AD is not reachable but it runs (The specified domain either does not exist or could not be contacted)

Jonas Bauer 26 Reputation points
2022-11-16T21:14:23.627+00:00

Hello,
I am still new in the administration area and currently face an unsolvable problem. If there are any questions, please just ask and do not just write technical terms, because I'm not quite so fit.

About my problem:
Currently a Windows Server 2012 is used as DC for AD and is currently the only server that runs the AD (still to be changed). The clients are Windows 10 21H2 or 22H2.
From one day to the next the domain was no longer accessible to add new users or join computers the domain. I can see all old entries in users, but cannot add a new one.
LDAP is still working and can be used by the current clients and websites for authentication.
Extra information for the dcdiag command, in the past there were up to 3 DC which are either unreachable or disabled.
Here is a link to the dcdiag command: https://justpaste.it/5v5zk
The first guess was after some searching, the DNS is broken.
Here is the information:

  • There is only one forward lookup domain for the AD
  • DNS is running stable
  • Dcdiag says that SOA Entry is missing, but it is there.
  • The server has entered itself as DNS
  • Only ipv4
    Ping to own server pdm.sam.company.de works fine.
    Translated with www.DeepL.com/Translator (free version)Nslookup to pdm.sam.company.de gives the ip address back from our webserver (extern hosted + extern dns) with the name pdm.sam.company.de.company.de that’s completely wrong.
    But nslookup to pdm.sam.company.de. works fine without problems.
    And the clients in your network can make nslookup to pdm.sam.company.de (without root) and works fine. Only the server itself has that problem.
    The errors which I get if I want to add a new computer or user:
    -> The specified domain either does not exist or could not be contacted.
    -> Windows cannot verify that user name is unique because the following error occured while contacting the global catalog.
    -> Windows cannot create the object <username> because: The directory service has exhausted the pool of relative identifiers.

And here some new errors from the event view:

  • SRMSVC Event 12344,
    -> File Server Resource Manager finished syncing claims from Active Directory and encountered errors during the sync (0x8007054b, The specified domain either does not exist or could not be contacted.).
  • GroupPolicy Event 1054,
    -> The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.
  • ActiveDirectory_DomainService Event 2092,
    -> This server is the owner of the following FSMO role, but does not consider it valid. For the partition which contains the FSMO, this server has not replicated successfully with any of its partners since this server has been restarted. Replication errors are preventing validation of this role. Operations which require contacting a FSMO operation master will fail until this condition is corrected. FSMO Role: CN=RID Manager$,CN=System,DC=sam,DC=company,DC=de

And I also got sometimes the error message the global catalog is missing.
Most of the answers which I read in the last weeks, say the problem is the DNS but I tried many things, rebuild both zones: sam.company.de and _msdcs.sam.company.de, started and stopped netlogon, flushed and registereddns with ipconfig.
It would be really nice if someone had that problem or maybe knows there to search because I have no idea anymore and sorry for my English.

Jonas

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,853 questions
Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
1,021 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426.1K Reputation points MVP
    2022-11-17T16:39:51.567+00:00

    PDMINNSTADT, failed connectivity
    EXCHANGE1, failed connectivity
    PDM-CONTACT-WIN failed connectivity

    If these ones have been removed or no longer exist, then seize roles to another healthy one (if needed)
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds

    then perform some cleanup
    https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/ad-ds-metadata-cleanup
    https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-manually-removing-a-domain-controller-server/ba-p/280564

    and rebuild failed ones if needed.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    2 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. darkdays 6 Reputation points
    2022-11-17T17:54:18.297+00:00

    Jonas,

    Your domain have or had 4 Domain Controllers, most of them seems to be down/gone.

    Domain: sam.company.de

    PDM-CONTACT-WIN FAIL FAIL n/a n/a n/a n/a n/a
    Exchange1 FAIL FAIL n/a n/a n/a n/a n/a
    pdmInnstadt FAIL FAIL n/a n/a n/a n/a n/a
    PDM PASS WARN PASS PASS PASS FAIL n/a

    You PDC Emulator is gone.

    Do you have any Active Directory Aware backup of this environment ?

    1 person found this answer helpful.
    0 comments No comments