Solved

Active directory users not showing up on all AD servers

Posted on 2009-05-19
12
955 Views
Last Modified: 2012-05-07
I have 3 AD servers, lets call them AD1, AD2, and AD3. AD1 has all of the primary fsmo roles, it is a windows 2008 server and I use it for new user creation. AD2 and AD3 are windows 2003.

On Friday I created 3 new users on AD1. Today I could not find those users anywhere except on AD2 - they are gone from AD1 and AD3.

What could be causing this to happen? I'll gladly provide any other info you need.

Thank you for your time.
0
Comment
Question by:b-mac
  • 6
  • 3
  • 3
12 Comments
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24426313
Hi,

Use Replmon http://technet.microsoft.com/en-us/library/cc772954(WS.10).aspx 

This will help you to see if there are any replication errors between the domain controllers in your domain.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24428209
Run a dcdiag on the system then post results it seems you might have some replication issues.
0
 

Author Comment

by:b-mac
ID: 24431814
Here is the result from "AD1" which is actually named ICX-AD. Please note that ANNAP-AD is the domain controller for a separate domain and is currently offline.

Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=X,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=ForestDnsZones,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:51:28.

            1006 failures have occurred since the last success.

         [ANNAP-AD] DsBindWithSpnEx() failed with error 1722,

         The RPC server is unavailable..
         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context:

            CN=Schema,CN=Configuration,DC=Wilmington,DC=inclinix,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:37.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: CN=Configuration,DC=Wilmington,DC=X,DC=com

            The replication generated an error (1722):

            The RPC server is unavailable.

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 11:46:38.

            1006 failures have occurred since the last success.

            The source remains down. Please check the machine.

         [Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

         ......................... ICX-AD failed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:31

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:32

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:33

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:34

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:35

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/20/2009   09:26:36

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.X.com

      Starting test: LocatorCheck

         ......................... Wilmington.X.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.X.com passed test

         Intersite


Thanks for your help!
0
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435981
Hi,

There's your problem

----------------------------------------------------------------------------------
[Replications Check,ICX-AD] A recent replication attempt failed:

            From ANNAP-AD to ICX-AD

            Naming Context: DC=Annapolis,DC=X,DC=com

            The replication generated an error (1256):

            The remote system is not available. For information about network troubleshooting, see Windows Help.

           

            The failure occurred at 2009-05-20 08:56:16.

            The last success occurred at 2009-04-08 12:05:47.

            1006 failures have occurred since the last success.

----------------------------------------------------------------------------------

Your server ANNAP-AD is unable to replicate to ICX-AD and hasent been able to since, 2009-04-08

Make sure the both servers have visability of each other. Try rebooting them one at a time as a quick fix.
0
 
LVL 4

Expert Comment

by:barryhiggins3
ID: 24435998
If that doesnt help see if any networking changes on that day, or any patches applied etc. Anything that may cause the servers to loose connectivity.
0
 

Author Comment

by:b-mac
ID: 24440860
Annap-ad is the domain controller for a different domain (annapolis domain) , and is currently off.

Would that affect the three domain controllers for my domain (wilmington domain) and prevent them from replicating correctly?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24441873
Yes, that would affect the domain controllers in the other domain because of replication problems that occur when a DC is down even if it is from another domain.
0
 

Author Comment

by:b-mac
ID: 24475766
Annap-ad, the annapolis domain controller, is back up now. I can access it from my machine which is on the wilmington domain.

However, I don't see the annapolis domain or its controller from any of the wilmington domain controllers.
0
 

Author Comment

by:b-mac
ID: 24482174
How do I get the domain controllers to recognize each other again and re-start the replication?
0
 

Author Comment

by:b-mac
ID: 24496668
The Annapolis domain controller is online again, and the replication errors are no longer present. However, I am still getting some errors (besides the printer drivers) and would like to fix them. Any idea what they are?


Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   Home Server = ICX-AD

   * Identified AD Forest.
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Connectivity

         ......................... ICX-AD passed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\ICX-AD

      Starting test: Advertising

         ......................... ICX-AD passed test Advertising

      Starting test: FrsEvent

         ......................... ICX-AD passed test FrsEvent

      Starting test: DFSREvent

         ......................... ICX-AD passed test DFSREvent

      Starting test: SysVolCheck

         ......................... ICX-AD passed test SysVolCheck

      Starting test: KccEvent

         ......................... ICX-AD passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ......................... ICX-AD passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ......................... ICX-AD passed test MachineAccount

      Starting test: NCSecDesc

         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Wilmington,DC=inclinix,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Wilmington,DC=inclinix,DC=com
         ......................... ICX-AD failed test NCSecDesc

      Starting test: NetLogons

         ......................... ICX-AD passed test NetLogons

      Starting test: ObjectsReplicated

         ......................... ICX-AD passed test ObjectsReplicated

      Starting test: Replications

         ......................... ICX-AD passed test Replications

      Starting test: RidManager

         ......................... ICX-AD passed test RidManager

      Starting test: Services

         ......................... ICX-AD passed test Services

      Starting test: SystemLog

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:46

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:47

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:48

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:49

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:50

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:51

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:49:53

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:03

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Call Center is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:04

            Event String:

            Driver Microsoft Office Document Image Writer Driver required for printer Microsoft Office Document Image Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:05

            Event String:

            Driver CutePDF Writer required for printer CutePDF Writer is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:06

            Event String:

            Driver RICOH Aficio MP C4500 PCL 6 required for printer RICOH Aficio MP C4500 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:07

            Event String:

            Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:09

            Event String:

            Driver Xerox Phaser 3500 PCL 6 required for printer Xerox Phaser 3500 Admin is unknown. Contact the administrator to install the driver before you log in again.

         An Error Event occurred.  EventID: 0x00000457

            Time Generated: 05/28/2009   13:54:10

            Event String:

            Driver HP Color LaserJet 4650 PCL 6 required for printer HP Color LaserJet 4650 is unknown. Contact the administrator to install the driver before you log in again.

         ......................... ICX-AD failed test SystemLog

      Starting test: VerifyReferences

         ......................... ICX-AD passed test VerifyReferences

   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : Wilmington

      Starting test: CheckSDRefDom

         ......................... Wilmington passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Wilmington passed test CrossRefValidation

   
   Running enterprise tests on : Wilmington.inclinix.com

      Starting test: LocatorCheck

         ......................... Wilmington.inclinix.com passed test

         LocatorCheck

      Starting test: Intersite

         ......................... Wilmington.inclinix.com passed test

         Intersite

0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 24507011
0
 

Author Closing Comment

by:b-mac
ID: 31583224
Thank you!
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SPAM and Ransomware and Backup 11 84
Hyper V cluster 2 31
Robocopy Skipped Directory 12 42
AD Activation of KMS Key 6 52
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now