?
Solved

Unable to Sync between Additional Domain Controller and Primary Domain Controller

Posted on 2013-05-18
4
Medium Priority
?
1,741 Views
Last Modified: 2013-05-31
Hi,
We are running Active Directory and DNS Server on the Same Windows Server 2008 R2 as Virtual Machine on vSphere 5 Platform. Since it is for College environment every month we have to delete or create 1000 users. Recently iSCSI based Storage which is used to store the Virtual Machines (Includes Active Directory VM also) is corrupted. Then we have restored the Active Directory Server from the Clone image (of Active Directory) which was taken in Dec 2012. Here Some client machines are authenticating to the Active Directory but still some client machines are authenticating through ADC. But ADC unable to sync from PDC. What can do now in order to sync ADC from PDC. I executed dcdiag on the ADC also.
out.txt
0
Comment
Question by:dhanush_support
4 Comments
 
LVL 81

Expert Comment

by:arnold
ID: 39177878
AD is intolerant of the process you under took.
You have to either flush the secondary and rejoin the primary after restore.

The other problem you will run into is that systems will have different machine passwords than the AD and will not be able to authenticate (loss of trust) which will require you to rejoin all the systems from the beginign.

The sync issue is the rid master has a different count then the one on the secondary.

For future reference, use powershell to deactivate/delete users or add/create new ones.


A image can only be done when you have a single DC (which is not advisable) ref issue with workstations/systems from before..
0
 
LVL 85

Expert Comment

by:David Johnson, CD, MVP
ID: 39178006
0
 
LVL 16

Expert Comment

by:cantoris
ID: 39178210
Never restore a domain controller like this or you'll end up in a world of pain!

Do you have at least one original unaffected domain controller in existence (?the PDC you mention) as well as this restored one?  If so, I suspect you would be best decommissioning the restored one, doing a metadata cleanup to remove references to it and then manually installing a new DC and let replication do the rest.
0
 
LVL 27

Accepted Solution

by:
Steve earned 1500 total points
ID: 39180737
the problem you appear to have is that you have restored a backup of your DC which contained an old version of your AD database. Your 2 domain controllers are therefore arguing about which one has the correct copy of AD and the two are not friends.

Shutdown the restored DC ASAP and fix AD. Once AD is fixed you can look at restoring your old DC WITHOUT AD and letting it replicate it from the working DC.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Excel can be a tricky bit of software to get your head around. Whilst you’ll be able to eventually get to grips with the basic understanding of how to get by, there are a few Excel tips that not everybody will even know about let alone know how to d…
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
The view will learn how to download and install SIMTOOLS and FORMLIST into Excel, how to use SIMTOOLS to generate a Monte Carlo simulation of 30 sales calls, and how to calculate the conditional probability based on the results of the Monte Carlo …
The viewer will learn how to use the =DISCRINV command to create a discrete random variable, use this command to model a set of probabilities and outcomes in a Monte Carlo simulation, and learn how to find the standard deviation of a set of probabil…
Suggested Courses

601 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question