Link to home
Start Free TrialLog in
Avatar of b-mac
b-mac

asked on

Active directory users not showing up on all AD servers

I have 3 AD servers, lets call them AD1, AD2, and AD3. AD1 has all of the primary fsmo roles, it is a windows 2008 server and I use it for new user creation. AD2 and AD3 are windows 2003.

On Friday I created 3 new users on AD1. Today I could not find those users anywhere except on AD2 - they are gone from AD1 and AD3.

What could be causing this to happen? I'll gladly provide any other info you need.

Thank you for your time.
Avatar of barryhiggins3
barryhiggins3
Flag of United Kingdom of Great Britain and Northern Ireland image

Hi,

Use Replmon http://technet.microsoft.com/en-us/library/cc772954(WS.10).aspx 

This will help you to see if there are any replication errors between the domain controllers in your domain.
Avatar of Darius Ghassem
Run a dcdiag on the system then post results it seems you might have some replication issues.
Avatar of b-mac
b-mac

ASKER

Here is the result from "AD1" which is actually named ICX-AD. Please note that ANNAP-AD is the domain controller for a separate domain and is currently offline.

Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=X,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:51:28.

            1006 failures have occurred since the last success.

         [ANNAP-AD] DsBindWithSpnEx() failed with error 1722,

         The RPC server is unavailable..
         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context:

            CN=Schema,CN=Configuration,DC=Wilmington,DC=inclinix,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:37.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: CN=Configuration,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

         ......................... ICX-AD failed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:31

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:32

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:33

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:34

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:35

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:36

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.X.com

      Starting test: LocatorCheck

         ......................... Wilmington.X.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.X.com passed test

         Intersite


Thanks for your help!
Hi,

There's your problem

----------------------------------------------------------------------------------
[Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

----------------------------------------------------------------------------------

Your server ANNAP-AD is unable to replicate to ICX-AD and hasent been able to since, 2009-04-08

Make sure the both servers have visability of each other. Try rebooting them one at a time as a quick fix.
If that doesnt help see if any networking changes on that day, or any patches applied etc. Anything that may cause the servers to loose connectivity.
Avatar of b-mac

ASKER

Annap-ad is the domain controller for a different domain (annapolis domain) , and is currently off.

Would that affect the three domain controllers for my domain (wilmington domain) and prevent them from replicating correctly?
Yes, that would affect the domain controllers in the other domain because of replication problems that occur when a DC is down even if it is from another domain.
Avatar of b-mac

ASKER

Annap-ad, the annapolis domain controller, is back up now. I can access it from my machine which is on the wilmington domain.

However, I don't see the annapolis domain or its controller from any of the wilmington domain controllers.
Avatar of b-mac

ASKER

How do I get the domain controllers to recognize each other again and re-start the replication?
Avatar of b-mac

ASKER

The Annapolis domain controller is online again, and the replication errors are no longer present. However, I am still getting some errors (besides the printer drivers) and would like to fix them. Any idea what they are?


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=inclinix,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=inclinix,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         ......................... ICX-AD passed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:46

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:47

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:48

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:49

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:50

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:51

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:53

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:03

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:04

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:05

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:06

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:07

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:09

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:10

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.inclinix.com

      Starting test: LocatorCheck

         ......................... Wilmington.inclinix.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.inclinix.com passed test

         Intersite

ASKER CERTIFIED SOLUTION
Avatar of Darius Ghassem
Darius Ghassem
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of b-mac

ASKER

Thank you!