Active Directory
--
Questions
--
Followers
Top Experts
Both DCs are Server 2012 Datacenter (not R2) with all current updates. They both have AD, DNS and DHCP.
DC1 is RID, PDC and Operations Master.
DC2 is getting AD and DNS updates but NO Group Policy replication is taking place. Users who end up with DC1 in their gpresult get the GPOs and no problems. Users who end up with DC2 "kind of" get GPOs but with a lof of missing settings. The records show that DC2's GPOs are over 100 days older than DC1, so they haven't synced/replicated in that long.
The problem DC is getting some errors.
-Error 1053
-Event ID 4012
Troubleshooting:
- Deleted all of the domain policies out of SYSVOL. They were over 100 days old, anyway (per event ID 4012).
- The NTFRS (File Replication) service will NOT start from the GUI or command line.
- I noticed that NTFRS won't start on the "working" DC
Any thoughts?
Research:
http://community.spiceworks.com/topic/765274-ntfrs-stopped-and-missing
This doesn't work because ntfrs isn't "missing". I see it there but it just won't start.
http://kpytko.pl/active-directory-domain-services/non-authoritative-sysvol-restore-frs/
I can follow this up to the point where it wants me to start the ntfrs service which results in error 1053.
https://support.microsoft.com/en-us/kb/2958414
The article did not address this specfic issue.
https://support.microsoft.com/en-us/kb/2218556
I did a non-authoratative restore, got Event ID 4614 in the DFS Replication log but still no replication in Group Policy.
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
There is no "/ALL" command for dcdiag. Are you looking for "/a"?
@Mohammed Khawaja
Won't I create problems across the enterprise by taking a domain controller out of play? ie- other services will fail like Exchange, Citrix, etc?
I am reading up on dcpromo and will perform the task in Remove Roles and Features. Where do I perform the meta data cleanup?






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
http://social.technet.microsoft.com/wiki/contents/articles/3984.domain-controller-demotion-and-metadata-cleanup.aspx
http://windocuments.net/forceremovaldc.html
DC2 IS connecting via DFSR to DC1 but I am not seeing any policies copied over to the c:\windows\SYSVOL\domain folder on DC2.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
I rebooted DC2 for good measure and the shared folder disappeared. Back to the drawing board.
Any article I look at about this particular issue (folders missing) says to do a non-authoritative or authoritative restore. I've done that already...
@mark bill
I know you asked for dcdiag /all but that command doesn't work.
I ran a simple dcdiag and I get two issues reported:
%%%%%%%%%%%%%
Warning: DsGetDcName returned information fo \\DC1.domain.local, when we were trying to reach DC2.
SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
..........................
Also, I get this:
%%%%%%%%%%%%%
Starting test: NetLogons
Unable to connect to the NETLOGON hsare! (\\DC2\netlogon)
[DC2] An net use or LsaPolicy operation failed with error 67,
The network name cannot be found..
..........................
All other tests pass
@pjam
I don't get the "replication hasn't taken place in xx days" anymore since I demoted and then promoted DC2. Now, it seems like the DFS share is just hosed. The DFSRPrivate folder has recent folders created a few days ago but no data in them.
Yes, all networking is solid. (ie- NIC, switch, ping tests, DNS, etc)
I ran the diagnostic but already discovered something new. The old/new (not sure) DC2 share is showing as Disabled because the old/new one is already there. I'm guessing since there are two DC2's then it won't let the newly promoted DC2 get activated.
(I've read articles about removing one server and adding it back but there is no option for that in my DFS Management.)
I clicked Yes to run the report
RESULTS:
Error - DC2 - The DFS Replication service is restarting frequently.
Warning - DC1 - This member is waiting for initial replication for replicated folder SYSVOL Share.
Warning - DC2 - This member is waiting for initial replication for replicated folder SYSVOL Share.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Not sure when it stopped, possibly after 2003.
gotta love all those confusing acronyms
That's what I figured.
Any solutions/thoughts on how to proceed? I'm working through the SYSVOL folders not being shared on DC2 right now until a better method of troubleshooting presents itself. (At this point, should I just make a new server?)

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
I fixed it. Say whhaaaattt? I have no idea why it started working this time.
I did an authoritative synchronization using this article.
My thoughts:
After demotion/promotion of DC2, I did an authoritative sync, but it still didn't work.
What might have made the difference:
-Playing around with creating a sysvol/netlogon share folder on DC2 and rebooting
-deleting contents of dc2 sysvol\domain folder and cutting contents of dc1 sysvol\domain folder to a temp folder. I then removed the replication group from DFS Management, moved the files back to DC1's sysvol\domain folder and then added the replication group back in DFS Management.
-Meticulously went through the authoritative sync instructions. (Perhaps I clicked the wrong server when entering the TRUE/FALSE commands?) I also restarted the DFSR service each time. I wasn't doing that before since other "guru" articles said that it wasn't necessary or didn't help.
After doing those things, I did the authoritative sync and it worked.
The only anomaly DCDIAG now shows is a DFSR Event in the last 24 hours but that should clear out by tomorrow.
Thank you to all who helped. I'll split up the points as best I can based on who helped the most.
Yes that article was to be my final attack as daunting as it looked. Luckily I got mine working without it, since I share the main DC with other sites.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Active Directory
--
Questions
--
Followers
Top Experts
Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.