none
GPO somehow not applied to all users after ransomeware attack.

    Question

  • Hi Experts,

    one of my client having this issue after ransomware attack, we could not tell whether the AD still in healthy status , but when run dcdiag, we get this

        Starting test: FrsEvent

             There are warning or error events within the last 24 hours after the SYSVOL has been

             shared.  Failing SYSVOL replication problems may cause Group Policy problems.
             ......................... MS-SVR-02 passed test FrsEvent

          Starting test: NCSecDesc

             Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

                Replicating Directory Changes In Filtered Set
             access rights for the naming context:

             DC=ForestDnsZones,DC=MaestroSwiss,DC=local
             Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have

                Replicating Directory Changes In Filtered Set
             access rights for the naming context:

             DC=DomainDnsZones,DC=MaestroSwiss,DC=local
             ......................... MS-SVR-02 failed test NCSecDesc

    failing sysvol replicating seems like is the root cause, but im not sure.if yes, how am i going to fix it ?

    Thanks

    Alfred

    Wednesday, April 12, 2017 2:23 AM

Answers

All replies