I had earlier posted an answer that pointed to DNS record permissions as the source of this problem. Turns out that was not the case, the actual cause of the problem was that the user account was in the "Protected Users" AD security group. I don't know exactly what aspect of that group is causing the issue (NTLM authentication being blocked?), but the problem resolved once I removed our user account from that group.
Access is denied when running DFS Replication Health report
Im receiving an "access is denied" error message on all of my replication groups when trying to run a health report:
There are no errors in the Windows server logs that help indicate any problem. The account I'm using to run the report has administrator rights on all of the file servers; I was able to recently add a new member to each replication group using the same account, no errors; the servers are all replicating fine. Any idea why I cant run these health reports?
Windows for business Windows Server User experience Other
1 additional answer
Sort by: Most helpful
-
Anonymous
2021-07-20T02:33:18.697+00:00 Hi,
To make the question more clearly, please confirm the following questions:
Do you mean the user running the report was delegated administrative permission on the file servers or is a member of the local administrators group?
Did you delegate DFS-R management permission?
To create a diagnostic report, you must be a member of the local Administrators group on each server that you prepare a report for.
Best Regards,