Re: NTDS Replication Event ID 1083/1955 and account lockouts



Here's a copy of the events

Event 1083

Active Directory could not update the following object with changes received
from the domain controller at the following network address because Active
Directory was busy processing information.

Object:
CN=Victor Gabriel - Adm,OU=Op Accts,OU=Admins,OU=Sydney,DC=avant,DC=local
Network address:
82713579-4787-439a-9a8f-185fd1e97325._msdcs.avant.local

This operation will be tried again later.

Event 1955

Active Directory encountered a write conflict when applying replicated
changes to the following object.

Object:
CN=Victor Gabriel - Adm,OU=Op Accts,OU=Admins,OU=Sydney,DC=avant,DC=local
Time in seconds:
0

Event log entries preceding this entry will indicate whether or not the
update was accepted.

A write conflict can be caused by simultaneous changes to the same object or
simultaneous changes to other objects that have attributes referencing this
object. This commonly occurs when the object represents a large group with
many members, and the functional level of the forest is set to Windows 2000.
This conflict triggered additional retries of the update. If the system
appears slow, it could be because replication of these changes is occurring.

User Action
Use smaller groups for this operation or raise the functional level to
Windows Server 2003.

For more information, see Help and Support Center at

"Marcin" wrote:

Vic,
have you tried any of the tools/methods described in the
http://technet.microsoft.com/en-us/library/cc738772.aspx and
http://technet.microsoft.com/en-us/library/cc776964.aspx?

hth
Marcin

"Vic" <Vic@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8CBC9020-5341-4862-B76A-6A305B763741@xxxxxxxxxxxxxxxx
Hi,

We have had problems for some time with user accounts being locked for
reasons other than users typing in their passwords incorrectly. The issue
does not descriminate and happens at random to all users reagrdless of
privilidges and roles, even when the user is logged in and working away.

The event log of our PDC does show Event 1083 and 1955 for a a user
account
that is locked.
Not sure if the event is ocurring after the account has been locked or the
event occurs and then the account is locked.

Is this event generated because the account is locked ?

We run a 2003 Environment, where the PDC was upgraded from a Win2000 box.
We
also run Citirx for all users apps.
We have a single domain, which was created by the merging of two older
domains.
The PDC server also tuns DHCP.

Checks I have performed already include :
- the are no duplicate objects
- The domain functional level is Win 2003
- repadmin shows success
- dcdiag passes all tests

We have several doamin controllers in other locations serviced by WAN
Links
serviced by 2-4 Mbps links.

Any help appreciated. Thanks




.



Relevant Pages

  • Re: Domain troubles
    ... Workgroup administrative environment and the machine account in Active ... Another possiblity is that the Active Directory DNS cannot resolve the ... For example if you built a network segment and abitrarily choose ...
    (microsoft.public.windows.server.general)
  • Re: Unable To Add DC
    ... then deleted the computer account ... from active directory and then ran DCPROMO, ... >> In my hast to try and get the server rebuild, ... >> the option of the domain controller is no longer ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Replication issues
    ... Please describe a bit more detailed the network setup. ... Please see output of AD Replication Monitor - Search Domain ... Active Directory Replication Domain Controller Replication Failure ...
    (microsoft.public.windows.server.active_directory)
  • Re: Unable To Add DC
    ... I have reloaded it with 2003 server again and given ... I have gone into active directory users and computers then ... it still had the old domain controller in there, ... account SERVERNAME$ to a domain controller ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active directory problem!!
    ... I did not seize the FSMO roles. ... But the problem is, when I disconnect the NAS DC from the network, ... I cannont connect to the active directory resources. ... One domain controller hosts network attached storage and the ...
    (microsoft.public.windows.server.active_directory)