I have recently removed my HPe Server from my domain to workgroup now trying to rejoin my domain but it’s giving me the following error:<\/p>\n
Note: This information is intended for a network administrator. If you are not your network’s administrator, notify the administrator that you received this information, which has been recorded in the file C:\\Windows\\debug\\dcdiag.txt.<\/em><\/p>\n
The following error occurred when DNS was queried for the service location (SRV) resource record used to locate an Active Directory Domain Controller (AD DC) for domain The error was: “This operation returned because the timeout period expired.”<\/em> The query was for the SRV record for _ldap._tcp.dc._msdcs.domainname.co.uk<\/em><\/p>\n The DNS servers used by this computer for name resolution are not responding. This computer is configured to use DNS servers with the following IP addresses:<\/em><\/p>\n 10.xx.xx.x<\/em><\/p>\n Verify that this computer is connected to the network, that these are the correct DNS server IP addresses, and that at least one of the DNS servers is running.<\/em><\/p>\n Few things to consider:<\/p>\n My DNS is installed on my primary domain controller (dc-01) and DNS is a primary zone here. I have a secondary domain controller (dc02) with DNS but it’s setup as a secondary zone.<\/p>\n<\/li>\n I use Hyper-V to host these domain controllers.<\/p>\n<\/li>\n I used to use my laptop to run these dc’s via Hyper-V and have moved over to my HPe server about a month ago. The dc-01 had DNS primary zone configured and so did dc02. When I realised dc02 had a primary dns i erased it and configured it as secondary dns zone. I took necessary measures when it came to removing/demoting the dcs from my laptop by; Removing the static IP address from the network adapters (changing from static to dynamic), removing the virtual adapters (hyper-v), removing all the roles it had (incl. dns manager) then finally demoting the servers from domain controller. All was done whilst the VM’s on my HPe server were offline so there are not conflicts (the VMs on both my laptop and HPe server have never been online at the same time). Lastly I wiped the OS for both so there was nothing left.<\/p>\n<\/li>\n My HPe server was joined to the domain when I was running the DCs on my laptop so after the migration I left the domain, rejoined and seemed to be working will. Only recently (about a week now) I am having a constant (trust relationship) error each time I RDP in to the machine. I believe this is happening because I changed the ip address of one of the NICs to an old ip static ip address so i can keep my static ip addresses numbered in order. I can get passed the trust relationship issue by re-entering my domain admin credentials however I was dealing with another issue (where my file server or any other server in that matter) are not able to find any of my domain users/groups when it came to adding them in an access control list for a folder (was using the local c: folder as an example). It keeps coming up with the error \"An object (User, Group, or Built-in security principal) with the following name cannot be found: “name”. Check the selected object types and locations for accuracy and ensure that you have typed the object name correctly, or remove this object from the selection.<\/em>\" This was the error I was initially trying to resolve, so I went to ping the name of my domain from the server as part of another troubleshooting article and the response was this: “Ping request could not find host DNS servers:<\/em><\/p>\n Steps I’ve taken:<\/p>\n I’ve gone into my DNS Manager > Forward Lookup Zones > _msdcs.“domainname”.co.uk > dc > _tcp > and can see the _ldap SRV file with the correct details. Went ahead an deleted that then re-created.<\/p>\n I then revisited DNS Manager > Forward Lookup zones > “ Went into my Revers Lookup Zones > 10.xx.xx.in-addr.arpa > selected my dc-01 PTR > deleted and re-added.<\/p>\n I did have trouble joining this HPe server in the past (after migration) but with a different error, done some research and added the Alias (CNAME) records for each folder within DNS Manager > Forward Lookup Zones > _msdcs.domainname.co.uk, and that seem to resolve that issue, so just fyi there is an Alias (CNAME) record there.<\/p>\n Was doing a lot of researching with copilot and various websites but i still can’t seem to get this hpe server to rejoin, maybe if i can get this working it would also fix my issue on the file server not able to see my users/groups? Also to add; I’m able to see users/groups when it comes to adding permissions within my DC-01, it’s just the other servers (DHCP servers, file server) that is not allowing me to.