] Stopping service NETLOGON
10/03/2014 09:54:49 [INFO] Configuring service NETLOGON to 1 returned 0
10/03/2014 09:54:49 [INFO] Stopped NETLOGON
10/03/2014 09:54:49 [INFO] Configuring service NTDS
10/03/2014 09:54:49 [INFO] Configuring service NTDS to 2112 returned 0
10/03/2014 09:54:49 [INFO] Stopping service IsmServ
10/03/2014 09:54:51 [INFO] Configuring service IsmServ to 577 returned 0
10/03/2014 09:54:51 [INFO] Stopping service kdc
10/03/2014 09:54:52 [INFO] Configuring service kdc to 65 returned 0
10/03/2014 09:54:52 [INFO] Stopping service NETLOGON
10/03/2014 09:54:52 [INFO] Configuring service NETLOGON to 273 returned 0
10/03/2014 09:54:52 [INFO] Configuring service NtFrs
10/03/2014 09:54:52 [INFO] Configuring service NtFrs to 2304 returned 0
10/03/2014 09:54:52 [INFO] Configuring service DFSR
10/03/2014 09:54:52 [INFO] Configuring service DFSR to 2304 returned 0
10/03/2014 09:54:52 [INFO] Configured domain controller services
10/03/2014 09:54:52 [INFO] Uninstalling the Directory Service
10/03/2014 09:54:52 [INFO] Invoking NtdsDemote
10/03/2014 09:54:52 [INFO] Preparing the security account manager (SAM) and Active Directory Domain Services for demotion...
10/03/2014 09:54:52 [INFO] Validating the removal of this Active Directory Domain Controller...
10/03/2014 09:54:52 [INFO] Authenticating supplied credentials
10/03/2014 09:54:52 [INFO] Creating new local account information...
10/03/2014 09:54:52 [INFO] Creating a new local security account manager (SAM) database...
10/03/2014 09:54:52 [INFO] Setting the new Local Security Authority (LSA) account information...
10/03/2014 09:54:52 [INFO] Removing Active Directory Domain Services objects that refer to the local Active Directory Domain Controller from the remote Active Directory Domain Controller ORANDC1.DPI.NSW.GOV.AU...
10/03/2014 09:54:58 [INFO] Removing LDAP and remote procedure call (RPC) access to Active Directory Domain Services...
10/03/2014 09:55:00 [INFO] Completing removal of Active Directory Domain Services, SAM and LSA...
10/03/2014 09:55:00 [INFO] NtdsDemote returned 0
10/03/2014 09:55:00 [INFO] DsRolepDemoteDs returned 0
10/03/2014 09:55:00 [INFO] This machine is no longer a domain controller
10/03/2014 09:55:01 [INFO] Successfully informed DNS Server to prepare for demotion
10/03/2014 09:55:04 [ERROR] Setting security on server files failed with 2
DCPROMOOUI.txt
Last log lines
dcpromoui 10EC.6F4 09AC 09:54:41.121 Enter Computer::IsDomainController WGONFP1
dcpromoui 10EC.6F4 09AD 09:54:41.121 Enter Computer::GetNetbiosName
dcpromoui 10EC.6F4 09AE 09:54:41.121 WGONFP1
dcpromoui 10EC.6F4 09AF 09:54:41.121 Enter Computer::GetRole WGONFP1
dcpromoui 10EC.6F4 09B0 09:54:41.121 role: 4
dcpromoui 10EC.6F4 09B1 09:54:41.121 is a domain controller
dcpromoui 10EC.6F4 09B2 09:54:41.121 Enter DoPreOperationStuffWithGUI
dcpromoui 10EC.6F4 09B3 09:54:41.121 Enter State::GetOperation DEMOTE
dcpromoui 10EC.6F4 09B4 09:54:41.121 Enter State::GetOperation DEMOTE
dcpromoui 10EC.6F4 09B5 09:54:41.121 Enter DS::DemoteDC
dcpromoui 10EC.6F4 09B6 09:54:41.121 Enter State::IsLastDCInDomain false
dcpromoui 10EC.6F4 09B7 09:54:41.121 Enter State::IsForcedDemotion false
dcpromoui 10EC.6F4 09B8 09:54:41.121 Enter State::GetAdminPassword
dcpromoui 10EC.6F4 09B9 09:54:41.121 Enter State::GetAppPartitionList
dcpromoui 10EC.6F4 09BA 09:54:41.121 Enter AllocateAppPartitionList
dcpromoui 10EC.6F4 09BB 09:54:41.121 Calling DsRoleDemoteDc
dcpromoui 10EC.6F4 09BC 09:54:41.121 lpServer : (null)
dcpromoui 10EC.6F4 09BD 09:54:41.121 lpDnsDomainName : (null)
dcpromoui 10EC.6F4 09BE 09:54:41.121 ServerRole : DsRoleServerMember
dcpromoui 10EC.6F4 09BF 09:54:41.121 lpAccount : (null)
dcpromoui 10EC.6F4 09C0 09:54:41.121 Options : 0x80
dcpromoui 10EC.6F4 09C1 09:54:41.121 fLastDcInDomain : false
dcpromoui 10EC.6F4 09C2 09:54:41.121 cRemoteNCs : 0
dcpromoui 10EC.6F4 09C3 09:54:41.355 HRESULT = 0x00000000
dcpromoui 10EC.6F4 09C4 09:54:41.355 Enter DeallocateAppPartitionList
dcpromoui 10EC.6F4 09C5 09:54:41.355 Enter DoProgressLoop
dcpromoui 10EC.6F4 09C6 09:54:41.355 Enter State::GetOperation DEMOTE
dcpromoui 10EC.6F4 09C7 09:54:41.355 Enter ProgressDialog::UpdateButton
dcpromoui 10EC.6F4 09C8 09:54:42.868 Enter ProgressDialog::UpdateText Located domain controller ORANDC1.DPI.NSW.GOV.AU for domain DPI.NSW.GOV.AU
dcpromoui 10EC.6F4 09C9 09:54:44.381 Enter ProgressDialog::UpdateText Preparing the directory service for demotion
dcpromoui 10EC.6F4 09CA 09:54:48.921 Enter ProgressDialog::UpdateText Stopping service NETLOGON
dcpromoui 10EC.6F4 09CB 09:54:50.434 Enter ProgressDialog::UpdateText Stopping service IsmServ
dcpromoui 10EC.6F4 09CC 09:54:51.947 Enter ProgressDialog::UpdateText Stopping service kdc
dcpromoui 10EC.6F4 09CD 09:54:53.460 Enter ProgressDialog::UpdateText Removing Active Directory Domain Services objects that refer to the local Active Directory Domain Controller from the remote Active Directory Domain Controller ORANDC1.DPI.NSW.GOV.AU...
dcpromoui 10EC.6F4 09CE 09:54:59.513 Enter ProgressDialog::UpdateText Removing LDAP and remote procedure call (RPC) access to Active Directory Domain Services...
dcpromoui 10EC.6F4 09CF 09:55:01.026 Enter ProgressDialog::UpdateText Completing removal of Active Directory Domain Services, SAM and LSA...