Directory Services ForumDiscussion on Windows Server Active Directory services© 2009 Microsoft Corporation. All rights reserved.Mon, 30 Nov 2009 17:08:29 Z5e5d4650-dd6f-43c7-933d-41ee70aba476http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/fd8bbfb4-4889-4b78-88fe-63d0a27979fehttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/fd8bbfb4-4889-4b78-88fe-63d0a27979few88tonhttp://social.technet.microsoft.com/Profile/en-US/?user=w88tonBrand New windows 2003 server with AD installationAll,<br/><br/>I am trying to ask myself the right questions as i am about to setup a brand new company and want to implement server 2003 with AD. <br/>What I need is to ask my self the right questions for the planning process. For example, what address range am i going to use? What am i going to call my domain? What Raid array to use? IS there going to be only one forest. etc.<br/><br/>Does anyone have a getting started checklist or something similar that I could use to make sure i have covered all topics. I am familiar with server 2003 but have never setup a network from scratch that needs all these services.<br/><br/>Really appreciate any advice. I have been refered to the &quot;Planning an Active Directory Deployment Project&quot; but this does not give me the questions that i need answered. <br/>Regards,<br/><br/>Kevin<br/>Mon, 30 Nov 2009 16:30:19 Z2009-11-30T17:08:29Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/38d08135-fbfb-4174-a679-17985cfdac24http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/38d08135-fbfb-4174-a679-17985cfdac24Brandon Humehttp://social.technet.microsoft.com/Profile/en-US/?user=Brandon%20HumeSubclassing "User" or "inetOrgPerson" breaks AD Users and Computers tool?I'm busy porting over a non-AD LDAP instance to AD, in the hopes of enabling the use of Exchange in the future while maintaining some compatibility with existing applications.  I'm largely successful importing user data, but I've notice one thing that confuses me:<br/> <br/> I'm adding a new custom schema, and object class to contain attributes specific to our organization.  I'd rather it be a structural object class, since as near as I can tell only a structural object class is allowed to specify a custom rdnAttId (and I want a custom rdn, as using &quot;cn&quot; is an absolute last resort for policy/privacy reasons).  Importing the data works fine.<br/> <br/> But when I view these programmatically-created users in AD Users and Computers, it only shows them as generic objects.  It has no idea how to deal with them.<br/> <br/> If I change my class to just an auxiliary class - which forces me back into using 'cn' as rdnAttId - ADUC suddenly knows what it's looking at.<br/> <br/> Am I doing something wrong?  The whole idea of a subclass is that the subclass IS a member of the parent class.  My custom class IS a User, and User is even in the objectclass value list.Fri, 27 Nov 2009 18:07:23 Z2009-11-30T16:55:36Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/d8874af1-a342-4909-a94b-2506cc95f51fhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/d8874af1-a342-4909-a94b-2506cc95f51fegoncharovhttp://social.technet.microsoft.com/Profile/en-US/?user=egoncharovCertificate Request for Exchange 2010 and PKI ConfigureWe have PKI and Exchange 2010 servers on Windows Server 2008 R2.<br/><br/>I try to add a new certificate for Client Access. I can prepare request file. But when I go to Certificate Authority Console on PKI server I can not approve this req. file. I don't know PKI very well and want to understand it. <br/>I click Issue Node in Certificate Authority Console and choose Submit New Request but nothing happend. <br/><br/>Furthermore there is no <a href="http://pkisrv/certsrv">http://pkisrv/certsrv</a> node. I configured PKI by <a href="http://technet.microsoft.com/en-us/library/cc772393(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc772393(WS.10).aspx</a> step-by-step guide.<br/><br/>How to resolve the issue with PKI?Mon, 30 Nov 2009 16:35:23 Z2009-11-30T16:35:24Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/a33763cb-18d2-4a62-a2c2-cbdecbfcaffehttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/a33763cb-18d2-4a62-a2c2-cbdecbfcaffeGarri Shttp://social.technet.microsoft.com/Profile/en-US/?user=Garri%20Sxfer schema master fsmo from 2003 to 2008 server Error when trying to register this dll; &quot;regsvr32 schmmgmt.dll &quot; on 2008 dc:<br/><br/>&quot;The module schmmgmt.dll was loaded but the call to dllregisterserver failed with error code 0x80040201.<br/><br/><br/><br/><br/>thanks in advanceMon, 30 Nov 2009 15:48:40 Z2009-11-30T16:14:51Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/dfa32405-41e5-44c4-9369-f6d074b82ddfhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/dfa32405-41e5-44c4-9369-f6d074b82ddfRick Sheikhhttp://social.technet.microsoft.com/Profile/en-US/?user=Rick%20SheikhCan you rename Windows Server 2008 domain ?Hi there,<br><br>I am wondering if its possible to rename a Windows server 2008 domain using Rendom utility. I have tried installing the Rendom utility available for Windows Server 2003 and it fails to install successfully, even if you try to install in the compatibility mode. I didn't find this utility for Windows Server 2008 domain specifically.<br><br>I understand the business case for this to be relatively low as Server 2008 is fairly new and wont be in production at most places for a while. My need is around my test lab.<br><br>Any help would be appreciated.<br><br>Regards,<br>Rick @ Toyota Motors<br>Mon, 31 Mar 2008 17:16:19 Z2009-11-30T16:01:36Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/50b0fc2b-240c-43ac-bee3-de2287cf8f33http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/50b0fc2b-240c-43ac-bee3-de2287cf8f33ThanaPhahttp://social.technet.microsoft.com/Profile/en-US/?user=ThanaPhaCan't clear security log on DCMy account is member of Domain Admins, and Enterprise Admins but can't clear security log. How can i clear security log on my DCs. please advise<br/>Thank you. <hr class=sig> ThanaFri, 27 Nov 2009 07:59:35 Z2009-11-30T15:51:05Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/0f0cba80-69ec-41f1-b6ad-1aceb9566495http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/0f0cba80-69ec-41f1-b6ad-1aceb9566495Skybreakhttp://social.technet.microsoft.com/Profile/en-US/?user=SkybreakActive Directory User to use a second router by defaultWe have a web Server running Windows Server 2003 with Exchange Server,Active Directory,IIS and Terminal Services. <br/>We have 2 routers with 2 different internet connections (both with a different static IP) assigned to local ip's 192.168.1.1 and 192.168.1.2. <br/>The first router holds the DHCP server.<br/>We would like to set an existing user to only use the secondary IP for downloading. It doesnt matter for us if we need to have this user make all his internet activity through the second router or make him use the second one in specific application types. We're concerned about downloads mostly.<br/>The Server also has 2 network cards, in case there is a solution that needs that. <br/>Also the server has IIS that runs about a dozen web sites, all configured with the IP of the 1st router.<br/><br/>Mon, 30 Nov 2009 12:02:45 Z2009-11-30T15:35:12Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/6f8dfe9a-a36d-4422-876d-413f50d9a0b6http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/6f8dfe9a-a36d-4422-876d-413f50d9a0b6scott.barrhttp://social.technet.microsoft.com/Profile/en-US/?user=scott.barrCross-forest trust: What permissions are required to lookup users in the trusted domain?We have a two-way selective authentication trust in which we would like to add users from the other domain to a group in our resource domain. We are challenged for the other domains credentials in order to resolve/lookup the user account in order to add it to our domain group.<br/> <br/> What specific permissions are required in the other domain to be able to resolve/lookup users from that domain to prevent the challenge each time?