Domain controller caught USN rollback

2022-09-25T12:52:41.683+00:00

Guys tell me what to do, there are two domain controllers DC1 (win2012) and DC2 (win2008) on the network. DHCP and DFS are spinning on DC1, there was a power outage, the server crashed after DC1 was loaded (There was an error 0xc00002e2, which I sort of overcame and the server booted up) caught USN rollback. Replication does not occur. servers are spinning in vvmware, there is a backup when it was operational. some advise in the registry to fix the DSA not writable key to 4 and make repadmin /options DC1 -DISABLE_OUTBOUND_REPL and also -DISABLE_INBOUND_REPL what could it be? the second option is to transfer the fsmo rolls to DC2 and downgrade DC1, but how to migrate DFS? on a bunch of client PCs, a network drive is mapped that refers to the DFS namespace. and option 3 to restore from a copy of DC1 with a disconnected network, make a backup and restore using regular means, turn off DC1 (which caught USN) and turn on the restored one. how to be? more interested in the first simplest option, what could be the consequences if you fix the registry and enable replication ... ..

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,525 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Dave Patrick 426K Reputation points MVP
    2022-09-25T12:56:51.327+00:00

    You could try a non authoritative sync
    https://support.microsoft.com/en-us/help/2218556/how-to-force-an-authoritative-and-non-authoritative-synchronization-fo

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  2. 2022-09-25T13:39:56.817+00:00

    and deleting the registry key(DSA not writable) and starting the synchronization will not help defeat Usn rollback?

    0 comments No comments

  3. Dave Patrick 426K Reputation points MVP
    2022-09-25T13:46:07.427+00:00

  4. Limitless Technology 43,921 Reputation points
    2022-09-28T07:48:16.677+00:00

    Hello there,

    Can you post the complete event viewer error if you have ?. Also give some information about the amount of DCs in use and how they are located, single subnet, single/multi domain forest.

    If the second server has tomb stoned the only solution is to size roles (if necessary) to another healthy one
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds

    This article describes a silent Active Directory replication failure that is caused by an update sequence number (USN) rollback. A USN rollback occurs when an older version of an Active Directory database is incorrectly restored or pasted into place.

    A Windows Server domain controller logs Directory Services event 2095 when it encounters a USN rollback https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/detect-and-recover-from-usn-rollback

    Domain Controllers Replication issue https://learn.microsoft.com/en-us/answers/questions/585483/domain-controllers-replication-issue.html

    I hope this information helps. If you have any questions please let me know and I will be glad to help you out.

    -----------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments