Jump to content

Recommended Posts

Posted (edited)
Bit worried about this one now, on GPMC I noticed that from the baseline controller it show all the other DCs are Replicating with ACLs errors in the Sysvol columnThis is a mixture of 2012 and 2016 DCs, in a 2012 forest level domain. Running repadmin on each DC shows no errors, and no fails. DCDiag on each shows DFRS errors - but only relating to me restarting the service on each DC to see if that helped. The thing is, I've checked a newly created GPO and its replicated, with the correct permissions across all of the DCs. Each DC in the list also seems to have a slightly different list of GPOs with mismatched ACLs but they're all ones I've edited in the last month or so. Does this mean I've got a bigger problem going on? I can't see any actual acl discrepancies which is a bit odd. Its not looking good - if I create a new GPO - it replicates but shows the ACL error for 4/5 of the other DCs - something is shafted on my DCs! Edited by Sheridan
Posted
Ok this is starting to panic me now - changing the security filtering on a policy shows that the ACLs replication isn't working at all - it replicated from a 2012 to a 2016, and a 2016 to a 2016, but most of the replication is stuck with the ACLs warning I've checked all the diagnostics and no errors, I've run the DFS Management diagnostics and it all comes up clean - but checking the GPO folders on each DC shows permissions are not being changed, even after waiting an hour So if replication is working (apparently) but ACLs aren't replicating, am I screwed and looking at restoring/rebuilding the domain and/or GPOs?
  • 3 months later...
Posted
Our 2016 servers are up to date, and only 1 of the 2012's is stuck on update (but it is the Sept one) I think I'll demote the dodgy 2012 server and see if it helps

Sheridan. Did you ever git this to resolve? I have the same problem. Mixed 2008R2 DCs with 2016 DCs.

Posted
Sheridan. Did you ever git this to resolve? I have the same problem. Mixed 2008R2 DCs with 2016 DCs.

 

I didn’t find out why, but I got rid of the errors by finding out which gpos it was objecting to and manually changing the folder permissions in sysvol to match those of the working gpos. After doing that all seems to be ok. I guess something went wrong in the replication at some point but I couldn’t find any other clues!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...