SYSVOL and NETLOGON issues on a BDC - REPOSTING INCLUDING THE LAST THREAD SINCE I NEED THIS ISSUE RESOLVED

Tech-Archive recommends: Speed Up your PC by fixing your registry



I'm confused as to what to do while connected to which DC (using NTDSUTIL).
It seems that the PDCE knows of all the FSMO roles. Here's what happens
when I run transfer PDC on the current PDCE:

fsmo maintenance: transfer pdc
Server "PDCE" knows about 5 roles
Schema - CN="NTDS Settings
DEL:ba8cf2d7-ae53-4c00-bf4d-ad5f7fde8124",CN="Old_PDCE_Name
DEL:e70c529c-5e96-4545-90b2-523e609f762a",CN=Servers,CN=Default-First-Site-Name,
CN=Sites,CN=Configuration,DC=domain,DC=com
Domain - CN="NTDS Settings
DEL:ba8cf2d7-ae53-4c00-bf4d-ad5f7fde8124",CN="Old_PDCE_Name
DEL:e70c529c-5e96-4545-90b2-523e609f762a",CN=Servers,CN=Default-First-Site-Name,
CN=Sites,CN=Configuration,DC=domain,DC=com
PDC - CN=NTDS Settings,CN=PDCE,CN=Servers,CN=Default-First-Site-Name,CN=Sit
es,CN=Configuration,DC=domain,DC=com
RID - CN=NTDS Settings,CN=PDCE,CN=Servers,CN=Default-First-Site-Name,CN=Sit
es,CN=Configuration,DC=domain,DC=com
Infrastructure - CN=NTDS Settings,CN=PDCE,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=domain,DC=com

DCPROMO removed AD from the server without isssues before the old PDC was
renamed. It didn't fail (it didn't display any errors at least). NTDSUTIL
is only showing the two current DCs when I do "list servers in site".

Thanks again for your help!


"Allen Firouz" <AllenFirouz@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1006BAD8-B302-4710-B90C-FBA69F9EA863@xxxxxxxxxxxxxxxx
> Fritz:
>
> There are a few issues, which may be critical! One of them, (based on the
> log) is that the DC is not aware of the FSMO role holders! Check to see
> if
> the FSMO roles are setup properly in your environment. It may be that the
> roles were not transferred properly during your migration. If they are
> lost,
> you need to seize the missing role(s) (
> http://support.microsoft.com/kb/255504 ) . The dcdiag command NETDOM
> QUERY
> FSMO command does not identify FSMO roles that reside on deleted domain
> controllers. So check your environment and seize the necessary roles.
> THAT
> is a biggie and the most likely cause of your woes.
>
> Also, if the FSMO roles are setup properly in your environment, then you
> may
> have a failed DCPROMO. In this case, follow this article to remove it and
> recreate it:
> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/91559a2b-b666-442c-bdd2-df4b7c46983c.mspx
>
> -Allen Firouz
>
> "Fritz" wrote:
>
>> Thanks for your help. I tried the link about troubleshooting SYSVOL /
>> NETLOGON shares before. It didn't help.
>>
>>
>> Here's more info (I'm wondering if it has to do with the Schema owner
>> being
>> deleted. How do I recreate it on another DC?). I hope that's enough:
>>
>>
>> DC Diagnosis
>>
>> Performing initial setup:
>> Done gathering initial info.
>>
>> Doing initial non skippeable tests
>>
>> Testing server: Default-First-Site-Name\BDC
>> Starting test: Connectivity
>> ......................... BDC passed test Connectivity
>>
>> Doing primary tests
>>
>> Testing server: Default-First-Site-Name\BDC
>> Starting test: Replications
>> ......................... BDC passed test Replications
>> Starting test: NCSecDesc
>> ......................... BDC passed test NCSecDesc
>> Starting test: NetLogons
>> ......................... BDC passed test NetLogons
>> Starting test: Advertising
>> ......................... BDC passed test Advertising
>> Starting test: KnowsOfRoleHolders
>> Warning: CN="NTDS Settings
>> DEL:ba8cf2d7-ae53-4c00-bf4d-ad5f7fde8124",CN="Old_PDCE_Name
>> DEL:e70c529c-5e96-4545-90b2-523e609f762a",CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domainname,DC=com
>> is the Schema Owner, but is deleted.
>> Warning: CN="NTDS Settings
>> DEL:ba8cf2d7-ae53-4c00-bf4d-ad5f7fde8124",CN="Old_PDCE_Name
>> DEL:e70c529c-5e96-4545-90b2-523e609f762a",CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domainname,DC=com
>> is the Domain Owner, but is deleted.
>> ......................... BDC failed test KnowsOfRoleHolders
>> Starting test: RidManager
>> ......................... BDC passed test RidManager
>> Starting test: MachineAccount
>> ......................... BDC passed test MachineAccount
>> Starting test: Services
>> ......................... BDC passed test Services
>> Starting test: ObjectsReplicated
>> ......................... BDC passed test ObjectsReplicated
>> Starting test: frssysvol
>> Error: No record of File Replication System, SYSVOL started.
>> The Active Directory may be prevented from starting.
>> There are errors after the SYSVOL has been shared.
>> The SYSVOL can prevent the AD from starting.
>> ......................... BDC passed test frssysvol
>> Starting test: kccevent
>> ......................... BDC passed test kccevent
>> Starting test: systemlog
>> An Error Event occured. EventID: 0x00002F1D
>> Time Generated: 04/20/2005 14:17:04
>> Event String: Session from user "prepressg5" was timed out
>> and
>>
>> ......................... BDC failed test systemlog
>>
>> Running enterprise tests on : domainname.com
>> Starting test: Intersite
>> ......................... domainname.com passed test Intersite
>> Starting test: FsmoCheck
>> ......................... domainname.com passed test FsmoCheck
>>
>>
>>
>



.



Relevant Pages

  • Re: SYSVOL and NETLOGON issues on a BDC
    ... I'm confused as to what to do while connected to which DC (using NTDSUTIL). ... It seems that the PDCE knows of all the FSMO roles. ... >> Starting test: Connectivity ...
    (microsoft.public.windows.server.active_directory)
  • Re: SYSVOL and NETLOGON issues on a BDC - REPOSTING INCLUDING THE LAST THREAD SINCE I NEED THIS
    ... NTDSUTIL was run to remove any traces of the old PDCE ... without properly tranferring the FSMO roles to the BDC. ... I renamed the old PDCE and re-ran DCPROMO to reinstall AD. DCPROMO ran ...
    (microsoft.public.windows.server.active_directory)
  • Re: PDC Dies, can I make another domain controller PDC?
    ... Begining with Windows 2000 domains and AD, PDCe is the ... special functions are handled by the PDCe. ... Same with the other FSMO roles. ... good and verified backups. ...
    (microsoft.public.windows.server.setup)
  • Re: FSMO Role Seizures for DR Testing?
    ... will I need to seize all the FSMO roles on these 3 "remote" DC's in order ... If you only seize the PDCe then this isn't an issue. ... transfer the role to the correct server again. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Configuration and Disaster Recovery
    ... When using ntdsutil you must be very careful. ... FSMO Roles from one existing Domain Controller to another existing Domain ... Of course if you are using them as file servers or to keep ...
    (microsoft.public.windows.server.active_directory)