Risk to recreate DFSR Group Replication in Windows 2008 R2

DFS replication group has been deleted and I need to recreate it. Now what I just want to make sure if I recreate the replication group are all folders between my 3 servers will resynch without probllem?
I mean I hope by doing that it will not create a mess. Is someone can confirm that I can recreate DFS Replication Group without problem. The used topology is full mesh.
Thanks

Hi,
If the replication group is deleted clearly, you will not have any issue in creating it - if it is not deleted clearly you will fail to create it with the same namespace or fail to create it with message "replication group already exists".
In creating a replication group, it will ask for a primary folder target and files with be replicated from it to other members regardless which server has the newest version. So if any newer files exist in other members you should backup them or overwrite
the old versions before creating the replication. 
If you have any feedback on our support, please send to [email protected]

Similar Messages

  • Replication issue Windows 2008 (not R2) FrsEvent error ?

    I've had a few netlogon share issues but with help from this forum they've all gone away.
    When I use the event log to look at administrative events all 3 give the same error "Access is denied" to the File replication service.
    DCdiag /e gives the following errors ?
    It looks like I''m actually down to just this error but its similar on all 3 Domain Controllers ?
    PDC (ch-dc1-2k8)
    Starting test: frsevent
    There are warning or error events within the last 24 hours after the SYSVOL has been shared.
    Failing SYSVOL replication problems may cause Group Policy problems.
    DC2 (ch-dc2-2k8)
    Starting test: FrsEvent        
    The event log File Replication Service on server          ch-dc1-2k8.companyname.local could not be queried, error 0x5          "Win32 Error 5"         
    ......................... CH-DC1-2K8 failed
    DC3 (na-dc2-2k8)
    Starting test: FrsEvent         
    The event log File Replication Service on server ch-dc1-2k8.companyname.local could not be queried,
    error 0x5          "Win32 Error 5"          ......................... CH-DC1-2K8 failed
    Any ideas ?
    Also I've put a test file into the scripts folder and it has NOT replicated ?

