DC FSMO roles - which on physical, which virtual?

jffnuggets wrote: while still keeping the BM DC but just not backing it up.
Why?  Move all the DCs (and all the other servers, too) to VMs.

So we've got a handful of DCs spread out over the sites; at home base, we've got two - one baremetal, one virtual.  The BM has RID/PDC/Infrastructure roles.  
Any issues with moving the roles to the VM DC?
Why I'm asking is this: I hear that they advise to back up two DCs to be safe.  This BM DC is the only machine that I'm still backing up with BackupExec.  I'd love to get all the roles to a VM DC if advisable, while still keeping the BM DC but just not backing it up.  Our VM infrastructure has failover over three ESX servers, plus daily offsite backups. 
Forest is still 2003, but to become 2008 shortly. 
Thanks much for all guidance.
This topic first appeared in the Spiceworks Community

Similar Messages

  • Procedure for deleting a role which is already in Production

    Hi,
    can any one explain me the procedure for deleting a role which is already in production
    i want to know procedure for deletion of
    1.single role
    2.composite role
    3.derived role
    4.parent role
    thanks,
    SSSS

    Hi,
    Role deletion must be done in development box and the deletion must be transported to quality and productuion
    For single and derrived roles create the transport request and delete the role and transport the deletion.
    For Deletion of parent role: you cannot delete the parent role unless all the derrived roles within it are deleted.
    To avoid the transport of user assignment make sure PRGN_CUST is set to 'NO' value for the parameter USER_REL_IMPORT.
    Rakesh

  • Disable / Hide Portal PCD roles which we don't want to display in UME.

    Hi Friends,
    I have configured ESS/MSS setup in our Portal;
    Step 1)   
        a) We downloaded ESS/MSS business packages from SAP Market place
        b) Deployed into our Portal.
        c) I have checked in Portal Content Administration; ESS/MSS PCD objects i.e. Roles,Worksets,Pages and iViews were created inside the SAP Standard folder.
    Step 2) As per my client recommendations u2013
       a) We donu2019t want to use PCD objects directly from SAP Standard folder and we will keep those PCD objects as backup. So,
       b) We created Client folder ex: xxABC inside Portal Content.
       c) I copied ESS/MSS PCD folder from SAP Standard Folder and Pasted inside folder xxABC; and then we customized Roles and worksets based on our requirements.
    Step 3) Role assignment to Users
          When I search for ESS/MSS roles like u201CEmployee Self-Serviceu201D and u201CManage Self-Serviceu201D I am able to see each role twice u2013 one is from SAP Standard folder and another from client folder which I was copied.
    So,
    1) I donu2019t want to display ESS/MSS role which is inside of SAP Standard folder in UME(role search).
    2) I donu2019t want to delete the role from this folder.
    I got an Idea that is u2013 disable/hide Portal PCD roles which we don't want to display in UME while role search.
    Please advise me, Is there any feature to disable/hide PCD roles in SAP Portal?

    Hi,
    You can try to set '''plugins.hide_infobar_for_outdated_plugin''' to true in [http://kb.mozillazine.org/About:config about:config].
    [http://kb.mozillazine.org/About:config_entries about:config Entries]

  • How to set role which can issue only one command

    I am thinking about setting role, which will be allowed to issue olny one command. I have created role test. Which has the following entries in the following files:
    /etc/user_attr
    test::::profiles=OneCommand;type=role
    /etc/security/exec_attr
    OneCommand:solaris:cmd:::/tmp/data.sh:euid=0
    After this I sill could issue all comands, not only test command /tmp/data.sh.
    When I issued comand profiles on test role I received the following:
    bash-3.00$ profiles test
    OneCommand
    Basic Solaris User
    All
    So I commented line in the /etc/policy.conf to read:
    #PROFS_GRANTED=Basic Solaris User
    After that, when I try to issue /tmp/data.sh command as a test role I receive the following error:
    $ /tmp/data.sh
    pfexec: Exec format error
    Does anybody know how to set up the role which can issue only one command ? Maybe there is a way to do this in the way which wil not affect another roles (ie, not to touch /etc/policy.conf).
    Best regards