<br/> <br/> Thx,<br/> <br/> -ScottFri, 20 Nov 2009 14:16:09 Z2009-11-30T15:30:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/2ca14089-f5d2-4060-b09c-614158911370http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/2ca14089-f5d2-4060-b09c-614158911370Sandy Woodhttp://social.technet.microsoft.com/Profile/en-US/?user=Sandy%20WoodUpgrading Windows 2008 Domain to Windows 2008 R2I can't seem to find any docs specific to an AD upgrade from Windows 2008 to Windows 2008 R2. It seems we should be able to run adprep /forestprep and adprep /domainprep and run the R2 upgrades on my current DCs. I've searched TechNet but can't find any docs that focus on my specific instance. Has anyone done what I'm considering?<hr class="sig">Orange County District AttorneyMon, 23 Nov 2009 16:30:24 Z2009-11-30T15:07:22Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/82ba66fd-1aa7-426f-b2be-3c27e24536f0http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/82ba66fd-1aa7-426f-b2be-3c27e24536f0suman bikramhttp://social.technet.microsoft.com/Profile/en-US/?user=suman%20bikramDomain Administrator is unable to install Softwares Hi<br/> My domain admin is unable to install software but all Administrator in same OU are working fine. The interesting thing is that its also an Enterprise Administrator. When I click on installers (MSI or other exe) nothing happens. Not a message or event id is generated.<br/> <br/> Can some one help me?Fri, 27 Nov 2009 05:13:34 Z2009-11-30T14:54:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b181cccc-bf57-45dc-8595-ee8be3c7678ahttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b181cccc-bf57-45dc-8595-ee8be3c7678aKGene1http://social.technet.microsoft.com/Profile/en-US/?user=KGene1Upgrade 2000 domain to 2003 domains fails adprep /forestprep<p>I am trying to uprgrade a win 2000 domain to Win 2003 the adprep fails with this error  <br/>LDAP API ldap_add_s() finished, return code is 0x44 <br/>And<br/>Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=4444c516-f43a-4c12-9c4b-b5c064941d61,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=XXXXX,DC=local.LDAP API ldap_search_s() finished, return code is 0x20 <br/><br/>ANy one see this before? Any ideas on the fix<br/>Thanks</p>Sat, 28 Nov 2009 15:29:19 Z2009-11-30T14:34:02Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/e85103b0-b7ac-4b12-9642-c28043de376fhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/e85103b0-b7ac-4b12-9642-c28043de376fmaor18http://social.technet.microsoft.com/Profile/en-US/?user=maor18administratos - built in group in domain 2003hello<br/><br/>i remove user from administrators built in domain group, and after couple of minutes the user return without that user add him.<br/>i look for GPO that apply on Domain Controllers OU and no definition that can add user to this group, and i dont why this happen<br/><br/>Thanks<br/>Thu, 19 Nov 2009 20:51:53 Z2009-11-30T14:25:47Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b769ce4f-2106-4ef6-b1f5-6f661eef7311http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b769ce4f-2106-4ef6-b1f5-6f661eef7311w88tonhttp://social.technet.microsoft.com/Profile/en-US/?user=w88tonWindows Server 2003 Active directory Sizer ToolHi all,<br/><br/>Does anyone know of a good sizer tool for deploying AD in server 2003. <br/>I know they did one for 2000 server and it looks like a good tool to follow to enable me to successfully plan and implement AD in server 2003.<br/>Any advice or something similar would be a great help. This will be a brand new domain with just one forest. It's probably not that difficult but I am currently studying MCSE this is my 1st major project. <br/><br/>Thanks in advance for any advice or help,<br/><br/>Regards,<br/><br/>KevinMon, 30 Nov 2009 12:57:50 Z2009-11-30T13:17:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b49aad3c-9aab-46ff-af5c-b548e2e8f103http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b49aad3c-9aab-46ff-af5c-b548e2e8f103Delukahttp://social.technet.microsoft.com/Profile/en-US/?user=DelukaHide or remove domain name at logon screenHey there. <div>I wanna remove the domain name at the logon screen. (win7 and Vista clients)<br/>Now i have &quot;domain\User account name&quot; and i just want to see a username just as if there a logon on locally.</div> <div>Wondering if this is possible at all</div>Sun, 29 Nov 2009 12:34:01 Z2009-11-30T12:02:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1866cf61-5a5d-41b0-8304-c5464ca25919http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1866cf61-5a5d-41b0-8304-c5464ca25919Pelucohttp://social.technet.microsoft.com/Profile/en-US/?user=PelucoSecond domain controler with W2K3Server 32bits when the primary is W2K3Server X64 ... possible ?I have a Primary Domain controles with Windows 2003 Server 64bits  R2. <br/>I want to have a second DC in case the primary one falls.  Is it possible ?<br/>I have tried with a virtual machine and is giving a problems win DNS, but everything is ok about it.<br/>Some Idea ?Thu, 19 Nov 2009 16:29:08 Z2009-11-30T10:27:47Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/7525ce2b-c6c5-4c2b-93fa-2ed4a74c76f3http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/7525ce2b-c6c5-4c2b-93fa-2ed4a74c76f3ErgoDavehttp://social.technet.microsoft.com/Profile/en-US/?user=ErgoDaveActive Directory Web Services fails to startWe've recently Upgrade a Windows 2003 R2 Domain Controller to Windows Server 2008 R2x64 DC.  The installation seemed to go well, except for the Active Directory Web Services have failed to start.   The event log items as below.<br/><br/><br/><br/>Log Name:      System<br/>Source:        Service Control Manager<br/>Date:          11/27/2009 8:34:04 PM<br/>Event ID:      7034<br/>Task Category: None<br/>Level:         Error<br/>Keywords:      Classic<br/>User:          N/A<br/>Computer:      bigger.cpu.local<br/>Description:<br/>The Active Directory Web Services service terminated unexpectedly.  It has done this 3 time(s).<br/>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Service Control Manager&quot; Guid=&quot;{555908d1-a6d7-4695-8e1e-26931d2012f4}&quot; EventSourceName=&quot;Service Control Manager&quot; /&gt;<br/>    &lt;EventID Qualifiers=&quot;49152&quot;&gt;7034&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;2&lt;/Level&gt;<br/>    &lt;Task&gt;0&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8080000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-11-28T04:34:04.644407000Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;8688&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;680&quot; ThreadID=&quot;4816&quot; /&gt;<br/>    &lt;Channel&gt;System&lt;/Channel&gt;<br/>    &lt;Computer&gt;bigger.cpu.local&lt;/Computer&gt;<br/>    &lt;Security /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;param1&quot;&gt;Active Directory Web Services&lt;/Data&gt;<br/>    &lt;Data Name=&quot;param2&quot;&gt;3&lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;<br/>Sat, 28 Nov 2009 04:42:00 Z2009-11-30T06:00:23Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/54c678a9-2cac-40d5-8f01-0dc777d013d6http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/54c678a9-2cac-40d5-8f01-0dc777d013d6DanielHachehttp://social.technet.microsoft.com/Profile/en-US/?user=DanielHacheDC migration problemHello,<br/> <br/> I need to move a DC from one server to another. The original server is W2k3 and also Exchange 2003 server. The destination server is running w2k8 and also an Exchange 2007 server.<br/> <br/> On the original server, Exchange 2003 has been removed. There is no way back on it.