Dear Friends,
I'm trying to join one of our ESXi 6.7 host to domain but getting error "Errors in Active Directory operations", I went thr' couple of KB articles available and tried all of them, but still getting the error. All required ports are opened -
Note: I am using RODC for domain joining; I have created an host object in primary DC and after sometime object replicated in RODC.
Please assist. Thanks in advance.
Logs:
20190419083242:ERROR:lsass: Failed to run provider specific request (request code = 12, provider = 'lsa-activedirectory-provider') -> error = 2692, symbol = NERR_SetupNotJoined, client pid = XXXX1
20190419083342:ERROR:lsass: Failed to run provider specific request (request code = 12, provider = 'lsa-activedirectory-provider') -> error = 2692, symbol = NERR_SetupNotJoined, client pid = XXXX2
20190419083442:ERROR:lsass: Failed to run provider specific request (request code = 8, provider = 'lsa-activedirectory-provider') -> error = 40286, symbol = LW_ERROR_LDAP_SERVER_DOWN, client pid = XXXX3
20190419083542:ERROR:lsass: Failed to run provider specific request (request code = 12, provider = 'lsa-activedirectory-provider') -> error = 2692, symbol = NERR_SetupNotJoined, client pid = XXXX4
20190419085316:INFO:lsass: Joining domain example.com
20190419085316:INFO:netlogon: Looking for a DC in domain 'example.com', site '<null>' with flags 10
20190419085316:INFO:netlogon: Filtering list of 3 servers with list of 0 black listed servers
20190419085331:ERROR:lsass: Failed to find DC for domain example.com
ESXi host and vCenter uses likewise binary to join to AD.
vCenter joining to writable AD does not make any difference to ESXi host adding to RODC (Still unsupported)
ESXi host is an object like VCSA so it cannot be written or updated on RODC when you are trying to join.
When you are joining ESXi host to AD, it creates object and updates the object properties. Both of these cannot happen in RODC hence its unsupported.
thanks,
MS
Ciao
If I remember correctly you can't join a DC RODC (read only domain controller)
For windows OS:
You have to provision the Computer account in AD on one of your writable DC's.
Once it replicates the computer account to the RODC. And try offline join.
but for Windows OS it works ... for ESXi I've never tried ... you should join a "normal" DOMAIN Controller.
Yes, I can't use RODC for domain join purpose, therefore I have created computer object at primary DC (Writable).
vCenter Server is already integrated to domain controller, here I am trying to join ESXi node to domain using RODC (which has ESXi objected replicated from primary DC).
ESXi host and vCenter uses likewise binary to join to AD.
vCenter joining to writable AD does not make any difference to ESXi host adding to RODC (Still unsupported)
ESXi host is an object like VCSA so it cannot be written or updated on RODC when you are trying to join.
When you are joining ESXi host to AD, it creates object and updates the object properties. Both of these cannot happen in RODC hence its unsupported.
thanks,
MS
Thank you so much for your support. Below KB article also confirm the same;
Configuring the ESXi host with Active Directory authentication (2075361) (vmware.com)