    RadekW wrote:
    I am thinking about setting role, which will be allowed to issue olny one command. I have created role test. Which has the following entries in the following files:They will need the ability to run at least a profile shell otherwise all bets are off. So now you're down to two commands. :-)
    bash-3.00$ profiles test
    OneCommand
    Basic Solaris User
    AllFirst you need to define what already exists by default. (policy.conf)
    Then you get to change those defaults or create a new default list just for test.
    Then you get to add a role or profile for test that allows the execution of a profile shell and one command.
    Then you should test all of the user accounts to ensure that something didn't break. This step might be a little overkill.
    alan

  • Do we have role which display all the authorizations in portal

    HI,
      Can any body tell me whether is there any role which display all authorizations in the protal.?
    If not can u tell me how to display all authorizations in the portal in detail.
    Thanks in advance
    Krishna.

    Hi,
    There are around 40+ Standard roles in EP7.  If you logon with J2ee_admin you can see all the roles attached to a user under user Management Tab.
    Regards,
    -Vijay

  • How do I see the users/roles which have quota access to a Tablespace?

    How do I see the users/roles which have quota access to a Tablespace?
    Thanks

    Thank you very much.
    select username from dba_ts_quotas where tablespace_name='&tablespacename';
    did the job!
    regards

  • Can i make a role which can grant roles?

    i want to make a role which can grants other users except ownself.
    How can i do that?

    i want to make a role which can grants other users except ownself.
    How can i do that? You can't. ROLE is not the same as USER. Role can't grant something to someone,
    only user can. Read the reference above.
    Rgds.

  • How to Install Physical and Virtual Host

    I am getting licensing issues after I installed Essentials 2012R2 on a physical machine and then used the same license to virtualize it.  It's saying my physical machine needs to hold all the FSMO roles in which my virtual machine is hosting those roles.
    I read that Microsoft allows you to use the Essentials license for the physical and virtual server.  Is that correct? 
    Is there a specific service I need to remove on the physical machine in order for these errors to stop?  I still have the Windows Server Essentials Experience service installed. Is that what needs to be removed?
    Thanks,
    Doug

    Hi Doug,
    There is an article that provide details of licensing for Windows Server 2012 R2 Essentials. Please refer to and check if can help us to understand licensing for Windows Server 2012 R2 Essentials better.
    Understanding Licensing for Windows Server 2012 R2 Essentials and the Windows
    Server Essentials Experience role
    Please also refer to following article and check if can help you.
    Customize Deployment - Windows Server Essentials
    If any update, please feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • DCPROMO fails because of FSMO roles...normal solutions not working

    I am trying to remove a 2008 R2 DC from our domain but receive this error:
    "Directory Service is missing mandatory configuration information...unable to determine ownership of floating single-master operation roles"
    In the even log we have this additional error:
    Error:
    Ownership of the following FSMO role is set to a server which is deleted or does not exist.
    Operations which require contacting a FSMO operation master will fail until this condition is corrected.
    FSMO Role: CN=Infrastructure,DC=DomainDnsZones,DC=lvcinc,DC=local
    FSMO Server DN: CN=NTDS Settings\0ADEL:464a6261-2c82-4ac1-b2b2-144d2e5e1b74,CN=SDOCS1\0ADEL:27fa192a-1f79-4a62-9557-d14ce99406d9,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=lvcinc,DC=local
    User Action:
    1. Determine which server should hold the role in question.
    2. Configuration view may be out of date. If the server in question has been promoted recently, verify that the Configuration partition has replicated from the new server recently. If the server in question has been demoted recently and the role transferred, verify that this server has replicated the partition (containing the latest role ownership) lately.
    3. Determine whether the role is set properly on the FSMO role holder server. If the role is not set, utilize NTDSUTIL.EXE to transfer or seize the role. This may be done using the steps provided in KB articles 255504 and 324801 on http://support.microsoft.com.
    4. Verify that replication of the FSMO partition between the FSMO role holder server and this server is occurring successfully.
    Steps to try resolving:
    Investigating the above error - it is referencing a Very old DC from a few years ago "SDOCS1". See bold type above.
    1.  Ran DCDiag /v /q on all servers and the only errors we receive are the ones that are manifested due to NOT having run the RODC switch with ADPREP
    (Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
       Replicating Directory Changes In Filtered Set
    access rights for the naming context:
    DC=ForestDnsZones,DC=lvcinc,DC=local
    Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
       Replicating Directory Changes In Filtered Set
    access rights for the naming context:
    DC=DomainDnsZones,DC=lvcinc,DC=local
    ......................... SVHOST2 failed test NCSecDesc
    2.  Checked the location of the FSMO roles and they are all located on our SDC1 server.  I even transferred the Infrastructure FSMO role to a different server and the DCPROMO to remove the server still failed with the same above error.
    3.  Ran through the "Seizing" of the roles specified by this KB:  http://support.microsoft.com/kb/255504.  The server mentioned in the error (SDOCS1) doesn't hold any of the roles and isn't listed in the list of servers
    3.  Went through this KB about removing the metadata of the defunct server:  http://support.microsoft.com/kb/216498.  The server mentioned doesn't exist in any of the locations.
    I'm at a loss as to how to resolve this.  Somewhere the AD Database has a reference to that old server (SDOCS1).  I have looked in all the obvious places in ADSIEDIT and DNS and have found no reference to it.
    I know I can do a force removal of this server (SVHOST2) - but it seems that I need to fix the greater problem of removing the referencen to SDOCS1.
    Thanks for any help for this perplexing issue!
    -David Miller

