• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5911
  • Last Modified:

Can't copy users in 2008 AD

Environmnet: Single Forest/Single Domain, 2 Domain Controllers on the same subnet, both global catalogs, domain 2008 functional level. One DC is 2008 R2, one is 2008. There is no exchange server in the environment.

I get the error: Windows cannot create the object because the name reference is invalid when trying to copy users on either dc. This happens on any user, any OU. I have tried multiple domain admin accounts and all of them have the issue.  I searched and found this link:

http://info.izzy.org/Technical/Lists/Issues%20%20Tips/DispForm.aspx?ID=182

however since I do not have exchange it does not apply.
0
sfagundes
Asked:
sfagundes
  • 5
  • 4
2 Solutions
 
Manpreet SIngh KhatraSolutions Architect, Project LeadCommented:
Are both the DC's in the same domain if so it wouldnt work as All DC's will have the same information in the domain :)

- Rancy
0
 
sfagundesAuthor Commented:
yes both dc's are the same domain.

I also tried resetting the security settings to default at the domain/ou/user level. This did not work
0
 
achaldaveCommented:
Check this
http://social.technet.microsoft.com/Forums/en/winserverDS/thread/4cbca3c9-44dc-4d03-82ed-936b44f33320

Also check accounts' attributes for any invalid characters in it.
0
Transaction-level recovery for Oracle database

Veeam Explore for Oracle delivers low RTOs and RPOs with agentless transaction log backup and transaction-level recovery of Oracle databases. You can restore the database to a precise point in time, even to a specific transaction.

 
Manpreet SIngh KhatraSolutions Architect, Project LeadCommented:
Are you trying to copy a user from one DC to another ?
Can you manually create a Object ?

Can you tell me what are you trying to achieve to assist you with the issue.

- Rancy
0
 
sfagundesAuthor Commented:
I am trying to create a new user by copying an existing user to avoid having to manually recreate all the group memberships. I can create new users in the same ou without issue.

I found that article as well, however I do not have any trusts since it is only one domain and forest and both of the DC's are global catalogs already.
0
 
Manpreet SIngh KhatraSolutions Architect, Project LeadCommented:
Are these server's VM ?
What if you go to Windows and run DSA with "Run as Administrator" and then try the same task ?

- Rancy
0
 
sfagundesAuthor Commented:
physical boxes.

Run As Administrator gives the same error.

Ran DCdiag an everything passed except netsec which is expected because we do not run any rodc's.

Opening a case with microsoft tomorrow. thanks for the suggestions
0
 
Manpreet SIngh KhatraSolutions Architect, Project LeadCommented:
Did you ever have another DC in the Domain ?

- Rancy
0
 
sfagundesAuthor Commented:
The issue was that "showinaddressbook" attribute for some older users had data. However because exchange was no longer in the environment, I needed to go into each user with adsiedit and remove those values.
0
 
sfagundesAuthor Commented:
RSAT tools had nothing to do with it, however it was related to an attribute so this got me going in the right direction.
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

  • 5
  • 4
Tackle projects and never again get stuck behind a technical roadblock.
Join Now