Problems after an upgrade from exchange 2000 to 2003

Posted on 2004-08-13
Last Modified: 2012-05-05

It seems i ran in some problems when i was doing an upgrade from a w2k server with exchange 2000 enterprise to w2k3 server with exchange 2003 enterprise.

This is the situation:
We have 2 dc's. 1 is a w2k file and print server, the other a w2k exchange 2000 server. The main problem with the file and print server is that the are running applications for finance that we are not sure of that they will work under windows 2003. So we decided to first upgrade the exchange server.

The upgrade went fine, there where no problems during the exchange upgrade and no problems after that during the windows 2003 upgrade.

All accounts are still working and mail is comming in. Even the web access is working internal. And that was one of the main reasons to do the upgrade. But right after the compleet install i found out that the eventviewer wasn't accesable. After some reading i found out that the administrator account probably belongt to the quest group and that was the case. So one problem solved.

When i looked in the eventviewer i saw 2 kinds of errors. Userevent errors and MSExchangeSA errors. We found out that when a user opend the outlook from office xp the server displayed an error. It wasn't possible to mail from clients, outlook just closed. On clients that have outlook 2003 on them it is possible to send email, but still new errors are shown in the eventviewer.

The 2 MSExchangeSA are

Event ID: 9074
Source MSExchangeSA  
Type Error  
Description The Directory Service Referral interface failed to service a client request. RFRI is returning the error code:[0x3f0].  

Event ID: 9143
Source MSExchangeSA  
Type Error  
Description Description: Referral Interface cannot contact any Global Catalog that supports the NSPI Service. Clients making RFR requests will fail to connect until a Global Catalog becomes available again. After a Domain Controller is promoted to a Global Catalog, it must be rebooted to support MAPI Clients.
For more information, click  

I have looked them up, to solve the problems but that didn't work.
as described in;EN-US;279742 i tried to resolve the 9143 error, but this didn't work.

If i try to solve error 9074 as described in;EN-US;Q314294, the following happens. If i use the Policytest.exe on the exchange server i get an Right found:  "SeSecurityPrivilege" on both dc's. If i try it on the w2k file and print server i get an !! LsaEnumerateAccountRights returned error 5 !! on the exchange server.

If i try to do it the way as described in;EN-US;Q300114 the ipconfig /flushdns and the ipconfig /registerdns work, but if i try it from the w2k file and print server the ipconfig /registerdns doesnt work.

I also found out that if i go to users and computers, and try to edit the policies on the exchange server i get an error, and i cant see the policies. If i do this on the file and print server everything works fine.

I personaly think the problems are there because there is one w2k server and 1 windows2003 server. Some how there is a problem with right on the exchange server, other wise i should be possible to change the policies. I use the administrator account, which has all the rights.

But do you know how to solve this. It will take several weeks before we will know for sure if we can safely upgrade the file and print server to windows 2003.


R Bosch

Question by:netbeheer
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

ID: 11798961
Have you changed  any default AD Container for Exchange server object ?
Your DNS is working Properly?
Check the  Network of the exchange server with Network Monitor and  find  any error in Network . ( check NIC settings for Half/Full/AUTO  ) .
GPO are applied properly on exchnage server ? check seccli events .

LVL 20

Expert Comment

ID: 11798965
Make sure that you are having a working Global Catalog in your domain. if not, make a Global catalog server and restart it.


Author Comment

ID: 11799128
If i go to the Active Directory Sites and Services on the exchange server and click on sites and the on sites name, i see 3 domain controlers. ! is the file and print server with ntds settings under it, 1 is the exchange server but that one is empty, and 1 is the exchange server with exchange setttings and ntds settings under it.  when i look at the properties i see on the file and printserver that global catalog is on and has a dns alias, and it was created bij the exchange server.

The same goes for the exchange server, it has global catalog on en the ntds settings where created bij de file and print server.

I dont know what the do with the dc exchange server that has nothing under it.
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.


Author Comment

ID: 11799138
I am unable to view or modify the GPO.  I get an error
when I do the following on the Domain Controller:

Start>Program>Administrative Tool>Active Directory Users
and Computers.  I select Domain Controllers>Right
Click>Properties>Group Policy Tab.  I select 'Default
Domain Controllers Policy' and Edit.  I get message box
coming up:  GROUP POLICY ERROR - Failed to open the Group
Policy Object.  You may not have appropriate rights.
Details:  The system connot find the path specified.

And i also get userevent errors on the exchange server every 5 minutes


Author Comment

ID: 11799223
I searched the web and found an artikel about not being able to access the gpo.

