Solved

AD / GC offline in single DC SBS domain after NTFRS error resolution attempt

Posted on 2013-11-30
2
858 Views
Last Modified: 2013-11-30
Good afternoon!

I believe I screwed myself while performing some routine maintenance on our single Domain Controller SBS 2011 Standard domain...

I was looking through the log files and saw this entry:
EVENT ID 13559 : NtFrs
"""""
The File Replication Service has detected that the replica root path has changed from "c:\windows\sysvol\domain" to "c:\windows\sysvol\domain". If this is an intentional move then a file with the name NTFRS_CMD_FILE_MOVE_ROOT needs to be created under the new root path.
This was detected for the following replica set:
    "DOMAIN SYSTEM VOLUME (SYSVOL SHARE)"
 
Changing the replica root path is a two step process which is triggered by the creation of the NTFRS_CMD_FILE_MOVE_ROOT file.
 
 [1] At the first poll which will occur in 5 minutes this computer will be deleted from the replica set.
 [2] At the poll following the deletion this computer will be re-added to the replica set with the new root path. This re-addition will trigger a full tree sync for the replica set. At the end of the sync all the files will be at the new location. The files may or may not be deleted from the old location depending on whether they are needed or not.
"""""

I proceeded to follow these instructions to repair this (supposed) issue. I created the file in the indicated location, and sure enough, it triggered some kind of rebuild, it moved the current files out to a "temporary" folder, and I went about my day. About an hour later, I realized that we were having login trouble across the domain, and saw numerous errors in event logs across several servers, indicating that AD was down.

After running more tests and looking at logs, I realized that the "resync" that I had triggered was not completing, and the Server was not advertising Authentication services without it.

So... I'm stuck. I have good backups, and can revert to the last good state if needed, HOWEVER, since this is SBS, I have Exchange data to worry about (as of right now, my last good backup is over 24 hours old), so I'd have to deal with that if I can't repair Active Directory.

Ideas? See attached files for DCDiag and IPConfig output - let me know if other logs/data are needed. Thanks!


ipconfig-all.txt

dcdiag.txt
0
Comment
Question by:Kadrel
2 Comments
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39687359
Please confirm If you have only one domain controller ?

If yes, you can Authoritatively restore Sysvol with D4 Burgflag method

To complete an authoritative restore, stop the FRS service, configure the
BurFlags registry key, and then start the FRS service.


To do so:
1.Click Start, and then click Run.
2.In the Open box, type cmd and then press ENTER.
3.In the Command box, type net stop ntfrs.
4.Click Start, and then click Run.
5.In the Open box, type regedit and then press ENTER.
6.Locate the following subkey in the registry:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process at Startup

7.In the right pane, double click BurFlags.
8.In the Edit DWORD Value dialog box, type D4 and then click OK.
9.Quit Registry Editor, and then switch to the Command box.
10.In the Command box, type net start ntfrs.


 When the FRS service is restarted, the following actions occur:
•The value for the BurFlags registry key is set back to 0.
• An event 13566 is logged to signal that an authoritative restore is started.
•Files in the reinitialized FRS replicated directories remain unchanged and become authoritative on direct replication. Additionally, the files become indirect replication partners through transitive replication.
•The FRS database is rebuilt based on current file inventory.
•When the process is complete, an event 13516 is logged to signal that FRS is operational. If the event is not logged, there is a problem with the FRS configuration.

Please check below articles for more information
http://support.microsoft.com/kb/290762 - Check Authoritative Restore Section
http://networkadminkb.com/KB/a473/how-to-fix-event-id-13559-the-replica-root-path-has-changed.aspx

Mahesh
0
 

Author Closing Comment

by:Kadrel
ID: 39687413
Mahesh, thank you! Spot on!

I performed the authoritative restore per your instructions (and the references provided), and am back up and running! Much less painful than I expected - thank you so much!!!!!!
0

Featured Post

Want to promote your upcoming event?

Attending an event? Speaking at a conference? Or exhibiting at a tradeshow? Easily inform your contacts by using a promotional banner in your email signature. This will ensure your organization’s most important contacts are in the know.

Join & Write a Comment

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now