Reecekellyy
Members-
Posts
27 -
Joined
-
Last visited
Reputation
12 GoodAbout Reecekellyy

-
So after leaving it over the weekend and checking the DC's, everything seems okay. When I run repadmin /showreps & repadmin /showsummary, they look normal. I can now consistently complete a gpupdate /force on the laptops after a few minutes of the laptop being logged into. However, I think part of this issue is related to the wireless network cards in the laptops. Now, when I boot up a laptop I am still seeing the same issue of the desktop icons not loading, this is because the icon files are stored in sysvol, so I know that policies haven't applied properly and when I run a gpupdate /force immediately after the laptop boots, I get the original error saying that policies can't be applied. So I go into file explorer and try to access \\domain\sysvol and I cannot access it, however, if I wait 3-5 minutes, I can access it. It seems like it just takes a while to access it, which is no good because any computer policies aren't getting applied at the point of booting up the laptop. I've connected the laptop via ethernet and I have no problem accessing sysvol immediately, so the wireless card is definitely the issue here. The laptops with the issue are brand new Lenovo V15 with wireless card of Intel Wireless-AC 9560. I've updated driver, reinstalled device, ensured fast boot is disabled, always wait for network GPO is enabled, nothing has fixed the issue. Anyone have any ideas?
-
Yeah the errors have gone when I run those commands. Source DSA largest delta fails/total %% error DC01 09m:51s 0 / 5 0 DC02 09m:51s 0 / 5 0 Destination DSA largest delta fails/total %% error DC01 09m:51s 0 / 5 0 DC02 09m:51s 0 / 5 0 ---------------------------------------------------------------------------------------------------------------------------------------------------------- DC01: DC01 DSA Options: IS_GC Site Options: (none) DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e DSA invocationID: 146558b1-3a6b-4603-a9b0-a7ee7fd46e1e ==== INBOUND NEIGHBORS ====================================== DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 15:41:24 was successful. CN=Configuration,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 15:31:59 was successful. CN=Schema,CN=Configuration,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 15:31:59 was successful. DC=DomainDnsZones,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 15:41:47 was successful. DC=ForestDnsZones,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 15:41:50 was successful. ---------------------------------------------------------------------------------------------------------------------------------------------------------- DC02: DC02 DSA Options: IS_GC Site Options: (none) DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c DSA invocationID: 0ee61e33-007b-47f7-a8e2-f57c9dcaf42e ==== INBOUND NEIGHBORS ====================================== DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 15:45:25 was successful. CN=Configuration,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 15:31:59 was successful. CN=Schema,CN=Configuration,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 15:31:59 was successful. DC=DomainDnsZones,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 15:41:32 was successful. DC=ForestDnsZones,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 15:41:35 was successful. ---------------------------------------------------------------------------- I'll wait until tomorrow and see if there are any issues on the laptops.
-
Yeah I ran all the code on both DC's. Both DC's running Server 2019 version 1809. I will try running dcdiag /c /v on both. When I power on one of the laptops, I run echo %logonserver% and it always shows DC01. Immediately after, I run gpresult /r and it says policies are being applied from DC02. I restarted the laptop, did eahc %logonserver% which showed DC01 again, I then checked gpresult /r and it says policies are being applied from DC01. So it seems that no matter which DC is applying policies, the problem persists. I did see some stuff online about lingering objects. So I used this command on DC01: repadmin /removelingeringobjects DC02 929103cd-f24f-4de7-b329-5f09a2b9473e DC=DomainDnsZones,DC=**,DC=local RemoveLingeringObjects successful on DC02 and when I run repadmin /showrepl again, it no longer says there are 18k+ errors. I don't know if that has helped anything. I've now ran repadmin /showobjmeta dc01 "<GUID=d111021f-068c-4d2c-bbce-c5d32fa9639c>" on both DC's, here are the outputs: DC01: repadmin /showobjmeta DC01 "<GUID=d111021f-068c-4d2c-bbce-c5d32fa9639c>" 14 entries. Loc.USN Originating DSA Org.USN Org.Time/Date Ver Attribute ======= =============== ========= ============= === ========= 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 objectClass 10938 d062f913-7c58-4bab-a2e9-e9116cc5b730 10938 2016-08-05 10:00:51 1 cn 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 instanceType 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 