Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Can anyone help me with a query on RODC replication?

$
0
0

Hi everyone,

I'm new to RODCs and have been looking into them as an ideal replacement for the current read/write Windows 2003 domain controllers at our branch sites. Ideally I'd like to replace all branch DCs with RODCs, leveraging a central core of read/write doman controllers at our hub site.

I can see one issue with replication. At our branch sites we typically use a 3 hour replication interval to reduce replication traffic over the network. Our central helpdesks currently work around this by creating new accounts and resettng passwords on the DC at the branch. In addition domain joins of new computers are done using the local read/write DC at the branch.

Now my thinking is that switching the branches to RODCs will cause problems in this situation as changes cannot be written to them. I understand though that they will  forward write operations to read/write DCs in the hub. My question - are such "referred" changes immediately available to the branch via the RODC?

A scenario:

  1. A branch worker locks their password
  2. The central helpdesk attempts to reset the password using the RODC
  3. The RODC fowards the request to a read/write DC in the hub site

Another scenario

  1. A computer is "flattened" and the O/S reloaded at a branch site with an RODC
  2. The scripted provisioning process attempts to delete/add the computer account using the RODC
  3. The RODC forwards the request to a read/write DC in the hub site

My question: Would the password reset / updated computer account be immediately available on the branch RODC (as would be the case with a targetted local read/write DC) or will the branch have to wait up to 3 hours for scheduled replication from the hub?

Clarification on this point would be most greatly appreciated.


Server 2008 R2 scheduled task not working - action

$
0
0

Server 2008 R2 scheduled task not working - action 

"C:\Windows\SYSTEM32\cmd.exe" with return code 1

RMS Issue after migration

$
0
0
Hello,

I have one Server containe Microsoft Windows Server 2003 with SP2, and have
RMS 1.0 with SP2 + Microsoft SQL Server 2005 with SP2.

The Server was working fine.

I Move Database to another SQL Server without any issue and RMS Server able
to connect to new DB Server after some configuration.

My problem start after installing 2 node RMS Server (Win2003) configured
with NLB, the client able to open a new doc and put configure a new
restraction and connect to new RMS, but if the open old doc, it still connect
to old RMS and faild because we already shutdown old RMS.

I already link a new RMS to AD and unlink old RMS, but maybe I should clean
up AD from old RMS.

I didn't found in Technet doc from microsoft describe migration, and
troubleshooting my issue.

Please advise

Time service reset to ten years ago on PDC

$
0
0
Time service reset to ten years ago on PDC today, which causes many network and replication issue. Is there public statement to describe this issue for the Microsoft's time provider? I notice it's not just me to encounter this issue.

Active Directory Web Services Event 1202

$
0
0

Hi all,

I am stuck with the event 1202 (source ADWS) error on my ADLDS server hosting sharepoint extranet user repository. My sharepoint server is a domain member butNOT a domain controller. I do not replicate this ADLDS instance with any other server. This ADLDS instance is not synched with AD's at all.

I already read posts existing on the subject and no one solved my problem as they're all related to ADLDS instances hosted on domain controllers

As a reminder the event 1202 (raised minutely) description is:

This computer is now hosting the specified directory instance, but Active Directory Web Services could not service it. Active Directory Web Services will retry this operation periodically.
Directory instance: NTDS
Directory instance LDAP port: 389
Directory instance SSL port: 636

My ADLDS instance is not named NTDS (and cannot as NTDS is the instance name of an ADDS domain) and ADWS correctly service it as the following 1200 event proove it:

Active Directory Web Services is now servicing the specified directory instance.
Directory instance: ADAM_ExtranetUsers
Directory instance LDAP port: 18589
Directory instance SSL port: 18836

So... my investigations result after enabling ADWS diagnostics are:

