Solved

DSA signature is not getting updated on the Domain Controller

Posted on 2011-03-23
3
1,126 Views
Last Modified: 2012-05-11
DC - Windows 2003 SP2
Backup Exec 11d runs on a Windows 2003 SP2

When I do a full backup of my DCs; (C drive, Utility partition, System State, Shadow Copy Components); the DSA signature is not getting updated by Backup Exec. I get the event ID 2089: "This directory partition has not been backed up since at least the following number of days".  Now, I do see all the pertinent information with regards the being able to backup & restore the DC and active directory within Backup Exec itself.

Here is the kicker ... When I do a backup of only the System State -  the DSA Signature is "updated" and all is well.

I do not want to have to have seperate jobs to run for the system state, HELP?!
0
Comment
Question by:RussTre
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35199502
There was also a thread about this over on the symantec forums  http://www.symantec.com/connect/forums/11-d-system-state-backup

It looks like Backup Exec may not be using the proper method to update it during that full backup.  I wish someone from Symantec could have verified that.  I'm not 100% sure.

 Probably safe to ignore if the backups are successful but I'll keep looking around.

Thanks

Mike
0
 
LVL 1

Accepted Solution

by:
RussTre earned 0 total points
ID: 35210718
I got it firgured out. Besides Domain admins and backup operators, the backup exec account needs to be part of these 'policies' under local policy > user rights assignment

•Act as part of the operating system
•Create a token object (which can be used to access any local resources)
•Log on as a service
•Log on as a batch job (allows a user to be logged on by means of a batch-queue facility)
•Backup files and directories (provides rights to backup files and directories)
•Restore files and directories (provides rights to restore files and directories)
•Manage auditing and security log
•Take ownership of files and other objects

After they are in them (if not add the account); at a command prompt run gpupdate /force

This fixed it for me.
0
 
LVL 1

Author Closing Comment

by:RussTre
ID: 35239132
This is what fixed it.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question