whenCreated 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 dMDLocation 36856980 DC02 36286623 2025-01-30 19:01:55 4 invocationId 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 showInAdvancedViewOnly 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 nTSecurityDescriptor 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 name 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 options 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 systemFlags 36856980 DC02 36286623 2025-01-30 19:01:55 3 retiredReplDSASignatures 10938 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 objectCategory 7919603 23913323-d1cd-4a58-bc46-3eaa3e35be64 8228940 2019-01-02 10:23:33 2 msDS-Behavior-Version 15 entries. Type Attribute Last Mod Time Originating DSA Loc.USN Org.USN Ver ======= ============ ============= ================= ======= ======= === Distinguished Name ============================= PRESENT hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10952 12704064 1 DC=**,DC=local PRESENT hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10954 12704063 1 CN=Configuration,DC=**,DC=local PRESENT hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10953 12704065 1 CN=Schema,CN=Configuration,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10958 14644 1 DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10961 14607 1 CN=Configuration,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:46:15 23913323-d1cd-4a58-bc46-3eaa3e35be64 10959 16519 1 CN=Schema,CN=Configuration,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10960 15071 1 DC=DomainDnsZones,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10957 14686 1 DC=ForestDnsZones,DC=**,DC=local PRESENT msDS-HasDomainNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10962 12704069 1 DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10964 14643 3 DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10967 14606 3 CN=Configuration,DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10965 12704068 1 CN=Schema,CN=Configuration,DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10966 15070 3 DC=DomainDnsZones,DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 10963 14685 3 DC=ForestDnsZones,DC=**,DC=local PRESENT msDS-EnabledFeature 2018-12-05 09:07:03 23913323-d1cd-4a58-bc46-3eaa3e35be64 7648835 7894896 1 CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=**,DC=local ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- DC02: repadmin /showobjmeta DC02 "<GUID=d111021f-068c-4d2c-bbce-c5d32fa9639c>" 14 entries. Loc.USN Originating DSA Org.USN Org.Time/Date Ver Attribute ======= =============== ========= ============= === ========= 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 objectClass 10942 23913323-d1cd-4a58-bc46-3eaa3e35be64 10942 2016-08-03 14:40:18 1 cn 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 instanceType 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 whenCreated 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 dMDLocation 36286623 DC02 36286623 2025-01-30 19:01:55 4 invocationId 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 showInAdvancedViewOnly 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 nTSecurityDescriptor 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 name 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 options 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 systemFlags 36286623 DC02 36286623 2025-01-30 19:01:55 3 retiredReplDSASignatures 10942 9262ab60-6755-4db8-8f93-92d42c0780b0 12704070 2016-08-03 14:39:39 1 objectCategory 8228940 23913323-d1cd-4a58-bc46-3eaa3e35be64 8228940 2019-01-02 10:23:33 2 msDS-Behavior-Version 15 entries. Type Attribute Last Mod Time Originating DSA Loc.USN Org.USN Ver ======= ============ ============= ================= ======= ======= === Distinguished Name ============================= PRESENT hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10947 12704064 1 DC=**,DC=local PRESENT hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10949 12704063 1 CN=Configuration,DC=**,DC=local PRESENT hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10948 12704065 1 CN=Schema,CN=Configuration,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 14644 14644 1 DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 14607 14607 1 CN=Configuration,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:46:15 23913323-d1cd-4a58-bc46-3eaa3e35be64 16519 16519 1 CN=Schema,CN=Configuration,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 15071 15071 1 DC=DomainDnsZones,DC=**,DC=local PRESENT msDS-HasInstantiatedNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 14686 14686 1 DC=ForestDnsZones,DC=**,DC=local PRESENT msDS-HasDomainNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10950 12704069 1 DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 14643 14643 3 DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 14606 14606 3 CN=Configuration,DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:39:39 9262ab60-6755-4db8-8f93-92d42c0780b0 10952 12704068 1 CN=Schema,CN=Configuration,DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 15070 15070 3 DC=DomainDnsZones,DC=**,DC=local PRESENT msDS-hasMasterNCs 2016-08-03 14:40:27 23913323-d1cd-4a58-bc46-3eaa3e35be64 14685 14685 3 DC=ForestDnsZones,DC=**,DC=local PRESENT msDS-EnabledFeature 2018-12-05 09:07:03 23913323-d1cd-4a58-bc46-3eaa3e35be64 7894896 7894896 1 CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=**,DC=local