    I am having a similar problem with our AD structure. My predecessor replaced a failed DC without performing any cleanup afterwards, and my first Monday on the job, our (newer) main AD server corrupted its SAM due to a failed drive and wouldn't login. This
    forced me to seize all the roles from the failing server to a secondary DC which was then promoted as our GC server. I'm in the process of migrating to a virtualized environment, and have promoted the VM AD server (AD1), but it fails to demote the other AD
    server (Zeus) even though all 5 FSMO roles are now held by AD1. I ran through the suggestions earlier in this thread, and found DCDiag
    /v /q  to be most helpful. Piping the results to a text file, I was able to determine that the first failed AD server still exists to some extent in our AD.
          Starting test: KccEvent
             * The KCC Event log test
             A warning event occurred.  EventID: 0x8000082B
                Time Generated: 12/07/2010   09:30:04
                Event String:
                Ownership of the following FSMO role is set to a server which is deleted or does not exist. 
                Operations which require contacting a FSMO operation master will fail until this condition is corrected. 
                FSMO Role: CN=Infrastructure,DC=DomainDnsZones,DC=icucare,DC=local 
                FSMO Server DN: CN=NTDS Settings\0ADEL:b59defe5-ba6e-4db4-a738-b24ffd8281b2,CN=WIN-WOI3YAPEZMC\0ADEL:b08771ed-4884-47b8-9b0c-4f2304279843,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=icucare,DC=local 
    What steps must I take to remove server WIN-W0U3YAPEZMC from our domain? This server no longer exists and I would NEVER give a server a name that I couldn't easily pronounce when discussing it with management :-) I have attempted a metadata cleanup but this
    old server is still showing up in our AD, preventing me from demoting an existing AD server so it can be replaced with a newer, virtualized version.
    Many thanks for your help.
    - Jeff Sepeta, network admin

  • Is It Possible to Add a Fileserver to a DFS Replication Group Without Connectivity to FSMO Roles Holder DC But Connectivity to Site DC???

