Migation from SBS2011 to Serve 2019 error

mstjohn1974

New Member
I am in the middle of a Server Migration from an SBS2011 Server to a Windows Server 2019. During the step of running ADPREP.EXE /ForestPrep I am encountering the following error:

C:\ADPrep\adprep>adprep /forestprep

ADPREP WARNING:

Before running adprep, all Windows Active Directory Domain Controllers in the fo
rest must run Windows Server 2003 or later.

You are about to upgrade the schema for the Active Directory forest named 'contoso.local', using the Active Directory domain controller (schema master) 'S
BS1.contoso.local'.
This operation cannot be reversed after it completes.

[User Action]
If all domain controllers in the forest run Windows Server 2003 or later and you
want to upgrade the schema, confirm by typing 'C' and then press ENTER to conti
nue. Otherwise, type any other key and press ENTER to quit.


C

Adprep was unable to create the object CN=Claims Configuration,CN=Services,CN=Co
nfiguration,DC=contoso,DC=local in Active Directory Domain Services.
[Status/Consequence]
This Adprep operation failed.
[User Action]
Check the log file ADPrep.log in the C:\Windows\debug\adprep\logs\20201025141729
directory for more information. Restart Adprep.

Adprep encountered an LDAP error.
Error code: 0x13. Server extended error code: 0x51b,
Server error message: 0000051B: AtrErr: DSID-03150DBE,
#1: 0: 0000051B: DSID-03150DBE, problem 1005 (CONSTRAINT_ATT_TYPE), data 0,
Att 20119 (nTSecurityDescriptor)

Adprep was unable to update forest information.
[Status/Consequence]
Adprep requires access to existing forest-wide information from the schema master
in order to complete this operation.
[User Action]
Check the log file, ADPrep.log, in the C:\Windows\debug\adprep\logs\20201025141729 directory for more information.

The network has only a single Domain Controller SBS1 and it holds all FSMO Roles, I also migrated from FRS to DFSR for the SysVol. Does someone know what the issue is? The user used for the preparation is a group member of the Enterprise Admins Group and Schema Admins Group as well as Domain Administrators. What Am I missing?
 

Neemobeer

Windows Forum Team
Staff member
Just to be clear you build a new server (2019), promoted it to a DC in the same AD environment?

You can upgrade an SBS server to Server 2019 directly
 

mstjohn1974

New Member
Well, not there yet, I am trying to promote it to a DC and when I run the adprep /forestprep or use the Server manager GUI in both cases it fails
 

mstjohn1974

New Member
Adprep encountered an LDAP error.

Error code: 0x13. Server extended error code: 0x51b, Server error message: 0000051B: AtrErr: DSID-03150DBE, #1:
0: 0000051B: DSID-03150DBE, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 20119 (nTSecurityDescriptor)



DSID Info:
DSID: 0x18111003
ldap error = 0x13
NT BUILD: 17763
NT BUILD: 1
 

Neemobeer

Windows Forum Team
Staff member
I would try running as the built in AD administrator account. This sounds like a permission problem still. The new system is joined to the domain?
 
Top