I have done exactly as desribed but dont get any result. I have all the structures

and used the Ldp.exe from the windows 2000 cd.

This is wath i got in the programm window.
ld = ldap_open("spielberg", 389);
Established connection to spielberg.
Retrieving base DSA information...
Result <0>: (null)
Matched DNs:
Getting 1 entries:
>> Dn:
      1> currentTime: 8/14/2004 11:51:31 W. Europe Standard Time W. Europe Daylight Time;
      1> subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=zthollandia,DC=nl;
      1> dsServiceName: CN=NTDS Settings,CN=SPIELBERG,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=zthollandia,DC=nl;
      5> namingContexts: DC=zthollandia,DC=nl; CN=Configuration,DC=zthollandia,DC=nl; CN=Schema,CN=Configuration,DC=zthollandia,DC=nl; DC=DomainDnsZones,DC=zthollandia,DC=nl; DC=ForestDnsZones,DC=zthollandia,DC=nl;
      1> defaultNamingContext: DC=zthollandia,DC=nl;
      1> schemaNamingContext: CN=Schema,CN=Configuration,DC=zthollandia,DC=nl;
      1> configurationNamingContext: CN=Configuration,DC=zthollandia,DC=nl;
      1> rootDomainNamingContext: DC=zthollandia,DC=nl;
      21> supportedControl: 1.2.840.113556.1.4.319; 1.2.840.113556.1.4.801; 1.2.840.113556.1.4.473; 1.2.840.113556.1.4.528; 1.2.840.113556.1.4.417; 1.2.840.113556.1.4.619; 1.2.840.113556.1.4.841; 1.2.840.113556.1.4.529; 1.2.840.113556.1.4.805; 1.2.840.113556.1.4.521; 1.2.840.113556.1.4.970; 1.2.840.113556.1.4.1338; 1.2.840.113556.1.4.474; 1.2.840.113556.1.4.1339; 1.2.840.113556.1.4.1340; 1.2.840.113556.1.4.1413; 2.16.840.1.113730.3.4.9; 2.16.840.1.113730.3.4.10; 1.2.840.113556.1.4.1504; 1.2.840.113556.1.4.1852; 1.2.840.113556.1.4.802;
      2> supportedLDAPVersion: 3; 2;
      12> supportedLDAPPolicies: MaxPoolThreads; MaxDatagramRecv; MaxReceiveBuffer; InitRecvTimeout; MaxConnections; MaxConnIdleTime; MaxPageSize; MaxQueryDuration; MaxTempTableSize; MaxResultSetSize; MaxNotificationPerConn; MaxValRange;
      1> highestCommittedUSN: 756718;
      4> supportedSASLMechanisms: GSSAPI; GSS-SPNEGO; EXTERNAL; DIGEST-MD5;
      1> dnsHostName:;
      1> ldapServiceName:$@ZTHOLLANDIA.NL;
      1> serverName: CN=SPIELBERG,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=zthollandia,DC=nl;
      3> supportedCapabilities: 1.2.840.113556.1.4.800; 1.2.840.113556.1.4.1670; 1.2.840.113556.1.4.1791;
      1> isSynchronized: TRUE;
      1> isGlobalCatalogReady: TRUE;
      1> domainFunctionality: 0;
      1> forestFunctionality: 0;
      1> domainControllerFunctionality: 2;
res = ldap_bind_s(ld, NULL, &NtAuthIdentity, 1158); // v.3
      {NtAuthIdentity: User='Administrator'; Pwd= <unavailable>; domain = ''.}
Authenticated as dn:'Administrator'.
Expanding base ','...
Error: Search: Referral. <10>
Result <10>: 0000202B: RefErr: DSID-031006D9, data 0, 1 access points
      ref 1: ''

Matched DNs:
Getting 0 entries:
maybe somebody can see something in it

Author Comment

ID: 11801555
wel as far as it looks now, the problems have been solved. I tried the Ldp.exe another time, but saw i made a mistake in the first attempt. I had to type dc=zthollandia,dc=nl instead of,

I am now abel to enter and edit the gpo. The last 2 hours when i was at the office, there where no new userevents, or MSExchangeSA errors. And the outlook clients where working. Will see what the eventviewer will say tomorrow. I hope all will be fine.

Accepted Solution

modulo earned 0 total points
ID: 14299178
PAQed with points refunded (500)

Community Support Moderator

Featured Post

[Live Webinar] The Cloud Skills Gap

As Cloud technologies come of age, business leaders grapple with the impact it has on their team's skills and the gap associated with the use of a cloud platform.

Join experts from 451 Research and Concerto Cloud Services on July 27th where we will examine fact and fiction.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question