    I apologize in advance for the rambling novella, but I tried to include as many details ahead of time as I could.
    I guess like most issues, this one's been evolving for a while, it started out with us trying to add a new member 
    to a replication group that's on a subnet without connectivity to the FSMO roles holder. I'll try to describe the 
    layout as best as I can up front.
    The AD only has one domain & both the forest & domain are at 2008R2 function level. We've got two sites defined in 
    Sites & Services, Site A is an off-site datacenter with one associated subnet & Site B with 6 associated subnets, A-F. 
    The two sites are connected by a WAN link from a cable provider. Subnets E & F at Site B have no connectivity to Site A 
    across that WAN, only what's available through the front side of the datacenter through the public Internet. The network 
    engineering group involved refuses to route that WAN traffic to those two subnets & we've got no recourse against that 
    decision; so I'm trying to find a way to accomplish this without that if possible.
    The FSMO roles holder is located at Site A. I know that I can define a Site C, add Subnets E & F to that site, & then 
    configure an SMTP site link between Sites A & C, but that only handles AD replication, correct? That still wouldn't allow me, for example, 
    to enumerate DFS namespaces from subnets E & F, or to add a fileserver on either of those subnets as a member to an existing
    DFS replication group, right? Also, root scalability is enabled on all the namespace shares.
    Is there a way to accomplish both of these things without transferring the FSMO roles from the original DC at Site A to, say, 
    the bridgehead DC at Site B? 
    When the infrastructure was originally setup by a former analyst, the topology was much more simple & everything was left
    under the Default First Site & no sites/subnets were setup until fairly recently to resolve authentication issues on 
    Subnets E & F... I bring this up just to say, the FSMO roles holder has held them throughout the build out & addition of 
    all sorts of systems & I'm honestly not sure what, if anything, the transfer of those roles will break. 
    I definitely don't claim to be an expert in any of this, I'll be the first to say that I'm a work-in-progress on this AD design stuff, 
    I'm all for R'ing the FM, but frankly I'm dragging bottom at this point in finding the right FM. I've been digging around
    on Google, forums, & TechNet for the past week or so as this has evolved, but no resolution yet. 
    On VMs & machines on subnets E & F when I go to DFS Management -> Namespace -> Add Namespaces to Display..., none show up 
    automatically & when I click Show Namespaces, after a few seconds I get "The namespaces on DOMAIN cannot be enumerated. The 
    specified domain either does not exist or could not be contacted". If I run a dfsutil /pktinfo, nothing shows except \sysvol 
    but I can access the domain-based DFS shares through Windows Explorer with the UNC path \\DOMAIN-FQDN\Share-Name then when 
    I run a dfsutil /pktinfo it shows all the shares that I've accessed so far.
    So either I'm doing something wrong, or, for some random large, multinational company, every sunbet & fileserver one wants 
    to add to a DFS Namespace has to be able to contact the FSMO roles holder? Or, are those ADs broken down with a child domain 
    for each Site & a FSMO roles holder for that child domain is located in each site?

    Hi,
    A DC in siteB should helpful. I still not see any article mentioned that a DFS client have to connect to PDC every time trying to access a DFS domain based namespace.
    Please see following article. I pasted a part of it below:
    http://technet.microsoft.com/en-us/library/cc782417(v=ws.10).aspx
    Domain controllers play numerous roles in DFS:
    Domain controllers store DFS metadata in Active Directory about domain-based namespaces. DFS metadata consists of information about entire namespace, including the root, root targets, links, link targets, and settings. By default,root servers
    that host domain-based namespaces periodically poll the domain controller acting as the primary domain controller (PDC) emulator master to obtain an updated version of the DFS metadata and store this metadata in memory.
    So Other DC needs to connect PDC for an updated metadata.
    Whenever an administrator makes a change to a domain-based namespace, the
    change is made on the domain controller acting as the PDC emulator master and is then replicated (via Active Directory replication) to other domain controllers in the domain.
    Domain Name Referral Cache
    A domain name referral contains the NetBIOS and DNS names of the local domain, all trusted domains in the forest, and domains in trusted forests. A
    DFS client requests a domain name referral from a domain controller to determine the domains in which the clients can access domain-based namespaces.
    Domain Controller Referral Cache
    A domain controller referral contains the NetBIOS and DNS names of the domain controllers for the list of domains it has cached. A DFS client requests a domain controller referral from a domain controller (in the client’s domain)
    to determine which domain controllers can provide a referral for a domain-based namespace.
    Domain-based Root Referral Cache
    The domain-based root referrals in this memory cache do not store targets in any particular order. The targets are sorted according to the target selection method only when requested from the client. Also, these referrals are based on DFS metadata stored
    on the local domain controller, not the PDC emulator master.
    Thus it seems to be acceptable to have a disconnect between sites shortly when cache is still working on siteB.
    If you have any feedback on our support, please send to [email protected].