Following is the trace corresponding to the 1202 event generation

InstanceMap: [14.11.2012 08:57:19] [4] OnTimedEvent: got an event
InstanceMap: [14.11.2012 08:57:19] [4] CheckAndLoadAll: beginning
InstanceMap: [14.11.2012 08:57:19] [4] CheckAndLoadNTDSInstance: entered
InstanceMap: [14.11.2012 08:57:19] [4] CheckAndLoadNTDSInstance: found NTDS Parameters key
InstanceMap: [14.11.2012 08:57:19] [4] CheckAndLoadNTDSInstance: trying to change state to DC
InstanceMap: [14.11.2012 08:57:19] [4] AddRemoveSessionPoolAndDictionaryEntry: trying to change state for identifier ldap:389
InstanceMap: [14.11.2012 08:57:19] [4] AddSessionPool: adding a session pool for NTDS
DirectoryDataAccessImplementation: [14.11.2012 08:57:19] [4] InitializeInstance: entering, instance=NTDS, init=5, max=20
LdapSessionPoolImplementation: [14.11.2012 08:57:19] [4] InitializeInstance: entering, instance=NTDS, init=5, max=20
InstanceMap: [14.11.2012 08:57:20] [4] AddSessionPool: DirectoryException trying to create pool: System.DirectoryServices.Protocols.LdapException: The LDAP server is unavailable.

For me the BUGGY part of this ADWS error state within the CheckAndLoadNTDSInstance process. It effectively try to service NTDS instance because it found the NTDS registry key supposed to contain the AD DS instance configuration parameters. The content of the key is the following on my system (and any system I think):

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NTDS\parameters]
"ldapserverintegrity"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NTDS\RID Values]

This is the normal content on any domain members. But this cause the ADWS service to think there is an NTDS domain service instance to serve which is not the case !!!!!

I resolved the error for a temporary period by removing the registry key above. Because I also think this key has nothing to do on client systems (as stated on technet). I also verified after removing the key that my ADLDS instance is still forcing SSL connections for simple bind (which is what the ldapserverintegrity registry value is supposed to do. Note this registry settings is also present is the ldap and my ADAM_ExtranetUsers service registry.) Everything worked like a charm for a day and my event log stopped reporting the 1202 event.

But during the first night, a process recreated the NTDS service registry key I deleted. So the event 1202 start reappearing every minute. Excepting filling my event log for nothing this error has no effect on the working ADLDS instance. So I can live with but it's rather annoying!

So finally my question is: Is it really a bug or did i make a mistake? If this is by design how can I prevent ADWS to try to serve an instance that does not exists on the system?

Can I set the undocumented ADWS configuration value "InstanceRediscoveryInterval" defaulted to "00:01:00" to something that say "NEVER".

At least to lower events count I will set it to something next to 1 hour or 1 day!

Does someone have a better solution?

Many thanks to any of you taking time to read my poor english ;-)

NETLOGON Share missing

$
0
0

Greetings,

We have 14 DCs in our network, all running W2K3R2 SP2. I had a user call yesterday that said she was having issues with email. Further inspection showed that the NETLOGON share was missing. Then I took a step further and found that it was missing on all DCs in our network. I've done a lot of searching and have found several documents on 'missing sysvol and netlogon'. We are missing some of the policies in the sysvol share, but completely missing the netlogon folder. Articles talk about restoring by setting bur flags. The problem is that from what I read, you need to have an operational DC. While across the network, users are able to access shared resources like email, files and have no problems logging in, since no DC has a NETLOGON share, none would be 'operational'. Below, I'm posting the dcdiag I ran on our FSMO role holder:

C:\>dcdiag /fix

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Operations\SVR00DC01
      Starting test: Connectivity
         ......................... SVR00DC01 passed test Connectivity

Doing primary tests

   Testing server: Operations\SVR00DC01
      Starting test: Replications
         ......................... SVR00DC01 passed test Replications
      Starting test: NCSecDesc
         ......................... SVR00DC01 passed test NCSecDesc
      Starting test: NetLogons
         Unable to connect to the NETLOGON share! (\\SVR00DC01\netlogon)
         [SVR00DC01] An net use or LsaPolicy operation failed with error 1203, N
o network provider accepted the given network path..
         ......................... SVR00DC01 failed test NetLogons
      Starting test: Advertising
         ......................... SVR00DC01 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... SVR00DC01 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... SVR00DC01 passed test RidManager
      Starting test: MachineAccount
         ......................... SVR00DC01 passed test MachineAccount
      Starting test: Services
         ......................... SVR00DC01 passed test Services
      Starting test: ObjectsReplicated
         ......................... SVR00DC01 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... SVR00DC01 passed test frssysvol
      Starting test: frsevent
         ......................... SVR00DC01 passed test frsevent
      Starting test: kccevent
         ......................... SVR00DC01 passed test kccevent
      Starting test: systemlog
         ......................... SVR00DC01 passed test systemlog
      Starting test: VerifyReferences
         ......................... SVR00DC01 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : secfedbank
      Starting test: CrossRefValidation
         ......................... secfedbank passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... secfedbank passed test CheckSDRefDom

   Running enterprise tests on : secfedbank.com
      Starting test: Intersite
         ......................... secfedbank.com passed test Intersite
      Starting test: FsmoCheck
         ......................... secfedbank.com passed test FsmoCheck

C:\>

I see no errors in the FRS event viewer. 

