AD DS errors after new 2022 DC promotion in 2012 domain

Tim Gibney 1 Reputation point
2022-02-02T17:05:57.393+00:00

Migrating to 2022 domain controllers. Two 2012 DCs existing, DC0 and DC1. Added one 2022 DC, DC2, transferred FSMO and included GC. Domain functional level is Windows Server 2012 and cannot be raised because of inappropriate versions of windows. Errors are causing GPO failures. Here are dcdiag /v listings for each domain controller, DC2, DC1, and DC0 all run from domain admin powershell on DC2.

PS C:\Windows\system32> dcdiag /v

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   * Verifying that the local machine DC2, is a Directory Server.
   Home Server = DC2
   * Connecting to directory service on server DC2.
   * Identified AD Forest.
   Collecting AD specific global data
   * Collecting site info.
   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=company,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded
   Iterating through the sites
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   Getting ISTG and options for the site
   * Identifying all servers.
   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=company,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
   The previous call succeeded....
   The previous call succeeded
   Iterating through the list of servers
   Getting information for the server CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=DC0,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   * Identifying all NC cross-refs.
   * Found 3 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC2
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         Determining IP4 connectivity
         * Active Directory RPC Services Check
         ......................... DC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC2
      Starting test: Advertising
         The DC DC2 is advertising itself as a DC and having a DS.
         The DC DC2 is advertising as an LDAP server
         The DC DC2 is advertising as having a writeable directory
         The DC DC2 is advertising as a Key Distribution Center
         The DC DC2 is advertising as a time server
         The DS DC2 is advertising as a GC.
         ......................... DC2 passed test Advertising
      Test omitted by user request: CheckSecurityError
      Test omitted by user request: CutoffServers
      Starting test: FrsEvent
         * The File Replication Service Event log test
         Skip the test because the server is running DFSR.
         ......................... DC2 passed test FrsEvent
      Starting test: DFSREvent
         The DFS Replication Event Log.
         There are warning or error events within the last 24 hours after the SYSVOL has been shared.  Failing SYSVOL
         replication problems may cause Group Policy problems.
         A warning event occurred.  EventID: 0x80001396
            Time Generated: 02/01/2022   16:08:16
            Event String:
            The DFS Replication service is stopping communication with partner DC1 for replication group Domain System Volume due to an error. The service will retry the connection periodically.

            Additional Information:
            Error: 9033 (The request was cancelled by a shutdown)
            Connection ID: 3D091FC6-B96D-4C56-AD2C-3635C6842066
            Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
         A warning event occurred.  EventID: 0x80001396
            Time Generated: 02/01/2022   16:14:31
            Event String:
            The DFS Replication service is stopping communication with partner DC0 for replication group Domain System Volume due to an error. The service will retry the connection periodically.