<br/> Whenever I ty to switch off the original server, the domain goes nuts. Rebooting the destination server ends up with Exchange services stopped and Events relating the the fact that the new server cannot find a DC for the domain. Here are different informations I grabed :<br/> <br/> ----------------------------------------------<br/> ActiveDirectory_DomainService EventID 2087<br/> <br/> Active Directory services could not resolve the DNS hostname for the AD controler. bla bla bla<br/> <br/> <br/> Source doamin controler : <br/>  MyOriginal W2K3 domain controler <br/> Nom de l’hôte DNS en échec : <br/>  40027475-dca3-43db-86db-6ac4b3a7576f._msdcs.oxygen-rp.com <br/> ----------------------------------------------<br/> MSExchange ADAccess EventId : 2130<br/> Processus SMEX_SystemWatcher.exe (EMS) (PID=2056). Exchange Active Directory did not find an available Active Directory Controler in the domain ...<br/> (rough translation from french)<br/> <br/> From this Event I can find tons of errors in concerning Exchange.<br/> ----------------------------------------------<br/> DCDIAG /s:NewDC<br/> <br/> C:\Users\administrateur.OXYGEN&gt;dcdiag /s:oxymail<br/> <br/> Diagnostic du serveur d'annuaire<br/> <br/> Exécution de l'installation initiale :<br/>    * Forêt AD identifiée.<br/>    Collecte des informations initiales terminée.<br/> <br/> Exécution des tests initiaux nécessaires<br/> <br/>    Test du serveur : Asnieres\OXYMAIL<br/>       Démarrage du test : Connectivity<br/>          ......................... Le test Connectivity<br/>           de OXYMAIL a réussi<br/> <br/> Exécution des tests principaux<br/> <br/>    Test du serveur : Asnieres\OXYMAIL<br/>       Démarrage du test : Advertising<br/>          ......................... Le test Advertising<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : FrsEvent<br/>          Erreurs ou avertissements détectés au cours des dernières 24 heures<br/>          après le partage de SYSVOL. Des problèmes liés à l'échec de la<br/>          réplication SYSVOL peuvent provoquer des problèmes de Stratégie de<br/>          groupe.<br/>          ......................... Le test FrsEvent<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : DFSREvent<br/>          ......................... Le test DFSREvent<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : SysVolCheck<br/>          ......................... Le test SysVolCheck<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : KccEvent<br/>          ......................... Le test KccEvent<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : KnowsOfRoleHolders<br/>          ......................... Le test KnowsOfRoleHolders<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : MachineAccount<br/>          ......................... Le test MachineAccount<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : NCSecDesc<br/>          L'erreur AUTORITE NT\ENTERPRISE DOMAIN CONTROLLERS n'a pas<br/>             Replicating Directory Changes In Filtered Set<br/>          de droits d'accès pour le contexte de nommage :<br/>          DC=ForestDnsZones,DC=oxygen-rp,DC=com<br/>          L'erreur AUTORITE NT\ENTERPRISE DOMAIN CONTROLLERS n'a pas<br/>             Replicating Directory Changes In Filtered Set<br/>          de droits d'accès pour le contexte de nommage :<br/>          DC=DomainDnsZones,DC=oxygen-rp,DC=com<br/>          ......................... Le test NCSecDesc<br/>           de OXYMAIL a échoué<br/>       Démarrage du test : NetLogons<br/>          ......................... Le test NetLogons<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : ObjectsReplicated<br/>          ......................... Le test ObjectsReplicated<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : Replications<br/>          ......................... Le test Replications<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : RidManager<br/>          ......................... Le test RidManager<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : Services<br/>          ......................... Le test Services<br/>           de OXYMAIL a réussi<br/>       Démarrage du test : SystemLog<br/>          Un événement Error s'est produit. Identificateur de l'événement :<br/>          0xC0002719<br/>             Temps généré : 11/27/2009   11:19:25<br/>             Chaîne d'événement :<br/>             DCOM n'a pas pu communiquer avec l'ordinateur 194.2.0.20 en utilisan<br/> t les protocoles configurés.<br/>          Un événement Error s'est produit. Identificateur de l'événement :<br/>          0xC0002719<br/>             Temps généré : 11/27/2009   11:19:25<br/>             Chaîne d'événement :<br/>             DCOM n'a pas pu communiquer avec l'ordinateur 194.2.0.50 en utilisan<br/> t les protocoles configurés.<br/>          Un événement Error s'est produit. Identificateur de l'événement :<br/>          0xC0002719<br/>             Temps généré : 11/27/2009   11:19:46<br/>             Chaîne d'événement :<br/>             DCOM n'a pas pu communiquer avec l'ordinateur 195.40.1.250 en utilis<br/> ant les protocoles configurés.<br/>          ......................... Le test SystemLog<br/>           de OXYMAIL a échoué<br/>       Démarrage du test : VerifyReferences<br/>          ......................... Le test VerifyReferences<br/>           de OXYMAIL a réussi<br/> <br/> <br/>    Exécution de tests de partitions sur ForestDnsZones<br/>       Démarrage du test : CheckSDRefDom<br/>          ......................... Le test CheckSDRefDom<br/>           de ForestDnsZones a réussi<br/>       Démarrage du test : CrossRefValidation<br/>          ......................... Le test CrossRefValidation<br/>           de ForestDnsZones a réussi<br/> <br/>    Exécution de tests de partitions sur DomainDnsZones<br/>       Démarrage du test : CheckSDRefDom<br/>          ......................... Le test CheckSDRefDom<br/>           de DomainDnsZones a réussi<br/>       Démarrage du test : CrossRefValidation<br/>          ......................... Le test CrossRefValidation<br/>           de DomainDnsZones a réussi<br/> <br/>    Exécution de tests de partitions sur Schema<br/>       Démarrage du test : CheckSDRefDom<br/>          ......................... Le test CheckSDRefDom<br/>           de Schema a réussi<br/>       Démarrage du test : CrossRefValidation<br/>          ......................... Le test CrossRefValidation<br/>           de Schema a réussi<br/> <br/>    Exécution de tests de partitions sur Configuration<br/>       Démarrage du test : CheckSDRefDom<br/>          ......................... Le test CheckSDRefDom<br/>           de Configuration a réussi<br/>       Démarrage du test : CrossRefValidation<br/>          ......................... Le test CrossRefValidation<br/>           de Configuration a réussi<br/> <br/>    Exécution de tests de partitions sur oxygen-rp<br/>       Démarrage du test : CheckSDRefDom<br/>          ......................... Le test CheckSDRefDom<br/>           de oxygen-rp a réussi<br/>       Démarrage du test : CrossRefValidation<br/>          ......................... Le test CrossRefValidation<br/>           de oxygen-rp a réussi<br/> <br/>    Exécution de tests d'entreprise sur oxygen-rp.com<br/>       Démarrage du test : LocatorCheck<br/>          ......................... Le test LocatorCheck<br/>           de oxygen-rp.com a réussi<br/>       Démarrage du test : Intersite<br/>          ......................... Le test Intersite<br/>           de oxygen-rp.com a réussi<br/> <br/> C:\Users\administrateur.OXYGEN&gt;<br/> ----------------------------------------------<br/> DCDIAG /test:dns /e<br/> <br/> C:\Users\administrateur.OXYGEN&gt;dcdiag /test:dns /e<br/> <br/> Diagnostic du serveur d'annuaire<br/> <br/> Exécution de l'installation initiale :<br/>    Tentative de recherche de serveur associé...<br/>    Serveur associé : oxymail<br/>    * Forêt AD identifiée.<br/>    Collecte des informations initiales terminée.<br/> <br/> Exécution des tests initiaux nécessaires<br/> <br/>    Test du serveur : Asnieres\ADELE<br/>       Démarrage du test : Connectivity<br/>          ......................... Le test Connectivity<br/>           de ADELE a réussi<br/> <br/>    Test du serveur : Asnieres\OXYMAIL<br/>       Démarrage du test : Connectivity<br/>          ......................... Le test Connectivity<br/>           de OXYMAIL a réussi<br/> <br/> Exécution des tests principaux<br/> <br/>    Test du serveur : Asnieres\ADELE<br/> <br/>    Test du serveur : Asnieres\OXYMAIL<br/> <br/>          Démarrage du test : DNS<br/> <br/>                Démarrage du test : DNS<br/> <br/>                   Les tests DNS sont en cours d'exécution et ne sont pas<br/>                   arrêtés. Veuillez patienter quelques minutes...<br/>                   ......................... Le test DNS<br/>                    de OXYMAIL a réussi<br/>          ......................... Le test DNS<br/>           de ADELE a réussi<br/> <br/>    Exécution de tests de partitions sur ForestDnsZones<br/> <br/>    Exécution de tests de partitions sur DomainDnsZones<br/> <br/>    Exécution de tests de partitions sur Schema<br/> <br/>    Exécution de tests de partitions sur Configuration<br/> <br/>    Exécution de tests de partitions sur oxygen-rp<br/> <br/>    Exécution de tests d'entreprise sur oxygen-rp.com<br/>       Démarrage du test : DNS<br/>          Résultats des tests des contrôleurs de domaine :<br/> <br/>             Contrôleur de domaine : oxymail.oxygen-rp.com<br/>             Domaine : oxygen-rp.com<br/> <br/> <br/>                TEST: Basic (Basc)<br/>                   Warning: The AAAA record for this DC was not found<br/> <br/>                TEST: Dynamic update (Dyn)<br/>                   Warning: Failed to delete the test record _dcdiag_test_record<br/> in zone oxygen-rp.com<br/> <br/>                TEST: Records registration (RReg)<br/>                   Carte réseau<br/>                   [00000006] Connexion réseau Intel(R) PRO/1000 MT :<br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      10.10.1.245 :<br/>                      oxymail.oxygen-rp.com<br/> <br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      ::1 :<br/>                      oxymail.oxygen-rp.com<br/> <br/>                Avertissement : inscriptions d'enregistrement introuvables sur<br/>                certaines cartes réseau<br/> <br/> <br/>             Contrôleur de domaine : adele.oxygen-rp.com<br/>             Domaine : oxygen-rp.com<br/> <br/> <br/>                TEST: Basic (Basc)<br/>                   Warning: The AAAA record for this DC was not found<br/> <br/>                TEST: Dynamic update (Dyn)<br/>                   Warning: Failed to delete the test record _dcdiag_test_record<br/> in zone oxygen-rp.com<br/> <br/>                TEST: Records registration (RReg)<br/>                   Carte réseau<br/>                   [00000001] Intel(R) PRO/1000 MT Network Connection :<br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      10.10.1.245 :<br/>                      adele.oxygen-rp.com<br/> <br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      10.10.1.245 :<br/>                      gc._msdcs.oxygen-rp.com<br/> <br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      10.10.1.5 :<br/>                      adele.oxygen-rp.com<br/> <br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      10.10.1.5 :<br/>                      gc._msdcs.oxygen-rp.com<br/> <br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      ::1 :<br/>                      adele.oxygen-rp.com<br/> <br/>                      Avertissement :<br/>                      Enregistrement AAAA manquant au niveau du serveur DNS<br/>                      ::1 :<br/>                      gc._msdcs.oxygen-rp.com<br/> <br/>                Avertissement : inscriptions d'enregistrement introuvables sur<br/>                certaines cartes réseau<br/> <br/>                oxymail                      PASS WARN PASS PASS WARN WARN n/a<br/>                adele                        PASS WARN PASS PASS WARN WARN n/a<br/>          ......................... Le test DNS<br/>           de oxygen-rp.com a réussi<br/> <br/> C:\Users\administrateur.OXYGEN&gt;<br/> <br/> <strong>--&gt; IPV6 is not installed on the original W2K3 server<br/> </strong> <br/> ----------------------------------------------<br/> The new W2K8 has the 5 FSMO roles<br/> (schema master, naming master, PDC, RID, Infrastructure)<br/> <br/> I guess my problem lies in the DNS configuration, but I must admin I don't know to start from !<br/> <br/> Any help / guidance / suggestion / link to any page on the internet will be appreciated !<br/> <br/> Daniel<br/> <br/> <br/> <br/>Fri, 27 Nov 2009 11:04:27 Z2009-11-30T05:21:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/2fe9e610-45b5-4c83-985a-45749d192b8ahttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/2fe9e610-45b5-4c83-985a-45749d192b8aAakash Shahhttp://social.technet.microsoft.com/Profile/en-US/?user=Aakash%20ShahWindows Log Off Problems On Wireless Laptops Connected To DomainWe've encountered a problem where Windows takes a very long time to log off if the laptop is on the wireless network.  On the wired network, the laptop works great (just like our desktops).  Please note that this is our first attempt at adding laptops to the domain (since more users are starting to request laptops we are looking for an easy way to manage them and hence are looking to add them to the domain to use group policy).<br/> <br/> The following 2 events are logged in the Application event log when the laptop logs off slowly on the company wireless network:<br/> 1. Event ID 6005, Source Winlogon: The winlogon notification subscriber &lt;GPClient&gt; is taking long time to handle the notification event (EndShell).<br/> <br/> 2. Event ID 6006, Source Winlogon: The winlogon notification subscriber &lt;GPClient&gt; took 233 seconds to handle the notification event (EndShell).<br/> <br/> During my testing, I found that if I turn off the wireless adapter while logging off, the log off occurs smoothly.  Also, if I keep the VPN client connected while I log off, the log off occurs smoothly. <br/> <br/> Since the problem only happened on the internal wireless network, I contacted the security folks and discovered that netbios is disabled on the company wireless network.  So to work around this, I attempted to disable netbios over TCP/IP for the wireless network adapter, but this did not help.<br/> <br/> I also attempted to play around with the &quot;Group Policy slow link detection&quot; group policy setting under the user configuration area with no success.<br/> <br/> I've moved both the laptop computer account and test user account under a new OU that blocks all inheritance.  So, no domain group policies are affecting this laptop.<br/> <br/> Any suggestions on getting around this problem?  It would be very useful to have these laptops connected to the domain so we can start pushing group policy settings to them, but I also want the user experience to the quick and responsive.  And, I would like to avoid having to have my users turn off the wireless adapter each time they log off while on the wireless network because I know that they will not remember.<br/> <br/> The client laptop is running Windows 7 RTM (this is my test laptop) connecting in to a Windows 2008 domain.  I'm not sure if it matters, but we are running at a Windows Server 2008 domain functional level and a Windows Server 2003 forest functional level.<br/> <br/> Thanks!Thu, 22 Oct 2009 01:50:12 Z2009-11-30T04:49:24Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1cafb73a-8549-4833-bfdd-3ba08af45217http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1cafb73a-8549-4833-bfdd-3ba08af45217Stephen Swanhttp://social.technet.microsoft.com/Profile/en-US/?user=Stephen%20SwanBitlocker Recovery Keys Not Available Within Active DirectoryWe have configured Group Policy to require the automatically back up bitlocker recovery keys to Active Directory. I am confident that this is, in fact, occurring based on the event logs of the PCs, which are logging TPM-WMI event 513...<br/><br/><em>TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.<br/></em><br/>Odd thing is that when we search for the recovery key in Active Directory, we receive...<br/><br/><em>Your search for &quot;xxxxxxxx&quot; returned no results.<br/></em><br/>When we look at the computer object directly, we see...