When a DC goes down, Exchange 2007 failed to respond for some time

Posted on 2009-05-03
Last Modified: 2012-05-06
All servers are running Windows 2008.  During a test we shuted down a DC, not the PDC.  Both DC ar GC.  For a reason or another one Exchange server was having problems with the system attendant, so the mailboxes were unavailable.  

I used "Modify configuration domain controller" to choose a DC.  The everything came back.  But as far as I know Exchange shouldn't have any trouble to run when a DC goes down, no matter which DC is down.  

Here is what I found in the event viewer
Microsoft Exchange System Attendant failed to read the membership of the universal security group '/dc=ca/dc=ourdomain/ou=Microsoft Exchange Security Groups/cn=Exchange Servers'; the error code was '8007203a'. The problem might be that the Microsoft Exchange System Attendant does not have permission to read the membership of the group.

If this computer is not a member of the group '/dc=ca/dc=ourdomain/ou=Microsoft Exchange Security Groups/cn=Exchange Servers', you should manually stop all Microsoft Exchange services, run the task 'add-ExchangeServerGroupMember,' and then restart all Microsoft Exchange services.

Could not read the Security Descriptor from the Exchange Server object with guid=D922679FE5725A4BBA65373361CF9BF1. As a result the Proxy Address Calculation RPC interface will not be available on the local Exchange Server.  

Error initializing session for virtual machine S2008MB001. The error number is 0x80040111. Make sure Microsoft Exchange Store is running. Also, make sure that there is a valid public folder database on the Exchange server.
Question by:quadrumane
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 58

Expert Comment

ID: 24293422

It is perfectly normal for Exchange to take somewhere in the region of 30 minutes to an hour to locate a new DC/GC to use when the one it is using is taken offline. Had you left it this long, it would have resolved the issue itself.

Bear in mind that as a best practice you should make all DCs Global Catalogs (GCs). Exchange communicates with Global Catalogs, so making all DCs GCs reduces confusion and will also ensure that if a DC is running, Exchange can communicate with it.

You must also verify that the Exchange Server is using more than one server for DNS. If it only has one DC configured as its DNS server, you need to install DNS on another DC and add that DC as an alternate DNS server. If the configured DNS Server goes down, Exchange will not be able to locate any resource records to find another DC, and will be in trouble.


Author Comment

ID: 24296077
Both DCs are GCs so all DCs are GCs.   Eventhough, you say it's perfectly normal that it takes up to an hour to locate a new DC/GC.  I'M surprised.  I thought it was faster.  

The DNS configuration is already as you said, I try to follow the best practices.


LVL 58

Expert Comment

ID: 24296101

If DNS has both DCs configured as DNS Servers on Exchange, then what you are seeing is normal.
If you wanted to force Exchange to detect a new DC quicker, you'd need to restart the Exchange services. Exchange won't do the detection automatically for up to an hour, as I stated previously.

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 24683842
I had to restart the Exchange topology service, which is restarting all other services.  Afterward, the System attendant and the information store can be restarted.  

It doesn't restart automatically after one hour.  It it fails to start, it won't start alone.

As far as I know to avoid this problem, you have to stop the services before rebooting the Exchange server.
LVL 58

Expert Comment

ID: 24690660

Exchange will detect a DC automatically after a period of time; a restart of the services is not required. If it were, it would be a major inconvenience for large Exchange topologies.


Accepted Solution

quadrumane earned 0 total points
ID: 25449389
Exchange is not detecting a DC after a period of time, or it can take too long.

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Change Exchange 2010 Namespace 6 68
Certificates for Exchange 2010 4 104
Exchange, OWA, PROXY 7 62
SECURITY CAM sends emails but they show 12 hours in the past..?? 2 54
Find out what you should include to make the best professional email signature for your organization.
After hours on line I found a solution which pointed to the inherited Active Directory permissions . You have to give/allow permissions to the "Exchange trusted subsystem" for the user in the Active Directory...
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question