We've taken on a site with a 2008 R2 server with what appears to be a corrupt OU in AD, and I'm looking for any advice on how to remove the OU.
When attempting to open the OU in ADUC an error message is displayed stating "Data from Users is not available from Domain Controller xxx because: An operations error occured." (the corrupt OU is named 'Users').
Attempting to open the OU in ASDI Edit, an error message is displayed stating "Operation failed. Error code: 0x80072020 An operations error occured.
Attempting to delete the OU in ASDI Edit displayes the error message: "Operation failed. Error code: 0x20ef The directory service encountered an unknown failure. 000020EF: SvcErr: DSID-02080F91, problem 5012 (Dir_ERROR), data -1017"
Also on this server, on attempting to open GPMC a message is displayed stating "The system cannot open the device or file specified.", and this is reapeated when attempting to view any GPO. In the Settings tab for every GPO is displayed "An
error occurred while generating report: An operations error occured."
GP Settings can be viewed in the GP Editor.
Everything else appears to be working OK, there are no warning or critical events in the System or Application event logs.
This is the only DC in the domain, and there were no backups being taken so fix by restore is not possible.
The Directory Service log has repeated 2008 and 1262 events as shown below:
Log Name: Directory Service
Source: Microsoft-Windows-ActiveDirectory_DomainService
Date: 26/03/2013 14:38:36
Event ID: 1262
Task Category: Internal Processing
Level: Error
Keywords: Classic
User: ANONYMOUS LOGON
Computer: SRV-01.Cxxx.local
Description:
The security descriptor propagation task could not process a propagation event starting from the following container.
Container:
OU=Users,OU=_Cxx xxx,DC=Cxxxx,DC=local
As a result, the security descriptor propagation task will either suspend processing for thirty minutes or wait until a security descriptor has changed for any object.
User Action
Check the security descriptor on this container.
Additional Data
Error value:
fffffc07 []
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-ActiveDirectory_DomainService" Guid="{0e8478c5-3605-4e8c-8497-1e730c959516}" EventSourceName="NTDS General" />
<EventID Qualifiers="49152">1262</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>9</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2013-03-26T14:38:36.489263200Z" />
<EventRecordID>9392</EventRecordID>
<Correlation />
<Execution ProcessID="644" ThreadID="856" />
<Channel>Directory Service</Channel>
<Computer>SRV-01.Cxxx.local</Computer>
<Security UserID="S-1-5-7" />
</System>
<EventData>
<Data>fffffc07</Data>
<Data>OU=Users,OU=_Cxx xxx,DC=Cxxx,DC=local</Data>
<Data>[]</Data>
</EventData>
</Event>
Log Name: Directory Service
Source: Microsoft-Windows-ActiveDirectory_DomainService
Date: 26/03/2013 14:38:36
Event ID: 2008
Task Category: Internal Processing
Level: Error
Keywords: Classic
User: N/A
Computer: SRV-01.Cxxx.local
Description:
Internal error: The security descriptor propagation task encountered an error while processing the following object. The propagation of security descriptors may not be possible until the problem is corrected.
Object:
(n/a)
Additional Data
Error value:
-1017 JET_errRecordDeleted, Record has been deleted
Internal ID:
20801d4
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-ActiveDirectory_DomainService" Guid="{0e8478c5-3605-4e8c-8497-1e730c959516}" EventSourceName="NTDS General" />
<EventID Qualifiers="49152">2008</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>9</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2013-03-26T14:38:36.426863100Z" />
<EventRecordID>9391</EventRecordID>
<Correlation />
<Execution ProcessID="644" ThreadID="856" />
<Channel>Directory Service</Channel>
<Computer>SRV-01.Cxxx.local</Computer>
<Security />
</System>
<EventData>
<Data>-1017</Data>
<Data>JET_errRecordDeleted, Record has been deleted</Data>
<Data>20801d4</Data>
<Data>(n/a)</Data>
</EventData>
</Event>