<br/><br/><em>No items in this view.<br/></em><br/>I know that this has worked properly in the past, because we have recovered bitlocker keys for hard drives previously. It seems to be a permisssions issue of some kind, however, we are using Domain/Enterprise/Schema admin to query AD for the recovery key.<br/><br/>This is occuring on Windows Server 2008, SP2.Fri, 20 Nov 2009 01:11:25 Z2009-11-30T03:34:52Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/c60f2418-ab77-4bd2-9d49-f6e97a03c5ddhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/c60f2418-ab77-4bd2-9d49-f6e97a03c5ddPeace Lohttp://social.technet.microsoft.com/Profile/en-US/?user=Peace%20LoDon't know how to fix replication issue!Dear all,<br/><br/>Current I have two DCs, one PDC (ssv01) and another BDC (ssv03). Both of them are Windows 2000 server SP4.<br/>I check and see have problem with BDC.<br/>- It is not able to share SYSVOL as long as NETLOGON<br/><br/>Event log showed as the following:<br/><br/>------------------------------------------<br/>Event Type: Warning<br/>Event Source: NtFrs<br/>Event Category: None<br/>Event ID: 13565<br/>Date:  11/18/2009<br/>Time:  9:19:51 AM<br/>User:  N/A<br/>Computer: SSV03<br/>Description:<br/>File Replication Service is initializing the system volume with data from another domain controller. Computer SSV03 cannot become a domain controller until this process is complete. The system volume will then be shared as SYSVOL. <br/> <br/>To check for the SYSVOL share, at the command prompt, type: <br/>net share <br/> <br/>When File Replication Service completes the initialization process, the SYSVOL share will appear. <br/> <br/>The initialization of the system volume can take some time. The time is dependent on the amount of data in the system volume, the availability of other domain controllers, and the replication interval between domain controllers. <br/>------------------------------------------<br/><br/>Event Type: Warning<br/>Event Source: NtFrs<br/>Event Category: None<br/>Event ID: 13508<br/>Date:  11/18/2009<br/>Time:  9:21:55 AM<br/>User:  N/A<br/>Computer: SSV03<br/>Description:<br/>The File Replication Service is having trouble enabling replication from <a>\\ssv01.mydomain.com.vn</a> to SSV03 for c:\winnt\sysvol\domain using the DNS name <a>\\ssv01.mydomain.com.vn</a>. FRS will keep retrying. <br/> Following are some of the reasons you would see this warning. <br/> <br/> [1] FRS can not correctly resolve the DNS name <a>\\ssv01.mydomain.com.vn</a> from this computer. <br/> [2] FRS is not running on <a>\\ssv01.mydomain.com.vn</a>. <br/> [3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers. <br/> <br/> This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established. <br/>Data:<br/>0000: d5 04 00 00               Õ...    <br/><br/><br/>------------------------------------------<br/><br/>I checked DNS, replication service are fine.<br/>Topology I use replicaiton monitor tool I also see that it is fine (and replicated successful between DCs).<br/>Could you please help me to fix the issue?<br/><br/>Thanks,<br/>-Binh.<br/><br/><br/> <br/>Wed, 18 Nov 2009 09:02:21 Z2009-11-30T01:49:05Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/a3ba17e3-a27d-4a5f-9bac-c0de8f5adb15http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/a3ba17e3-a27d-4a5f-9bac-c0de8f5adb15Reiner Siebenmorgenhttp://social.technet.microsoft.com/Profile/en-US/?user=Reiner%20SiebenmorgenProblems with Server 2008 AD snap-in & Terminal Server settings<p>Hi,<br/><br/>just installed a new w2k8-AD. Users have roaming TS-profiles.</p> <p>What i found out is: As soon as i use the AD mmc snapin from w2k8-server and change anything on the tabs remote control, terminal services profile, environment or sessions then automatically the &quot;starting program...&quot; option is selected in environment tab. But i can only see that it is selected i if i use the AD mmc snaping from w2k3-server.</p> <p>Regars</p> <p>Reiner</p>Sat, 28 Nov 2009 12:59:59 Z2009-11-29T21:22:49Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/54c2d7e8-3cb5-432f-ac6f-0b69c039ea67http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/54c2d7e8-3cb5-432f-ac6f-0b69c039ea67Lars Riisagerhttp://social.technet.microsoft.com/Profile/en-US/?user=Lars%20Riisagerproblem using dsadd<p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:x-small">Hi all</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">Have an annoying problem, using dsadd command-line tool, on 2008 R2. And the problem existist on 3 different test Domain Controllers and 1 production. Non of the servers have any thing with each other to do, regarding domain, trust, etc. Separate installations, just out of the box – no scripted installation or reuse of image.</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong style=""><span style="" lang=EN-US><span style="font-size:x-small">Problem</span></span></strong></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">C:\Users\administrator&gt;DSADD OU &quot;OU=Domain Member Servers,OU=IT-Services,DC=one, </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">DC=local&quot; -desc &quot;Containing any Member Servers, fully managed by Operations&quot;</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">dsadd failed:'any' is an unknown parameter.</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">type dsadd /? for help. </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small"><span style=""> </span></span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">As you can se, the word in the description “any” is causing the line to fail.</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong style=""><span style="" lang=EN-US><span style="font-size:x-small">This one works</span></span></strong></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">C:\Users\administrator&gt;DSADD OU &quot;OU=Admin Users,OU=Admin,OU=IT-Services,DC=one,</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">DC=local&quot; -desc &quot;Containing any Domain wide Admin Users”</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">dsadd succeeded:OU=Admin Users,OU=Admin,OU=IT-Services4,DC=one,DC=local</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">What the heck is the difference?</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">Removing the –desc “Containing any Member Servers, fully managed by Operations&quot; will succeeded the one with the problem. Any thinkable combination of setting quotes or removing them, doesn’t make any difference.</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">In a 100 lines copy/paste from a .txt file, 45 fails with similar descriptions, like “some word is an unknown parameter”</span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="" lang=EN-US><span style="font-size:x-small">Is this a bug?</span></span></p><hr class="sig">Regards Lars Sun, 29 Nov 2009 13:02:00 Z2009-11-29T15:58:25Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/2d4e2260-c440-4db8-879e-dff3024b8b59http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/2d4e2260-c440-4db8-879e-dff3024b8b59Deejeridoohttp://social.technet.microsoft.com/Profile/en-US/?user=DeejeridooRODC in DMZ - Member Server AuthenticationWe have deployed an RODC in the perimeter and are having issues with authentication on our member servers.  We have no communication between member servers in the perimeter and the RWDCs inside.  According to the <a title="Deploying RODCs in the Perimeter Network" href="http://technet.microsoft.com/en-us/library/dd728035(WS.10).aspx">Deploying RODCs in the Perimeter Network</a> guidance, we understand we'll have to manually update DNS records, but all other operations <em>should</em> work.  However, if we attempt to log onto a member server with a user who has not been cached on the member server previously, we receive a &quot;no logon servers available&quot; message, and associated NETLOGON errors in the event log (Event ID 5719).  