Domain Controller Replication access was denied.

Steve Bona
Steve Bona used Ask the Experts™
on
I have Active Directory replication error 1925 event on one of ours DCs S-ADS049.
I check replication using Repadmin,  and the command that i use is repadmin /showrepl * /csv > showrepl.csv
The errors come from Default Naming Context partition only
ReplErrors
 

When i list all domain i don't find the DC S-ADS049
AllDCs
And finally when i check the group member of S-ADS049, it is a member of the domain computer group only.
My question is how a domain member server promoted to DC, keeps as domain computer group member, and gets to replicate with some DCs ?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
These issues are almost always DNS or site and services related. Perform a metadata cleanup to remove the old DC object if you have not done so already.

https://www.petri.com/delete_failed_dcs_from_ad

You should also check AD Sites and services and make sure there are no objects for this DC there. Also delete the relevant DNS records for this DC (e.g. SRV, etc.).
Steve BonaInformation Technology Specialist

Author

Commented:
Indeed there was an old DC that had not been properly removed. After following the procedure from https://www.petri.com/delete_failed_dcs_from_ad the replication of the dc S-ADS049 has been corrected.

Thanks for help!!!

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial