Solved

Active directory users not showing up on all AD servers

Posted on 2009-05-19
12
952 Views
Last Modified: 2012-05-07
I have 3 AD servers, lets call them AD1, AD2, and AD3. AD1 has all of the primary fsmo roles, it is a windows 2008 server and I use it for new user creation. AD2 and AD3 are windows 2003.

On Friday I created 3 new users on AD1. Today I could not find those users anywhere except on AD2 - they are gone from AD1 and AD3.

What could be causing this to happen? I'll gladly provide any other info you need.

Thank you for your time.
0
Comment
Question by:b-mac
  • 6
  • 3
  • 3
12 Comments
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24426313
Hi,

Use Replmon http://technet.microsoft.com/en-us/library/cc772954(WS.10).aspx

This will help you to see if there are any replication errors between the domain controllers in your domain.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24428209
Run a dcdiag on the system then post results it seems you might have some replication issues.
0
 

Author Comment

by:b-mac
ID: 24431814
Here is the result from "AD1" which is actually named ICX-AD. Please note that ANNAP-AD is the domain controller for a separate domain and is currently offline.

Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=X,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:51:28.

            1006 failures have occurred since the last success.

         [ANNAP-AD] DsBindWithSpnEx() failed with error 1722,

         The RPC server is unavailable..
         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context:

            CN=Schema,CN=Configuration,DC=Wilmington,DC=inclinix,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:37.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: CN=Configuration,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

         ......................... ICX-AD failed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:31

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:32

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:33

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:34

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:35

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:36

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.X.com

      Starting test: LocatorCheck

         ......................... Wilmington.X.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.X.com passed test

         Intersite


Thanks for your help!
0
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435981
Hi,

There's your problem

----------------------------------------------------------------------------------
[Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

----------------------------------------------------------------------------------

Your server ANNAP-AD is unable to replicate to ICX-AD and hasent been able to since, 2009-04-08

Make sure the both servers have visability of each other. Try rebooting them one at a time as a quick fix.
0
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435998
If that doesnt help see if any networking changes on that day, or any patches applied etc. Anything that may cause the servers to loose connectivity.
0
 

Author Comment

by:b-mac
ID: 24440860
Annap-ad is the domain controller for a different domain (annapolis domain) , and is currently off.

Would that affect the three domain controllers for my domain (wilmington domain) and prevent them from replicating correctly?
0
Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24441873
Yes, that would affect the domain controllers in the other domain because of replication problems that occur when a DC is down even if it is from another domain.
0
 

Author Comment

by:b-mac
ID: 24475766
Annap-ad, the annapolis domain controller, is back up now. I can access it from my machine which is on the wilmington domain.

However, I don't see the annapolis domain or its controller from any of the wilmington domain controllers.
0
 

Author Comment

by:b-mac
ID: 24482174
How do I get the domain controllers to recognize each other again and re-start the replication?
0
 

Author Comment

by:b-mac
ID: 24496668
The Annapolis domain controller is online again, and the replication errors are no longer present. However, I am still getting some errors (besides the printer drivers) and would like to fix them. Any idea what they are?


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=inclinix,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=inclinix,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         ......................... ICX-AD passed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:46

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:47

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:48

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:49

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:50

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:51

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:53

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:03

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:04

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:05

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:06

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:07

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:09

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:10

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.inclinix.com

      Starting test: LocatorCheck

         ......................... Wilmington.inclinix.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.inclinix.com passed test

         Intersite

0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 24507011
0
 

Author Closing Comment

by:b-mac
ID: 31583224
Thank you!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now