Active Directory questions
what happens when active directory server turned off accident 6 months. after 6 months dc turned on , out of sync other dcs. since passed default tombstone of ad, replication occur or try occur. 6 month dc turned off, replicate missing changes or try replicate missing changes other dcs dont have has causing stale records or other dcs try update new information?
second question related ad replication. ran command repadmin /showpostmail /latency dc=va,dc=postmail,dc=com , showed me sids below instead of showing me site link , dc name. entries expired, trying understand doing , if harm if leave them or disappear automatically.
c992b4e5-4bb9-4183-a9d3-57c82c4a6e6f @ usn 135422 @ time 2012-01-26 18:48:58
8cce4140-02d9-4c05-94y4-80235eeae424 @ usn 131209 @ time 2012-02-17 19:59:56
what happens when active directory server turned off accident 6 months. after 6 months dc turned on , out of sync other dcs. since passed default tombstone of ad, replication occur or try occur. 6 month dc turned off, replicate missing changes or try replicate missing changes other dcs dont have has causing stale records or other dcs try update new information?
when exceed tombstone lifetime period of forest, not able replicate other dcs. why need proceed mentioned in following wiki article: http://social.technet.microsoft.com/wiki/contents/articles/18513.active-directory-replication-issues-basic-troubleshooting-steps-single-ad-domain-in-a-single-ad-forest.aspx
"
domain controller becomes tombstoned if exceeds forest tombstone lifetime period without replicating other domain contollers.
determine tombstone lifetime forest: http://technet.microsoft.com/en-us/library/cc784932(v=ws.10).aspx
condition can identified running dcdiag and repadmin commands. details in following microsoft kb.
troubleshooting ad replication error 8614: "the active directory cannot replicate server because time since last replication server has exceeded tombstone lifetime": http://support.microsoft.com/kb/2020053
if have tombstoned domain controller, need proceed following:
- force demotion of domain controller using dcpromo /forceremoval command (you can re-install or decommission it)
- seize fsmo roles domain controller holding domain controller (you can use netdom query fsmo command list of fsmo holders): http://support.microsoft.com/kb/255504
- do metadata cleanup of faulty domain controller references: http://technet.microsoft.com/en-us/library/cc736378(v=ws.10).aspx
"
second question related ad replication. ran command repadmin /showpostmail /latency dc=va,dc=postmail,dc=com , showed me sids below instead of showing me site link , dc name. entries expired, trying understand doing , if harm if leave them or disappear automatically.
proceed first mentioned previously. once done, re-run command , check again.
this posting provided "as is" no warranties or guarantees , , confers no rights.
get active directory user last logon create active directory test domain similar production one management of test accounts in active directory production domain - part i management of test accounts in active directory production domain - part ii management of test accounts in active directory production domain - part iii reset active directory user password
Windows Server > Directory Services
Comments
Post a Comment