Chris

Account Lockout in Active Directory 2008 R2

$
0
0

We've implemented Account Logout policies in our Windows 2008 R2 domain with these settings

Lockout duration: 30 minutes
Lockout threshold: 15 invalid login attempts
Reset account lockout counter after: 30 minutes

We've turned on NETLOGON.log logging and are watching for any user problems. On a few users, we see over 300 attempted logins from a machine (0xC000006A Transitive Login attempt) over a 4 hour period. We're watching the account but it's not locking out. Are these types of login exempt from the Account Lockout policy?


Orange County District Attorney


NTDS Replication error

$
0
0

ADC server replication summary - 

C:\>repadmin /showrepl

repadmin running command /showrepl against server localhost

Default-First-Site-Name\ADCMOFTWARE
DC Options: IS_GC
Site Options: (none)
DC object GUID: 700f4da0-0471-42dc-9a0a-453a5656d2a9
DC invocationID: e88f24d9-5108-4513-922f-d62497b6db6e

==== INBOUND NEIGHBORS ======================================

DC=fi,DC=com
    Default-First-Site-Name\DCM via RPC
        DC object GUID: 8fdd74a5-c2b9-4ba9-89fc-8f2fa97af716
        Last attempt @ 2012-11-26 16:28:09 failed, result 8614 (0x21a6):
            The Active Directory cannot replicate with this server because the t
ime since the last replication with this server has exceeded the tombstone lifet
ime.
        4013 consecutive failure(s).
        Last success @ 2012-11-20 03:00:24.

CN=Configuration,DC=Fi,DC=com
    Default-First-Site-Name\DCM via RPC
        DC object GUID: 8fdd74a5-c2b9-4ba9-89fc-8f2fa97af716
        Last attempt @ 2012-11-26 16:24:52 was successful.

CN=Schema,CN=Configuration,DC=fi,DC=com
    Default-First-Site-Name\DCM via RPC
        DC object GUID: 8fdd74a5-c2b9-4ba9-89fc-8f2fa97af716
        Last attempt @ 2012-11-26 16:24:52 was successful.

DC=ForestDnsZones,DC=fi,DC=com
    Default-First-Site-Name\DCM via RPC
        DC object GUID: 8fdd74a5-c2b9-4ba9-89fc-8f2fa97af716
        Last attempt @ 2012-11-26 16:24:52 was successful.

DC=DomainDnsZones,DC=fi,DC=com
    Default-First-Site-Name\DCM via RPC
        DC object GUID: 8fdd74a5-c2b9-4ba9-89fc-8f2fa97af716
        Last attempt @ 2012-11-26 16:24:52 was successful.

Source: Default-First-Site-Name\DCM
******* 3992 CONSECUTIVE FAILURES since 2012-11-20 03:00:24
Last error: 8614 (0x21a6):
            The Active Directory cannot replicate with this server because the t
ime since the last replication with this server has exceeded the tombstone lifet
ime.

******************************************************************************************

Main domain controller repadmin summary - 

C:\>repadmin /showrepl

repadmin running command /showrepl against server localhost

Default-First-Site-Name\DCM
DC Options: IS_GC
Site Options: (none)
DC object GUID: 8fdd74a5-c2b9-4ba9-89fc-8f2fa97af716
DC invocationID: 19470c50-6d7e-48d0-afcc-54faac6dacc4

==== INBOUND NEIGHBORS ======================================

DC=fi,DC=com
    Default-First-Site-Name\ADCM via RPC
        DC object GUID: 700f4da0-0471-42dc-9a0a-453a5656d2a9
        Last attempt @ 2012-11-26 14:52:52 was successful.

CN=Configuration,DC=fi,DC=com
    Default-First-Site-Name\ADCM via RPC
        DC object GUID: 700f4da0-0471-42dc-9a0a-453a5656d2a9
        Last attempt @ 2012-11-26 14:29:20 was successful.

