Solved

D2 Authoritative Restore

Posted on 2013-05-28
13
490 Views
Last Modified: 2013-05-28
Hey guys

Ok, I was having FRS issues on my domain controller and so I followed the advise of a support forum and they said that my event logs were saying I should do a D2 Restore.  So I backed up the sysvol\policies and sysvol\domain and did the D2 Restore.  Now the DC is having MORE issues and no one can login.  Can I stop the NTFRS and Net Logon Services and do a restore from backup of the 2 directories I backed up or am I screwed?

I tried logging into my Partner website from Microsoft but they ARE DOWN (yes, I am pissed) and the phone number they have goes to some Dish Network crap.

Thanks
0
Comment
Question by:jonmenefee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 5
13 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39201723
Is this your only DC?   What errors are you seeing in your logs.

As far as phone numbers for support start here   http://support.microsoft.com/contactus/

Thanks


Mike
0
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39201743
No, you can not paste your backups because this folders are created by dfs and can not be modified. Is more easy:
- Use a full backup and made a system restore to get back your domain
- Depromote and promote again this DC. You can do this procedure if you have more than one domain controller. If you have got only one DC you can not do this!.

When you restore your DC, some computers may lost his machine account password, this article may help you to restore: http://support.microsoft.com/kb/325850
0
 

Author Comment

by:jonmenefee
ID: 39201778
The other DC I have was having issues and thats why I was trying to get the DFS working on main controller.
The backups started failing two weeks ago and I dont think they are any good.

There are 5 users in the domain and an exchange server.  If it wasnt for the exchange server I would just start all over (but they also have roaming profiles and they cant get their desktops.  This whole thing is just about to drive me nuts
0
Salesforce Has Never Been Easier

Improve and reinforce salesforce training & adoption using WalkMe's digital adoption platform. Start saving on costly employee training by creating fast intuitive Walk-Thrus for Salesforce. Claim your Free Account Now

 

Author Comment

by:jonmenefee
ID: 39201810
error logs are as follows

application:  EventID 1054 windows cannot obtain the domin controller name for your computer network (this is on the Domain Controller

Application:  eventID  1006  Windows cannot bind to xxx.local domainu [Local Error] Group Policy Abortinug

Application:  EventID  1030 Windows cannot query for the list of Group Policy objects

File Replication Services:  EventID  13566  FRS is scanning the data in the system volume. Computer xxx cnnot become a domain controller until this process is complete

FRS:  EventID  13508
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 39201813
Have you tried the D4 to rebuild/authoritative restore?

Thanks

Mike
0
 

Author Comment

by:jonmenefee
ID: 39201834
Not yet.  Do I do the same?  Just stop NTFRS and Net Logon and then go to the same registry key and put in D4?
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39201864
yes. should be in the same article that you used for the D2 steps.
0
 

Author Comment

by:jonmenefee
ID: 39201920
MKline You are the MAN!!

Ok, its all back up now.  I still cannot replicate to the other DC but at least for now the main one is up and operational :-)
0
 

Author Closing Comment

by:jonmenefee
ID: 39201929
quick and concise :-)
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39201936
ok good, for now the pressure is off, users are logging on and working :)

You can try and fight with DC2 and get it fixed or try and demote/repromote.  If the graceful demotion doesn't work  you can force it off and clean it up and then promote it again (sounds worse than it is)

Thanks

Mike
0
 

Author Comment

by:jonmenefee
ID: 39202152
I think a demote/promote is what I will do.  Thank you again.  :-)
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39202168
no problem, and if you run into issues with it, open a new Q...we will help you if you need it.

Nice work getting your users back online.

Thanks

Mike
0
 

Author Comment

by:jonmenefee
ID: 39202206
I was actually on the Microsoft pay for support website and almost hit the submit link when your answer came.  Ya saved me nearly 300.00. So thank you. :-)
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article runs through the process of deploying a single EXE application selectively to a group of user.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question