Problems after an upgrade from exchange 2000 to 2003

Posted on 2004-08-13
Last Modified: 2012-05-05

It seems i ran in some problems when i was doing an upgrade from a w2k server with exchange 2000 enterprise to w2k3 server with exchange 2003 enterprise.

This is the situation:
We have 2 dc's. 1 is a w2k file and print server, the other a w2k exchange 2000 server. The main problem with the file and print server is that the are running applications for finance that we are not sure of that they will work under windows 2003. So we decided to first upgrade the exchange server.

The upgrade went fine, there where no problems during the exchange upgrade and no problems after that during the windows 2003 upgrade.

All accounts are still working and mail is comming in. Even the web access is working internal. And that was one of the main reasons to do the upgrade. But right after the compleet install i found out that the eventviewer wasn't accesable. After some reading i found out that the administrator account probably belongt to the quest group and that was the case. So one problem solved.

When i looked in the eventviewer i saw 2 kinds of errors. Userevent errors and MSExchangeSA errors. We found out that when a user opend the outlook from office xp the server displayed an error. It wasn't possible to mail from clients, outlook just closed. On clients that have outlook 2003 on them it is possible to send email, but still new errors are shown in the eventviewer.

The 2 MSExchangeSA are

Event ID: 9074
Source MSExchangeSA  
Type Error  
Description The Directory Service Referral interface failed to service a client request. RFRI is returning the error code:[0x3f0].  

Event ID: 9143
Source MSExchangeSA  
Type Error  
Description Description: Referral Interface cannot contact any Global Catalog that supports the NSPI Service. Clients making RFR requests will fail to connect until a Global Catalog becomes available again. After a Domain Controller is promoted to a Global Catalog, it must be rebooted to support MAPI Clients.
For more information, click  

I have looked them up, to solve the problems but that didn't work.
as described in;EN-US;279742 i tried to resolve the 9143 error, but this didn't work.

If i try to solve error 9074 as described in;EN-US;Q314294, the following happens. If i use the Policytest.exe on the exchange server i get an Right found:  "SeSecurityPrivilege" on both dc's. If i try it on the w2k file and print server i get an !! LsaEnumerateAccountRights returned error 5 !! on the exchange server.

If i try to do it the way as described in;EN-US;Q300114 the ipconfig /flushdns and the ipconfig /registerdns work, but if i try it from the w2k file and print server the ipconfig /registerdns doesnt work.

I also found out that if i go to users and computers, and try to edit the policies on the exchange server i get an error, and i cant see the policies. If i do this on the file and print server everything works fine.

I personaly think the problems are there because there is one w2k server and 1 windows2003 server. Some how there is a problem with right on the exchange server, other wise i should be possible to change the policies. I use the administrator account, which has all the rights.

But do you know how to solve this. It will take several weeks before we will know for sure if we can safely upgrade the file and print server to windows 2003.


R Bosch

Question by:netbeheer

Expert Comment

ID: 11798961
Have you changed  any default AD Container for Exchange server object ?
Your DNS is working Properly?
Check the  Network of the exchange server with Network Monitor and  find  any error in Network . ( check NIC settings for Half/Full/AUTO  ) .
GPO are applied properly on exchnage server ? check seccli events .

LVL 20

Expert Comment

ID: 11798965
Make sure that you are having a working Global Catalog in your domain. if not, make a Global catalog server and restart it.


Author Comment

ID: 11799128
If i go to the Active Directory Sites and Services on the exchange server and click on sites and the on sites name, i see 3 domain controlers. ! is the file and print server with ntds settings under it, 1 is the exchange server but that one is empty, and 1 is the exchange server with exchange setttings and ntds settings under it.  when i look at the properties i see on the file and printserver that global catalog is on and has a dns alias, and it was created bij the exchange server.

The same goes for the exchange server, it has global catalog on en the ntds settings where created bij de file and print server.

I dont know what the do with the dc exchange server that has nothing under it.
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud


Author Comment

ID: 11799138
I am unable to view or modify the GPO.  I get an error
when I do the following on the Domain Controller:

Start>Program>Administrative Tool>Active Directory Users
and Computers.  I select Domain Controllers>Right
Click>Properties>Group Policy Tab.  I select 'Default
Domain Controllers Policy' and Edit.  I get message box
coming up:  GROUP POLICY ERROR - Failed to open the Group
Policy Object.  You may not have appropriate rights.
Details:  The system connot find the path specified.

And i also get userevent errors on the exchange server every 5 minutes


Author Comment

ID: 11799223
I searched the web and found an artikel about not being able to access the gpo.