CN=Schema,CN=Configuration,DC=fi,DC=com
    Default-First-Site-Name\ADCM via RPC
        DC object GUID: 700f4da0-0471-42dc-9a0a-453a5656d2a9
        Last attempt @ 2012-11-26 14:23:30 was successful.

DC=DomainDnsZones,DC=fi,DC=com
    Default-First-Site-Name\ADCM via RPC
        DC object GUID: 700f4da0-0471-42dc-9a0a-453a5656d2a9
        Last attempt @ 2012-11-26 14:50:11 was successful.

DC=ForestDnsZones,DC=fi,DC=com
    Default-First-Site-Name\ADCM via RPC
        DC object GUID: 700f4da0-0471-42dc-9a0a-453a5656d2a9
        Last attempt @ 2012-11-26 14:23:30 was successful.

*****************************************************************************

Check this line

"4013 consecutive failure(s).
        Last success @ 2012-11-20 03:00:24."

At the same time (2012-11-20 03:00:24) i have checked on DCM time was goes to 10 Years back like (2002) And i have sync time on DCM server manually. and automatic all client time goes automatically correct. But still ADCM and DCM did not synchroniz properly.

Thanks

Rakesh


Rakesh Kumar


selective authentication trusts

$
0
0

We have a domain trust between DomainA.com and DomainB.local.

DomainA.com is an external non-transitive incoming trust to DomainB.local and DomainB.local is an external non-transitive outgoing trust to DomainA.com. Both are set to selective authentication.

The issue is: I can’t lookup users or groups or computer objects from domainB.local   in DomainA.com.

I am a Domain and Enterprise admin in the DomainB.local .

So , when I log-on to a DC in the domainB.local domain and use ADUC to search for objects in the domainA.com. Nothing comes up.

I have double check DNS resolutions and that is working fine. What can I test or do to get this working,

 I will need to add user objects from domainA.com to resources in the DomainB.local for our migration.

Thanks

AD RMS SSL Enabling

$
0
0

Greetings,

When first installing AD RMS via the wizard, I chose an HTTP: address rather than the https: address.

I would like to change this to the https:\\rms.clustername.com address.

Can I do this through the registry below?

http://technet.microsoft.com/en-us/library/dd772665%28v=ws.10%29.aspx

Also, where do i make the change so that the environment is pointing to the cname (alias) for my sql server? I do not see registry keys or any way of doing this without uninstalling and reinstalling.

Thank you kindly,

Frank


Frank Garcia

Windows 2008 domain and NT 4 clients

$
0
0

All Windows 2003 domain controllers will be replaced with  Windows 2008 R2 domain controllers

Domain functional level is Windows 2003 will be upgraded later

There are few NT 4 and Windows 2000 clients .

Will upgrading all domain controllers to 2008 r2 cause problem for NT 4.0 and Windows 2000. Consider domain functional level is still 2003.

Active Directory Operations Master Isolated itself

$
0
0

So, Active Directory Newbie here. Have enough experience/knowledge to be dangerous. We have some trouble in the office, but I got a good feeling whats going on, but I don't how to professionally handle the problem.

We have 3 DCs. The DC with all the operations master roles seemed to flat out stop replicating with the other two. Those two are still communicating and replicating with each other just fine. Have troubles accessing network shares because of it. Can't pull down Group Policy because of it to desktops.

I'm interested in learning the quick and dirty way to get us back in good shape.

I was thinking demote the machine with all the operation's master roles, configure one of the other DCs to have all the roles, and the re-promote it DC. Switching the operation masters a second time isn't a requirement here.

I'm uncomfortable pulling the trigger with that method.

Could I bother anyone to share how they would approach this situtation? I would perfer not to try create any dump files or post error messages related to why the server became "isolated." I want to know how to fix this in the shortest amount of time, not a complex procedure of complete rebuilding my schema.

Please and Thank you.


"Knowledge changes life" "The quieter you are, the more you are able to hear" >Backtrack Linux FAN<

LDIFDE Problem

$
0
0

Hi, I'm working on the 70-640 training kit. I'm having trouble getting 2 accounts created with LDIFDE, checked for typos and can't find any. It gives me an add error starting on line 1. Says attribute doesn't exist. Here is what I have typed in Notepad. Saved it as NewUsers.ldf. Trying to run as: ldifde -i -f NewUsers.ldf -k -h The User Account OU exists so I don't know what I'm doing wrong.

