Quantcast
Channel: Directory Services Forum
Viewing all 2536 articles
Browse latest View live

Ways to access,explore,create,delete and do other operations on objects in AD

$
0
0

Hi ppl,

I am a newbie and have been creating, exploring and deleting objects in AD via ADUC. Is there a different way without using ADUC to do these operations ?

Anand Kumar D

This posting is provided "AS IS" with no warranties, and confers no rights.


Site not using local domain controller

$
0
0

Hello,

I could use a little help with a slight problem.  I have 6 Server 2003 domain controllers and sites set up.  Five of the sites are using the local controller to process the logon requests.  I have one site that when a user logs on, it bounces to any other domain controller except for the local domain controller.  This is also the pdc and a gc.  I double checked all entries in DNS and all appear to be correct.

Any ideas of diagnostics, logs or other settings that I can check to get this resolved?

Thanks in advance for any input.

Making users to access ADUC

$
0
0

Hi ppl,

I see that only administrator users are allowed access to ADUC. And more deeply, I found out from my threads that Backup Operators are also allowed permissions to access ADUC. So, I guess there is a list of users or groups that can have access to ADUC. Where is this list and how is it possible to edit this list ?

Anand Kumar D

This posting is provided "AS IS" with no warranties, and confers no rights.

Event ID 4625 not getting logged with username

$
0
0
Hello,

I'm currently managing windows server 2008 DC's.Schema master and Infra master are at other location. I only have a primary and sec. server for my site.  For security purpose, i need to monitor failed logons with user name. But for 95% of cases the user name is Blank  or NA. I'm monitoring event ID 4625, please let me know what can be the issue?

Also, I'm not getting any event ID 4740 (account locked out) and 4723 (password change), even if there are locked accounts and password changes in the env. 

I'm monitoring the events using a 3rd party application along with event logs from the server. So there are no changes of logs getting full or events are getting replaced/ deleted. There is issues for both the cases in application as well as event logs. 

Please help

Regards,
Arnav Sharma

DNS Resolution Question

$
0
0

We are running 2 Windows 2008 R2 DCs in our network (for the sake of this our domain is corp.foobar.com). We then run a query for www.google.com. When we look at our DNS debug logs we see queries for

www.google.com.corp.foobar.com

www.google.com.foobar.com

www.google.com

We see queries to our 2 internal DCs/DNS servers and then the queries go out to the Internet for resolution. I understand why this is happening. What I need help figuring out is how to keep the queries for "www.google.com.corp.foobar.com" and "www.google.com.foobar.com" from ever going out of our network. What I would like to do is set up some type of rules that says anything that goes to "corp.foobar.com" or "foobar.com" only goes to the internal DNS servers (and then never goes to the root hints) and everything else goes to our ISPs DNS servers.

Any help/explanation would be greatly appreciated.

Thanks.

Can't promote Windows Server 2003 member server to DC

$
0
0

I have a single domain Server 2003 forest with two domain controllers.  One of my DCs, which happened to hold all the FSMO roles, died earlier this week.  I seized the FMSO roles on the remaining DC and cleaned up metadata referring to the dead DC.  Now, I want to promote one of my member servers to be a DC but I'm running into a problem.

Each time I run dcpromo, I get through the wizard questions where it asks for the admin credentials and a password to assign to the directory services restore mode admin account, then it throws up the following error and reboots the server:

"The wizard is unable to determine the status of the Active Directory service on this computer"

I've analyzed the dcpromoui.log and compared it to the same log on remaining good DC (from when it was promoted years ago), and everything looks nearly identical until it gets to this point:

Enter DoubleCheckRoleChangeState
Enter EvaluateRoleChangeState
Enter MyDsRoleGetPrimaryDomainInformation
Enter MyDsRoleGetPrimaryDomainInformationHelper
Calling DsRoleGetPrimaryDomainInformation
lpServer : (null)
InfoLevel : 0x3 (DsRoleOperationState)
HRESULT = 0x800706BA
Exception caught
catch completed
handling exception

