?
Solved

DCdiag errors on new Windows 2008 Domain Controller

Posted on 2009-07-08
4
Medium Priority
?
2,940 Views
Last Modified: 2013-12-05
I am deploying a new Windows 2008 DC in an existing Windows 2000 forest/domain. When running Dcdiag /s:DC-1 (as Domain Admin) I am receiving the following errors; things appear to be working OK otherwise. If someone could point me to likely casues/solutions I'd appreciate it.

 Starting test: NetLogons
    [DC-1] User credentials does not have permission to perform this operation.
    The account used for this test must have network logon privileges
    for this machine's domain.

Starting test: Replications
   [Replications Check,DC-1] DsReplicaGetInfo(PENDING_OPS, NULL) failed, error 0x2105
   "Replication access was denied."

 Starting test: Services
       Could not open NTDS Service on DC-1, error 0x5 "Access is denied."
0
Comment
Question by:agradmin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 11

Assisted Solution

by:loftyworm
loftyworm earned 1000 total points
ID: 24808503
So, you added the 2k8 as a member server, then ran DCPromo?
No errors during setup?

From a working DC, can you go to shares \\dc-1\sysvol or \\dc-1\netlogon

It looks like a permissions issue, like the pcpromo didn't run correctly.
0
 
LVL 10

Assisted Solution

by:dnilson
dnilson earned 1000 total points
ID: 24810145
Have you checked file ACLs and registry permissions, say using the MMC securty configuration, resultant security and security template adins?

open a command prompt

run mmc /a
File | add remove snapin
add
Resultant set of policy
Security configuration and analysis
Security templates

Close the dialogs, right click on Security configuration and analysis
Select the appropriate template, perhaps secure DC

and run the analysis

You will clearly see the differences between the policy and the machine.

Check the system logs to see if the access denied message gives any further clues as to what is being denied, check the analysis in that area and make appropriate changes,

If you are nor certain WHERE the secuity settings that are causing you isses are coming from (i.e. "That doesnt ake sense") run the RSOP tool which will TEEL you if its a local, or domain policy, etc so you know where to make the changes.

You can also APPLY the policy whic will correct most such access errors
0
 

Author Comment

by:agradmin
ID: 24814388
I can get to both Sysvol AND Netlogon shares from other DC's using the same credentials (actually a memebr of the Enterprise Admin group). Like I said, things appear to be working OK (logon script runs, policies ar being set, GPresult indicates as expected), it's almost as though the errors are red-herrings.

Tried running the Security Analysis tool - where the heck are the security templates on Windows 2008?
0
 

Accepted Solution

by:
agradmin earned 0 total points
ID: 25062156
Problem solved - apparently tests have to be run under a local admin account (ie open CMD as RunaAs, select admin account). Run as the local admin all tests run perfectly.
It doesn't really make a lot of sense to me why domain/enterprise admin accounts cannot run tests on domains when a local admin account can, but it does work.
Thanks for your suggestions.
0

Featured Post

Want to be a Web Developer? Get Certified Today!

Enroll in the Certified Web Development Professional course package to learn HTML, Javascript, and PHP. Build a solid foundation to work toward your dream job!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently changeā€¦
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses
Course of the Month9 days, 15 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question