Data from active directory users and computers[dc.local.xx] is not available from domain controller dc.local.xx because the specified directory service attribute or value does not exist....

Etech 1 Reputation point
2022-01-25T09:45:15.527+00:00

Hello,

we are encountering the following issue as shown in the attached screenshot whenever we log in to the domain controller.

I need your help please as soon as possible

168253-adds-issue.jpg

Windows for business Windows Client for IT Pros Directory services Active Directory
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 39,916 Reputation points
    2022-02-01T09:57:40.287+00:00

    Hello Etech-6440,

    Thank you for your question.

    I just did some testing on my test domain, dsacls doesn't provide the ability to remove a specific ace that has been set. You will need to use ldp to remove the deny permission.

    1) If you open ldp connect and link to your ad

    2) Select the tree in the view menu and select your default NC

    3) In the tree pane right click your domain root and select advanced, security descriptor

    4) In the dialog check all nt authority entries/authenticated users to find the deny permission
    When you find the deny permission offensive, delete it and update

    This worked on my test domain!

    See also the article below that contains useful information:

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/dcpromo-demotion-fails


    If the answer is helpful, please upvote and accept it as an answer.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.