Hallo Nochmal,
du bist dir absolut sicher, dass du das gelesen hast ?
http://support.microsoft.com/default...b;en-us;232070
Auszug:
--------------
When you run Dcpromo.exe to create a replica domain controller, you receive the "Failed to modify the necessary properties for the machine account. Access is denied." error message
Die Informationen in diesem Artikel beziehen sich auf:
This article was previously published under Q232070
SYMPTOMS
When you run Dcpromo.exe to create a replica domain controller, you may receive the following error message in Dcpromo.exe:
Failed to modify the necessary properties for the machine account. Access is denied.
Examination of the Dcpromoui.log file indicates that the initial part of the promotion was successful (this is also verified because the computer becomes a member server in the domain), but that the promotion to domain controller did not succeed because Dcpromo.exe could not modify the machine account.
CAUSE
This problem can occur if the account that is used for the promotion operation has not been assigned the "Delegation Privilege" right. Or, if this right has been assigned, the policy has not propagated yet, possibly because of replication latency. By default, only members in the Administrators group have the "Delegation Privilege" right.
....
mfg
Ritchy