Event Id | 12295 |
Source | SAM |
Description | The SAM database attempted to delete the file %1 as it contains account information that is no longer used. The error is in the record data. Please have an administrator delete this file. |
Event Information | According to Microsoft : Cause : This event is logged when the SAM database attempted to delete the file as it contains account information that is no longer used. Resolution : Delete the referenced file manually The Security Accounts Manager (SAM) was not able to delete the file that was referred to in the Event Viewer event text. Go to the file location that is referred to in the Event Viewer event text, and delete the file. If you are not able to delete the file, try again after you restart the computer. Perform the following procedure using a domain member computer that has domain administrative tools installed. To perform this procedure, you must have membership in Domain Admins or you must have been delegated the appropriate authority. To manually delete the referenced file:
Verify : To ensure that the domain controller demotion was successful, verify that the Active Directory database files were removed and that the computer account is no longer in the Domain Controllers organizational unit (OU) or in the Domain Controllers group in Active Directory Users and Computers. Perform the following procedures using a domain member computer that has domain administrative tools installed. To perform these procedures, you must have membership in Domain Admins or you must have been delegated the appropriate authority. Verify that the Active Directory database files were removed To verify that the Active Directory database files were removed:
To verify that the computer account is no longer in the Domain Controllers OU or the Domain Controllers group:
|
Reference Links | Event ID 12295 from Source SAM |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.