Re: Two accounts getting locked out



What does DCDiag on each DC show?

The following is focused on DNS for AD but has
some AD troubleshooting references too....


DNS for AD
1) Dynamic for the zone supporting AD
2) All internal DNS clients NIC\IP properties must specify SOLELY
that internal, dynamic DNS server (set.)
3) DCs and even DNS servers are DNS clients too -- see #2
4) If you have more than one Domain, every DNS server must
be able to resolve ALL domains (either directly or indirectly)

netdiag /fix

....or maybe:

dcdiag /fix

(Win2003 can do this from Support tools):
nltest /dsregdns /server:DC-ServerNameGoesHere
http://support.microsoft.com/kb/q260371/

Ensure that DNS zones/domains are fully replicated to all DNS
servers for that (internal) zone/domain.

Also useful may be running DCDiag on each DC, sending the
output to a text file, and searching for FAIL, ERROR, WARN.

Single Label domain zone names are a problem Google:
[ "SINGLE LABEL" domain names DNS 2000 | 2003 microsoft: ]


.



Relevant Pages

  • Re: DCDIAG Command Result
    ... >I want to ask two things in following result of dcdiag command. ... > warning messages in KnowsOfRoleHolders Test. ... DNS for AD ... Single Label domain zone names are a problem Google: ...
    (microsoft.public.win2000.active_directory)
  • Re: Active Directory in a mess
    ... Check netdiag and dcdiag for errors. ... start investigating DNS. ... replication uses these GUIDs of each other to replicate. ... Set the DNS server in each computers NIC->IP ...
    (microsoft.public.win2000.active_directory)
  • Re: test domain completely offline.. help
    ... If you don't have the support tools installed, install them from your server install disk. ... Run dcdiag, netdiag and repadmin in verbose mode. ... If you download a gui script I wrote it should be simple to set and run (DCDiag and NetDiag). ... registered etc(which I assume was a symptom of DNS being offline). ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Controller Stops Processing All Login Requests Randomly
    ... But you seem pretty competent and if you have checked all of the DCDiag ... They are both holding the same exact zone. ... DNS is not case sensitive and although NetBIOS ... > "waimea.coe.cudenver.edu" in the server field. ...
    (microsoft.public.windows.server.dns)
  • Re: Active Directory could not resolve DNS host name
    ... If you don't have the tools installed, install them from your server install ... Run dcdiag, netdiag and repadmin in verbose mode. ... Active Directory could not resolve the following DNS host name of the ... domain controller to an IP address. ...
    (microsoft.public.windows.server.active_directory)