?
Solved

I can't add new group policies on additional domain controller

Posted on 2012-08-30
6
Medium Priority
?
1,352 Views
Last Modified: 2012-09-04
I added a Windows 2008 R2 server as a domain controller to an existing windows 2003 domain.  I ran all the adprep commands before I added the server.  When I try to open GP management, I receive an error message "The domain.com forest could not be loaded and will be removed.  The error message was: Unspecified error."

What do I need to do to be able to run group policy from the new server.
0
Comment
Question by:GreyHippo
  • 5
6 Comments
 

Author Comment

by:GreyHippo
ID: 38349899
Here is the result of a dcdiag

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\administrator.domain>dcdiag

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = server2
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\server2
      Starting test: Connectivity
         ......................... server2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\server2
      Starting test: Advertising
         ......................... server2 passed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... server2 passed test FrsEvent
      Starting test: DFSREvent
         ......................... server2 passed test DFSREvent
      Starting test: SysVolCheck
         ......................... server2 passed test SysVolCheck
      Starting test: KccEvent
         ......................... server2 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... server2 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... server2 passed test MachineAccount
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=local,DC=domain,DC=com
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=DomainDnsZones,DC=local,DC=domain,DC=com
         ......................... server2 failed test NCSecDesc
      Starting test: NetLogons
         ......................... server2 passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... server2 passed test ObjectsReplicated
      Starting test: Replications
         ......................... server2 passed test Replications
      Starting test: RidManager
         ......................... server2 passed test RidManager
      Starting test: Services
         ......................... server2 passed test Services
      Starting test: SystemLog
         An error event occurred.  EventID: 0x00000457
            Time Generated: 08/30/2012   08:08:30
            Event String:
            Driver Xerox WorkCentre 7428 PS required for printer !!domain-SERVER2!
Xerox WorkCentre 7428 PS is unknown. Contact the administrator to install the dr
iver before you log in again.
         

         ......................... server2 failed test SystemLog
      Starting test: VerifyReferences
         ......................... server2 passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : local
      Starting test: CheckSDRefDom
         ......................... local passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... local passed test CrossRefValidation

   Running enterprise tests on : local.domain.com
      Starting test: LocatorCheck
         ......................... local.domain.com passed test LocatorCheck
      Starting test: Intersite
         ......................... local.domain.com passed test Intersite

C:\Users\administrator.domain>
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 38349983
Before you promoted the 2K8 R2 DC did you run the adprep /domainprep /gpprep ? /gpprep is done for group policy so that they compatible across different OS versions. 2008 has features that 2003 does not have and this command is necessary.

You would run this command on the Infrastructure Master holder.
0
 

Author Comment

by:GreyHippo
ID: 38349990
Yes.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:GreyHippo
ID: 38350418
I am not able to edit the GPs thru the GP management console but I can access them thru Server Manager.  I was able to create a GP and link to an OU.

Why can't I access it thru GP Management console?
0
 

Accepted Solution

by:
GreyHippo earned 0 total points
ID: 38351703
It now works after I had to re-add my domain to the group policy management console
0
 

Author Closing Comment

by:GreyHippo
ID: 38362906
Not sure why I had to re-add my domain but it worked
0

Featured Post

Configuration Guide and Best Practices

Read the guide to learn how to orchestrate Data ONTAP, create application-consistent backups and enable fast recovery from NetApp storage snapshots. Version 9.5 also contains performance and scalability enhancements to meet the needs of the largest enterprise environments.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question