Your account | Cart Cart
 Search

UMove for Active Directory
IntroductionIntroduction
Choice of OperationChoice of Operation
Planned MovePlanned Move
Plan ChecklistPlan Checklist
Demonstration ModeDemonstration Mode
Preparing the Destination ComputerPreparing the Destination Computer
DCPROMO Not NecessaryDCPROMO Not Necessary
WinPE or WinRE Not NecessaryWinPE or WinRE Not Necessary
Windows Server 2003 Release 2 (R2)Windows Server 2003 Release 2 (R2)
Windows Server 2008 Release 2 (R2)Windows Server 2008 Release 2 (R2)
Transferring the BackupTransferring the Backup
CleanupCleanup
Windows Product Activation on Windows Server 2003Windows Product Activation on Windows Server 2003
Loading Active DirectoryLoading Active Directory
Advanced TopicsAdvanced Topics
Error MessagesError Messages
Cleanup

The following tasks can help you to clean up Active Directory after you move it to the destination computer.

Resetting the DC Shared Secret

Each domain controller (DC) has a shared secret that it shares with the other domain controllers to establish a secure channel for communication. It is used for replication and for authentication between DCs.

If there are other domain controllers in the domain, and if more than 14 days have elapsed, you may need to re-establish the shared secret with the other domain controllers. This is because the domain controllers change their shared security secret every 14 days.

The symptom of a lapsed shared secret is an error message in the Event Log that the computer was unable to update the Service Principal Name (SPN) of the computer object in Active Directory. (See Microsoft KB article KB329708.)

To reset the shared secret you must fix the computer's DC machine account. Open an administrative console and use the utility DCDIAG.EXE. DCDIAG.EXE can be found in the Windows Server 2003 Support Tools, located on the Windows Server 2003 CD/DVD. (It is standard on Windows Server 2008.)

On the restored computer open an administrative console and type:
Usage: DCDIAG.EXE /s:DomainController /u:Domain\UserName /p:* /test:MachineAccount /fix

For DomainController type the name of the computer (for example, busybox.acme.com). If necessary add the /u and /p switches to provide the domain administrator account and password.

If DCDIAG fails, add the additional option /FixMachineAccount. If DCDIAG still fails, instead add the additional option /RecreateMachineAccount.

An alternate method is to use the console utility NLTEST.EXE:

Usage: NLTEST.EXE /server:DomainController /sc_reset:DomainName

For DomainName type the name of the domain (for example, acme.com).

Windows Product Activation (WPA) on Windows Server 2003

See Windows Product Activation on Windows Server 2003.

Uninstall UMove

When you are satisfied that Active Directory is working ok you can delete the staging folder and uninstall UMove. Congratulations, you are done!


Algin Technology LLC