Solved

Windows Server 2012 SYSVOL and Group Policy Replication

Posted on 2015-01-15
4
310 Views
Last Modified: 2015-01-16
We have two Windows Server 2012 Datacenter (non R2) DC's running on VMWare 5.1 ESXi hosts.

The DC's are in the same subnet. They appear to be replicated but I am concerned about the domain status being shown on the Group Policy Management status page. When I click Detect Now from either DC, the other DC is always shows as "replication in progress". At no time do they ever show as "replication in sync". (See picture)
gp.PNG
My troubleshooting:
I've run dcdiag and every test successfully passes except for the DFSREvent which says: There are warning or error events within the last 24 hours...." (See picture)
dcdiag.PNG
The only warning is at 1am each night when our backup system does its thing. (See picture)
warning.PNG
repadmin /syncall works fine
There aren't any red exclamation errors in the event viewer
The NETLOGON and SYSVOL shares are working fine
We don't have any DFS NameSpaces


QUESTION:
Is this something I need to be worried about? It would seem that even if the service is interrupted during backup, I should be able to update it during the day to see the DCs in sync.
0
Comment
Question by:Paul Wagner
  • 2
  • 2
4 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40552602
Have you tried to open DFS Management and run a health report on the DC replication?

Have you checked the sysvol folder on each of your domain controllers to ensure the same data is present on both?

Will.
0
 
LVL 5

Author Comment

by:Paul Wagner
ID: 40553966
Health Report shows no errors or warnings.
SYSVOL\domain folder shows 4 GPO folders but the date on one of them is a few months off.
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 40553990
DFS-R only replicates changes not the entire folder. What are the timestamps on the policies? Do they match up?

If all tests are coming back clean there shouldn't be too much to worry about. Did you recently do an AD upgrade or was one done in the past?

Sometimes what I have seen is if you do an AD upgrade and you have domain controllers issues not all of the data is replicated during the upgrade or there are orphaned objects on some domain controllers.

Aside from that if all your tests are clean and there are no issues in regards to Policies apply etc I would not worry.

Will.
0
 
LVL 5

Author Comment

by:Paul Wagner
ID: 40554015
Ya, everything matches up. I just wish Group Policy Management said that the DC's were in sync. The tests all seem to pass so I guess we're good. Thanks for setting my mind at ease. :-)
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question