-
Neither DC has the key DSA Not Writable. I've ran repadmin /showreps on both: DC01 DSA Options: IS_GC Site Options: (none) DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e DSA invocationID: 146558b1-3a6b-4603-a9b0-a7ee7fd46e1e ==== INBOUND NEIGHBORS ====================================== DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 13:45:28 was successful. CN=Configuration,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 12:55:55 was successful. CN=Schema,CN=Configuration,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 12:55:55 was successful. DC=DomainDnsZones,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 13:44:55 failed, result 8606 (0x219e): Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected. 18791 consecutive failure(s). Last success @ 2025-03-20 09:18:00. DC=ForestDnsZones,DC=**,DC=local DC02 via RPC DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c Last attempt @ 2025-05-15 13:41:26 was successful. Source: DC02 ******* 18777 CONSECUTIVE FAILURES since 2025-03-20 09:18:00 Last error: 8606 (0x219e): Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected. --------------------------------------------------------------------------------------------------------------------------------------------------------------------- DC02 DSA Options: IS_GC Site Options: (none) DSA object GUID: d111021f-068c-4d2c-bbce-c5d32fa9639c DSA invocationID: 0ee61e33-007b-47f7-a8e2-f57c9dcaf42e ==== INBOUND NEIGHBORS ====================================== DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 13:45:56 was successful. CN=Configuration,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 13:45:51 was successful. CN=Schema,CN=Configuration,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 13:45:51 was successful. DC=DomainDnsZones,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 13:45:53 was successful. DC=ForestDnsZones,DC=**,DC=local DC01 via RPC DSA object GUID: 929103cd-f24f-4de7-b329-5f09a2b9473e Last attempt @ 2025-05-15 13:45:51 was successful. --------------------------------------------------------------------------------------------------------------------------------------------------------------------- 18777 consecutive failures since the migration 56 days ago hmm
-
Yeah apologies for not mentioning the migration, it wasn't until we discovered the 55 day thing did that come to mind. I do appreciate you taking the time and helping me with this, I've learnt a lot. I've ran that command on both DC's and got this: DC01 DC01 @ USN 38198459 @ Time 2025-05-15 12:32:50 DC02 @ USN 37740814 @ Time 2025-05-15 12:31:54 DC02 DC02 @ USN 37740830 @ Time 2025-05-15 12:32:42 DC01 @ USN 38198459 @ Time 2025-05-15 12:32:42
-
Thanks for this info. I do really want to go full cloud, I'll do my research and find out the best way to proceed!
-
We've recently consolidated our servers and got all the main virtual machines onto 1 host. DC02 was migrated to the new host 103 days ago and DC01 was migrated (drumroll please...) 55 days ago. So clearly this is part of the issue. I am fairly inexperienced with servers and networks in general so we hire a consultant to do all the server heavy lifting. He dealt with getting things moved over to the new host. I did raise this problem with him but he couldn't work out what the issue was. We're planning on rebuilding the entire domain during the summer holidays, which will be great for me to learn what goes into it. I inherited this domain which was created 15+ yrs ago so I'm trying to get my head around all the intricacies. I guess I was just hoping I'd get this problem resolved before we rebuild the domain since we're due to get a load more new devices before the rebuild in the summer. I'll show him what I've found from you very helpful folk on here and see if he can piece it together.
-
Yeah I thought 55 days was a bit high. Everything else seems okay (from what I can tell): I've **'d any identifying information, no idea if that was necessary or not just thought it'd be safe. C:\WINDOWS\system32> Netdom Query FSMO Schema master DC01.local Domain naming master DC01.local PDC DC01.local RID pool manager DC01.local Infrastructure master DC01.local The command completed successfully. --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- C:\WINDOWS\system32> Get-ADDomain AllowedDNSSuffixes : {} ChildDomains : {} ComputersContainer : CN=Computers,DC=**,DC=local DeletedObjectsContainer : CN=Deleted Objects,DC=**,DC=local DistinguishedName : DC=**,DC=local DNSRoot : ** DomainControllersContainer : OU=Domain Controllers,DC=**,DC=local DomainMode : Windows2012R2Domain DomainSID : S-1-5-21-2670031880-** ForeignSecurityPrincipalsContainer : CN=ForeignSecurityPrincipals,DC=**,DC=local Forest : ** InfrastructureMaster : DC01.local LastLogonReplicationInterval : LinkedGroupPolicyObjects : {cn={1184592F-CAFD-4B39-9793-FAF35FFAC059},cn=policies,cn=system,DC=CHS,DC=local, cn={D7862049-B621-4BE7-A475-09E1F72BFA16},cn=policies,cn=system,DC=CHS,DC=local, cn={61BAB1FD-8C01-4D7B-B1C3-C5F28688E552},cn=policies,cn=system,DC=CHS,DC=local, c n={AE0AD057-A353-4738-846F-EFE53471919B},cn=policies,cn=system,DC=CHS,DC=local...