Solved

Intermittent Issues querying Outlook Global Address List

Posted on 2014-01-31
3
444 Views
Last Modified: 2014-03-20
Hi guys,

We are currently experiencing an issue with users querying the GAL.  Throughout the day we have about 20+ users out of 400 who complain about the fact they can't view the GAL.  it just errors.  We find if we change their hosts file tempoarily  by adding the domain IP ... 10.*.*.* domain.com we can usually fix it.
We have recently built an additional DC for a site, which in a rush, had to build up in our main site and simulate the routing, but for some reason I believe DNS and replication did not fully replicate.  This server is now in the physical site and is setup within sites & services.
with correct subnet etc.
I have run dcdiag on all DCs in all sites and all looks to be healthy.  But we are still having users complain about this issue.  It seems to be incorrect information in ther GC on a particular DC which the clients are querying.
Could anyone point us in the right direction to diagnose this.  I can't find much on the internet as to understand the exact steps the outlook client will query a DC apart from its primary DNS server, it looks at the list of DC that host a GC and I guess it queries these to confirm they are alive and round robins every hour ?!?  I f can understand this better I might help me to pin point exactly when to look in DNS.

Just to also note.  We are currently in transition between AD2003 and DS2008r2


Kind regards,

Jim
0
Comment
Question by:macleandata
  • 2
3 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
Comment Utility
First off, what is the error you are getting? What are the users using for Outlook "cached mode or online mode"? The users that are running into the issue, if they try OWA are they able to see the GAL without issue?

If the users are using Outlook with cached mode enabled the GAL will be presented using the Offline Address Book. If the user has a corrupted OST or profile this could be causing the issue.

I would test with 1 users having the issue first and see if creating a new OUtlook profile correct the issue. If not, i would then look and see about creating a new OAB as it might be the generation server which is encountering the issue.

Will.
0
 

Accepted Solution

by:
macleandata earned 0 total points
Comment Utility
Hi Will,

I think I have just cracked this.  I was a limit on one of the GC with NSPI connections which has a limit in 2008 to 50 per user.  the user it related to was exchsrv20$ which is one of our exchange nodes.  I found out how to increase the size of this, but 1 a reboot is out of the question during the day and 2 need to understand why it is hitting this limit.  So I enable a GC on one of the 2003 DCs and removed the 2008 GC which was showing the errors -

Event 2820 - ActiveDirectory_DomainService

NSPI max connection limit for the user has reached. You need to do NSPI unbind on old connections before making new connections.

So far so good.


To answer your questions,  I can't remember the exact error.  and clients are not running cached ex mode.

I will confirm if this has resolved the issue (hopefully) if not it's back the drawing board.

Thanks

Jim
0
 

Author Closing Comment

by:macleandata
Comment Utility
Resolved the issue myself in the end
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Granting full access permission allows users to access mailboxes present in their database. By giving full access permission one can open and read the content of any mailbox but cannot send emails from that mailbox.
Use email signature images to promote corporate certifications and industry awards.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now