Domain Controller Diagnostic Errors on SBS 2008

Posted on 2016-10-05
Medium Priority
Last Modified: 2016-10-18
Got a strange one here.

I received a report that one of our client's server is beginning to have dc/AD errors.

I rand a dcdiag and attached the results.  There is no RODC in the environment, but what really has me scratching my head are the 0xC0002719 and 0x40000004 event IDs.

I also did a dcdiag /test:dns and attached the results as well.

I did some checking online but couldn't really find anything that looked like it would address this issue.

The clients don't seem to be impacted by this but the number of entries has increases over the past few days.

The server is SBS 2008.

This is a long-standing client, so what I'm looking for are step-by-step instructions on troubleshooting and resolving this issue.  Thank you.

Question by:Scott C
  • 2
LVL 44

Accepted Solution

Adam Brown earned 2000 total points
ID: 41830225

      Starting test: NCSecDesc


            Replicating Directory Changes In Filtered Set
         access rights for the naming context:


            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         ......................... NCDTSERVER failed test NCSecDesc

is probably the bigger problem. That basically means the DNS zones can't be replicated. If you open ADSIEdit and connect to DC=DomainDnsZones,DC=COMPANY,DC=LOCAL and DC=ForestDnsZones,DC=COMPANY,DC=LOCAL you should be able to fix those permissions easily enough.

As for the syslog errors, you'll get much better information on the net by searching the event IDs from the System log for those errors. That particular section of the DCDiag only shows the warning and error events in the system log. Those DCOM errors are usually a sign of DNS records not being updated correctly on client computers. They come up a lot when the DC or some other process tries to remotely access a system using DCOM and the computer's actual name doesn't match the computer name used to access. Basically, that means the DNS entry for the computer has the IP of a different computer listed. Best way to fix that is to force all the client machines to re-register their DNS information. Most likely, though, fixing your permissions issues on the DNS zones with ADSIEdit, as I mentioned, will resolve this issue after a while.
LVL 33

Author Comment

by:Scott C
ID: 41831704
Thanks for the reply.

Could you please provide me the steps to fix these permissions?  

I want to be able to go in there and get this right the first time.

Thank you.
LVL 33

Author Comment

by:Scott C
ID: 41832016
Ok.  Took your advice and looked in the Event logs.  I'm seeing tons of DCOM 10009 errors.

I followed KB957713 and changed the firewall GPO.  Will see if that does anything.

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Microsoft Jet database engine errors can crop up out of nowhere to disrupt the working of the Exchange server. Decoding why a particular error occurs goes a long way in determining the right solution for it.
There’s hardly a doubt that Business Communication is indispensable for both enterprises and small businesses, and if there is an email system outage owing to Exchange server failure, it definitely results in loss of productivity.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

619 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question