On the good DC, the same "DsRoleOperationState" check came up with this result:

Enter DoubleCheckRoleChangeState
Enter EvaluateRoleChangeState
Enter MyDsRoleGetPrimaryDomainInformation
Enter MyDsRoleGetPrimaryDomainInformationHelper
Calling DsRoleGetPrimaryDomainInformation
lpServer : (null)
InfoLevel : 0x3 (DsRoleOperationState)
HRESULT = 0x00000000
OperationState : 0x0

Of course, on the problem server the log ends shortly after that exception, while on the good DC the log shows that it ran through a number of additional checks and successfully promoted the server.

Any suggestions?  FWIW, the member server was configured to use the good DC, which is also an AD-Integrated DNS server, as its primary DNS server.  I have since configured the server to be a DNS server with a secondary DNS zone and have the server configured to use itself for DNS, but of course dcpromo still fails.


Removing a child domain in windows server 2003 : error 0x2162_The requested domain could not be deleted because there exist domain controllers that still host this domain.

$
0
0

Good morning,

I want to remove a child domain in windows server 2003 in order to raise the forest functional level from windows 2000 native to windows 2003 to create an interforest trust. Using the ntdsutil processhttp://support.microsoft.com/kb/230306/EN-US, i receive this error message :

error 0x2162 The requested domain could not be deleted because there exist domain controllers that still host this domain.

i tried this solution : http://trinityhome.org/Home/index.php?wpid=121& , i could find neither the server nor computer accounts in this domain. when i put a computer on it,  it gives me: "this domain ... doesn't exist "; I tried to recreate a child domain with the same name, an error message told me that this domain is already exist. I verified all computer names in the parent domain even if this domain doesn't exist for us. I permanently receive this error .

Does someone can help me please or give me suggestions? i think that i'll find an answer today on this forum , i'm waiting for.....

Thank you.


How Do I Disable Adaptive Menus in Office at the AD Level?

$
0
0

How Do I Disable Adaptive Menus in Office at the AD Level?

I know that I can do this in the registry with the following information:

User Key: [HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Common\Toolbars]
Value Name: AdaptiveMenus
Data Type: REG_DWORD (DWORD Value)
Value Data: 0 = disabled, 1 = enabled

What I would like to be able to do is to apply it at the AD level, through Computer Configuration OR User Configuration > Preferences > Windows Settings > Registry but the registry key for Microsoft\Office does not exist on the AD server. Thoughts? 


Setting up server 2008 AD in an 2003 network.

$
0
0

Hello, and thanks for your assistance in advance.  I have setup a windows 2008R2 server and am trying to implement it into an existing windows 2003 domain.  As per my understanding, the first step is to make it an Active Directory domain controller.  So I run the dcpromo wizard.  That wizard fails with the following - "To install a domain controller into this active directory forest, you must first prepare the forest using adprep /forestprep.  So I goto the utility located on the install CD, and run adprep /forestprep as admin.  Get the following error:  Adprep cannot run on this platform because it is not an active directory domain controller. 

So it seems I have circular errors.  Again, any suggestions greatly appreciated.  I am not an AD expert.

Thanks.

Trouble creating Forest Trust between Windows 2000 Forest and Windows 2012 Forest

$
0
0

I've got an old AD that I am attempting to transition off of. I am attempting to establish a two-way transitive trust between the new (Windows 2012) forest running on Windows Server 2012, and the old (Windows 2000) forest running on Windows Server 2003 R2.

Both DCs are running their own DNS servers. Both DCs can ping each other, can nslookup the other domain.

The 2012 DC was able to establish the trust on its side without issue. When I attempt to create the trust on the 2003 R2 side, after providing the NETBIOS name for the new domain, it gives me the following error:

"The Local Security Authority is unable to obtain an RPC connection to the domain controller BMUSJAXDC01. Please check that the name can be resolved and that the server is available."



C:\>ping bmusjaxdc01

Pinging bmusjaxdc01 [192.168.1.9] with 32 bytes of data:

Reply from 192.168.1.9: bytes=32 time<1ms TTL=128
Reply from 192.168.1.9: bytes=32 time<1ms TTL=128
Reply from 192.168.1.9: bytes=32 time<1ms TTL=128
Reply from 192.168.1.9: bytes=32 time<1ms TTL=128

Ping statistics for 192.168.1.9:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms



C:\>nslookup us
*** Can't find server name for address 192.168.1.8: Non-existent domain
Server:  UnKnown
Address:  192.168.1.8

Name:    us.mydomain.com
Address:  192.168.1.9


In the event log, I am seeing this error over and over:

A Kerberos Error Message was received:
         on logon session 
 Client Time: 
 Server Time: 19:52:51.0000 1/18/2013 Z
 Error Code: 0x7  KDC_ERR_S_PRINCIPAL_UNKNOWN
 Extended Error: 
 Client Realm: 
 Client Name: 
 Server Realm: CORP.MYOLDDOMAIN.COM
 Server Name: cifs/BMUSJAXDC01
 Target Name: cifs/BMUSJAXDC01@CORP.MYOLDDOMAIN.COM
 Error Text: 
 File: 9
 Line: b22
 Error Data is in record data.

For more information, see Help and Support Center at 


I then try to create the cifs record with SETSPN...

C:\Program Files\Windows Resource Kits\Tools>setspn -a cifs/us.mydomain.com us\bmusjaxdc01

Failed to bind to DC of domain US, error 0x5/5 -> Access is denied.


I then tried a PORTQRY to see if UDP connecitivy was working...



C:\Program Files\Windows Resource Kits\Tools>portqry -n 192.168.1.9 -e 389 -p UDP

Querying target system called:

 192.168.1.9

Attempting to resolve IP address to a name...


IP address resolved to BMUSJAXDC01


UDP port 389 (unknown service): LISTENING or FILTERED

Sending LDAP query to UDP port 389...

LDAP query response:


currentdate: 01/18/2013 22:28:13 (unadjusted GMT)
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=us,DC=mydomain,D
C=com
dsServiceName: CN=NTDS Settings,CN=BMUSJAXDC01,CN=Servers,CN=Default-First-Site-
Name,CN=Sites,CN=Configuration,DC=us,DC=mydomain,DC=com
namingContexts: DC=us,DC=mydomain,DC=com
defaultNamingContext: DC=us,DC=mydomain,DC=com
schemaNamingContext: CN=Schema,CN=Configuration,DC=us,DC=mydomain,DC=com
configurationNamingContext: CN=Configuration,DC=us,DC=mydomain,DC=com
rootDomainNamingContext: DC=us,DC=mydomain,DC=com
supportedControl: 1.2.840.113556.1.4.319
supportedLDAPVersion: 3
supportedLDAPPolicies: MaxPoolThreads
highestCommittedUSN: 14841
supportedSASLMechanisms: GSSAPI
dnsHostName: BMUSJAXDC01.us.mydomain.com
ldapServiceName: us.mydomain.com:bmusjaxdc01$@US.MYDOMAIN.COM
serverName: CN=BMUSJAXDC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Con
figuration,DC=us,DC=mydomain,DC=com
supportedCapabilities: 1.2.840.113556.1.4.800
isSynchronized: TRUE
isGlobalCatalogReady: TRUE
domainFunctionality: 5
forestFunctionality: 5
domainControllerFunctionality: 5


======== End of LDAP query response ========

UDP port 389 is LISTENING

After spending all day reading umpteenth threads on RPC connectivity issues, I'm kind of running out of ideas. It seems like the old DC can make the RPC connection to the new DC, but a variety of things just kick back what essentially equates to "Access Denied". When I attempt to access the network share from the old DC to the new DC, all I get is:

bmusjaxdc01 is not accessible. You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions.

The network name cannot be found.

I've disabled all the firewalls on the 2012 Server (domain, private and public), but it seems like something (group policy?) on the new DC is preventing specific connections, hence the variety of errors. Any ideas would be appreciated.

Install Domain Controller from backup media when DC is down

$
0
0

Is it possible to use "dcpromo /adv"  install from media option of a Windows 2003 Domain Controller on a new Windows 2008 computer?  I have the System Backup backup available from the Windows 2003 server.  

However, the 2003 domain controller is *DEAD* and I can not verify credentials of that domain.

Is it possible to install a new replica domain controller from the backup media and get the domain back up and functioning?

Many thanks.


Server 2008 on 2003 functional domain reporting a second Domain GUID that is missing

$
0
0

We have a remote server running 2008 R2 standard that has been connected to an existing domain running at the 2003 functional level

on doing a DCDiag /test:dns the 2 2003 servers report everything is ok, however the 2008 server reports a problem - it cannot find the domain GUID. a bit of digging reveals it finds the first Domain GUID, which happens to be the correct one according to the other 2 servers. The one its looking for is different and is only reported as missing on the 2008 server.

the report looks like this -

 Missing SRV record at DNS server 192.168.21.250:
 _ldap._tcp.d952a97b-b6fc-4e87-b88e-7e61026aefc6.domains._msdcs.DOMAIN.local

 Error:
 Missing SRV record at DNS server 192.168.2.4:
 _ldap._tcp.d952a97b-b6fc-4e87-b88e-7e61026aefc6.domains._msdcs.DOMAIN.local

the *.21 network is the home network. the *.2 network is the remote network with the server. 

the dcdiag tests on the other 2 servers do not report this. Under the _msdcs.domains object in DNS there is one GUID, and the reported missing one is not it.

So is this a problem? it does not appear to be affecting functionality of the domain, but we do see some strange logs from netlogon sometimes, which is how we found it.

and can it be corrected?

Client Authentication Issue...

$
0
0

Guys,

     Is MaxConcurrentAPI will be the resolution of NETLOGON error found at Domain Contoller - increasing and adding this to Windows Registry domain controller to resolved the issue of Client Authentication Issue?

     Any other ideas, suggestions would be a great help...

Thanks and Regards,

AD account unlock

$
0
0
Is there any method to automate AD account unlocking.. Some Script to find locked account and unlocked them....

What should be the scope of the group ?

$
0
0

Hi ppl,

I would like to create 3 different groups for 3 different operations. The 3 operations are listed below. Please suggest the scope of the 3 groups to be created and the reasons to choose those scopes.

  • Give privilege to access a network share folder to set of users within the domain
  • Give privilege to access same network share folder to child domain users
  • Give privilege to access same network share folder to cross forest domain users

Anand Kumar D

This posting is provided AS-IS with no warranties or guarantees and confers no rights.


AD/DNS not working after following steps in article 875495

$
0
0
Two Windows Server 2008 R2 domain controllers. One was cloned, and the clone was introduced into the network. This created AD problems - group policy did not run, users could not access network drives, DNS lookup failures. I followed the steps in article 875495 to fix. All steps were completed: cloned DC forced demoted, metadata cleaned, FSMO roles seized.

DC1 = cloned and demoted server - now a member server
DC2 = domain controller that seized FSMO roles from DC1

Any assistance would be appreciated. Thanks.

****Cannot access DNS Manager on DC2: when DNS Manager is expanded in Server Manager, an error pops up:"The server DC2 could not be contacted. The error was: access is denied. Would you like to add anyway?" If I add the server, the there is a red circle with a white dash through it. There are no zones shown. I tried to add DNS Manager through an empty MMC too, not luck with name, FQDN, IP address or localhost.

All commands and errors are from DC2.

***FSMO
netdom query fsmo
Schema master               DC2..local
Domain naming master        DC2..local
PDC                         DC2..local
RID pool manager            DC2..local
Infrastructure master       DC2..local
The command completed successfully.

****Errors in Event Viewer ->
--DFS Replication:
The DFS Replication service failed to contact domain controller  to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. 

This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues. 
 
Additional Information: 
Error: 160 (One or more arguments are not correct.)

--Directory Service:
Active Directory Domain Services was unable to establish a connection with the global catalog. 
 
Additional Data 
Error value:
8430 The directory service encountered an internal failure. 
Internal ID:
3200db0 
 
User Action: 
Make sure a global catalog is available in the forest, and is reachable from this domain controller. You may use the nltest utility to diagnose this problem.

Active Directory Domain Services attempted to communicate with the following global catalog and the attempts were unsuccessful. 
 
Global catalog:
\\DC2..local 
 
The operation in progress might be unable to continue. Active Directory Domain Services will use the domain controller locator to try to find an available global catalog server. 
 
Additional Data 
Error value:
5 Access is denied.

--DNS Server:
The DNS server was unable to open Active Directory.  This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it.  Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.

--FRS:
Following is the summary of warnings and errors encountered by File Replication Service while polling the Domain Controller DC2..local for FRS replica set configuration information. 
 
 Could not bind to a Domain Controller. Will try again at next polling cycle.

 
--System:
The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

The processing of Group Policy failed. Windows attempted to read the file \\.local\sysvol\.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following: 
a) Name Resolution/Network Connectivity to the current domain controller. 
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller). 
c) The Distributed File System (DFS) client has been disabled.

***IPCONFIG 
ipconfig /all
Windows IP Configuration

   Host Name . . . . . . . . . . . . : DC2
   Primary Dns Suffix  . . . . . . . : .local
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : .local

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
   Physical Address. . . . . . . . . : 00-0C-29-20-58-9E
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::9582:81bf:c619:4af8%11(Preferred)
   IPv4 Address. . . . . . . . . . . : 10.154.1.22(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.224
   Default Gateway . . . . . . . . . : 10.154.1.254
   DHCPv6 IAID . . . . . . . . . . . : 234884137
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-D5-1E-58-00-0C-29-20-58-9E

   DNS Servers . . . . . . . . . . . : 10.154.1.22
   Primary WINS Server . . . . . . . : 10.154.1.20
   Secondary WINS Server . . . . . . : 10.154.1.22
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{169A634F-5876-49F7-AFE5-319BD7B78A89}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

dcdiag /test:dns ->

 Directory Server Diagnosis
Performing initial setup:

   Trying to find home server...

   Home Server = DC2

   * Identified AD Forest. 
   Done gathering initial info.


Doing initial required tests

   
   Testing server: Default-First-Site-Name\DC2

      Starting test: Connectivity

         The host cd24f743-c955-4530-9a42-358a4869b53f._msdcs..local

         could not be resolved to an IP address. Check the DNS server, DHCP,

         server name, etc.

         Got error while checking LDAP and RPC connectivity. Please check your

         firewall settings.

         ......................... DC2 failed test Connectivity



Doing primary tests

   
   Testing server: Default-First-Site-Name\DC2

   
      Starting test: DNS

         

         DNS Tests are running and not hung. Please wait a few minutes...

         ......................... DC2 failed test DNS

   
   Running partition tests on : ForestDnsZones

   
   Running partition tests on : DomainDnsZones

   
   Running partition tests on : Schema

   
   Running partition tests on : Configuration

   
   Running partition tests on : 

   
   Running enterprise tests on : .local

      Starting test: DNS

         Test results for domain controllers:

            
            DC: DC2..local

            Domain: .local

            

                  
               TEST: Basic (Basc)
                  Error: No LDAP connectivity
                  Warning: adapter

                  [00000007] Intel(R) PRO/1000 MT Network Connection has

                  invalid DNS server: 10.154.1.22 (DC2)

                  Error: all DNS servers are invalid

                  No host records (A or AAAA) were found for this DC

                  Warning: no DNS RPC connectivity (error or non Microsoft DNS server is running)
         
         Summary of test results for DNS servers used by the above domain

         controllers:

         

            DNS server: 10.154.1.22 (DC2)

               1 test failure on this DNS server

               Name resolution is not functional. _ldap._tcp..local. failed on the DNS server 10.154.1.22
               
         Summary of DNS test results:

         
                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: .local

               DC2                PASS FAIL n/a  n/a  n/a  n/a  n/a  
         
         ......................... .local failed test DNS


Do We need to Run the ADPREP32.exe /DomainPrep /gpprep on Child Domain Controller ?

$
0
0

Hello DS Experts!

I have got one forest with one child domain (forest:xyz.com and child is abc.xyz.com) which has 2003R2.

I have ran adprep32.exe /forestprep and adprep32.exe /Domainprep /Gpprep on xyz.com.

So now question is - do i still needs to run the adprep32.exe /Domainprep /Gpprep on abc.xyz.com ?

While running what permission do i needed to run the (adprep32.exe /Domainprep /Gpprep) on abc.xyz.com, because I have one account in root domain using which i have ran forestprep and domainprep in the Root Doamin, but when i ran it in Child domain - it says you need to be part of Domain Admin of abc.Xyz.com,
When i try my Account (which is part of SchemaAdmin,DomainAdmin, EnterpriseAdmin for the root domain) making a member of Child Domain Domain Admin, it wont allow me.

Any Help would be appriciated

Thnaks,
Kumar


Know more about Messaging :-)

FRS errors 13552 & 13555. SYSVOL not replicating.

$
0
0

Hi All, looking for a little help here...

Here is the scenario. My (new) client has ONLY 1 domain controller (Windows Server 2003 which I will call SERVER1). I recently installed a new 2008 R2 server and made it a replica domain controller. Everything went well until I realised that there was no SYSVOL share on the new server. I checked FRS event logs on SERVER1 and noticed that event ID errors 13552 & 13555 have been occuring since December 2010. 

I've been reading about changing burflags to do a nonauthorative restore from a replica DC however in this case there is only 1 DC. Can someone advise how I go about fixing this?

 

------------------------------------------------------------------------------

Event Type: Error
Event Source: NtFrs
Event Category: None
Event ID: 13552
Date:  21/06/2011
Time:  2:15:57 PM
User:  N/A
Computer: SERVER1
Description:
The File Replication Service is unable to add this computer to the following replica set:
    "DOMAIN SYSTEM VOLUME (SYSVOL SHARE)"
 
This could be caused by a number of problems such as:
  --  an invalid root path,
  --  a missing directory,
  --  a missing disk volume,
  --  a file system on the volume that does not support NTFS 5.0
 
The information below may help to resolve the problem:
Computer DNS name is "server1.mydomain.local"
Replica set member name is "SERVER1"
Replica set root path is "c:\windows\sysvol\domain"
Replica staging directory path is "c:\windows\sysvol\staging\domain"
Replica working directory path is "c:\windows\ntfrs\jet"
Windows error status code is 
FRS error status code is FrsErrorMismatchedJournalId 
 
------------------------------------------------------------------------------

Event Type: Error
Event Source: NtFrs
Event Category: None
Event ID: 13555
Date:  21/06/2011
Time:  2:15:57 PM
User:  N/A
Computer: SERVER1
Description:
The File Replication Service is in an error state. Files will not replicate to or from one or all of the replica sets on this computer until the following recovery steps are performed: 

------------------------------------------------------------------------------

 

 

Domain Admin Account Lockout Issue - Authentication

$
0
0
First, I've tried all the norm checks, services, updates, misc map drives and so forth. Ran MS Lockout tools as well as Netwrix Account Lockout tracer, but this one has me stuck. Have a Domain Admin Account used for various tasks that is failing authentication every minute exactly until fifth time it locks for 15 minutes due to how GPO is set. I know it's on the one DC, but can't find it and doesn't make sense. Shut down anything related to services and tasks or mapping drives. Have two DC's so I shut the one down I thought has the issue and the issue does go away as account stays active with the one DC off that I believe is the issue. Below is the event I see continually with only the Source Port changing and then the 264 event for locked out on the fifth try; (changed account, domain and ip here for security.) The user ID and PW are correct as I use it for other things and can log into the DC with it if unlocked. I've read other threads here on Technet, but haven't found any that show issue is on DC.

An account failed to log on.

Subject:
Security ID: SYSTEM
Account Name: MODC01$
Account Domain: MYDOMAIN
Logon ID: 0x3e7

Logon Type: 3

Account For Which Logon Failed:
Security ID: NULL SID
Account Name: MYADMIN
Account Domain: MYDOMAIN

Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc000006a

Process Information:
Caller Process ID: 0x1e4
Caller Process Name: C:\Windows\System32\lsass.exe

Network Information:
Workstation Name: MYDC01
Source Network Address: 192.168.1.1
Source Port: 1027

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

Any help would be appreciated here......Thanks, Mark

users accounts is getting lockout with out attempts

$
0
0

Dear All,

we implemented GPO for Account lockout policy in our domain with the below setting.

Setting details.

Account lockout threshold : 3 invalid logon attempts

Account lockout duration: 0

Reset account lockout after : 5 mints

We have 70 users with 5 Group, but some users account are getting lockout with out attempts  

Event Log details.

Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          7/27/2012 10:15:03 AM
Event ID:      4625
Task Category: Account Lockout
Level:         Information
Keywords:      Audit Failure
User:          N/A
Computer:      XXXXXXXXXXXXXXXX
Description:
An account failed to log on.

Subject:
    Security ID:        NULL SID
    Account Name:        -
    Account Domain:        -
    Logon ID:        0x0

Logon Type:            3

Account For Which Logon Failed:
    Security ID:        NULL SID
    Account Name:        XXXXXXX
    Account Domain:        

Failure Information:
    Failure Reason:        Account locked out.
    Status:            0xc0000234
    Sub Status:        0x0

Process Information:
    Caller Process ID:    0x0
    Caller Process Name:    -

Network Information:
    Workstation Name:    XXXXXXXXXXXX
    Source Network Address:    XXXXXXXXXXXX
    Source Port:        XXXXXX

Detailed Authentication Information:
    Logon Process:        NtLmSsp
    Authentication Package:    NTLM
    Transited Services:    -
    Package Name (NTLM only):    -
    Key Length:        0

This event is generated when a logon request fails. It is generated on the computer where access was attempted.

The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).

The Process Information fields indicate which account and process on the system requested the logon.

The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
    - Transited services indicate which intermediate services have participated in this logon request.
    - Package name indicates which sub-protocol was used among the NTLM protocols.
    - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>4625</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12546</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2012-07-27T09:15:03.151737000Z" />
    <EventRecordID>3211925</EventRecordID>
    <Correlation />
    <Execution ProcessID="480" ThreadID="5160" />
    <Channel>Security</Channel>
    <Computer>XXXXXXXXXXXX</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="SubjectUserSid">S-1-0-0</Data>
    <Data Name="SubjectUserName">-</Data>
    <Data Name="SubjectDomainName">-</Data>
    <Data Name="SubjectLogonId">0x0</Data>
    <Data Name="TargetUserSid">S-1-0-0</Data>
    <Data Name="TargetUserName">XXXXXXX</Data>
    <Data Name="TargetDomainName">
    </Data>
    <Data Name="Status">0xc0000234</Data>
    <Data Name="FailureReason">%%2307</Data>
    <Data Name="SubStatus">0x0</Data>
    <Data Name="LogonType">3</Data>
    <Data Name="LogonProcessName">NtLmSsp </Data>
    <Data Name="AuthenticationPackageName">NTLM</Data>
    <Data Name="WorkstationName">XXXXX_XXXXX</Data>
    <Data Name="TransmittedServices">-</Data>
    <Data Name="LmPackageName">-</Data>
    <Data Name="KeyLength">0</Data>
    <Data Name="ProcessId">0x0</Data>
    <Data Name="ProcessName">-</Data>
    <Data Name="IpAddress">XX.XXXX.XXXX</Data>
    <Data Name="IpPort">57779</Data>
  </EventData>
</Event>

i want to know where is the error , why its getting lockout for some users ?

Thanks,


Srinivasan.B

Viewing all 2536 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>