    Testing server: Cardiff\CH-DC2-2K8
          Starting test: Replications
             * Replications Check
             CN=Schema,CN=Configuration,DC=companyname,DC=local has 7 cursors.
             CN=Configuration,DC=companyname,DC=local has 7 cursors.
             DC=companyname,DC=local has 7 cursors.
             * Replication Latency Check
                CN=Schema,CN=Configuration,DC=companyname,DC=local
                   Latency information for 4 entries in the vector were ignored.
                      4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency
    information (Win2K DC).  
                CN=Configuration,DC=companyname,DC=local
                   Latency information for 4 entries in the vector were ignored.
                      4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency
    information (Win2K DC).  
                DC=companyname,DC=local
                   Latency information for 4 entries in the vector were ignored.
                      4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency
    information (Win2K DC).  
             * Replication Site Latency Check
             Site Settings = CN=NTDS Site Settings,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             [0x904de,v=62142,t=2015-04-23 09:16:18,g=a1d47848-fb4f-497b-a8a2-f11d40b71481,orig=20719256,local=20719256]
             Elapsed time (sec) = 2264
             Site Settings = CN=NTDS Site Settings,CN=Edinburgh,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Site
             CN=NTDS Site Settings,CN=Edinburgh,CN=Sites,CN=Configuration,DC=companyname,DC=local
             was skipped because it never had an ISTG running in it.
             Site Settings = CN=NTDS Site Settings,CN=London,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Site
             CN=NTDS Site Settings,CN=London,CN=Sites,CN=Configuration,DC=companyname,DC=local
             was skipped because it never had an ISTG running in it.
             Site Settings = CN=NTDS Site Settings,CN=Belfast,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Site
             CN=NTDS Site Settings,CN=Belfast,CN=Sites,CN=Configuration,DC=companyname,DC=local
             was skipped because it never had an ISTG running in it.
             ......................... CH-DC2-2K8 passed test Replications
          Starting test: Topology
             * Configuration Topology Integrity Check
             * Analyzing the connection topology for CN=Schema,CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the connection topology for CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the connection topology for DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             ......................... CH-DC2-2K8 passed test Topology
          Starting test: CutoffServers
             * Configuration Topology Aliveness Check
             * Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             ......................... CH-DC2-2K8 passed test CutoffServers
          Starting test: NCSecDesc
             * Security Permissions check for all NC's on DC CH-DC2-2K8.
             * Security Permissions Check for
               CN=Schema,CN=Configuration,DC=companyname,DC=local
                (Schema,Version 2)
             * Security Permissions Check for
               CN=Configuration,DC=companyname,DC=local
                (Configuration,Version 2)
             * Security Permissions Check for
               DC=companyname,DC=local
                (Domain,Version 2)
             ......................... CH-DC2-2K8 passed test NCSecDesc
          Starting test: NetLogons
             * Network Logons Privileges Check
             Verified share \\CH-DC2-2K8\netlogon
             Verified share \\CH-DC2-2K8\sysvol
             ......................... CH-DC2-2K8 passed test NetLogons
          Starting test: Advertising
             The DC CH-DC2-2K8 is advertising itself as a DC and having a DS.
             The DC CH-DC2-2K8 is advertising as an LDAP server
             The DC CH-DC2-2K8 is advertising as having a writeable directory
             The DC CH-DC2-2K8 is advertising as a Key Distribution Center
             The DC CH-DC2-2K8 is advertising as a time server
             The DS CH-DC2-2K8 is advertising as a GC.
             ......................... CH-DC2-2K8 passed test Advertising
          Starting test: KnowsOfRoleHolders
             Role Schema Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role Domain Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role PDC Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role Rid Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role Infrastructure Update Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             ......................... CH-DC2-2K8 passed test KnowsOfRoleHolders
          Starting test: RidManager
             ridManagerReference = CN=RID Manager$,CN=System,DC=companyname,DC=local
             * Available RID Pool for the Domain is 12100 to 1073741823
             fSMORoleOwner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             * ch-dc1-2k8.companyname.local is the RID Master
             * DsBind with RID Master was successful
             rIDSetReferences = CN=RID Set,CN=CH-DC2-2K8,OU=Domain Controllers,DC=companyname,DC=local
             * rIDAllocationPool is 11100 to 11599
             * rIDPreviousAllocationPool is 9100 to 9599
             * rIDNextRID: 9425
             ......................... CH-DC2-2K8 passed test RidManager
          Starting test: MachineAccount
             Checking machine account for DC CH-DC2-2K8 on DC CH-DC2-2K8.
             * SPN found :LDAP/ch-dc2-2k8.companyname.local/companyname.local
             * SPN found :LDAP/ch-dc2-2k8.companyname.local
             * SPN found :LDAP/CH-DC2-2K8
             * SPN found :LDAP/ch-dc2-2k8.companyname.local/companyname
             * SPN found :LDAP/abb03237-e91b-457f-ab16-788d5dc3930e._msdcs.companyname.local
             * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/abb03237-e91b-457f-ab16-788d5dc3930e/companyname.local
             * SPN found :HOST/ch-dc2-2k8.companyname.local/companyname.local
             * SPN found :HOST/ch-dc2-2k8.companyname.local
             * SPN found :HOST/CH-DC2-2K8
             * SPN found :HOST/ch-dc2-2k8.companyname.local/companyname
             * SPN found :GC/ch-dc2-2k8.companyname.local/companyname.local
             ......................... CH-DC2-2K8 passed test MachineAccount
          Starting test: Services
             * Checking Service: Dnscache
             * Checking Service: NtFrs
             * Checking Service: IsmServ
             * Checking Service: kdc
             * Checking Service: SamSs
             * Checking Service: LanmanServer
             * Checking Service: LanmanWorkstation
             * Checking Service: RpcSs
             * Checking Service: w32time
             * Checking Service: NETLOGON
             ......................... CH-DC2-2K8 passed test Services
          Starting test: OutboundSecureChannels
             * The Outbound Secure Channels test
             ** Did not run Outbound Secure Channels test
             because /testdomain: was not entered
             ......................... CH-DC2-2K8 passed test OutboundSecureChannels
          Starting test: ObjectsReplicated
             CH-DC2-2K8 is in domain DC=companyname,DC=local
             Checking for CN=CH-DC2-2K8,OU=Domain Controllers,DC=companyname,DC=local in domain DC=companyname,DC=local on 3 servers
                Object is up-to-date on all servers.
             Checking for CN=NTDS Settings,CN=CH-DC2-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local in domain CN=Configuration,DC=companyname,DC=local on 3 servers
                Object is up-to-date on all servers.
             ......................... CH-DC2-2K8 passed test ObjectsReplicated
          Starting test: frssysvol
             * The File Replication Service SYSVOL ready test
             File Replication Service's SYSVOL is ready
             ......................... CH-DC2-2K8 passed test frssysvol
