|
||||||||
|
CleanupThe following tasks can help you to clean up Active Directory after you move it to the destination computer. Resetting the DC Shared SecretEach domain controller (DC) has a shared secret that it shares with the other domain controllers to establish a secure channel for communication. It is used for replication and for authentication between DCs. If there are other domain controllers in the domain, and if more than 14 days have elapsed, you may need to re-establish the shared secret with the other domain controllers. This is because the domain controllers change their shared security secret every 14 days. The symptom of a lapsed shared secret is an error message in the Event Log that the computer was unable to update the Service Principal Name (SPN) of the computer object in Active Directory. (See Microsoft KB article KB329708.) To reset the shared secret you must fix the computer's DC machine
account. Open an administrative console
and use the utility On the restored computer open an administrative console and type: For DomainController type the name of the
computer (for example, If DCDIAG fails, add the additional option An alternate method is to use the console utility
Usage:
For DomainName type the name of the domain (for example,
Windows Product Activation (WPA) on Windows Server 2003See Windows Product Activation on Windows Server 2003. Uninstall UMoveWhen you are satisfied that Active Directory is working ok you can delete the staging folder and uninstall UMove. Congratulations, you are done! |
|