            Additional Information:
            Error: 9036 (Paused for backup or restore)
            Connection ID: 29FD6D3F-8786-4BE2-99BD-706CCD3D5966
            Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
         ......................... DC2 passed test DFSREvent
      Starting test: SysVolCheck
         * The File Replication Service SYSVOL ready test
         File Replication Service's SYSVOL is ready
         ......................... DC2 passed test SysVolCheck
      Starting test: KccEvent
         * The KCC Event log test
         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... DC2 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         Role Schema Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role Domain Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role PDC Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role Rid Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         ......................... DC2 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         Checking machine account for DC DC2 on DC DC2.
         * SPN found :LDAP/DC2.company.local/company.local
         * SPN found :LDAP/DC2.company.local
         * SPN found :LDAP/DC2
         * SPN found :LDAP/DC2.company.local/company
         * SPN found :LDAP/e4108a20-33b9-4078-90df-ddfcbb424bc3._msdcs.company.local
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/e4108a20-33b9-4078-90df-ddfcbb424bc3/company.local
         * SPN found :HOST/DC2.company.local/company.local
         * SPN found :HOST/DC2.company.local
         * SPN found :HOST/DC2
         * SPN found :HOST/DC2.company.local/company
         * SPN found :GC/DC2.company.local/company.local
         ......................... DC2 passed test MachineAccount
      Starting test: NCSecDesc
         * Security Permissions check for all NC's on DC DC2.
         * Security Permissions Check for
           DC=ForestDnsZones,DC=company,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for
           DC=DomainDnsZones,DC=company,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for
           CN=Schema,CN=Configuration,DC=company,DC=local
            (Schema,Version 3)
         * Security Permissions Check for
           CN=Configuration,DC=company,DC=local
            (Configuration,Version 3)
         * Security Permissions Check for
           DC=company,DC=local
            (Domain,Version 3)
         ......................... DC2 passed test NCSecDesc
      Starting test: NetLogons
         * Network Logons Privileges Check
         Verified share \\DC2\netlogon
         Verified share \\DC2\sysvol
         ......................... DC2 passed test NetLogons
      Starting test: ObjectsReplicated
         DC2 is in domain DC=company,DC=local
         Checking for CN=DC2,OU=Domain Controllers,DC=company,DC=local in domain DC=company,DC=local on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local in domain CN=Configuration,DC=company,DC=local on 1 servers
            Object is up-to-date on all servers.
         ......................... DC2 passed test ObjectsReplicated
      Test omitted by user request: OutboundSecureChannels
      Starting test: Replications
         * Replications Check
         * Replication Latency Check
            DC=ForestDnsZones,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            DC=DomainDnsZones,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            CN=Schema,CN=Configuration,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            CN=Configuration,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
         ......................... DC2 passed test Replications
      Starting test: RidManager
         * Available RID Pool for the Domain is 3101 to 1073741823
         * DC2.company.local is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 2601 to 3100
         * rIDPreviousAllocationPool is 2601 to 3100
         * rIDNextRID: 2604
         ......................... DC2 passed test RidManager
      Starting test: Services
         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: DFSR
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... DC2 passed test Services
      Starting test: SystemLog
         * The System Event log test
         A warning event occurred.  EventID: 0x000003FC
            Time Generated: 02/02/2022   08:12:27
            Event String: Scope, 192.168.1.0, is 85 percent full with only 34 IP addresses remaining.
         A warning event occurred.  EventID: 0x00000560
            Time Generated: 02/02/2022   08:12:27
            Event String: IP address range of scope 192.168.1.0 is 85 percent full with only 34 IP addresses available.
         Found no errors in "System" Event log in the last 60 minutes.
         ......................... DC2 passed test SystemLog
      Test omitted by user request: Topology
      Test omitted by user request: VerifyEnterpriseReferences
      Starting test: VerifyReferences
         The system object reference (serverReference) CN=DC2,OU=Domain Controllers,DC=company,DC=local and backlink on
         CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local are correct.
         The system object reference (serverReferenceBL)
         CN=DC2,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=company,DC=local and backlink
         on CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         are correct.
         The system object reference (msDFSR-ComputerReferenceBL)
         CN=DC2,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=company,DC=local and backlink
         on CN=DC2,OU=Domain Controllers,DC=company,DC=local are correct.
         ......................... DC2 passed test VerifyReferences
      Test omitted by user request: VerifyReplicas

      Test omitted by user request: DNS
      Test omitted by user request: DNS

   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : company
      Starting test: CheckSDRefDom
         ......................... company passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... company passed test CrossRefValidation

   Running enterprise tests on : company.local
      Test omitted by user request: DNS
      Test omitted by user request: DNS
      Starting test: LocatorCheck
         GC Name: \\DC2.company.local
         Locator Flags: 0xe003f1fd
         PDC Name: \\DC2.company.local
         Locator Flags: 0xe003f1fd
         Time Server Name: \\DC2.company.local
         Locator Flags: 0xe003f1fd
         Preferred Time Server Name: \\DC1.company.local
         Locator Flags: 0xe00073fc
         KDC Name: \\DC2.company.local
         Locator Flags: 0xe003f1fd
         ......................... company.local passed test LocatorCheck
      Starting test: Intersite
         Skipping site Default-First-Site-Name, this site is outside the scope provided by the command line arguments
         provided.
         ......................... company.local passed test Intersite
PS C:\Windows\system32> dcdiag /v /s:DC1

