Active Directory
--
Questions
--
Followers
Top Experts
1. TimeSync with NTP (There was a time issue but it is now resolved - all are sync'ing with nist.gov)
2. DNS has valid entries in the domain in the _msdcs folder
3. Ran repadmin to trouble shoot and saw the following:
 for /syncall run -
CALLBACK MESSAGE: The following replication is in progress:
  From: 26a54e69-1984-4e95-9491-f4
  To  : 6068dd17-a0fb-4a57-819a-01
CALLBACK MESSAGE: Error issuing replication: 8453 (0x2105):
  Replication access was denied.
  From: 26a54e69-1984-4e95-9491-f4
  To  : 6068dd17-a0fb-4a57-819a-01
CALLBACK MESSAGE: SyncAll Finished.
SyncAll reported the following errors:
Error issuing replication: 8453 (0x2105):
  Replication access was denied.
  From: 26a54e69-1984-4e95-9491-f4
  To  : 6068dd17-a0fb-4a57-819a-01
for a /showreps -
C:\Users\swalsh>repadmin /showreps
Default-First-Site-Name\AV
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 6068dd17-a0fb-4a57-819a-01
DSA invocationID: 6068dd17-a0fb-4a57-819a-01
==== INBOUND NEIGHBORS ==========================
DC=lss,DC=company,DC=com
  Default-First-Site-Name\AV
    DSA object GUID: 26a54e69-1984-4e95-9491-f4
    Last attempt @ 2008-10-10 15:04:00 was successful.
CN=Configuration,DC=lss,DC
  Default-First-Site-Name\AV
    DSA object GUID: 26a54e69-1984-4e95-9491-f4
    Last attempt @ 2008-10-10 14:56:54 was successful.
CN=Schema,CN=Configuration
  Default-First-Site-Name\AV
    DSA object GUID: 26a54e69-1984-4e95-9491-f4
    Last attempt @ 2008-10-10 14:56:54 was successful.
DC=DomainDnsZones,DC=lss,D
  Default-First-Site-Name\AV
    DSA object GUID: 26a54e69-1984-4e95-9491-f4
    Last attempt @ 2008-10-10 14:56:54 was successful.
DC=ForestDnsZones,DC=lss,D
  Default-First-Site-Name\AV
    DSA object GUID: 26a54e69-1984-4e95-9491-f4
    Last attempt @ 2008-10-10 14:56:54 was successful.
DsReplicaGetInfo() failed with status 8453 (0x2105):
  Replication access was denied.
DsReplicaGetInfo() failed with status 8453 (0x2105):
  Replication access was denied.
There is also an 4013 error in DNS that I don't know how to fix and there is no info on Microsoft's site that I have found:
Event Type: Â Â Â Â Â Warning
Event Source: Â Â Â Â Â DNS
Event Category: Â Â Â Â Â None
Event ID: Â Â Â Â Â 4013
Date: Â Â Â Â Â Â Â Â Â Â Â 10/10/2008
Time: Â Â Â Â Â Â Â Â Â Â Â 2:27:14 PM
User: Â Â Â Â Â Â Â Â Â Â Â N/A
Computer: Â Â Â Â Â AVAMAR252.lss.company.com
Description:
The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical DNS data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the Internet Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
I am unsure if these are interrelated. Any guidance greatly appreciated.
- Steve
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Active Directory
--
Questions
--
Followers
Top Experts
Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.