We've attempted to follow the solution in <a href="http://blogs.technet.com/instan/archive/2009/03/24/troubleshooting-rodc-s-troubleshooting-rodc-location-in-the-dmz.aspx">Troubleshooting RODC location in the DMZ</a> with no success, though the details about configuring the DNS security are vague at best.  However, it doesn't look like the generic SRV records are being created for the RODC.  <br/><br/>I'm looking for some assistance on how to properly adjust the security on the DNS zone to allow the RODC to create its records, then validate this has happened?<br/><br/>That being said, I'm still not 100% sure this will solve my issue (although I do see on the firewall the member server attempting to connect to the internal RWDC).  The member server was joined to the domain whilst attached to the internal network, then moved to the perimeter.  Could this somehow weirdly be the issue? Would following the manual/scripted procedure in the guidance resolve these issues?<br/><br/>This is happening in a lab environment with pretty much OOTB settings and built following the step-by-step instructions on TechNet.  The machine and user accounts are in the PRP and I pre-populated the passwords, DNS was manually updated.Wed, 25 Nov 2009 20:17:42 Z2009-11-30T07:00:09Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1d18b9ad-0a2a-437b-94e0-edeebf156e9fhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1d18b9ad-0a2a-437b-94e0-edeebf156e9frealsurferhttp://social.technet.microsoft.com/Profile/en-US/?user=realsurferUnable to join machines to RODC in DMZ network<p class=MsoNormal style="margin:0in 0in 0pt"><em><span style="font-family:'Verdana','sans-serif';color:black;font-size:9.5pt">We rolled out a RODC to our Perimeter network.  There is a firewall between our perimeter network and our Corp Network.  We followed the steps per TechNet article:  <a href="http://technet.microsoft.com/en-us/library/dd728035(WS.10).aspx"><span style="color:#800080">http://technet.microsoft.com/en-us/library/dd728035(WS.10).aspx</span></a><br/><br/>The problem we are having is trying to add machines via the suggested script.  We are trying to add a Windows 2003 server to the network from the Perimeter.  We were getting &quot;Error: 87&quot; until we applied hotfix: &quot;WindowsServer2003-KB944043-v5-x86-ENU.exe&quot;.  <br/><br/>Now that the hotfix has been applied we are now getting &quot;Error: 1354&quot;  Still unable to add the server to the Domain from the Perimeter network.<br/><br/>Has anyone run into this issue?</span></em></p> <p class=MsoNormal style="margin:0in 0in 0pt"><em><span style="font-family:Calibri;font-size:small"> </span></em></p>Wed, 18 Nov 2009 22:24:33 Z2009-11-30T01:53:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/6ff833b6-d70e-4b4f-a3e3-3aa2bae5bc14http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/6ff833b6-d70e-4b4f-a3e3-3aa2bae5bc14Andyhudhttp://social.technet.microsoft.com/Profile/en-US/?user=AndyhudCant Raise Domain or Forest Function Level from 2008 to 2008 R2Hi all<br/> <br/> I have had 4 Windows 2008 Server Core Dc's running (2 sites, 2 dc's in each site) for a while now.<br/> <br/> We have slowly decommed each one one at a time (moving FSMO roles accordingly etc etc) and replaced with new Windows 2008 R2 Standard Edition Server Core.<br/> <br/> We finally replaced the last DC yesterday and removed one completely (from one site) temporarily. So now we have 2 x 2008 R2 DC's in 1 sites, and 1 x 2008 R2 DC in the other site. Everything is fine AD wise, FSMO roles all placed correctly, AD working just as it should, HOWEVER I cant seem to even get the option to raise either the Forest or Domain functional level from 2008 to 2008 R2 (we want the AD recycle bin!).<br/> <br/> We have prepped the schema a while ago with<br/> <br/> adprep /domainprep<br/> adprep /domainprep /gpprep<br/> adprep /forestprep<br/> <br/> and if I try and run these again it says &quot;Its already been done, so no need&quot; or something like that.<br/> <br/> But if I go into ADUC or ADDT and connect to any of the DC's it just says &quot;Forest level = Windows 2008&quot; or &quot;Domain Level = Windows 2008&quot; and &quot;This is the highest level you can have at the moment&quot; etc etc<br/> <br/> Any ideas?<br/> <br/> Cheers!<br/> <br/> Andy<br/>Tue, 03 Nov 2009 16:39:48 Z2009-11-28T23:20:38Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/55553427-b2df-4294-b184-bb2b263a2b4ehttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/55553427-b2df-4294-b184-bb2b263a2b4estuarty1874http://social.technet.microsoft.com/Profile/en-US/?user=stuarty1874Using DNSCMD to set Conditional Forwarders to Active Directory Intergrated (Windows 2003)<span style="font-family:Tms Rmn"><span style="font-family:Arial Narrow;font-size:small"><span style="font-family:Arial Narrow;font-size:small"> <p dir=ltr>Windows 2003 SP2 Domain.  Single Domain<br/><br/>Guys,  I'm using the following command to integrate our DNS conditional forwarders with AD.  The command works great and it does replicate the forwarders to all other DNS servers.<br/><br/><strong>dnscmd /zoneadd test3.ca /dsforwarder 11.11.11.11 12.12.12.12 /TimeOut 30</strong><br/><br/>What I'm finding though is that I cannot get the Time Out Value to replicate.<br/><br/>If I use the command it successfully sets the Time Out value on the DNS server on which I execute the command, but if I check another DNS server is sets the time value on the zone to the default 5. Is this by design?</p> <strong> <p> </p> <span style="font-family:Tms Rmn"><span style="font-family:Arial Narrow;font-size:small"><span style="font-family:Arial Narrow;font-size:small"> <p dir=ltr> </p> </span></span></span></strong></span><span style="font-family:Tms Rmn"><span style="font-family:Arial Narrow;font-size:small"> <p dir=ltr> </p> </span></span></span> <p dir=ltr> </p> </span><strong><span style="font-family:Helv;font-size:x-small"><strong><span style="font-family:Helv;font-size:x-small"> </span></strong></span> <p> </p> <br/></strong>Wed, 21 Oct 2009 17:14:57 Z2009-11-28T23:10:39Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b0842c59-1879-49da-b5dd-322b98e62961http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/b0842c59-1879-49da-b5dd-322b98e62961VicAbhhttp://social.technet.microsoft.com/Profile/en-US/?user=VicAbhActive Directory RestorePlease can somebody help me. Am working on a project on how i would recover my active directory at the event of failure. I setup two DC on a vittual environment, create a couple of OUs, I then backup the second DC and then thrashed the second DC after the backup, i built the server again and join it to the domain again, if am joining domain, do i need to change the computer name? I rebooted the server and press F8 for AD recovery mode and i restored the system state i backed on the second DC, and after the restore ,i then rebooted the server. The issue am now having is that the restored server is not a DC and when i open the DC OU, i cannot find the name of my rebuilt server and the do not contain the Netlogon and SYSVOL folder.<br/>Please can somebody help me with the details step-by-step process instructions on how to achive this aim. What i wanted is to have my recovered server as a DC after the system state restore. I have looked up the Microsoft web site, but there was nothing on what i wanted to do.<br/><br/>Regards<br/>VictorFri, 13 Nov 2009 16:51:31 Z2009-11-28T04:24:45Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/ac76fce6-c82c-4e07-b4bc-e486543eb0c8http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/ac76fce6-c82c-4e07-b4bc-e486543eb0c8Venmani Khttp://social.technet.microsoft.com/Profile/en-US/?user=Venmani%20KWhy we need additional domain controller?In what situation we need additional domain controller?<br/>Fri, 27 Nov 2009 01:35:38 Z2009-11-28T00:16:50Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/0a2bccec-a8c0-430c-9284-6a8c4f69dc69http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/0a2bccec-a8c0-430c-9284-6a8c4f69dc69Bryce.Lawsonhttp://social.technet.microsoft.com/Profile/en-US/?user=Bryce.Lawson"Display information about previous logons during user logon"<p>I enabled “Display information about previous logons during user logon” in Computer Configuration\Administrative Templates\Windows Components\Windows Logon Options thinking that it would work on Server 08, setup for 03+ DC's, and I was wrong...