DN: CN=April Stewart,OU=User Accounts,DC=contoso,DC=com
changeType: add
CN: April Stewart
objectClass: user
sAMAccountName: april.stewart
userPrincipalName: april.stewart@contoso.com
givenName: April
sn: Stewart
displayName: Stewart, April
mail: april.stewart@contoso.com
description: Sales Representative in the USA
title: Sales Representative
department: Sales
company: Contoso, Ltd.
unicodePwd::IgBQAGEAJAAkAHcAMAByAGQAIgA=
userAccountControl:512

DN: CN=Tony Krijnen,OU=User Accounts,DC=contoso,DC=com
changeType: add
CN: Tony Krijnen
objectClass: user
sAMAccountName: tony.krijnen
userPrincipalName: tony.krijnen@contoso.com
givenName: Tony
sn: Krijnen
displayName: Krijnen, Tony
mail: tony.krijnen@contoso.com
description: Sales Representative in the Netherlands
title: Sales Representative
department: Sales
company: Contoso, Ltd.
unicodePwd::IgBQAGEAJAAkAHcAMAByAGQAIgA=
userAccountControl:512


adprep32 /domainprep /gpprep fails with: adprep was unable to complete because the call back function failed gpprep

$
0
0

Running adprep32 to prep our Windows 2003 domain for new Windows Server 2008 R2 DCs.

adprep32 /forrestprep ran without error after changing domain to native mode.  However running adprep32 /domainprep /gpprep fails with adprep was unable to complete because the call back function failed.  After running it a second time, it looks like /domainprep worked as it says that the domain-wide information was already updated.  However the log shows this:

[Status/Consequence]

Adprep did not attempt to rerun this operation.
[2012/11/20:16:03:17.312]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net.
[2012/11/20:16:03:17.312]
LDAP API ldap_search_s() finished, return code is 0x20 
[2012/11/20:16:03:17.312]
Adprep verified the state of operation cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net. 

[Status/Consequence]

The operation has not run or is not currently running. It will be run next.
[2012/11/20:16:03:17.312]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net.
[2012/11/20:16:03:17.328]
LDAP API ldap_search_s() finished, return code is 0x0 
[2012/11/20:16:03:17.328]
Adprep checked to verify whether operation cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net has completed.

[Status/Consequence]

The operation GUID already exists so Adprep did not attempt to rerun this operation but is continuing.
[2012/11/20:16:03:17.328]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net.
[2012/11/20:16:03:17.390]
LDAP API ldap_search_s() finished, return code is 0x0 
[2012/11/20:16:03:17.390]
Adprep checked to verify whether operation cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net has completed.

[Status/Consequence]

The operation GUID already exists so Adprep did not attempt to rerun this operation but is continuing.
[2012/11/20:16:03:17.390]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net.
[2012/11/20:16:03:17.406]
LDAP API ldap_search_s() finished, return code is 0x20 
[2012/11/20:16:03:17.406]
Adprep verified the state of operation cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=4Seasons,DC=net. 

[Status/Consequence]

The operation has not run or is not currently running. It will be run next.
[2012/11/20:16:03:18.953]
Adprep was unable to complete because the call back function failed. 

[Status/Consequence]

Error message: (null)

[User Action] 

Check the log file ADPrep.log, in the C:\WINDOWS\debug\adprep\logs\20121120160315 directory for more information.
[2012/11/20:16:03:18.953]
Adprep was unable to update domain information. 

[Status/Consequence]

Adprep requires access to existing domain-wide information from the infrastructure master in order to complete this operation.

[User Action] 

Check the log file, ADPrep.log, in the C:\WINDOWS\debug\adprep\logs\20121120160315 directory for more information. 

I've check other forum questions and not found an answer.  I've check all the symptoms mentioned by http://technet.microsoft.com/en-us/library/dd464018(WS.10).aspx and all of those check out.

What I have found is that if I look in ADUC (after going to view ->advanced features), under system -> domainupdates -> operations there is no a3dac986-80e7-4e59-a059-54cb1ab43cb9 listed.  This appears to be my issue, but I can't find a resolution.  Please Advise.

Thanks!

LastLogonTimeStamp query result is 0?

$
0
0

Hi Guys,

Our client has a script that they are using to query the LastLogonTimeStamp of their users in their domains. Unfortunately, they have this domain that when they use this script to query for users LastLogonTimeStamp, the displayed result is 0? Do you think this could be a setting in the Domain Controller that needs to be enabled for the script to function properly? By the way, they are using Windows Server 2003. Please advise.