<\/p>\n Also to add; firewalls have been switched off temporarily for both hpe server & dc-01. the hpe server is able to ping my dc-01 ip address and receive all 4 replies. the hpe server also has a static ip address and subnet, gateway, dns (pointing to my dc-01 ip) all set up correctly, as i mentioned earlier it was previously joined and all was working well but now cant rejoin.<\/p>","upvoteCount":3,"answerCount":12,"datePublished":"2025-03-30T12:34:41.656Z","author":{"@type":"Person","name":"Guilde3389","url":"https://community.spiceworks.com/u/Guilde3389"},"suggestedAnswer":[{"@type":"Answer","text":" I have recently removed my HPe Server from my domain to workgroup now trying to rejoin my domain but it’s giving me the following error:<\/p>\n Note: This information is intended for a network administrator. If you are not your network’s administrator, notify the administrator that you received this information, which has been recorded in the file C:\\Windows\\debug\\dcdiag.txt.<\/em><\/p>\n The following error occurred when DNS was queried for the service location (SRV) resource record used to locate an Active Directory Domain Controller (AD DC) for domain The error was: “This operation returned because the timeout period expired.”<\/em> The query was for the SRV record for _ldap._tcp.dc._msdcs.domainname.co.uk<\/em><\/p>\n The DNS servers used by this computer for name resolution are not responding. This computer is configured to use DNS servers with the following IP addresses:<\/em><\/p>\n 10.xx.xx.x<\/em><\/p>\n Verify that this computer is connected to the network, that these are the correct DNS server IP addresses, and that at least one of the DNS servers is running.<\/em><\/p>\n Few things to consider:<\/p>\n My DNS is installed on my primary domain controller (dc-01) and DNS is a primary zone here. I have a secondary domain controller (dc02) with DNS but it’s setup as a secondary zone.<\/p>\n<\/li>\n I use Hyper-V to host these domain controllers.<\/p>\n<\/li>\n I used to use my laptop to run these dc’s via Hyper-V and have moved over to my HPe server about a month ago. The dc-01 had DNS primary zone configured and so did dc02. When I realised dc02 had a primary dns i erased it and configured it as secondary dns zone. I took necessary measures when it came to removing/demoting the dcs from my laptop by; Removing the static IP address from the network adapters (changing from static to dynamic), removing the virtual adapters (hyper-v), removing all the roles it had (incl. dns manager) then finally demoting the servers from domain controller. All was done whilst the VM’s on my HPe server were offline so there are not conflicts (the VMs on both my laptop and HPe server have never been online at the same time). Lastly I wiped the OS for both so there was nothing left.<\/p>\n<\/li>\n My HPe server was joined to the domain when I was running the DCs on my laptop so after the migration I left the domain, rejoined and seemed to be working will. Only recently (about a week now) I am having a constant (trust relationship) error each time I RDP in to the machine. I believe this is happening because I changed the ip address of one of the NICs to an old ip static ip address so i can keep my static ip addresses numbered in order. I can get passed the trust relationship issue by re-entering my domain admin credentials however I was dealing with another issue (where my file server or any other server in that matter) are not able to find any of my domain users/groups when it came to adding them in an access control list for a folder (was using the local c: folder as an example). It keeps coming up with the error \"An object (User, Group, or Built-in security principal) with the following name cannot be found: “name”. Check the selected object types and locations for accuracy and ensure that you have typed the object name correctly, or remove this object from the selection.<\/em>\" This was the error I was initially trying to resolve, so I went to ping the name of my domain from the server as part of another troubleshooting article and the response was this: “Ping request could not find host DNS servers:<\/em><\/p>\n Steps I’ve taken:<\/p>\n I’ve gone into my DNS Manager > Forward Lookup Zones > _msdcs.“domainname”.co.uk > dc > _tcp > and can see the _ldap SRV file with the correct details. Went ahead an deleted that then re-created.<\/p>\n I then revisited DNS Manager > Forward Lookup zones > “ Went into my Revers Lookup Zones > 10.xx.xx.in-addr.arpa > selected my dc-01 PTR > deleted and re-added.<\/p>\n I did have trouble joining this HPe server in the past (after migration) but with a different error, done some research and added the Alias (CNAME) records for each folder within DNS Manager > Forward Lookup Zones > _msdcs.domainname.co.uk, and that seem to resolve that issue, so just fyi there is an Alias (CNAME) record there.