} LostAndFoundContainer : CN=LostAndFound,DC=**,DC=local ManagedBy : Name : ** NetBIOSName : ** ObjectClass : domainDNS ObjectGUID : abffd92a-7a97-421e-b720-** ParentDomain : PDCEmulator : DC01.local PublicKeyRequiredPasswordRolling : QuotasContainer : CN=NTDS Quotas,DC=**,DC=local ReadOnlyReplicaDirectoryServers : {} ReplicaDirectoryServers : {DC02.local, DC01.local} RIDMaster : DC01.local SubordinateReferences : {DC=DomainDnsZones,DC=**,DC=local, DC=ForestDnsZones,DC=**,DC=local, CN=Configuration,DC=**,DC=local} SystemsContainer : CN=System,DC=**,DC=local UsersContainer : CN=Users,DC=**,DC=local --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- C:\WINDOWS\system32> Get-ADForest ApplicationPartitions : {DC=DomainDnsZones,DC=**,DC=local, DC=ForestDnsZones,DC=**,DC=local} CrossForestReferences : {} DomainNamingMaster : DC01.local Domains : {**.local} ForestMode : Windows2012Forest GlobalCatalogs : {DC02.local, DC01.local} Name : **.local PartitionsContainer : CN=Partitions,CN=Configuration,DC=**,DC=local RootDomain : **.local SchemaMaster : DC01.local Sites : {**} SPNSuffixes : {} UPNSuffixes : {**} --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- C:\WINDOWS\system32> $Services='DNS','DFS Replication','Intersite Messaging','Kerberos Key Distribution Center','NetLogon','Active Directory Domain Services' >> ForEach ($Service in $Services) {Get-Service $Service | Select-Object Name, Status} Name Status ---- ------ DNS Running DFSR Running IsmServ Running Kdc Running Netlogon Running NTDS Running --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- C:\WINDOWS\system32> DCDiag /Test:DNS /e /v Summary of DNS test results: Auth Basc Forw Del Dyn RReg Ext _________________________________________________________________ Domain: **.local DC02 PASS PASS PASS PASS PASS PASS n/a DC01 PASS PASS PASS PASS PASS PASS n/a ......................... **.local passed test DNS --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- C:\WINDOWS\system32> Get-WinEvent -FilterHashtable @{ >> LogName = 'Security' >> ID = 2889 >> } Get-WinEvent : No events were found that match the specified selection criteria.
-
Thanks, I've ran these commands and everything looks normal apart from the 'Repadmin /replsummary' which returned: Source DSA largest delta fails/total %% error DC01 25m:35s 0 / 5 0 DC02 55d.03h:53m:18s 1 / 5 20 (8606) Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected. Destination DSA largest delta fails/total %% error DC01 55d.03h:53m:18s 1 / 5 20 (8606) Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected. DC02 25m:35s 0 / 5 0 I must be honest, this could be completely normal but my knowledge doesn't stretch this far, I just saw error and assume that's bad.
-
Thanks, your message made me realise that the error message was literally telling me which policy wasn't being applied. So the policy GUID beginning with A5F2 was a policy related to Google Chrome and the policy GUID beginning with ED69 was a policy with locale settings. I unlinked both policies and restarted the laptop and did gpupdate /force and got 2 different GUIDs that failed to apply. This time, the always wait for network policy & a policy which sets some general taskbar settings. So I unlink those 2 policies, restart the laptop, do another gpupdate /force and now I am getting another GUID which can't apply and this one relates to a default internet browser. So it seems that when I unlink the 'problem' GPO's, something else becomes a problem. But like I've said, there's loads of devices that have these policies applied with no problems so I don't think the GPOs are the problem.
-
Yeah we do have this GPO
-
Thanks for this, we do have this policy already applied.
-
Thanks for that! Just done that and it appears replication is working fine. Created a file on DC01 which appeared on DC02, Created a file on DC02 which appeared on DC01.
-
I've just turned on a laptop, GP wasn't applied so I did gpupdate /force and got the error I mentioned in my post. I did gpresult /r and it says policy was applied from DC01. I restarted the laptop, GP still not applied, gpupdate /force and got the same error, did gpresult /r again and this time it was applied from DC02
-
2 DC's. Replication seems to be okay from what I've checked, my knowledge doesn't span too far in replication so I've just followed some guidance online and it looks like replication is fine. But I suspect it's not, how can I check for sure? DNS is happy for both DC's.
