Hi
I have root domain contoso.dom (DC1 and DC2) and subdomain sub.contoso.dom (DC3).
I see error event 2896 on DC3
A client made a DirSync LDAP request for a directory partition. Access was denied due to the following error.
Directory partition:
DC=sub,DC=contoso,DC=DOM
Error value:
8453 Replication access was denied.
User Action
The client may not have access for this request. If the client requires it, they should be assigned the control access right "Replicating Directory Changes" on the directory partition in question.
No fails or errors in BPA.
Also if I try to run on DC1 repadmin /replsummary I can see:
site\DC3 via RPC
DSA object GUID: 0458a97c-437e-49a4-8f9c-095fd7340834
Last attempt @ 2013-12-19 15:27:27 failed, result 8418 (0x20e2):
The replication operation failed because of a schema mismatch between the servers involved.
118 consecutive failure(s).
Last success @ 2013-12-18 08:12:03.
How can I solve this problem?