  • Physical to virtual ends with errors, other methods export but launch with windows repair 2008 r2

    New to hyperV here, plan to implement it in a few months. So I am practicing with it now.
    I am trying to convert a working 2008 r2 physical to virtual using Microsoft virtual machine converter.  in the settings I was point it to my hyperv- server and I was getting errors, this was due to permissions. No matter what I did I can't get it to
    work, not sure whats wrong. SO I installed hyper V under my win8.1 pro machine shared the folders and the export started.
    Upon the end of the export where it goes into "Fixing disk' I get an instant error no matter how may times I do this or how which server I try to export I get an error here.
    It still created files and when I then copy those over to my test hyper V the win2008 R2 export goes into repair mode, I'm sure it's a driver issue but I would have expected that MS would have stripped the drivers our before export.
    I then tried Acronis backup server and was able to export to MS virtual machine but this export also goes into windows repair more.
    In the past I've used acronis and restored a physical server , this would also go into repair mode unless I use the "intelligent restore" which strips the drivers.
    I don't want to tinker with the live server to get this to work since It's still in production, but I would like to get this to work , would any one have a tip, what can I do to provide more information on the root of the problem?
    nambi

    Hi Sir,
    >>I am trying to convert a working 2008 r2 physical to virtual using
    Microsoft virtual machine converter. 
    Generally, I would suggest you to use
    Disk2Vhd to convert a physical computer to Virtual Machine (virtual hard disk) then create a VM and attach that VHD .
    Please refer to this
    article .
    Any further information please feel free to let us know .
    Best Regards,
    Elton Ji
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] .

  • DC not functioning with FSMO roles

    hello every body,
    I have 0 DC and 01 ADC lets say that DC and ADC. both were replicating AD and working properly. few days ago the motherboard of my DC failed and we replaced with new one. and obviously NIC card was attached with M.Board which also changed. when i boot up
    my DC, i see its not functioning as domain controller as i saw in server manager all FSMO roles are with red cross. i assign the ip address which it hold previous i.e 192.168.0.1. but still FSMO roles are disabled. While my only ADC is working properly with
    following errors and warning in AD DS roles. 
    Warning on ADC:
    The remote server which is the owner of a FSMO role is not responding.  This server has not replicated with the FSMO role owner recently. 
    Error on ADC:
    Log Name:      Directory Service
    Source:        Microsoft-Windows-ActiveDirectory_DomainService
    Date:          12/15/2014 11:18:07 AM
    Event ID:      1863
    Task Category: Replication
    Level:         Error
    Keywords:      Classic
    User:          ANONYMOUS LOGON
    Computer:      KHI-ADC.jehanpakistan.com
    Description:
    This is the replication status for the following directory partition on this directory server. 
    Directory partition:
    DC=ForestDnsZones,DC=jehanpakistan,DC=com 
    This directory server has not received replication information from a number of directory servers within the configured latency interval. 
    Latency Interval (Hours): 
    24 
    Number of directory servers in all sites:

    Number of directory servers in this site:

    The latency interval can be modified with the following registry key. 
    Registry Key: 
    HKLM\System\CurrentControlSet\Services\NTDS\Parameters\Replicator latency error interval (hours) 
    To identify the directory servers by name, use the dcdiag.exe tool. 
    You can also use the support tool repadmin.exe to display the replication latencies of the directory servers.   The command is "repadmin /showvector /latency <partition-dn>".
    My DC is working properly as a System.
    should i have to do something with my NIC or AD DS roles or i have to transfer FSMOs to ADC. or sieze fsmo roles of DC on ADC.
    please help.

    Is your DC (role holder) a DNS Server as well? I assume it is, if so open the server role properties and ensure the DNS server role shows the IP in the interface if it does not you may need to uninstall/ re-install the DNS server role (assuming it is a 2008
    R2 DC or above... Also did you look at your NIC settings? Did you re-establish the exact same NIC configuration as before?
    When the motherboard gets replaced and new NICS are introduced I normally look at the NIC settings and DNS Server roles... That is the Microsoft side of things. On the LAN/ WAN side of things if your network team has port security enabled on the switches
    the port may be locked down due to the new MAC Address.

  • Required FSMO Roles to Bring up Domain Controller

    I have an unusual situation.  Our network team is moving to a new vendor for our WAN circuits and this change which has left our network split. I have 10 domain controllers which can't talk to the other seven domain controllers. This situation
    will last about another 2 months.
    I have been asked to bring up an RODC domain controller in a location which can't connect to the DC which hosts the FSMO roles, but has communication with seven domain controllers.
    Is this possible?  What FSMO roles are required to bring up a DC?
    Thanks
    LRL

    In a worse case scenario, replication may fail between domain controllers when a WAN link is re-established:
    http://pmeijden.wordpress.com/2011/01/12/domain-replication-has-exceeded-the-tombstone-lifetime/
    "This can also happen when your network isn’t working properly or when replication error’s have occurred for to long without anyone noticing them. In large environments it’s possible that a complete site has been disconnected due to unavailable WAN
    connections. [...]
    The reason why the domain controllers will not continue the replication is because they are protected for so called Lingering Objects. For example, one or more objects that are deleted from Active Directory on all other domain controllers might remain on
    the disconnected domain controller. Such objects are called Lingering Objects. Because the domain controller is offline during the entire time that the tombstone is alive, the domain controller never receives replication of the tombstone and therefor doesn’t
    know that the object has been deleted."
    If your tombstone lifetime is still 60 days (the original default), that is about 2 months.
    You can check like this:
    http://technet.microsoft.com/en-us/library/cc784932(v=ws.10).aspx
    If it is 180 days (new default - I won't go into the details of how and when this changed), you may avoid the worse case scenario. But you still might have problems.
    Two months... how much time has already passed?
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you.

  • Best way to convert Exchange 2010 Physical to Virtual (esxi 5.1)

    Hello,
    I've been doing a bit of research on best practices for Exchange 2010 in VMware and I am pretty sure at this point my hardware and vmware config is going to be able to handle it.  What to people recommend for moving exchange 2010 off a physical server and onto a virtual machine?  Just building an Exchange VM and then migrating the mailboxes, etc?

    The best and simple way to do that is:
    Make new Exchange nodes as virtual machines to be member on your current physical DAG after that move your Databases on it, then make additional domain controller on virtual machine then transfer the FSMO roles from your current physical domain controller to it... at the end demote your physical environment.
    Note: there is no down time in this solution.

  • Conversion from physical to virtual server

    Our server technology group wants to convert our physical
    server that contains the RoboEngine to a virtual server (using ESX
    VMware). We are using RoboHelp 5 to publish WebHelp to the
    RoboEngine. Has anyone else converted from a physical to a virtual
    server? If so, could you tell me about any problems you
    encountered?
    Thanks,
    Liz

    Hello Nelson, 
    There are quite lot of things in TMG which are dependent on Hardware.
    If you want to migrate from physical to virtual server, you can follow the steps here which are recommended/supported way of doing it.
    Though this article is for ISA to TMG migration, still you can follow the same steps for Physcial to Virtual migration.
    http://technet.microsoft.com/en-us/library/dd440994.aspx
    Please let us know, how it goes!

Maybe you are looking for

  • How do you change the default email client (Mail) to Outlook when sharing?

    In iPhoto I used Outlook as the default email to forward photos to friends.  How do you change it from Mail in Photos to Outlook?

  • Is it possible to load music onto an iPod in Disc Mode?

    Hi guys, Is it possible to load music onto an iPod in Disc Mode? I recently sold my 5th Gen 30Gb iPod on eBay, about a week later the buyer sent it back claiming it was faulty, he could not switch it on etc etc... Within a few minutes I had it runnin

  • Nokia N8 with Belle : where is the scroll menu to ...

    It may sound like a dumb question but after the troublesome update to Belle ( it deleted many apps from my phone, and also my phonebook and mixed up things here and there), I am not able anymore to find the scroll menu where you can see the open apps

  • How to get the anchor tag values in next jsp

    Hey all, I have two jsp files. in first jsp, I am getting the resultset. I am setting the resultset to the anchor tag. below is the code... <a target="_top" rel="contents" rev="contents" class="fordynamiclabel" href="ASCMasterTwo.jsp"><%=rSet.getStri

  • H.264 Output Fails in After Effects and AME

    I'm having the same problem - H.264 export crashes around the 1:03 mark every time. DNxHD is fine. Dragging comps to Adobe Media Encoder and trying to render from there doesn't work either. My CS6 install [last week] is on a brand new Dell Precision