</p> <p align=left> </p> <p align=left>Now, whenever I try to logon to the server, I get &quot;Security policies on this computer are set to display information about the last interactive logon. Windows could not retrieve this information. Please contact your network administrator for assistance.&quot;</p> <p align=left> </p> <p align=left>Now, I since I have additional Domain Admins, I attempted to logon to a workstation (Vista) as a Domain Admin... Surprise, can't login there either. It's telling me my password is incorrect. I'm pretty sure I got it right, and have locked myself out a few times by checking my old passes...</p> <p align=left> </p> <p align=left>Thankfully, this Domain isn't in use by any production clients, however I really want to save the work that I already have on this PDC (btw, it's not just a PDC, it has additional roles installed, as it isn't a production machine).</p> <p align=left> </p> <p align=left>Is there any way I can save this machine?</p>Wed, 27 Feb 2008 02:31:17 Z2009-11-27T22:13:31Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/e21a3c1c-0873-46ac-b580-42d38db11a41http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/e21a3c1c-0873-46ac-b580-42d38db11a41Delukahttp://social.technet.microsoft.com/Profile/en-US/?user=DelukaCan't disable users from adding workstations to domainFollowing some howto's i'm trying do disable users from adding workstations to the domain. (windows server 2k8) <div>in my default domain policy i have changed the setting for &quot;add workstations to domain&quot; to &quot;dezuttere\Administrator&quot;.</div> <div>Also set the deligation of the computers OU to the &quot;&quot;dezuttere\Administrator&quot;.</div> <div>But normal user still can add workstations to the domain.</div> <div>What i'm i missing here.</div>Fri, 27 Nov 2009 15:06:21 Z2009-11-29T12:26:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/ce57b9ba-cd46-4793-95bd-c2adf989e29ahttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/ce57b9ba-cd46-4793-95bd-c2adf989e29aArunkumar GMhttp://social.technet.microsoft.com/Profile/en-US/?user=Arunkumar%20GMHow to generate a PKCS7 or PKCS10 file format from the given ssl certificate?Hi Forum Members,<br/><br/>I need to know the process by which the generation of PKCS 7 or PKCS 10 file for the issued SSL certificate can be achieved. I am in the process of renewal of certificates issued by standalone 2003 CA server.<br/><br/>Another issue is please see this post <a href="http://social.technet.microsoft.com/Forums/en/winserversecurity/thread/768f3352-8830-4d41-846c-bdf2727da080">http://social.technet.microsoft.com/Forums/en/winserversecurity/thread/768f3352-8830-4d41-846c-bdf2727da080</a><br/><br/>I am facing some errors while trying the renewal process of ssl certificate issued by standalone CA .<br/>I invite the valuable response from this forum<br/>Thanks <br/>Arunkumar.GFri, 27 Nov 2009 12:58:42 Z2009-11-27T12:58:42Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/ab42f27a-2f6a-4368-856d-81bc46e56d2ehttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/ab42f27a-2f6a-4368-856d-81bc46e56d2eRomain romshttp://social.technet.microsoft.com/Profile/en-US/?user=Romain%20romsIncrease a fonctionality level Hello,<br/> <br/> I have two Domains in my forest, with 6 DCs in each domains<br/> <br/> the root domain, all the servers are in Windows 2003 but in a child domain there is Dcs in Windows 2000.<br/> <br/> here is my qsuestion :<br/> <br/> Can i increase the fonctionnality level for the root forest domain into &quot;Windows server 2003&quot;?<br/> <br/> Best Regards<br/> RomainFri, 27 Nov 2009 11:07:53 Z2009-11-27T22:21:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/9355f8d1-2cc1-4506-95a4-47417ef9431ehttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/9355f8d1-2cc1-4506-95a4-47417ef9431ezachavmhttp://social.technet.microsoft.com/Profile/en-US/?user=zachavmAdding Central Server to combine two domains into one forest.note:  All on windows server 2003<br/><br/>My organization currently has two small (less than 50 clients) domains that are currently on seperate forests.  We are hoping to implement a central server that would provide backup to both domain controllers, centralize some shares that would be propogated to both domain controllers, and share users accross these two domains.  I'm currently trying to determin the structure that we should use for this enviroment.  Also, keep in mind either domain could go offline at any time and we want to maintain syncronization which is why we aren't just creating a trust between the forests. <br/><br/>Anyway, I'm having trouble figuring out exactly what shape this enviroment should take.  We want to keep two seperate domains.  I'm considering creating a domain on the central server that would be a parent to our two existing domains.  However, I don't know if it would then provide us any backup for the child domains.  Also, I don't know if one server can provide backup for both domains.  My other consideration would be to just have two trees that are part of the same forest.  However, what then would be my role of the central server?  I don't think it can be a backup to both domain controllers.  <br/><br/>As you can see, I'm still learning all this and my understanding is limited.  I hope all of this made sense.Wed, 25 Nov 2009 18:56:04 Z2009-11-30T09:53:13Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/5eb7f9b2-4154-43c3-ad4a-b4f584ff6d63http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/5eb7f9b2-4154-43c3-ad4a-b4f584ff6d63Mphandihttp://social.technet.microsoft.com/Profile/en-US/?user=MphandiEvent IDs: 1030 and 1058<p>Hi guys<br/><br/>i have a big problem that i have been fighting with for quite some time and have found no solution:<br/><br/>I have a domain &quot;<strong>catoca.com</strong>&quot; with 2 sites:<br/><br/><em><span style="text-decoration:underline">1-Luanda (10.9.48.x - 255.255.255.0 network)</span></em><br/>*This site have 2 domain controllers:<br/>1-LDADC001 = DC, GC, DNS, DHCP, also holds FSMO<br/>2-LDADC002 = DC, GC, DNS<br/><br/><em><span style="text-decoration:underline">2-SAURIMO (10.9.32.x - 255.255.252.0 network)</span></em><br/>*This site has one domain controller which is the problematic one<br/>1-SAUDC001 = DC, GC, DNS, DHCP<br/><br/>This SAUDC001 has been constantly flooded with these 2 events:<br/><br/>Event Type: Error<br/>Event Source: Userenv<br/>Event Category: None<br/>Event ID: 1030<br/>Date:  26-11-2009<br/>Time:  20:46:43<br/>User:  NT AUTHORITY\SYSTEM<br/>Computer: SAUDC001<br/>Description:<br/>Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.</p> <p>Event Type: Error<br/>Event Source: Userenv<br/>Event Category: None<br/>Event ID: 1058<br/>Date:  26-11-2009<br/>Time:  20:46:43<br/>User:  NT AUTHORITY\SYSTEM<br/>Computer: SAUDC001<br/>Description:<br/>Windows cannot access the file gpt.ini for GPO cn={862C7901-E768-4E70-992B-E2CE4DA4219C},cn=policies,cn=system,DC=catoca,DC=com. The file must be present at the location &lt;<a>\\catoca.com\SysVol\catoca.com\Policies\{862C7901-E768-4E70-992B-E2CE4DA4219C}\gpt.ini</a>&gt;. (The network location cannot be reached. For information about network troubleshooting, see Windows Help. ). Group Policy processing aborted.<br/><br/>These are my current problems at SAURIMO SITE (SAUDC001)<br/><br/>1- If i try to acess any of the domain shares (sysvol and netlogon) i receive the error:<br/>*\\saudc001\sysvol is not accessible. You might not have permission to use this network resource. Contact the Adminstrator of this server to find out if you have access permissions.<br/><br/>2-If i try to connect to the domain <a>\\catoca.com</a>, i receive the error:<br/>* the network location cannot be reached.....