Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Domain controller cloning fails with error 8610 in dcpromo.log


View products that this article applies to.

Symptoms

You use the Virtualized Domain Controller (VDC) cloning feature that Windows Server 2012 introduced. After you clone a new domain controller, you find that the server starts in Directory Services Repair Mode (DSRM). If you examine the c:\windows\debug\dcpromo.log, you find the following error entry:

8610


This error code translates to 0x21a2, which is as follows:
ERROR_DS_ROLE_NOT_VERIFIED

The FSMO role ownership could not be verified because its directory partition has not replicated successfully with at least one replication partner

↑ Back to the top


Cause

VDC cloning requires a Windows Server 2012 primary domain controller emulator (PDCe). In this case, the PDCe is discoverable by using the domain controller locator (Locator,�also known as "DCLocator") and Domain Name System (DNS), and the PDCe is running the correct operating system. However, the PDCe was recently transferred from another server. And, the PDCe has not yet performed incoming (also known as "inbound") replication of the domain partition to learn about the current state of PDCe FSMO ownership before the PDCe can reassert ownership of this role (INITSYNC).

↑ Back to the top


Resolution

  1. Let the PDCe replicate Active Directory Domain Services with at least one partner, or use Dssites.msc or repadmin.exe to trigger immediate replication
  2. Run the following commands from an elevated command prompt:

    Bcdedit.exe /deletevalue safeboot

    Shutdown.exe /r /t 0

  3. Verify that the server is cloned successfully.

↑ Back to the top


More information

This behavior is by design. DSRM is intentionally invoked as part of the cloning process in order to safeguard the network and the domain from duplicated domain controllers.

Directory Services Repair Mode was called Directory Services Restore Mode in previous Windows operating systems.

For more information about how to configure and troubleshoot VDC together with details and step-by-step guidance, go to the following Microsoft websites:

↑ Back to the top


Keywords: KB2742916

↑ Back to the top

Article Info
Article ID : 2742916
Revision : 8
Created on : 9/20/2012
Published on : 9/20/2012
Exists online : False
Views : 309