Solved

Active directory users not showing up on all AD servers

Posted on 2009-05-19
12
961 Views
Last Modified: 2012-05-07
I have 3 AD servers, lets call them AD1, AD2, and AD3. AD1 has all of the primary fsmo roles, it is a windows 2008 server and I use it for new user creation. AD2 and AD3 are windows 2003.

On Friday I created 3 new users on AD1. Today I could not find those users anywhere except on AD2 - they are gone from AD1 and AD3.

What could be causing this to happen? I'll gladly provide any other info you need.

Thank you for your time.
0
Comment
Question by:b-mac
  • 6
  • 3
  • 3
12 Comments
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24426313
Hi,

Use Replmon http://technet.microsoft.com/en-us/library/cc772954(WS.10).aspx 

This will help you to see if there are any replication errors between the domain controllers in your domain.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24428209
Run a dcdiag on the system then post results it seems you might have some replication issues.
0
 

Author Comment

by:b-mac
ID: 24431814
Here is the result from "AD1" which is actually named ICX-AD. Please note that ANNAP-AD is the domain controller for a separate domain and is currently offline.

Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=X,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:51:28.

            1006 failures have occurred since the last success.

         [ANNAP-AD] DsBindWithSpnEx() failed with error 1722,

         The RPC server is unavailable..
         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context:

            CN=Schema,CN=Configuration,DC=Wilmington,DC=inclinix,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:37.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: CN=Configuration,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

         ......................... ICX-AD failed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:31

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:32

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:33

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:34

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:35

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:36

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.X.com

      Starting test: LocatorCheck

         ......................... Wilmington.X.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.X.com passed test

         Intersite


Thanks for your help!
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435981
Hi,

There's your problem

----------------------------------------------------------------------------------
[Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

----------------------------------------------------------------------------------

Your server ANNAP-AD is unable to replicate to ICX-AD and hasent been able to since, 2009-04-08

Make sure the both servers have visability of each other. Try rebooting them one at a time as a quick fix.
0
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435998
If that doesnt help see if any networking changes on that day, or any patches applied etc. Anything that may cause the servers to loose connectivity.
0
 

Author Comment

by:b-mac
ID: 24440860
Annap-ad is the domain controller for a different domain (annapolis domain) , and is currently off.

Would that affect the three domain controllers for my domain (wilmington domain) and prevent them from replicating correctly?
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24441873
Yes, that would affect the domain controllers in the other domain because of replication problems that occur when a DC is down even if it is from another domain.
0
 

Author Comment

by:b-mac
ID: 24475766
Annap-ad, the annapolis domain controller, is back up now. I can access it from my machine which is on the wilmington domain.

However, I don't see the annapolis domain or its controller from any of the wilmington domain controllers.
0
 

Author Comment

by:b-mac
ID: 24482174
How do I get the domain controllers to recognize each other again and re-start the replication?
0
 

Author Comment

by:b-mac
ID: 24496668
The Annapolis domain controller is online again, and the replication errors are no longer present. However, I am still getting some errors (besides the printer drivers) and would like to fix them. Any idea what they are?


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=inclinix,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=inclinix,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         ......................... ICX-AD passed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:46

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:47

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:48

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:49

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:50

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:51

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:53

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:03

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:04

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:05

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:06

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:07

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:09

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:10

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.inclinix.com

      Starting test: LocatorCheck

         ......................... Wilmington.inclinix.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.inclinix.com passed test

         Intersite

0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 24507011
0
 

Author Closing Comment

by:b-mac
ID: 31583224
Thank you!
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question