Active Directory Domain Services could not replicate the directory partition CN=Configuration,DC=xxxx,DC=LOCAL from the remote Active Directory Domain Controller xxx.xxxx.LOCAL. "Replication access was denied."

Saleh Al Adwan 136 Reputation points
2022-01-15T15:23:38.357+00:00

I face an issue while promoting new Domain Controller (Additional Domain Controller); this domain controller must be the 7th DC in the forset/domain, the promotion is failed each time with the Following error:

The operation failed because:

Active Directory Domain Services could not replicate the directory partition CN=Configuration,DC=xxxx,DC=LOCAL from the remote Active Directory Domain Controller xxx.xxxx.LOCAL.

"Replication access was denied."

The user account I used for promotion is member of: Enterprise Admins, Schema Admins, Domain Admins, Administrators, also I set it in Domain Controllers Group, with full controll/permission on Configuration Partition (Adsi Edit)

I am able to promote Read Only Domain Controller (RODC) but the issue appreaes only during promoting new Writable DC, which lead to failed promotion process.

appreciate Any help.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} vote

3 answers

Sort by: Most helpful
  1. Saleh Al Adwan 136 Reputation points
    2022-01-17T15:22:02.467+00:00

    Thankfully I am able to solve this issue, it was due to Deny permission on “Replicating Directory Changes All” role for Administrators group on configuration partition at “ADSIEdit”, when I changed it to allow the issue resolved successfully.

    3 people found this answer helpful.

  2. Falcon IT Services 226 Reputation points
    2022-01-15T16:08:23.437+00:00

    Hello,

    Have you run repadmin to verify that bi-directional replication is healthy on all other DC's?

    Check that DNS role is installed and it may help to make sure server is a domain member

    Miguel Fra
    https://www.falconitservices.com


  3. Anonymous
    2022-01-15T16:44:22.777+00:00

    You can work through this one.
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/replication-error-8453

    --please don't forget to upvote and Accept as answer if the reply is helpful--


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.