Solved

DSA signature is not getting updated on the Domain Controller

Posted on 2011-03-23
3
1,117 Views
Last Modified: 2012-05-11
DC - Windows 2003 SP2
Backup Exec 11d runs on a Windows 2003 SP2

When I do a full backup of my DCs; (C drive, Utility partition, System State, Shadow Copy Components); the DSA signature is not getting updated by Backup Exec. I get the event ID 2089: "This directory partition has not been backed up since at least the following number of days".  Now, I do see all the pertinent information with regards the being able to backup & restore the DC and active directory within Backup Exec itself.

Here is the kicker ... When I do a backup of only the System State -  the DSA Signature is "updated" and all is well.

I do not want to have to have seperate jobs to run for the system state, HELP?!
0
Comment
Question by:RussTre
  • 2
3 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35199502
There was also a thread about this over on the symantec forums  http://www.symantec.com/connect/forums/11-d-system-state-backup

It looks like Backup Exec may not be using the proper method to update it during that full backup.  I wish someone from Symantec could have verified that.  I'm not 100% sure.

 Probably safe to ignore if the backups are successful but I'll keep looking around.

Thanks

Mike
0
 
LVL 1

Accepted Solution

by:
RussTre earned 0 total points
ID: 35210718
I got it firgured out. Besides Domain admins and backup operators, the backup exec account needs to be part of these 'policies' under local policy > user rights assignment

•Act as part of the operating system
•Create a token object (which can be used to access any local resources)
•Log on as a service
•Log on as a batch job (allows a user to be logged on by means of a batch-queue facility)
•Backup files and directories (provides rights to backup files and directories)
•Restore files and directories (provides rights to restore files and directories)
•Manage auditing and security log
•Take ownership of files and other objects

After they are in them (if not add the account); at a command prompt run gpupdate /force

This fixed it for me.
0
 
LVL 1

Author Closing Comment

by:RussTre
ID: 35239132
This is what fixed it.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question