Thank You,

Arnel


Event id 1864 NTDS Replication

$
0
0
repadmin /showvector /latency dc=forestdnszones,dc=mydomain,dc=com
servers are continously getting this error i have check the replication thats is working fine bu when i run the    repadmin /showvector /latency dc=forestdnszones,dc=mydomain,dc=com     command then i get the following command plz help me that is it ok or some demoted DCs ares till exists:

OUTPUT:

Caching GUIDs.
..
3e7f911b-0470-4c29-a1af-d073bb0a69a3 @ USN   1331224 @ Time 2006-08-09 14:24:37
4101e9f1-9b7e-405a-8758-4984f705b7bd @ USN   2757306 @ Time 2006-08-28 15:54:27
cb86f234-8e28-49d0-a4df-80bcdd58847f @ USN   3748096 @ Time 2007-03-06 13:52:50
1a2c4537-a407-4a2c-b75f-c80f968c1656 @ USN   3108481 @ Time 2007-03-12 20:43:56
c7a266b2-977a-416d-93aa-cd055151c99d @ USN   4250688 @ Time 2007-04-23 11:46:53
400335de-b226-4361-9e10-fefa95e93391 @ USN    673065 @ Time 2007-06-16 16:02:39
732579aa-3453-4e7b-9c6b-f2751fa30a91 @ USN    172049 @ Time 2008-01-19 12:17:41
9cc1408e-eabe-4336-9bee-539a3042aad9 @ USN   9441768 @ Time 2008-04-11 11:55:39
0dc14863-5a33-42a8-bb00-3eafabc4933d @ USN    262155 @ Time 2008-07-03 12:02:05
14fb6ac5-50bd-495f-bb42-cd6ebf19534b @ USN   2908329 @ Time 2008-08-08 15:52:47
8e23fb34-8e5b-4bb9-91eb-4a7825d0e752 @ USN    133879 @ Time 2009-02-26 05:10:52
f01dc939-567f-43ab-ba14-63906c002d24 @ USN     98638 @ Time 2009-06-01 13:40:37
35db421d-c465-4a0c-938d-6f7f3ec8f44e @ USN   1211723 @ Time 2010-09-20 14:52:15
e9ff9358-cac8-4dc6-b470-855a5dab4da0 @ USN     57576 @ Time 2010-09-21 12:07:24
3bf5e5e2-bfe2-4d98-99a9-0ce667f290ca @ USN    470580 @ Time 2010-09-28 08:58:50
48a210d2-2e3b-407c-95aa-ebf5a553a14e @ USN 102035866 @ Time 2010-10-01 10:19:11
Mydomain\LostAndFoundConfig          @ USN    208379 @ Time 2010-10-02 22:53:41
6a05a1ba-feec-48e4-8ebb-3a598deb40bb @ USN  12187033 @ Time 2011-01-05 19:50:51
170602c5-f2e7-4b69-816d-8f108e55c3eb @ USN    208008 @ Time 2011-07-05 20:44:36
de6905ab-6180-41e2-a85e-81b9276339db @ USN   1678250 @ Time 2011-07-21 06:17:21
1da1b356-40a1-433d-808e-1ce744f3d43e @ USN    645858 @ Time 2011-07-21 06:22:32
0f9f1a40-7ccf-4cc0-87b9-76159c642573 @ USN  37943887 @ Time 2011-08-05 08:26:59
1a27a070-2291-4d6b-b8b2-4e022f2a56ef @ USN   6493129 @ Time 2011-08-05 08:27:00
2d8b9f4f-4e33-41d9-9419-e4c58b25c6df @ USN 131322040 @ Time 2011-08-05 08:27:00
c704fd70-d5e0-44a8-b3bb-50bb1f2a6228 @ USN  19322608 @ Time 2011-08-13 02:19:20
1d73526d-45fc-45d0-8934-9bb6c281c3f7 @ USN  23332619 @ Time 2011-08-13 03:25:22
e4458b25-c876-4da3-9cd1-84ca9c2204f0 @ USN  26592774 @ Time 2011-10-20 15:37:11
6bbdc018-e1d1-4cd5-9b33-e906efe31a94 @ USN    245775 @ Time 2012-05-29 04:51:00
2be91d85-ad19-491b-9759-286e4b5fae87 @ USN 150491368 @ Time 2012-06-19 22:07:41
e933c38e-91cc-4a76-aa48-0c0138d2cef4 @ USN  26493322 @ Time 2012-08-13 13:25:10
94117ea0-bb6c-4f59-a48d-fb4066c2b7dd @ USN  67732028 @ Time 2012-09-17 19:53:25
b1a328ea-f666-4d67-bd5f-0cdd81000367 @ USN  65181201 @ Time 2012-09-19 17:32:59
087261e1-0d94-44ae-9d21-baf8882472cf @ USN  32871998 @ Time 2012-09-25 15:40:54
cc506f69-04a1-4f16-89dd-f0db9a45e551 @ USN  32495111 @ Time 2012-10-12 23:52:53
54652063-33a0-40a5-97ed-f4fb78218ebb @ USN  19706574 @ Time 2012-11-01 16:00:01
Mysite\DC01                          @ USN   5075034 @ Time 2012-11-13 12:54:53
Mysite\DC02                          @ USN  33169929 @ Time 2012-11-27 08:54:59
Mysite\DC03                          @ USN   5789494 @ Time 2012-11-27 08:54:59
Mysite\DC04                          @ USN  38809392 @ Time 2012-11-27 08:54:59
Mysite\DC05                          @ USN   9971984 @ Time 2012-11-27 08:54:59
Mysite\DC06                          @ USN  24965752 @ Time 2012-11-27 08:54:59
Mysite\DC07                          @ USN  37034212 @ Time 2012-11-27 08:55:39
Mysite\DC08                          @ USN  39244078 @ Time 2012-11-27 08:55:43
Mysite\DC09                          @ USN  10674081 @ Time 2012-11-27 08:55:47
Mysite\DC10                          @ USN 117922538 @ Time 2012-11-27 08:55:48
Mysite\DC11                          @ USN   6376988 @ Time 2012-11-27 08:55:48
Mysite\DC12                          @ USN  27220948 @ Time 2012-11-27 09:02:19

