| Previous | Next |
| ERROR_DS_MISSING_FSMO_SETTINGS | ERROR_DS_DRA_GENERIC |
ERROR_DS_UNABLE_TO_SURRENDER_ROLES
A domain controller could not hand off its single-master responsibilities
Graceful demotion and planned role movement try to transfer FSMO ownership to healthy domain controllers. A transfer is coordinated with the existing owner and depends on directory connectivity and replication; it differs from seizure, which is used when the previous role holder cannot be recovered.
Identify every role currently owned by the server and determine which transfer failed. Check the naming context that stores that role, inbound and outbound replication, and the reachability of the intended destination. If the server is being forcibly removed, the remaining environment may require explicit seizure and metadata cleanup. Do not assume all five roles failed because one transfer produced the wrapper status.
What to inspect
- List the current FSMO role holders before retrying demotion or maintenance.
- Test replication for the NC that contains each affected role owner object.
- Use seizure only for a role whose previous owner will not resume authoritative service.
References
- Microsoft: transfer FSMO roles
- Microsoft: Active Directory FSMO roles
- Microsoft: clean up domain controller metadata
Looking for a different code? Search another status or error code.