domain controllers not replicating computer/user accounts

Posted on 2007-04-02
Medium Priority
Last Modified: 2010-04-18
I had an issue (still have an issue) with the global catalog in our domain.  There is a template file that somehow got corrupted and caused the global catalog for our domain to not function.  I worked with Microsoft for quite some time, and for now the temporary fix was to create another child domain on-site with a working global catalog.

Since Microsoft got their paws on my domain controllers things haven't been right.  Now my two domain controllers aren't replicating computer and user accounts between themselves.  Because of this weird things are happening that users are noticing.  Does anyone know how can I resolve this or at least narrow down the problem?
Question by:philmaceri
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
LVL 30

Expert Comment

ID: 18838155
They told you to configure a child domain...as a troubleshooting issue?

*shakes head*

Anyway.  How many DCs do you currently have, and in how many domains?

To begin troubleshooting your replication issues, run the following tools on all of your DCs:

netdiag /v
dcdiag /v
repadmin /replsum

That said, 99% of AD replication errors stem back to DNS, so you will almost certainly find this to be the case here. The netdiag tool will help point out any errors in your DNS configuration, as will the dcdiag tool.

Hope this helps.

Laura E. Hunter - Microsoft MVP: Windows Server - Networking
LVL 33

Expert Comment

ID: 18838699
"I worked with Microsoft for quite some time, and for now the temporary fix was to create another child domain on-site with a working global catalog."  Can we assume that you didn't create a sub domain (child domain) rather you created an additional domain controller to the existing domain?  I would think that this make more sence as this would provide a temp fix for GC in the domain.  Also, this would make more sense regarding the user account and computer account replication (as computer accounts , user accounts don't replication between domains).

I still would agree with laura's thoughts here...


Author Comment

ID: 18842349
We tried many things.  We created another child domain different from our existing domain.  We did try creating another domain controller in our domain, but whatever the problem was with our global catalog (and template file according to Microsoft) would always get replicated to the new domain controller we created and it wouldn't work as a global catalog.  I am not concerned with the global catalog issue right now.  We've exhausted all possibilities and ways to try to fix it.  At this point the permanent fix is to migrate to the new child domain all our users, computers, etc.

But that migration might not happen for a while because we are so busy.  The issue at hand that I am concerned with is the replication between our existing domain controllers.  I will try running the following 3 commands this morning:  netdiag /v, dcdiag /v, repadmin /replsum.
Need protection from advanced malware attacks?

Look no further than WatchGuard's Total Security Suite, providing defense in depth against today's most headlining attacks like Petya 2.0 and WannaCry. Keep your organization out of the news with protection from known and unknown threats.

LVL 33

Expert Comment

ID: 18842684
Just to clarify...  

In your configuration, the computer and user accounts will NOT replicate between domains.  

For example, if you create a user account called BOB in domain A, the BOB account will not get replicated to domain B.  This is by design.

However, if you have two domain controllers in the SAME domain, the user accounts and computers account should be replicated between.


Author Comment

ID: 18842697
User accounts and computer accounts are not replicating within the same domain.  

I was thinking of just demoting and repromoting one of the domain controllers.
LVL 30

Accepted Solution

LauraEHunterMVP earned 1500 total points
ID: 18842736
I would recommend running the utilities that I mentioned first, as well as confirming and re-confirming physical connectivity and DNS name resolution between your DCs, since any of these will likely point to a cause for the issue.
LVL 33

Expert Comment

ID: 18842832
Laura is correct here... DNS is probably the cause of your problems ...but you will have to run the tools to see this...  

Also checking Event viewer would be good step to take as well.

It would help to give us the TCP/IP settings of your DC's...and the roles...  For example, do you have the DNS service running on both DC's.

good luck...later


Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question