<\/p>\n Was doing a lot of researching with copilot and various websites but i still can’t seem to get this hpe server to rejoin, maybe if i can get this working it would also fix my issue on the file server not able to see my users/groups? Also to add; I’m able to see users/groups when it comes to adding permissions within my DC-01, it’s just the other servers (DHCP servers, file server) that is not allowing me to.<\/p>\n Also to add; firewalls have been switched off temporarily for both hpe server & dc-01. the hpe server is able to ping my dc-01 ip address and receive all 4 replies. the hpe server also has a static ip address and subnet, gateway, dns (pointing to my dc-01 ip) all set up correctly, as i mentioned earlier it was previously joined and all was working well but now cant rejoin.<\/p>","upvoteCount":3,"datePublished":"2025-03-30T12:34:41.950Z","url":"https://community.spiceworks.com/t/unable-to-join-my-hpe-server-to-my-domain/1190835/1","author":{"@type":"Person","name":"Guilde3389","url":"https://community.spiceworks.com/u/Guilde3389"}},{"@type":"Answer","text":" The server you removed, why? Was it a DC?<\/p>\n What is it using for DNS?<\/p>\n Why is DC02 a secondary zone?<\/p>\n Based on it being on your laptop previously, this is a lab - right? I’m worried if it’s not.<\/p>\n
domainname.co.uk<\/code>:<\/em><\/p>\n
\n(error code 0x000005B4 ERROR_TIMEOUT)<\/em><\/p>\n\n
domain.co.uk<\/code>. Please check the name and try again.” So I went to my dc and ran the command dcdiag /test:DNS /v which came back with the result:<\/p>\n<\/li>\n<\/ul>\n
\n
Warning:*\n<\/code><\/pre>\n<\/li>\n
10.xx.xx.x (DC-01) [Invalid]*\n<\/code><\/pre>\n<\/li>\n
Warning: adapter [00000019] Microsoft Hyper-V Network Adapter has invalid DNS server:*\n<\/code><\/pre>\n<\/li>\n
10.xx.xx.x (DC-01)*\n<\/code><\/pre>\n<\/li>\n
Error: all DNS servers are invalid*\n<\/code><\/pre>\n<\/li>\n
The A host record(s) for this DC was found*\n<\/code><\/pre>\n<\/li>\n
The SOA record for the Active Directory zone was found*\n<\/code><\/pre>\n<\/li>\n
Warning: no DNS RPC connectivity (error or non Microsoft DNS server is running)*\n<\/code><\/pre>\n<\/li>\n
[Error details: 5 (Type: Win32 - Description: Access is denied.)]*\n<\/code><\/pre>\n<\/li>\n
Summary of test results for DNS servers used by the above domain controllers:*\n<\/code><\/pre>\n<\/li>\n
DNS server: xx.xx.xx.x (DC-01)*\n<\/code><\/pre>\n<\/li>\n
1 test failure on this DNS server*\n<\/code><\/pre>\n<\/li>\n
Name resolution is not functional. _ldap._tcp.domainname.co.uk. failed on the DNS server 10.xx.xx.x*\n<\/code><\/pre>\n<\/li>\n
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]*\n<\/code><\/pre>\n<\/li>\n
Summary of DNS test results:*\n<\/code><\/pre>\n<\/li>\n
Auth Basc Forw Del Dyn RReg Ext*\n<\/code><\/pre>\n<\/li>\n
_________________________________________________________________*\n<\/code><\/pre>\n<\/li>\n
Domain: domainname.co.uk*\n<\/code><\/pre>\n<\/li>\n
DC-01 PASS FAIL n/a n/a n/a n/a n/a*\n<\/code><\/pre>\n<\/li>\n<\/ul>\n
\n
domainname.co.uk<\/code>” > and deleted the Host (A) record for my DC-01 and re-added with the same settings which included ticking the checkbox for PTR.<\/p>\n
\n
\n
domainname.co.uk<\/code>:<\/em><\/p>\n
\n(error code 0x000005B4 ERROR_TIMEOUT)<\/em><\/p>\n\n
domain.co.uk<\/code>. Please check the name and try again.” So I went to my dc and ran the command dcdiag /test:DNS /v which came back with the result:<\/p>\n<\/li>\n<\/ul>\n
\n
Warning:*\n<\/code><\/pre>\n<\/li>\n
10.xx.xx.x (DC-01) [Invalid]*\n<\/code><\/pre>\n<\/li>\n
Warning: adapter [00000019] Microsoft Hyper-V Network Adapter has invalid DNS server:*\n<\/code><\/pre>\n<\/li>\n
10.xx.xx.x (DC-01)*\n<\/code><\/pre>\n<\/li>\n
Error: all DNS servers are invalid*\n<\/code><\/pre>\n<\/li>\n
The A host record(s) for this DC was found*\n<\/code><\/pre>\n<\/li>\n
The SOA record for the Active Directory zone was found*\n<\/code><\/pre>\n<\/li>\n
Warning: no DNS RPC connectivity (error or non Microsoft DNS server is running)*\n<\/code><\/pre>\n<\/li>\n
[Error details: 5 (Type: Win32 - Description: Access is denied.)]*\n<\/code><\/pre>\n<\/li>\n
Summary of test results for DNS servers used by the above domain controllers:*\n<\/code><\/pre>\n<\/li>\n
DNS server: xx.xx.xx.x (DC-01)*\n<\/code><\/pre>\n<\/li>\n
1 test failure on this DNS server*\n<\/code><\/pre>\n<\/li>\n
Name resolution is not functional. _ldap._tcp.domainname.co.uk. failed on the DNS server 10.xx.xx.x*\n<\/code><\/pre>\n<\/li>\n
[Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]*\n<\/code><\/pre>\n<\/li>\n
Summary of DNS test results:*\n<\/code><\/pre>\n<\/li>\n
Auth Basc Forw Del Dyn RReg Ext*\n<\/code><\/pre>\n<\/li>\n
_________________________________________________________________*\n<\/code><\/pre>\n<\/li>\n
Domain: domainname.co.uk*\n<\/code><\/pre>\n<\/li>\n
DC-01 PASS FAIL n/a n/a n/a n/a n/a*\n<\/code><\/pre>\n<\/li>\n<\/ul>\n
\n
domainname.co.uk<\/code>” > and deleted the Host (A) record for my DC-01 and re-added with the same settings which included ticking the checkbox for PTR.<\/p>\n
\n
\n