G
Guest
I currently have a Win2K AD in native mode with 4 local DC and 2 at another
site. I have one server in the site with 4 DC that cannot replicate to the
other three and vice-versa. The error I get is that Access is Denied. I
looked at the article regarding this on Microsoft's site but there are a
couple of steps I am not sure how to check on and I have done the steps noted
and it does not resolve the issue. Can someone direct me to how to resolve
this? I even tried to demote the server with the intention to promote it and
it would not let me demote it because of the same error.
This is the article I have been working from;
http://www.microsoft.com/technet/pr...irectory/maintain/opsguide/part1/adogd12.mspx
The steps in the process that Microsoft outlines that I need help with are
as follows;
"Confirm that the Enterprise Domain Controllers group contains the "access
this computer from network" right."
There is a Domain Controllers group in AD but not an Enterprise DC group and
I cannot find that right to check on in the DC group anywhere.
The other piece that I canont find is;
Synchronize the domain naming context of the replication partner with the
PDC emulator.
How is this done? I verified that the Kerberos entries in the DNS on both
the PDC and the server in question are the same but is there more than this?
Also, this server is holding the Global Catalog role though there is another
in the domain that also has the role.
Any suggestions would be appreciated.
Thanks,
site. I have one server in the site with 4 DC that cannot replicate to the
other three and vice-versa. The error I get is that Access is Denied. I
looked at the article regarding this on Microsoft's site but there are a
couple of steps I am not sure how to check on and I have done the steps noted
and it does not resolve the issue. Can someone direct me to how to resolve
this? I even tried to demote the server with the intention to promote it and
it would not let me demote it because of the same error.
This is the article I have been working from;
http://www.microsoft.com/technet/pr...irectory/maintain/opsguide/part1/adogd12.mspx
The steps in the process that Microsoft outlines that I need help with are
as follows;
"Confirm that the Enterprise Domain Controllers group contains the "access
this computer from network" right."
There is a Domain Controllers group in AD but not an Enterprise DC group and
I cannot find that right to check on in the DC group anywhere.
The other piece that I canont find is;
Synchronize the domain naming context of the replication partner with the
PDC emulator.
How is this done? I verified that the Kerberos entries in the DNS on both
the PDC and the server in question are the same but is there more than this?
Also, this server is holding the Global Catalog role though there is another
in the domain that also has the role.
Any suggestions would be appreciated.
Thanks,