Forum Discussion

EtotheC's avatar
EtotheC
Copper Contributor
Feb 28, 2023

Trouble running DCPromo through Server Manager - Wont accept domain credentials

I've added Azure DS, ive joined the windows VM to the Azure domain, ive installed the roles on the VM.

 

During promo, at the Select Deployment Operation, I have Add DC to Existing Domain, selected.

The domain in the Select field is the newly created Azure Domian. 

 In the Supply Credentials to Perform this Operation, I have tried the admin account for

My local domain - domain\admin

The admin credentials for the RDP session

The domain.onmicrosoft.com\admin

And I get errors ranging from the referenced account is locked, to supply valid account, to the Wizard cannot access the list of domains in the forest 

 

What am I supposed to use here?! We have a hybrid setup and we have AD Sync, which brought our on premise domain accounts into azure. And we have the new Azure domain with a slightly different name. Which admin account does the server manager wizard, on the vm inside azure, want? 

  

3 Replies

  • LukeJMadden's avatar
    LukeJMadden
    Brass Contributor
    Hello EtotheC,

    Check if the account you are using to perform the operation is actually locked out. You could try logging in to the domain controller with the same account to verify this.

    Try using a different account with the necessary permissions to perform the operation. Make sure that the account is not locked out and that the password is correct.

    Make sure that the domain controller can communicate with the Azure domain and that there are no connectivity issues. You could try pinging the Azure domain to verify connectivity.

    Check if there are any firewall rules or network security groups that could be blocking communication between the domain controller and the Azure domain.

    I hope this helps you in resolving the issue.

    Kind Regards,

    Luke Madden
    • EtotheC's avatar
      EtotheC
      Copper Contributor

      Kidd_Ip 

       

       

       

      I have a site-to-azure vpn, ad sync is working, but do I need a "Trust?"