Solved

Windows NT BDC does not authenticate users when Win 2k AD PDC is offline

Posted on 2003-11-20
6
372 Views
Last Modified: 2013-12-19
Heres the scenario.  I have a Windows 2000 Server SP-4 Active Directory Domain Controller acting as the PDC emulator.  I have a second Windows NT 4 SP-6a server running as the BDC.  When the Win 2k server is up and running all is well.  If I take the Win 2k AD server offline for any reason no one can log onto the domain.  For some reason the BDC does not authenticate users.  I can synchronize between the two machines with no problem.  There are no errors in the log when both machines are running.  When the PDC is offline the BDC generates netlogon error events 5719 and 5722.  These errors state that there is no domain controller available and that the computer accont cannot be validated.

Any one have any suggestions?

Thanks
Joe
0
Comment
Question by:jpmigliozzi
  • 2
  • 2
6 Comments
 
LVL 37

Expert Comment

by:bbao
ID: 9793930
FYI:

Event ID 3210 and 5722 Appear When Synchronizing Entire Domain
http://support.microsoft.com/?id=kb;en-us;142869

Netlogon Event ID 5770 and 5722 on Primary Domain Controller
http://support.microsoft.com/?id=kb;en-us;180114

heop it helps,
bbao
0
 
LVL 1

Author Comment

by:jpmigliozzi
ID: 9797146
Thanks for the input.  I already took a look at these articles and neither of them explain my specific problem.  I have a Win 2k AD domain controller with a Win NT 4 BDC.  They synchronize just fine.  Its when the Win 2k AD server is offline that no one can authenticate against the BDC.  The BDC throughs errors in the event log about no domin controllers exist and that computer accounts with access denied errors.
0
 
LVL 37

Expert Comment

by:bbao
ID: 9939853
sorry for late reply. i think you may try netdom.exe, available in w2k resource kit.
0
 
LVL 1

Author Comment

by:jpmigliozzi
ID: 11887015
Upgraded the Win NT 4 machine to Win 2k.  Problem resolved.

joe
0
 

Accepted Solution

by:
modulo earned 0 total points
ID: 11922610
PAQed, with points refunded (250)

modulo
Community Support Moderator
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
An article on effective troubleshooting
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question