troubleshooting Question

Active Directory Stopped Working

Avatar of Jack D
Jack DFlag for United States of America asked on
Active DirectoryWindows Server 2008
17 Comments2 Solutions1411 ViewsLast Modified:
Active Directory seems to have stopped working on my server. I have one server that functions as the PDC. Sometime in last week AD stopped. I have reviewed a lot of steps in previous questions and don't think it is a time issue or DNS issue but at this point who knows!

NLTEST results:
nltest /server:sjssrv01 /dsgetdc:sjscompany.com /gc /force
Getting DC name failed: Status = 1355 0x54b ERROR_NO_SUCH_DOMAIN

DCDIAG results:
C:\Users\administrator.SJSCOMPANY>dcdiag

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SJSSRV01
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SJSSRV01
      Starting test: Connectivity
         ......................... SJSSRV01 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SJSSRV01
      Starting test: Advertising
         Fatal Error:DsGetDcName (SJSSRV01) call failed, error 1355
         The Locator could not find the server.
         ......................... SJSSRV01 failed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the SYSVOL has been
         shared.  Failing SYSVOL replication problems may cause Group Policy problems.
         ......................... SJSSRV01 passed test FrsEvent
      Starting test: DFSREvent
         ......................... SJSSRV01 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... SJSSRV01 passed test SysVolCheck
      Starting test: KccEvent
         An error event occurred.  EventID: 0xC0000466
            Time Generated: 07/10/2012   10:55:28
            Event String:
            Active Directory Domain Services was unable to establish a connection with the global ca
talog.
         ......................... SJSSRV01 failed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... SJSSRV01 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... SJSSRV01 passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=sjscompany,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=DomainDnsZones,DC=sjscompany,DC=com
         ......................... SJSSRV01 failed test NCSecDesc
      Starting test: NetLogons
         Unable to connect to the NETLOGON share! (\\SJSSRV01\netlogon)
         [SJSSRV01] An net use or LsaPolicy operation failed with error 67,
         The network name cannot be found..
         ......................... SJSSRV01 failed test NetLogons
      Starting test: ObjectsReplicated
         ......................... SJSSRV01 passed test ObjectsReplicated
      Starting test: Replications
         ......................... SJSSRV01 passed test Replications
      Starting test: RidManager
         ......................... SJSSRV01 passed test RidManager
      Starting test: Services
         ......................... SJSSRV01 passed test Services
      Starting test: SystemLog
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:08:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:13:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0xC00038D6
            Time Generated: 07/10/2012   10:17:34
            Event String:
            The DFS Namespace service could not initialize cross forest trust information on this do
main controller, but it will periodically retry the operation. The return code is in the record data
.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:18:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0xC0001B6F
            Time Generated: 07/10/2012   10:23:07
            Event String: The Windows Time service terminated with the following error:
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:23:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         A warning event occurred.  EventID: 0x0000000C
            Time Generated: 07/10/2012   10:26:04
            Event String:
            Time Provider NtpClient: This machine is configured to use the domain hierarchy to deter
mine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so the
re is no machine above it in the domain hierarchy to use as a time source. It is recommended that yo
u either configure a reliable time service in the root domain, or manually configure the AD PDC to s
ynchronize with an external time source. Otherwise, this machine will function as the authoritative
time source in the domain hierarchy. If an external time source is not configured or used for this c
omputer, you may choose to disable the NtpClient.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:28:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:33:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:38:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         A warning event occurred.  EventID: 0x0000A001
            Time Generated: 07/10/2012   10:39:04
            Event String:
            The Security System could not establish a secured connection with the server ldap/sjscom
pany.com/sjscompany.com@SJSCOMPANY.COM. No authentication protocol was available.
         An error event occurred.  EventID: 0x0000168F
            Time Generated: 07/10/2012   10:40:11
            Event String:
            The dynamic deletion of the DNS record '_kerberos._tcp.sjscompany.com. 600 IN SRV 0 100
88 SJSSRV01.sjscompany.com.' failed on the following DNS server:
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:43:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:48:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:53:54
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         A warning event occurred.  EventID: 0x000003F6
            Time Generated: 07/10/2012   10:54:08
            Event String:
            Name resolution for the name sjscompany.com timed out after none of the configured DNS s
ervers responded.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:57:36
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   10:58:55
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         An error event occurred.  EventID: 0x0000041E
            Time Generated: 07/10/2012   11:03:55
            Event String:
            The processing of Group Policy failed. Windows could not obtain the name of a domain con
troller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is
configured and working correctly.
         ......................... SJSSRV01 failed test SystemLog
      Starting test: VerifyReferences
         ......................... SJSSRV01 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : sjscompany
      Starting test: CheckSDRefDom
         ......................... sjscompany passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... sjscompany passed test CrossRefValidation

   Running enterprise tests on : sjscompany.com
      Starting test: LocatorCheck
         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
         A Global Catalog Server could not be located - All GC's are down.
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1355
         A Good Time Server could not be located.
         Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355
         A KDC could not be located - All the KDCs are down.
         ......................... sjscompany.com failed test LocatorCheck
      Starting test: Intersite
         ......................... sjscompany.com passed test Intersite

SFC /scannow says Windows Resource Protection did not find any integrity violations.

Any help is greatly appreciated. Thanks.
ASKER CERTIFIED SOLUTION
Jack D

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 2 Answers and 17 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 17 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros