Hi experts,
My secondary DC(Domain Controller) does not have any objects in Computers and Users OUs(Organization Unit). I ran dcdiag and found the error: “Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have Replicating Directory Changes
In Filtered Set”.
I google and found two links mentioning about permission issues but they do not mention the location very clearly, please help.
http://www.squidworks.net/2013/02/solved-dcdiag-fails-for-ncsecdesc-test-and-adprep-rodcprep-fails-to-fix-it/
https://mpgnotes.wordpress.com/tag/error-nt-authorityenterprise-domain-controllers-doesnt-have-replicating-directory-changes-in-filtered-set-access-rights-for-the-naming-context-dcforestdnszonesdcdomainxxxdcxxx-security-permi/
Is it in ADSI Edit -> Configuration[qrdcsapdc7.qcisap.corp] -> CN=Configuration,DC=qcisap,C=corp -> properties -> Security -> ENTERPRISE DOMAIN CONTROLLER -> Advanced -> Auditing -> Administrators -> Edit?
Should it have only five permissions here?
Is there any Microsoft documents mentioning this?
------ dcdiag ------
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = qrdcsapdc7
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\QRDCSAPDC7
Starting test: Connectivity
......................... QRDCSAPDC7 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\QRDCSAPDC7
Starting test: Advertising
......................... QRDCSAPDC7 passed test Advertising
Starting test: FrsEvent
......................... QRDCSAPDC7 passed test FrsEvent
Starting test: DFSREvent
......................... QRDCSAPDC7 passed test DFSREvent
Starting test: SysVolCheck
......................... QRDCSAPDC7 passed test SysVolCheck
Starting test: KccEvent
......................... QRDCSAPDC7 passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... QRDCSAPDC7 passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... QRDCSAPDC7 passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=qcisap,DC=corp
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=qcisap,DC=corp
......................... QRDCSAPDC7 failed test NCSecDesc
Starting test: NetLogons
......................... QRDCSAPDC7 passed test NetLogons
Starting test: ObjectsReplicated
......................... QRDCSAPDC7 passed test ObjectsReplicated
Starting test: Replications
......................... QRDCSAPDC7 passed test Replications
Starting test: RidManager
......................... QRDCSAPDC7 passed test RidManager
Starting test: Services
Invalid service startup type: DFSR on QRDCSAPDC7, current value
DISABLED, expected value AUTO_START
DFSR Service is stopped on [QRDCSAPDC7]
......................... QRDCSAPDC7 failed test Services
Starting test: SystemLog
......................... QRDCSAPDC7 passed test SystemLog
Starting test: VerifyReferences
......................... QRDCSAPDC7 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : qcisap
Starting test: CheckSDRefDom
......................... qcisap passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... qcisap passed test CrossRefValidation
Running enterprise tests on : qcisap.corp
Starting test: LocatorCheck
......................... qcisap.corp passed test LocatorCheck
Starting test: Intersite
......................... qcisap.corp passed test Intersite
------ showrepl.csv ------
showrepl_COLUMNS | Destination DSA Site | Destination DSA | Naming Context | Source DSA Site | Source DSA | Transport Type | Number of Failures | Last Failure Time | Last Success Time | Last Failure Status |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC3 | DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC7 | RPC | 0 | 0 | 2018/10/1 13:40 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC3 | CN=Configuration,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC7 | RPC | 0 | 0 | 2018/10/1 12:57 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC3 | CN=Schema,CN=Configuration,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC7 | RPC | 0 | 0 | 2018/10/1 12:57 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC3 | DC=DomainDnsZones,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC7 | RPC | 0 | 0 | 2018/10/1 12:57 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC3 | DC=ForestDnsZones,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC7 | RPC | 0 | 0 | 2018/10/1 12:57 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC7 | DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC3 | RPC | 0 | 0 | 2018/10/1 13:40 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC7 | CN=Configuration,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC3 | RPC | 0 | 0 | 2018/10/1 12:51 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC7 | CN=Schema,CN=Configuration,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC3 | RPC | 0 | 0 | 2018/10/1 12:51 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC7 | DC=DomainDnsZones,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC3 | RPC | 0 | 0 | 2018/10/1 12:51 | 0 |
showrepl_INFO | Default-First-Site-Name | QRDCSAPDC7 | DC=ForestDnsZones,DC=qcisap,DC=corp | Default-First-Site-Name | QRDCSAPDC3 | RPC | 0 | 0 | 2018/10/1 12:51 | 0 |