<br/><br/>3-If i try to join any computer to the domain on this site, i receive the error:<br/>*windows cannot find the network path. Verify that the netiwork path is correct and the destination computer is not busy or turned off.......<br/><br/>4- I tried to dcpromo another Windows 2003 server machine in hope that i could replace the problematic one but i receive this error:<br/>*The wizard cannot gain access to the list of domains in the forest. The error is: The network address is invalid<br/><br/><br/>Right now i dont know what else to do and i am very preocupied because this is the only DC on this site and i have a lot of users authenticating on it<br/><br/>PLEASE NEED HELP URGENTLYYYYYYYYY<br/><br/>REGARDS</p>Thu, 26 Nov 2009 20:37:47 Z2009-11-27T10:09:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/e117a732-0b8f-4a4e-9a15-19ea0f8128e8http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/e117a732-0b8f-4a4e-9a15-19ea0f8128e8S.Vijay Kumarhttp://social.technet.microsoft.com/Profile/en-US/?user=S.Vijay%20KumarActive Directory Federation Services to integrate IBM WEbsphere appsHi,<br/><br/>I am going through ADFS and could see how to authenticate between two windows Forests and establish trust beteen them. I could also see integration to IIS6 based webserver. <br/>I have different scenario, I am looking at my Java apps sitting on IBM websphere with LDAP authenticating users from AD using SSO token from ADFS server. Can any one guide me through this and help me giving a solution.<br/><br/>Fri, 27 Nov 2009 10:00:58 Z2009-11-27T10:00:59Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/5c84974c-f9f1-4497-867f-05ac20657e17http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/5c84974c-f9f1-4497-867f-05ac20657e17madalhttp://social.technet.microsoft.com/Profile/en-US/?user=madalExporting GPOHello all,<br/> <br/> Is there a way to export all GPO from windows 2003 AD domain to windows 2008 R2 different domain ? If there are please do point some KB or link.<br/> <br/> MThu, 26 Nov 2009 10:50:28 Z2009-11-27T08:08:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1b8e674f-1086-43b9-abd2-e6707a65749bhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/1b8e674f-1086-43b9-abd2-e6707a65749bHelder Nascimentohttp://social.technet.microsoft.com/Profile/en-US/?user=Helder%20NascimentoRENDOM - Error during step 7 (rendom.exe /prepare)Hi All,<br/> <br/> I'm trying to do a domain rename, but I'm getting errors during the &quot;rendom.exe /prepare&quot; step.<br/> <br/> The forest has a root domain, with 7 child domains. I'm just trying to change the DNS name of the forest, from &quot;abcde&quot; to &quot;abcde.local&quot; (yes, right now it's a SLD). This, of course, affects all the child domains, so they are all being renamed to include the new &quot;.local&quot; portion.<br/> <br/> I only have one DC in each one of the 8 domains (1 root + 7 child domains), and only one DNS server for all the forest (which is the DC for the root domain).<br/> <br/> Yes, I know that there should be a couple more DCs and DNS, but I'm relatively new to this structure and didn't had the time to correct some things :)<br/> <br/> The error that I'm getting on the &quot;rendom.exe /prepare&quot; is this, for all the DCs, except the root DC.<br/> <br/> <strong>Failed to find SPN LDAP/dc1.abcde/abcde.local on CN=DC1,OU=Domain Controllers,DC=abcde</strong> <br/> <br/> This shows up as error 30169 on the control station, if I remember correctly.<br/> <br/> This is happening on all the 7 child DCs, the root DC is the only one that gets to the &quot;prepared&quot; state, all the others give this error (all refering the root DC), and all refer the root DC.<br/> <br/> I've checked the DNS records and they seem ok (at least acording to the &quot;Step-by-step guide to implementing domain rename&quot;), and I've checked the actual servicePrincipalName for the DC1 server, and the SPN mentioned is there (LDAP/dc1.abcde/abcde.local), along with a ton of others :)<br/> <br/> I'm using an Enterprise Admin account.<br/> <br/> Netdiag and DCDiag run fine on the 8 DCs. No errors on event log.<br/> <br/> I've rerung the &quot;rendom.exe /prepare&quot; command a couple of times, as sugested on the white papers, but to no avail, the error keeps showing up. <br/> <br/> Can anyone help me out with this? I suspect that I might be missing a DNS entry somewere, although I seem to have all the records mentioned on the papers. I might have some other structure problem that isn't quite visible during day to day operations, but I'm not sure what to check.<br/> <br/> I've searched this problem on the net, but couldn't find anything specific to this problem.<br/> <br/> If any of you could give me a hand, you will get my eternal thanks ;)<br/> <br/> Thanks in advance!<br/> <br/> Cheers,<br/> <br/> HelderThu, 19 Nov 2009 10:48:32 Z2009-11-27T03:29:08Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/721e8ac6-3ed7-4124-aee4-c7ab0e4538c6http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/721e8ac6-3ed7-4124-aee4-c7ab0e4538c6Guy Melamedhttp://social.technet.microsoft.com/Profile/en-US/?user=Guy%20MelamedUnable to create files on Windows 2008 R2 Netlogon shareHi,<br/><br/>I have installed 2 new Windows 2008 R2 Domain Controllers in a new forest.<br/>In all the tests I used the same account, which is member of the domain admins group. <br/>I cannot create files or directories in the netlogon share (<a>\\dc1\netlogon</a>) , if I am trying to do this from the same domain controller (dc1). The error I get is access denied, and I have an option to try again or cancel. Trying again does not help.<br/>I tried to access the folder C:\Windows\Sysvol\Sysvol\domain.com\Scripts using explorer, and I can create only folders. The option to create other kind of files does not exist in the menu.<br/><br/>I tried using CMD, to create files in the local folder C:\Windows\Sysvol\Sysvol\domain.com\Scripts and also got an access denied error.<br/><br/>When I connect to the Netlogon share from another computer (lets say dc2, or another member server), I can create files and folders.<br/><br/>I know this used to work without a problem on Windows 2000, Windows 2003 and Windows 2008.<br/><br/>Any one knows why I have this problem on Windows 2008 R2?<br/><br/>Thanks,<br/><br/>Guy<br/><br/><br/>Thu, 26 Nov 2009 09:41:36 Z2009-11-27T03:22:32Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/948b5d96-654d-48e4-93ae-245942491a9ehttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/948b5d96-654d-48e4-93ae-245942491a9eIHateDominohttp://social.technet.microsoft.com/Profile/en-US/?user=IHateDominoExternal Trusts<span><span style="color:#b75f11">I have several forests with the same domain componants in the last two dc of the name space, how will this effect Trusts?</span></span> I need to create trusts between several domains that share the name space, after setting them up in a test environment, I do not feel they will remain stable. Is the trust based on Netbios naming of the domain only? If so then the SID should keep everything seperate.Wed, 25 Nov 2009 12:46:40 Z2009-11-30T03:49:39Zhttp://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/d6252ea1-401b-4d0f-965c-65fe89c52fd6http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/d6252ea1-401b-4d0f-965c-65fe89c52fd6JanisAlushttp://social.technet.microsoft.com/Profile/en-US/?user=JanisAlusNew domain with old domain name (users account problem)Hallo,<br/><br/>I had win2000 srv (DC) domain and now it is gone, fortunatelly the directories are saved.<br/>I installed a new domain controller (using the same name as old for the DC and domain) on new machine with win2003 srv R2.<br/><br/>Is there any possibility to connect the old domain computers and users to the new one without creating new user profiles on the user computers.<br/>Is there any possibility to extract user account information from the old domain directories and import into the new.<br/><br/>Thanx in advance.<br/>Thu, 26 Nov 2009 21:41:11 Z2009-11-26T22:28:22Z