If a domain controller has tombstoned the recommended (and only) solution is to demote, reboot, promo it again.
--please don't forget to Accept as answer if the reply is helpful--
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi everyone, i have problem in my environment, we are using 4 domain controllers and in 2 domain controller in event day, every 24 hours give error EventID 1864.
CN=Schema,CN=Configuration,DC=AGH,DC=com
CN=Configuration,DC=AGH,DC=com
DC=AGH,DC=com
This directory server has not recently received replication information from a number of directory servers. The count of directory servers is shown, divided into the following intervals.
More than 24 hours:
1
More than a week:
1
More than one month:
1
More than two months:
1
More than a tombstone lifetime:
0
Tombstone lifetime (days):
372
Directory servers that do not replicate in a timely manner may encounter errors. They may miss password changes and be unable to authenticate. A DC that has not replicated in a tombstone lifetime may have missed the deletion of some objects, and may be automatically blocked from future replication until it is reconciled.
To identify the directory servers by name, use the dcdiag.exe tool.
You can also use the support tool repadmin.exe to display the replication latencies of the directory servers. The command is "repadmin /showvector /latency <partition-dn>".
also i tried to check with this commands:
repadmin /kcc
repadmin /replsummary
repadmin /syncall
always received "passed test"
i cannot understand where is problem?
If a domain controller has tombstoned the recommended (and only) solution is to demote, reboot, promo it again.
--please don't forget to Accept as answer if the reply is helpful--
I'd also check the required ports are flowing between sites.
https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts
https://www.microsoft.com/en-us/download/details.aspx?id=24009
--please don't forget to Accept as answer
if the reply is helpful--
Hi,
Try the methods for Troubleshoot Active Directory replication error 8614:
https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/replication-error-8614
Best Regards,
Have you tried moving roles off, demote, reboot, promo it again?
--please don't forget to Accept as answer
if the reply is helpful--
Then I'd check the required ports are flowing between them.
https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts
https://www.microsoft.com/en-us/download/details.aspx?id=24009
--please don't forget to Accept as answer
if the reply is helpful--