thanks

W32tm / query /source issue

$
0
0

Hi

I'm trying to use "w32tm" to check on out servers here and I'm,
seeing the following problem with some (not all) of our server and can't seem to find out why. Here's the command:

w32tm /query /verbose /computer:server1 /status

w32tm /query /computer:server1 /source
The following error occurred: The procedure number is out of range.
(0x800706D1)

but other machines are fine. Any ideas what I should check here?

Also This issue occurring only for windows 2003 Server DC.

Error 1068: the dependency service or group failed to start

$
0
0

Hi,

I´ve created a service in a windows server 2008 R2, but when I try to start the service :

Windows could not start the Test service on Local Computer

Error 1068: The dependency service or group failed to start

I´ve checked the service dependencies, and all services which appear in the dependencies tab are started.

So any idea why is failing?

Thanks thaks thanks

OU disappear from the system

$
0
0

i know this might sound strange, i was working in a customer side fixing a direct access related issue - along with a Microsoft support engineer

the last thing we were working on is unlink some GPO from an OU using the GPMC

this OU disappeared suddenly i went to the AD users and computers - refresh and it is gone - logically deleted some how

me & the engineer are banging our heads on the wall and as you know all fingers are pointing @ us and looks like we will lose this whole project for this

the OU was restored using a backup solution and the SCCM showing items deleted inside this OU the same time this happened

the question is did anyone face such a thing before - does anyone know how to find out what happened & how could this happen

if it was only me i could have doubted myself but both of us are 100% sure we did not delete this OU

the DC we were working on is a 2008, they have many DCs in the network some of them is 2003, the deletion of this OU was replicated in a blink if a eye

i would really appreciate any help in this case

How to perform the merge of two users in Active Directory

$
0
0
Hi all, I need tomergethetwoaccounts in ActiveDirectory.

The version ofActive Directory2008 R2,aftermigrating fromExchangeServer, I have seenthat I have twoaccountsof thesame user inActive Directory, auser'smailboxandotherusermigrated existing one.

Requirethe userin ActiveDirectorythat existedbefore,convergeswiththe user created inthemailboxmigrationanotherAD forest.

The user shouldbe the same asinADhadbefore,andhe agreedtomigratedmailbox.

Do you know howthis can be done?


bestregards

Microsoft Certified IT Professional Server Administrator

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>