Solved

DCdiag errors on new Windows 2008 Domain Controller

Posted on 2009-07-08
4
2,759 Views
Last Modified: 2013-12-05
I am deploying a new Windows 2008 DC in an existing Windows 2000 forest/domain. When running Dcdiag /s:DC-1 (as Domain Admin) I am receiving the following errors; things appear to be working OK otherwise. If someone could point me to likely casues/solutions I'd appreciate it.

 Starting test: NetLogons
    [DC-1] User credentials does not have permission to perform this operation.
    The account used for this test must have network logon privileges
    for this machine's domain.

Starting test: Replications
   [Replications Check,DC-1] DsReplicaGetInfo(PENDING_OPS, NULL) failed, error 0x2105
   "Replication access was denied."

 Starting test: Services
       Could not open NTDS Service on DC-1, error 0x5 "Access is denied."
0
Comment
Question by:agradmin
  • 2
4 Comments
 
LVL 11

Assisted Solution

by:loftyworm
loftyworm earned 250 total points
ID: 24808503
So, you added the 2k8 as a member server, then ran DCPromo?
No errors during setup?

From a working DC, can you go to shares \\dc-1\sysvol or \\dc-1\netlogon

It looks like a permissions issue, like the pcpromo didn't run correctly.
0
 
LVL 10

Assisted Solution

by:dnilson
dnilson earned 250 total points
ID: 24810145
Have you checked file ACLs and registry permissions, say using the MMC securty configuration, resultant security and security template adins?

open a command prompt

run mmc /a
File | add remove snapin
add
Resultant set of policy
Security configuration and analysis
Security templates

Close the dialogs, right click on Security configuration and analysis
Select the appropriate template, perhaps secure DC

and run the analysis

You will clearly see the differences between the policy and the machine.

Check the system logs to see if the access denied message gives any further clues as to what is being denied, check the analysis in that area and make appropriate changes,

If you are nor certain WHERE the secuity settings that are causing you isses are coming from (i.e. "That doesnt ake sense") run the RSOP tool which will TEEL you if its a local, or domain policy, etc so you know where to make the changes.

You can also APPLY the policy whic will correct most such access errors
0
 

Author Comment

by:agradmin
ID: 24814388
I can get to both Sysvol AND Netlogon shares from other DC's using the same credentials (actually a memebr of the Enterprise Admin group). Like I said, things appear to be working OK (logon script runs, policies ar being set, GPresult indicates as expected), it's almost as though the errors are red-herrings.

Tried running the Security Analysis tool - where the heck are the security templates on Windows 2008?
0
 

Accepted Solution

by:
agradmin earned 0 total points
ID: 25062156
Problem solved - apparently tests have to be run under a local admin account (ie open CMD as RunaAs, select admin account). Run as the local admin all tests run perfectly.
It doesn't really make a lot of sense to me why domain/enterprise admin accounts cannot run tests on domains when a local admin account can, but it does work.
Thanks for your suggestions.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question