          Starting test: frsevent
             * The File Replication Service Event log test
             There are warning or error events within the last 24 hours after the
             SYSVOL has been shared.  Failing SYSVOL replication problems may cause
             Group Policy problems.
             An Warning Event occured.  EventID: 0x800034C4
                Time Generated: 04/22/2015   14:53:29
                Event String: The File Replication Service is having trouble
    enabling replication from CH-DC1-2K8 to
    CH-DC2-2K8 for c:\windows\sysvol\domain using the
    DNS name ch-dc1-2k8.companyname.local. FRS
    will keep retrying.
     Following are some of the reasons you would see
    this warning.
     [1] FRS can not correctly resolve the DNS name
    ch-dc1-2k8.companyname.local from this
    computer.
     [2] FRS is not running on
    ch-dc1-2k8.companyname.local.
     [3] The topology information in the Active
    Directory Domain Services for this replica has
    not yet replicated to all the Domain Controllers.
     This event log message will appear once per
    connection, After the problem is fixed you will
    see another event log message indicating that the
    connection has been established.
             An Warning Event occured.  EventID: 0x800034C4
                Time Generated: 04/22/2015   14:53:29
                Event String: The File Replication Service is having trouble
    enabling replication from NA-DC1-2K8 to
    CH-DC2-2K8 for c:\windows\sysvol\domain using the
    DNS name na-dc1-2k8.companyname.local. FRS
    will keep retrying.
     Following are some of the reasons you would see
    this warning.
     [1] FRS can not correctly resolve the DNS name
    na-dc1-2k8.companyname.local from this
    computer.
     [2] FRS is not running on
    na-dc1-2k8.companyname.local.
     [3] The topology information in the Active
    Directory Domain Services for this replica has
    not yet replicated to all the Domain Controllers.
     This event log message will appear once per
    connection, After the problem is fixed you will
    see another event log message indicating that the
    connection has been established.
             ......................... CH-DC2-2K8 failed test frsevent
          Starting test: kccevent
             * The KCC Event log test
             Found no KCC errors in Directory Service Event log in the last 15 minutes.
             ......................... CH-DC2-2K8 passed test kccevent
          Starting test: systemlog
             * The System Event log test
             An Error Event occured.  EventID: 0x40000004
                Time Generated: 04/23/2015   09:30:54
                Event String: The Kerberos client received a
    KRB_AP_ERR_MODIFIED error from the server
    Administrator. The target name used was
    companyname\CH-DC1-2K8$. This indicates that
    the target server failed to decrypt the ticket
    provided by the client. This can occur when the
    target server principal name (SPN) is registered
    on an account other than the account the target
    service is using. Please ensure that the target
    SPN is registered on, and only registered on, the
    account used by the server. This error can also
    happen when the target service is using a
    different password for the target service account
    than what the Kerberos Key Distribution Center
    (KDC) has for the target service account. Please
    ensure that the service on the server and the KDC
    are both updated to use the current password. If
    the server name is not fully qualified, and the
    target domain (companyname.LOCAL) is different
    from the client domain (companyname.LOCAL),
    check if there are identically named server
    accounts in these two domains, or use the
    fully-qualified name to identify the server.
             An Error Event occured.  EventID: 0x40000004
                Time Generated: 04/23/2015   09:30:54
                Event String: The Kerberos client received a
    KRB_AP_ERR_MODIFIED error from the server
    Administrator. The target name used was
    companyname\NA-DC1-2K8$. This indicates that
    the target server failed to decrypt the ticket
    provided by the client. This can occur when the
    target server principal name (SPN) is registered
    on an account other than the account the target
    service is using. Please ensure that the target
    SPN is registered on, and only registered on, the
    account used by the server. This error can also
    happen when the target service is using a
    different password for the target service account
    than what the Kerberos Key Distribution Center
    (KDC) has for the target service account. Please
    ensure that the service on the server and the KDC
    are both updated to use the current password. If
    the server name is not fully qualified, and the
    target domain (companyname.LOCAL) is different
    from the client domain (companyname.LOCAL),
    check if there are identically named server
    accounts in these two domains, or use the
    fully-qualified name to identify the server.
             ......................... CH-DC2-2K8 failed test systemlog
          Starting test: VerifyReplicas
             ......................... CH-DC2-2K8 passed test VerifyReplicas
          Starting test: VerifyReferences
             The system object reference (serverReference)
             CN=CH-DC2-2K8,OU=Domain Controllers,DC=companyname,DC=local and
             backlink on
             CN=CH-DC2-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             are correct.
             The system object reference (frsComputerReferenceBL)
             CN=CH-DC2-2K8,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=companyname,DC=local
             and backlink on
             CN=CH-DC2-2K8,OU=Domain Controllers,DC=companyname,DC=local are
             correct.
             The system object reference (serverReferenceBL)
             CN=CH-DC2-2K8,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=companyname,DC=local
             and backlink on
             CN=NTDS Settings,CN=CH-DC2-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             are correct.
             ......................... CH-DC2-2K8 passed test VerifyReferences
          Starting test: VerifyEnterpriseReferences
             ......................... CH-DC2-2K8 passed test VerifyEnterpriseReferences
          Starting test: CheckSecurityError
             * Dr Auth:  Beginning security errors check!
             Found KDC CH-DC1-2K8 for domain companyname.local in site Cardiff
             Checking machine account for DC CH-DC2-2K8 on DC CH-DC1-2K8.
             * SPN found :LDAP/ch-dc2-2k8.companyname.local/companyname.local
             * SPN found :LDAP/ch-dc2-2k8.companyname.local
             * SPN found :LDAP/CH-DC2-2K8
             * SPN found :LDAP/ch-dc2-2k8.companyname.local/companyname
             * SPN found :LDAP/abb03237-e91b-457f-ab16-788d5dc3930e._msdcs.companyname.local
             * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/abb03237-e91b-457f-ab16-788d5dc3930e/companyname.local
             * SPN found :HOST/ch-dc2-2k8.companyname.local/companyname.local
             * SPN found :HOST/ch-dc2-2k8.companyname.local
             * SPN found :HOST/CH-DC2-2K8
             * SPN found :HOST/ch-dc2-2k8.companyname.local/companyname
             * SPN found :GC/ch-dc2-2k8.companyname.local/companyname.local
             Checking for CN=CH-DC2-2K8,OU=Domain Controllers,DC=companyname,DC=local in domain DC=companyname,DC=local on 2 servers
                Object is up-to-date on all servers.
             [CH-DC2-2K8] No security related replication errors were found on this DC!  To target the connection to a specific source DC use /ReplSource:<DC>.
             ......................... CH-DC2-2K8 passed test CheckSecurityError
       Testing server: Cardiff\NA-DC1-2K8
          Starting test: Replications
             * Replications Check
             CN=Schema,CN=Configuration,DC=companyname,DC=local has 7 cursors.
