Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Active directory users not showing up on all AD servers

Posted on 2009-05-19
12
Medium Priority
?
965 Views
Last Modified: 2012-05-07
I have 3 AD servers, lets call them AD1, AD2, and AD3. AD1 has all of the primary fsmo roles, it is a windows 2008 server and I use it for new user creation. AD2 and AD3 are windows 2003.

On Friday I created 3 new users on AD1. Today I could not find those users anywhere except on AD2 - they are gone from AD1 and AD3.

What could be causing this to happen? I'll gladly provide any other info you need.

Thank you for your time.
0
Comment
Question by:b-mac
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 3
  • 3
12 Comments
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24426313
Hi,

Use Replmon http://technet.microsoft.com/en-us/library/cc772954(WS.10).aspx 

This will help you to see if there are any replication errors between the domain controllers in your domain.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24428209
Run a dcdiag on the system then post results it seems you might have some replication issues.
0
 

Author Comment

by:b-mac
ID: 24431814
Here is the result from "AD1" which is actually named ICX-AD. Please note that ANNAP-AD is the domain controller for a separate domain and is currently offline.

Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=X,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:51:28.

            1006 failures have occurred since the last success.

         [ANNAP-AD] DsBindWithSpnEx() failed with error 1722,

         The RPC server is unavailable..
         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context:

            CN=Schema,CN=Configuration,DC=Wilmington,DC=inclinix,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:37.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: CN=Configuration,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

         ......................... ICX-AD failed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:31

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:32

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:33

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:34

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:35

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:36

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.X.com

      Starting test: LocatorCheck

         ......................... Wilmington.X.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.X.com passed test

         Intersite


Thanks for your help!
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435981
Hi,

There's your problem

----------------------------------------------------------------------------------
[Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

----------------------------------------------------------------------------------

Your server ANNAP-AD is unable to replicate to ICX-AD and hasent been able to since, 2009-04-08

Make sure the both servers have visability of each other. Try rebooting them one at a time as a quick fix.
0
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435998
If that doesnt help see if any networking changes on that day, or any patches applied etc. Anything that may cause the servers to loose connectivity.
0
 

Author Comment

by:b-mac
ID: 24440860
Annap-ad is the domain controller for a different domain (annapolis domain) , and is currently off.

Would that affect the three domain controllers for my domain (wilmington domain) and prevent them from replicating correctly?
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24441873
Yes, that would affect the domain controllers in the other domain because of replication problems that occur when a DC is down even if it is from another domain.
0
 

Author Comment

by:b-mac
ID: 24475766
Annap-ad, the annapolis domain controller, is back up now. I can access it from my machine which is on the wilmington domain.

However, I don't see the annapolis domain or its controller from any of the wilmington domain controllers.
0
 

Author Comment

by:b-mac
ID: 24482174
How do I get the domain controllers to recognize each other again and re-start the replication?
0
 

Author Comment

by:b-mac
ID: 24496668
The Annapolis domain controller is online again, and the replication errors are no longer present. However, I am still getting some errors (besides the printer drivers) and would like to fix them. Any idea what they are?


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=inclinix,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=inclinix,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         ......................... ICX-AD passed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:46

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:47

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:48

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:49

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:50

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:51

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:53

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:03

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:04

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:05

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:06

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:07

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:09

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:10

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.inclinix.com

      Starting test: LocatorCheck

         ......................... Wilmington.inclinix.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.inclinix.com passed test

         Intersite

0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 2000 total points
ID: 24507011
0
 

Author Closing Comment

by:b-mac
ID: 31583224
Thank you!
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question