I have done exactly as desribed but dont get any result. I have all the structures

and used the Ldp.exe from the windows 2000 cd.

This is wath i got in the programm window.
ld = ldap_open("spielberg", 389);
Established connection to spielberg.
Retrieving base DSA information...
Result <0>: (null)
Matched DNs:
Getting 1 entries:
>> Dn:
      1> currentTime: 8/14/2004 11:51:31 W. Europe Standard Time W. Europe Daylight Time;
      1> subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=zthollandia,DC=nl;
      1> dsServiceName: CN=NTDS Settings,CN=SPIELBERG,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=zthollandia,DC=nl;
      5> namingContexts: DC=zthollandia,DC=nl; CN=Configuration,DC=zthollandia,DC=nl; CN=Schema,CN=Configuration,DC=zthollandia,DC=nl; DC=DomainDnsZones,DC=zthollandia,DC=nl; DC=ForestDnsZones,DC=zthollandia,DC=nl;
      1> defaultNamingContext: DC=zthollandia,DC=nl;
      1> schemaNamingContext: CN=Schema,CN=Configuration,DC=zthollandia,DC=nl;
      1> configurationNamingContext: CN=Configuration,DC=zthollandia,DC=nl;
      1> rootDomainNamingContext: DC=zthollandia,DC=nl;
      21> supportedControl: 1.2.840.113556.1.4.319; 1.2.840.113556.1.4.801; 1.2.840.113556.1.4.473; 1.2.840.113556.1.4.528; 1.2.840.113556.1.4.417; 1.2.840.113556.1.4.619; 1.2.840.113556.1.4.841; 1.2.840.113556.1.4.529; 1.2.840.113556.1.4.805; 1.2.840.113556.1.4.521; 1.2.840.113556.1.4.970; 1.2.840.113556.1.4.1338; 1.2.840.113556.1.4.474; 1.2.840.113556.1.4.1339; 1.2.840.113556.1.4.1340; 1.2.840.113556.1.4.1413; 2.16.840.1.113730.3.4.9; 2.16.840.1.113730.3.4.10; 1.2.840.113556.1.4.1504; 1.2.840.113556.1.4.1852; 1.2.840.113556.1.4.802;
      2> supportedLDAPVersion: 3; 2;
      12> supportedLDAPPolicies: MaxPoolThreads; MaxDatagramRecv; MaxReceiveBuffer; InitRecvTimeout; MaxConnections; MaxConnIdleTime; MaxPageSize; MaxQueryDuration; MaxTempTableSize; MaxResultSetSize; MaxNotificationPerConn; MaxValRange;
      1> highestCommittedUSN: 756718;
      4> supportedSASLMechanisms: GSSAPI; GSS-SPNEGO; EXTERNAL; DIGEST-MD5;
      1> dnsHostName:;
      1> ldapServiceName:$@ZTHOLLANDIA.NL;
      1> serverName: CN=SPIELBERG,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=zthollandia,DC=nl;
      3> supportedCapabilities: 1.2.840.113556.1.4.800; 1.2.840.113556.1.4.1670; 1.2.840.113556.1.4.1791;
      1> isSynchronized: TRUE;
      1> isGlobalCatalogReady: TRUE;
      1> domainFunctionality: 0;
      1> forestFunctionality: 0;
      1> domainControllerFunctionality: 2;
res = ldap_bind_s(ld, NULL, &NtAuthIdentity, 1158); // v.3
      {NtAuthIdentity: User='Administrator'; Pwd= <unavailable>; domain = ''.}
Authenticated as dn:'Administrator'.
Expanding base ','...
Error: Search: Referral. <10>
Result <10>: 0000202B: RefErr: DSID-031006D9, data 0, 1 access points
      ref 1: ''

Matched DNs:
Getting 0 entries:
maybe somebody can see something in it

Author Comment

ID: 11801555
wel as far as it looks now, the problems have been solved. I tried the Ldp.exe another time, but saw i made a mistake in the first attempt. I had to type dc=zthollandia,dc=nl instead of,

I am now abel to enter and edit the gpo. The last 2 hours when i was at the office, there where no new userevents, or MSExchangeSA errors. And the outlook clients where working. Will see what the eventviewer will say tomorrow. I hope all will be fine.

Accepted Solution

modulo earned 0 total points
ID: 14299178
PAQed with points refunded (500)

Community Support Moderator

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
how to add IIS SMTP to handle application/Scanner relays into office 365.

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question