This all came to light when I tried to add a user to our BlackBerry Enterprise Server that just happens to be on this box. The RIM support tech and I quickly determined the problem was AD related.
In ADSI Edit on a member server, a user (CN=Jane Smith) appears as a text file icon rather than the folder icon you would expect to see. There is also an empty space in the Class column where you would expect to see 'user'. There is no response when I right-click and choose properties.
I cannot resolve the user when I try to add them to the security pane of a local directory. Here's the strange thing though... The changes stick if I go in from another machine via the administrative share and add the user from another PC that actually CAN query the DC properly. Odd!
Both servers are 2K3. The DC is R1 and the member server is R2.
This is the only user out of a domain of well over one hundred that has this problem.
Everything appears as it should in ADSI Edit on the domain controllers and all other member servers.
What is the cause of this unusual condition and how do I correct?