             CN=Configuration,DC=companyname,DC=local has 7 cursors.
             DC=companyname,DC=local has 7 cursors.
             * Replication Latency Check
                CN=Schema,CN=Configuration,DC=companyname,DC=local
                   Latency information for 4 entries in the vector were ignored.
                      4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency
    information (Win2K DC).  
                CN=Configuration,DC=companyname,DC=local
                   Latency information for 4 entries in the vector were ignored.
                      4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency
    information (Win2K DC).  
                DC=companyname,DC=local
                   Latency information for 4 entries in the vector were ignored.
                      4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency
    information (Win2K DC).  
             * Replication Site Latency Check
             Site Settings = CN=NTDS Site Settings,CN=Edinburgh,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Site
             CN=NTDS Site Settings,CN=Edinburgh,CN=Sites,CN=Configuration,DC=companyname,DC=local
             was skipped because it never had an ISTG running in it.
             Site Settings = CN=NTDS Site Settings,CN=London,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Site
             CN=NTDS Site Settings,CN=London,CN=Sites,CN=Configuration,DC=companyname,DC=local
             was skipped because it never had an ISTG running in it.
             Site Settings = CN=NTDS Site Settings,CN=Belfast,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Site
             CN=NTDS Site Settings,CN=Belfast,CN=Sites,CN=Configuration,DC=companyname,DC=local
             was skipped because it never had an ISTG running in it.
             Site Settings = CN=NTDS Site Settings,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             [0x904de,v=62142,t=2015-04-23 09:16:18,g=a1d47848-fb4f-497b-a8a2-f11d40b71481,orig=20719256,local=5719216]
             Elapsed time (sec) = 2265
             ......................... NA-DC1-2K8 passed test Replications
          Starting test: Topology
             * Configuration Topology Integrity Check
             * Analyzing the connection topology for CN=Schema,CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the connection topology for CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the connection topology for DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             ......................... NA-DC1-2K8 passed test Topology
          Starting test: CutoffServers
             * Configuration Topology Aliveness Check
             * Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for CN=Configuration,DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for DC=companyname,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             ......................... NA-DC1-2K8 passed test CutoffServers
          Starting test: NCSecDesc
             * Security Permissions check for all NC's on DC NA-DC1-2K8.
             * Security Permissions Check for
               CN=Schema,CN=Configuration,DC=companyname,DC=local
                (Schema,Version 2)
             * Security Permissions Check for
               CN=Configuration,DC=companyname,DC=local
                (Configuration,Version 2)
             * Security Permissions Check for
               DC=companyname,DC=local
                (Domain,Version 2)
             ......................... NA-DC1-2K8 passed test NCSecDesc
          Starting test: NetLogons
             * Network Logons Privileges Check
             Verified share \\NA-DC1-2K8\netlogon
             Verified share \\NA-DC1-2K8\sysvol
             ......................... NA-DC1-2K8 passed test NetLogons
          Starting test: Advertising
             The DC NA-DC1-2K8 is advertising itself as a DC and having a DS.
             The DC NA-DC1-2K8 is advertising as an LDAP server
             The DC NA-DC1-2K8 is advertising as having a writeable directory
             The DC NA-DC1-2K8 is advertising as a Key Distribution Center
             The DC NA-DC1-2K8 is advertising as a time server
             The DS NA-DC1-2K8 is advertising as a GC.
             ......................... NA-DC1-2K8 passed test Advertising
          Starting test: KnowsOfRoleHolders
             Role Schema Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role Domain Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role PDC Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role Rid Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             Role Infrastructure Update Owner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             ......................... NA-DC1-2K8 passed test KnowsOfRoleHolders
          Starting test: RidManager
             ridManagerReference = CN=RID Manager$,CN=System,DC=companyname,DC=local
             * Available RID Pool for the Domain is 12100 to 1073741823
             fSMORoleOwner = CN=NTDS Settings,CN=CH-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local
             * ch-dc1-2k8.companyname.local is the RID Master
             * DsBind with RID Master was successful
             rIDSetReferences = CN=RID Set,CN=NA-DC1-2K8,OU=Domain Controllers,DC=companyname,DC=local
             * rIDAllocationPool is 11600 to 12099
             * rIDPreviousAllocationPool is 11600 to 12099
             * rIDNextRID: 11670
             ......................... NA-DC1-2K8 passed test RidManager
          Starting test: MachineAccount
             Checking machine account for DC NA-DC1-2K8 on DC NA-DC1-2K8.
             * SPN found :LDAP/na-dc1-2k8.companyname.local/companyname.local
             * SPN found :LDAP/na-dc1-2k8.companyname.local
             * SPN found :LDAP/NA-DC1-2K8
             * SPN found :LDAP/na-dc1-2k8.companyname.local/companyname
             * SPN found :LDAP/2961b38b-570f-4a35-908f-9818a8080c0d._msdcs.companyname.local
             * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/2961b38b-570f-4a35-908f-9818a8080c0d/companyname.local
             * SPN found :HOST/na-dc1-2k8.companyname.local/companyname.local
             * SPN found :HOST/na-dc1-2k8.companyname.local
             * SPN found :HOST/NA-DC1-2K8
             * SPN found :HOST/na-dc1-2k8.companyname.local/companyname
             * SPN found :GC/na-dc1-2k8.companyname.local/companyname.local
             ......................... NA-DC1-2K8 passed test MachineAccount
          Starting test: Services
             * Checking Service: Dnscache
             * Checking Service: NtFrs
             * Checking Service: IsmServ
             * Checking Service: kdc
             * Checking Service: SamSs
             * Checking Service: LanmanServer
             * Checking Service: LanmanWorkstation
             * Checking Service: RpcSs
             * Checking Service: w32time
             * Checking Service: NETLOGON
             ......................... NA-DC1-2K8 passed test Services
          Starting test: OutboundSecureChannels
             * The Outbound Secure Channels test
             ** Did not run Outbound Secure Channels test
             because /testdomain: was not entered
             ......................... NA-DC1-2K8 passed test OutboundSecureChannels
          Starting test: ObjectsReplicated
             NA-DC1-2K8 is in domain DC=companyname,DC=local
             Checking for CN=NA-DC1-2K8,OU=Domain Controllers,DC=companyname,DC=local in domain DC=companyname,DC=local on 3 servers
                Object is up-to-date on all servers.
             Checking for CN=NTDS Settings,CN=NA-DC1-2K8,CN=Servers,CN=Cardiff,CN=Sites,CN=Configuration,DC=companyname,DC=local in domain CN=Configuration,DC=companyname,DC=local on 3 servers
                Object is up-to-date on all servers.
             ......................... NA-DC1-2K8 passed test ObjectsReplicated
          Starting test: frssysvol
             * The File Replication Service SYSVOL ready test
             File Replication Service's SYSVOL is ready
             ......................... NA-DC1-2K8 passed test frssysvol

