troubleshooting Question

Are these Netlogon Errors a concern?

Avatar of jnordeng
jnordeng asked on
* windows 2016 serverWindows Server 2008Active Directory
3 Comments2 Solutions23 ViewsLast Modified:
We have a Windows 2008 R2 domain functional and forest level and are primary FSMO role holders are Windows 2008 R2 Servers.  We have introduced Windows 2016 DC's and are checking health so we can move FSMO roles.

I've noticed running DCDiag on the Windows 2008 systems give me a ton of Netlogon errors but I don't see this on the Windows 2016 Servers.

            Event String:
            The Netlogon service allowed a vulnerable Netlogon secure channel co
nnection because the machine account is allowed in the  "Domain controller: Allo
w vulnerable Netlogon secure channel connections" group policy.
         A warning event occurred.  EventID: 0x000016C6
            Time Generated: 05/04/2021   09:26:59
            Event String:
            The Netlogon service allowed a vulnerable Netlogon secure channel co
nnection because the machine account is allowed in the  "Domain controller: Allo
w vulnerable Netlogon secure channel connections" group policy.
         A warning event occurred.  EventID: 0x000016C6
            Time Generated: 05/04/2021   09:27:44
            Event String:
            The Netlogon service allowed a vulnerable Netlogon secure channel co

Should add, running the standard repadmin/showrepl and repadmin /replsummary does not show issues.

Googling a bit, I've seen some things indicating that Sysvol isn't replicating properly, but I do see it on the Windows 2016 servers and Windows 2008 R2 servers are the primaries.  I have also read that this isn't an issue.  Or is this rather a Group Policy issue?

We are trying to do our due diligence to make sure AD is healthy before we move FSMO roles.

Thanks
SOLUTION
Andrew Porter
Chief Information Security Officer

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 2 Answers and 3 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 3 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros