Windows Server 2012R2 ActiveDirectory domain controller lose all group policy configuration

国靖 陆 20 Reputation points
2023-02-08T07:58:56+00:00

Hello everyone

The Windows Server 2012 R2 domain of our enterprise was lost in the early morning of February 1st, including the domain default policy and the domain controller default policy, and all configurations were missing.

Checked the logs and did not see any related errors. The data replication mode is checked, and the current FRS replication is used, and the relevant logs are only recorded until February 3.

How can I troubleshoot what caused it?

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,770 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,170 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,898 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426.1K Reputation points MVP
    2023-02-09T03:12:32.29+00:00

    It isn't recommended to restore a single DC in a multi-DC environment. The much cleaner / safer method is to seize roles to another healthy one.

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds

    then perform cleanup to remove the remnants of failed one from active directory.

    Clean up Active Directory Domain Controller server metadata

    Step-By-Step: Manually Removing A Domain Controller Server

    Then use dcdiag / repadmin tools to verify health correcting all errors found before starting any operations. Then stand up the new one for replacement, patch it fully, license it, join existing domain, add active directory domain services, promote it also making it a GC (recommended), transfer FSMO roles over (optional), transfer pdc emulator role (optional), use dcdiag / repadmin tools to again verify health.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


2 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,586 Reputation points
    2023-02-08T11:29:47.72+00:00

    Hi @国靖 陆

    Check in event viewer if there is any error on DFSR replication for sysvol folder.

    Run the following to check health of the impacted domain controller dcdiag

    Check the statut of AD replication , repadmin /showrepl

    Don't forget to mark helpful answer as accepted


  2. Dave Patrick 426.1K Reputation points MVP
    2023-02-08T13:36:18.6566667+00:00

    The Windows Server 2012 R2 domain of our enterprise was lost

    Are there other domain controllers? Did you restore from a backup?