  • Remote Access to Windows 2008 R2 Server configured with local IP

    Hello,
    I have a Windows 2008 R2 Server configured with local IP (e.g. 192.168.1.115).
    Please how can I access it remotely outside its local domain through (remote desktop connection).
    Thank you.
    Tony.

    Hi Tony,
    Based on your description, you would like to connect to the Windows 2008 R2 server via remote desktop connection.
    So you need to enable remote desktop on the Windows 2008 R2 server if it is not already.
    1.Install and configure the Remote Desktop Session Host role service in the Windows 2008 R2 server.
    2.Add related user to the Remote Desktop Users group in the Windows 2008 R2 server.
    3.Configure remote desktop connection in the Client.                   
    Also, due to you would like to access it remotely outside the domain, so you will need a VPN connection or a port forward to connect through.
    For more details, please refer to the guide below,
    Installing and Configuring Remote Desktop Session Host
    http://technet.microsoft.com/en-us/library/dd883253.aspx
    Allow Remote Desktop connections from outside your home network
    http://windows.microsoft.com/en-IN/windows7/allow-remote-desktop-connections-from-outside-your-home-network
    Best Regards,
    Tina

  • Audio recording redirection in Windows 2008 R2

    Hi, i try to setting up audio recording redirection with no success. I use Windows 2008 R2 with Remote Desktop Services role installed and Windows Seven as client computer. I edit local group policy on Windows 2008 R2. Computer settings - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Device and resource redirection:
    Allow audio and video playback redirection - Enabled.
    Allow audio recording redirection - Enabled.
    With this setting i can hear audio on my local computer, but no recording devices in sound properties. Anybody know how to troubleshooting this behavior?
    Some screenshots from RDP Sessions.
    http://img27.imageshack.us/i/soundplayback.png/
    http://img24.imageshack.us/i/soundrecording.png/

    Hello Pavel,
    Thanks for your feedback.
    Regarding the sound latency issue, I agree with TP on the suggestions to troubleshoot it via hardware/driver level. Based on your feedback, this issue doesn’t appear after rebooting the terminal server. Please let us know if it happens again.
    Regarding your new question, I’d like to share the some assessment based on my experience.
    After the Remote Desktop Services role is removed from the server, the remote desktop connection will start administrative sessions to access the server. In such a case, redirections audio recording redirection is not supported any more, but Audio Playback redirection is still supported. Therefore, you can still get the sound redirection provided it is configured so. therefore, it is a normal behavior.
    Please feel free to let us know if you need any further assistance. Thanks.
    Lionel Chen
    TechNet Subscriber Support in forum
    If you have any feedback on our support, please contact [email protected]

  • How to check DFS replication status in windows 2008 r2 file server

    Hi,
    I have created File server DFS namespace between 2 windows 2008 R2 server. namespace mode is 2008. I have copied 3 TB data on file server 1. now it is getting replicated from file server 1 to file server 2. till now the data is not fully replicated.
    My question is how can I check the status of DFS replication? how will I come to know that the initial replication is completed.

    Scorpio. Yes you are right. Microsoft officially says it will not work. My apologies. Thanks for the correction.
    Do Ultrasound and Sonar work with DFS Replication?
    No. DFS Replication has its own set of monitoring and diagnostics tools. Ultrasound and Sonar are only capable of monitoring FRS.
    Is there a way to know the state of replication?
    Yes. There are a number of ways to monitor replication:
    DFS Replication has a management pack for System Center Operations Manager 2007 that provides proactive monitoring.
    DFS Replication has an in-box diagnostic report for the replication backlog, replication efficiency, and the number of files and folders in a given replication group.
    Dfsrdiag.exe is a command-line tool that can generate a backlog count or trigger a propagation test. Both show the state of replication. Propagation shows you if files are being replicated to all nodes. Backlog shows you how many files still need to replicate
    before two computers are in sync. The backlog count is the number of updates that a replication group member has not processed. On computers running Windows Server 2008 R2, Dfsrdiag.exe can also display the updates that DFS Replication is currently
    replicating.
    Scripts can use WMI to collect backlog information—manually or through MOM.
    Miguel Fra /
    Falcon IT Services
    Computer & Network Support, Miami, FL
    Visit our Knowledgebase and Support Sharepoint Site

  • Windows 2008 R2 group policy not applied on some of the computers

    Dear All,
    I have windows 2008 r2 as domain controller and configured group policy. when I am changing existing group policy most of the computers not affecting with update policy.
    is there any server or any other method required to configure?
    every time i need to update group policy manually on computers.
    pls help
    SUNIL PATEL SYSTEM ADMINISTRATOR

    You have an issue with AD DS replication.Ensure all domain controllers are in sync

  • Group policy Preferences server 2008 and windows 7

    Hi I have been struggling with an issue with group policy preferences for a while now with regard to pushing out printers to windows 7 (32/64 bit) Machines. I have two DC servers one is 2008 and the other is 2008 r2. I have setup the group policies on the
    2008 server as it is the only one i am allowed to access regularly to do this.
    Basically here is my problem. I have created multiple GPO's to send out printers from out print server to classrooms across the school district I work for, I have a mix of xp and windows 7 machines. I have the server setup with both 32 and 64bit drivers
    for all printers on that server, we have a mix of oki and hp and ricoh. I know all the connections work and the drivers work well, however when I push them out using the group policy, the windows 7 machines don't install the printers. The xp machines do this
    perfectly well when I install the client side extensions patch, but they just will not pull down on the 7 machines unless i install the printer first manually, then delete it and then run gpupdate. In that instance it will work, but obviously i don't want
    to have to go round thousands of computers doing this manually.
    Just as a side note, each classroom has its own user account and its own printer.
    If anyone has any advice as to how i can go about resolving this issue i would greatly appreciate it, this has been a problem i have been researching and trying to fix since January.......

    Hi,
    >>The xp machines do this perfectly well when I install the client side extensions patch, but they just will not pull down on the 7 machines unless i install the
    printer first manually, then delete it and then run gpupdate.
    Before going further, we can run command
    gpresult/h gpreport.html with admin privileges to collect group policy result on the troubled Windows 7 clients to check the issue. Besides, we can also check event logs in Event Viewer to see if some related error events were logged.
    Besides, I want to confirm if we have disabled
    Point and Print Restrictions under both User Configuration and Computer Configuration. To have a consistent experience, it’s recommended that we disable the policy setting in both locations if we are dealing with mixed-level clients.
    Regarding this point, the following article can be referred to for more information.
    Point and Print Restrictions policies are ignored in Windows Vista SP2, Windows Server 2008 SP2, and later Windows operating systems
    http://support.microsoft.com/kb/2307161/en-us
    Best regards,
    Frank Shen

  • Windows 2008 Group Policy not working in Windows 8.1

    Hi ,
    We found that the GPO settings created in Windows 2008 is not working in a Windows 8.1 machine.
    One example is the proxy settings.
    We confirmed from gpresult that the GPO is in the list but checking the actual proxy settings, it is not applied.
    Regards,
    Jhun

    Hi,
    How did we configure the proxy settings, using Internet Explorer Maintenance? If it is this case, just as Martin suggested, we can’t use IEM to manage
    IE 10 and IE 11.  However, we can configure the proxy setting via Group Policy Preferences (GPP).
    Regarding this point, the following blog can be referred to for more information.
    Configuring Internet Explorer 10′s
    Proxy Via Group Policy
    http://johnfail.wordpress.com/2013/06/15/configuring-internet-explorer-10s-proxy-via-group-policy/
    In addition, when we use this GPP extension, pay attention to GPP F5-F8 keys.
    Regarding this point, the following blog can be referred to for more information.
    Group Policy Preferences F5 F6 F7 F8 “documentation”
    http://msitpros.com/?p=1014
    Please Note: Since the above two websites are not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy
    of this information.
    In addition, regarding the deprecation of IEM, the following article can be referred to for more information.
    Appendix B: Replacements for Internet Explorer Maintenance
    http://technet.microsoft.com/en-us/library/jj890998.aspx
    Best regards,
    Frank Shen

  • Risks of two development groups in the same system

    Hi,
    I need your help.
    I'm looking for a document about the risks having two development groups in the same system.
    The point is: An external party will come soon and start the implementation of a mini H2R in the same system as we (the internal team) are working for SD, MM, CO,... As the developments are cross-client, I'm asked to write a document explaining the risks in such cases like:
    conflicts: working on the same objects
    authorisations: each group should be assigned to different packages
    planning: the go-live should be at the same time
    transports: there can be conflicts on a transport-level
    If you have any documentation that can help me, please let me know.
    Kind regards, Gilles.

    I hope this is not considered a link farm:
    Potential conflicts between already released transports:
    Program to validate transport sequence
    Uwe Schieferstein's blog on "Dangerous Liaisons in User-Exits and How to Avoid Them":
    /people/uwe.schieferstein/blog/2008/11/11/dangerous-liaisons-in-user-exits-and-how-to-avoid-them
    Just two of many things to observe...
    Thomas

  • Windows 2008 R2 - Group Policy Preference - folder option "Open with" Access denied

    Similar to this post:
    social.technet.microsoft.com/Forums/en-US/d42a81bc-96de-4af3-bc41-079e88e6ea4a
    We have Citrix terminal servers running Windows 2008 R2 and attempting to force PDF files to open with Acrobat versus PDF editing software we have installed for a small subset of users.  So I created a Group Policy Preference and added a OpenWith item
    to the Folder Options to use Acrobat as the default and linked it to a Users OU.  However, if I run gpresult the OpenWith setting fails with error code 0x80070005.  You can change it to not run in the user's security context which eliminates the
    error but then it won't actually do anything.
    The problem seems to be that when a user sets another program as their default via Windows Explorer the permissions on HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice get changed so that the user is specifically
    denied the ability to set that key.  Remove the special permissions added and the group policy succeeds and changes it back to the default ... until the user changes it back (intentionally or otherwise) and the permissions are changed again.
    Any ideas here?

    > Any ideas here?
    We use GPP Registry to achieve this goal, so we do not run into that
    issue (we unchecked "run in users context", so privs are not an issue)
    But I agree, this really should work as intended...
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Import Windows XP Group Policy into Windows 7?

    Is it possible to import a Windows XP Group Policy into Windows 7? It seems ZCM will not let you edit the XP policy from Windows 7 even though you can apply the policy to a Windows 7 Workstation and have the policy applied without issue. I'm still researching it, but the search terms return many Active Directory results.
    ZCM 10.3.3 on Linux. and eDirectory only.

    jcsmith1,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://forums.novell.com/

  • Material Group Replication from ECC

    Dear SRMers,
    System Landscape : ECC 6.0 and SRM 5.0.
    I am doing a material group replication from  ECC to SRM using the DNL_CUST_PROD1 customizing object. Before the replication ECC  was trying to confirm the target RFC destination(SRM) by prompting a logon. I logged in as myself and  the system gave a CALL_FUNCTION_OPEN_ERROR.
    I defined the CRM Consumer as SRM in the CRM middleware parameters..
    My question is do we need to define the User SRM in SU01 and when ECC tries to confirm the target RFC destination, do we need to login as the SRM User ?
    Points will be rewarded for answers.
    Thanks in advance,
    Bob

    Hi,
    The RFC user which you define in the SRM RFC detsination has to be obviously as SU01 user in SRM.Also the RFC user need to have SAP_ALL and SAP_NEW profile attached.See note 642202 for details.
    Also Check:
    http://help.sap.com/saphelp_erp2005vp/helpdata/en/84/d3eb4190966024e10000000a1550b0/frameset.htm
    BR,
    Disha.
    Pls reward points for useful answers.

  • WLC 5508 LDAP Windows 2008 Server - auth based on AD groups

    hi NG,
    i'm trying to web-authenticate my Wifi user of an WLC 5508 against LDAP.
    Thereby i'm trying to autenticate all users within a GROUP, not an OU within the MS Active Directory based upon an Windows 2008 Server.
    I can authenticate against a user, witch is beeing put into an OU, according to examples based here: https://www.cisco.com/en/US/products/ps6366/prod_configuration_examples_list.html
    Checking based upon Users within OUs works fine.
    But i have not got all of those users wihin one single OU!
    Need help for following:    LDAP-Auth based on AD Groups:
    Using:
    MS-Domain:                          MY-DOMAIN.CH
    AD-GROUP:                          VPN-USERS
    AD-Structure:
    MY-DOMAIN.CH
    |
    GROUPS
            |
        Administrative Groups
                          |
                     VPN-USERS
                              (-> Member of this Groups (Wireless1, Wirless2, ...)
    Server Adress:               IP.IP.IP.IP
    Port:                                 389
    Enable Server Stats      YES
    Simple Bind                    Authenticated
    Bind Username              LDAP-USER
    Bind Password               supersecret
    Bind Passw. confirm      supersecret
    User Base DN:               ?-1-?
    User Attribute:                ?-2-?
    User Object Type:          Person
    Server Timeout               2
    What happens for instance, if i put a GROUP within a GROUP regarding the LDAP Authentication.
    I guess i have to authenticate against the "upper" GROUP, or do i have to create an entry on the WLC for every GROUP i'm questoning?
    Could some one provide my with an example, since i have not found documentation regarding this topic.
    Thank you.

    Hi,
    User Base DN : this is in case you want to restrict the search area. If you put "dc=mydomain,dc=CH", you will search your whole AD. Depending on the size, it can be slow ...
    Remember that the User Base DN is also used for the admin user.
    In conclusion, User Base DN should be the most restrictive path that leads to both the admins and the users you want to authenticate.
    Example :
    OU=Employees,OU=Humans,DC=Mydomain,DC=CH
    This would prevent to search in machines or any assets. This implies that the admin you bind with is an employee and you are only authenticating employees. You can have any number of OUs under employees, it doesn't matter
    Attribute : This is the object attribute that the WLC uses to compare with the user name. In general, you would go with sAMAccountName in AD. CN would be another common example for LDAP databases.
    If what you are looking for is to restrict access and only authenticate people who belong to a certain group. Then you need a radius server like ACS.
    That server will be able to make selections and check the "memberOf" attribute to make sure it is in a certain group.
    Nicolas
    ===
    Don't forget to rate answers that you find useful

  • Windows 2008 R2 group policy not applied to windows 8 Workstations, but applied to XP and Win 7

    I have a Windows 2008 R2 Domain Controllers and have a Policy to put a specify wallpaper, eventuality i have to change the Wallpaper, this setting applied sucesfully in Windows xp and Windows 7 workstations, but not applied in Windows 8 workstations even
    if i run gpupdate /forcé,
    Best Regards,
    Thank you

    Hi,
    Thanks for posting in the forum.
    Before going further, would you please let me know how did you configure the Group Policy setting to deploy the wallpaper? Have you configured some settings to limit the scope the GPO applying?
    If all Windows 8 machines failed to receive the GPO settings? In order to narrow down the cause of the issue, I suggest we could try to collect the following information for troubleshooting.
    GPMC.log
    ==================
    a. On domain controller, click Start ->Run, type GPMC.MSC, it will load the GPMC console.
    b. Right click on "Group Policy Result" and choose wizard to generate a report for the problematic computer and user account (please place appropriately). (Choose computer and select the proper
    user in the wizard)
    c. Right click 
    the resulting group policy result and click the "Save Report…" => save report to save the report to a HTML file.
    Once we get the report, please check if the settings have been applied to the target correctly.
    In addition, would you please let me know whether you have imported the latest Windows 8 Administrative Templates to the Windows Server 2008 DC? If not, please try to download and import it.
    Then try to configure the wallpaper GPO settings again to see if it could help.
    For details, please refer to the following articles.
    Administrative Templates (.admx) for Windows 8 and Windows Server 2012
    http://www.microsoft.com/en-us/download/details.aspx?id=36991
    Set Desktop Background via Group Policy in Windows 7, Windows 8 in a Server 2008 or Server 2012 Domain
    http://dizzyit.com/2013/04/14/set-desktop-background-group-policy-windows-7-windows-8-server-2008-server-2012-domain/
    Hope this helps.
    Best Regards,
    Andy Qi
    TechNet Subscriber Support
    If you are
    TechNet Subscription user and have any feedback on our support quality, please send your feedback
    here.
    Andy Qi
    TechNet Community Support

  • Windows 2008 r2 Server: Cant update the group belonging

    Hello,
    I have a Windows 7 client computer which is administered by a Windows 2008 Server.
    When I try to change the local grants of the user account in that client computer,  it appears to me the following message:
    "Cant update the group belonging for NameDomain\user"
    As result I cant change local grants for the user. I cant change his status from administrator to user of that machine.
    Can anybody tell me how can I solve this issue?
    Thanks in advance
    Regards

    Hi,
    Thanks for your feedback. Did you mean that the issue exists after you removed
    DameWare tools?
    Please make sure that you have more than one administrator account on your computer, or you can't change it to a standard account since Windows requires at least one administrator account on a computer.
    If you have another administrator account, you can try to use it to change the user’s account type.
    Best regards,
    Susie

Maybe you are looking for

  • Mail and Attachments on 10.8

    Using Mail how do you get an attachment to post as an actual attachment rather than as an image in the mail.  If I sign a document, then scan it, and attach the jpeg to an email it is incorporated into the mail as an image.  Same thing happens if the

  • Issue with Keyboard Viewer

    I won't apologize for the cross-post because even though the following got a 100 views, it generated no responses in the MacBook forum. Maybe now that Eric is back from the Super Bowl...(:>) I'm trying to verify that Keyboard Viewer works the same in

  • DTW error while uploading the GL account

    Hi all I m trying to upload GL accounts from dtw with segment account and I created segment in sap but dtw uploaded the title account but active account is not uploading and its giving error ...enter valid code . please help Thanks \ ricky

  • App Tabs not being saved as it says they will

    In help it says: All of the App Tabs you have set when you close Firefox will open as App Tabs when you start Firefox again. Not true. I set about 10 App Tabs, close FF and when it came back NO App Tabs.

  • MMC cannot see network drives

    I have just build several PCs with Windows 8.1 Pro for my team. I have a problem with mmc.exe - it cannot seem to see any network drives. When I try to save a custom console, the dialog box only presents the local drives. If I try to open a saved fil