Sheridan Posted May 17, 2020 Posted May 17, 2020 I've added a new 2019 server to our domain as a DC - currently its got 2012/2016 DCs in 2012 Domain level, and my intention is to migrate the 2012's to 2019 All is working as expected, no dcdiag errors, SYSVOL is populated etc - but when I run the GPMC infrastructure test it shows replication in progress (ACLs) for the new server - for every single GPO! I've checked everything I can but this error state will not go - repadmin shows no errors and replication is up to date. Add a new policy and it replicates to the new server! So I'm about the ditch using server 2019 for now, as I'm not convinced its working correctly, and MS offer no information for this other than the usual checks I've already done - which all show up OK! Has anyone else seen this behaviour with 2019?
dblight Posted May 17, 2020 Posted May 17, 2020 Do you have a passive file screen on the system disk of the 2019 DC? There is a bug updating GPO’s on a 2019 DC if you have a passive file screen using FSRM. May not be the case here but worth a check. Other than that issue we have had no issues with 2019.
Sheridan Posted May 17, 2020 Author Posted May 17, 2020 No, no file screens on the new server - I’ve barely set it up yet I found an old thread saying that’s the acls sometimes have duplicate entries for the Domain Admins group, and when I checked it did seem to have 2. This was relating to 2008 server but I set this domain up back in the Server 2000 days! When I deleted the acl and recreated it that one gpo then disappeared from the list. So I’m not sure why but it seems my gpos may have odd entries in the permissions list, and I’ll have to find a way to check all 190 of them!
computer_expert Posted May 18, 2020 Posted May 18, 2020 (edited) Are you using DFS or FRS SYSVOL replication? If FRS, you'll need to upgrade to DFS as the FRS stuff has been removed starting with server 2016 rs3: https://techcommunity.microsoft.com/t5/storage-at-microsoft/streamlined-migration-of-frs-to-dfsr-sysvol/ba-p/425405 Edited May 18, 2020 by computer_expert
Sheridan Posted May 18, 2020 Author Posted May 18, 2020 Its DFSR - and its seems like it is the duplicate Domain Admins issue. I created a batch file to remove and add the domain admins group from every single policy folder. Running this on all the DCs and letting replication take place and its all showing up ok! Running it on one DC didn't work, the 'hidden' entry mustn't replicate properly
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now