Directory Server Diagnosis

Performing initial setup:
   * Connecting to directory service on server DC1.
   * Identified AD Forest.
   Collecting AD specific global data
   * Collecting site info.
   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=company,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded
   Iterating through the sites
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   Getting ISTG and options for the site
   * Identifying all servers.
   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=company,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
   The previous call succeeded....
   The previous call succeeded
   Iterating through the list of servers
   Getting information for the server CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=DC0,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   * Identifying all NC cross-refs.
   * Found 3 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         Determining IP4 connectivity
         * Active Directory RPC Services Check
         ......................... DC1 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\DC1
      Starting test: Advertising
         The DC DC1 is advertising itself as a DC and having a DS.
         The DC DC1 is advertising as an LDAP server
         The DC DC1 is advertising as having a writeable directory
         The DC DC1 is advertising as a Key Distribution Center
         The DC DC1 is advertising as a time server
         The DS DC1 is advertising as a GC.
         ......................... DC1 passed test Advertising
      Test omitted by user request: CheckSecurityError
      Test omitted by user request: CutoffServers
      Starting test: FrsEvent
         * The File Replication Service Event log test
         Skip the test because the server is running DFSR.
         ......................... DC1 passed test FrsEvent
      Starting test: DFSREvent
         The DFS Replication Event Log.
         There are warning or error events within the last 24 hours after the SYSVOL has been shared.  Failing SYSVOL replication problems may cause Group Policy problems.
         A warning event occurred.  EventID: 0x800008A5
            Time Generated: 02/01/2022   16:08:31
            Event String:
            The DFS Replication service stopped replication on volume C:. This occurs when a DFSR JET database is not shut down cleanly and Auto Recovery is disabled. To resolve this issue, back up the files in the affected replicated folders, and then use the ResumeReplication WMI method to resume replication.

            Additional Information:
            Volume: C:
            GUID: 3546FBC5-C955-11E5-93E7-806E6F6E6963

            Recovery Steps
            1. Back up the files in all replicated folders on the volume. Failure to do so may result in data loss due to unexpected conflict resolution during the recovery of the replicated folders.
            2. To resume the replication for this volume, use the WMI method ResumeReplication of the DfsrVolumeConfig class. For example, from an elevated command prompt, type the following command:
            wmic /namespace:\\root\microsoftdfs path dfsrVolumeConfig where volumeGuid="3546FBC5-C955-11E5-93E7-806E6F6E6963" call ResumeReplication

            For more information, see http://support.microsoft.com/kb/2663685.
         ......................... DC1 passed test DFSREvent
      Starting test: SysVolCheck
         * The File Replication Service SYSVOL ready test
         File Replication Service's SYSVOL is ready
         ......................... DC1 passed test SysVolCheck
      Starting test: KccEvent
         * The KCC Event log test
         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... DC1 passed test KccEvent
      Starting test: KnowsOfRoleHolders
         Role Schema Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role Domain Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role PDC Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role Rid Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
         ......................... DC1 passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         Checking machine account for DC DC1 on DC DC1.
         * SPN found :LDAP/DC1.company.local/company.local
         * SPN found :LDAP/DC1.company.local
         * SPN found :LDAP/DC1
         * SPN found :LDAP/DC1.company.local/company
         * SPN found :LDAP/3eb456f6-a2a8-4e85-8519-4f93c6dfff82._msdcs.company.local
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/3eb456f6-a2a8-4e85-8519-4f93c6dfff82/company.local
         * SPN found :HOST/DC1.company.local/company.local
         * SPN found :HOST/DC1.company.local
         * SPN found :HOST/DC1
         * SPN found :HOST/DC1.company.local/company
         * SPN found :GC/DC1.company.local/company.local
         ......................... DC1 passed test MachineAccount
      Starting test: NCSecDesc
         * Security Permissions check for all NC's on DC DC1.
         * Security Permissions Check for
           DC=ForestDnsZones,DC=company,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for
           DC=DomainDnsZones,DC=company,DC=local
            (NDNC,Version 3)
         * Security Permissions Check for
           CN=Schema,CN=Configuration,DC=company,DC=local
            (Schema,Version 3)
         * Security Permissions Check for
           CN=Configuration,DC=company,DC=local
            (Configuration,Version 3)
         * Security Permissions Check for
           DC=company,DC=local
            (Domain,Version 3)
         ......................... DC1 passed test NCSecDesc
      Starting test: NetLogons
         * Network Logons Privileges Check
         Verified share \\DC1\netlogon
         Verified share \\DC1\sysvol
         ......................... DC1 passed test NetLogons
      Starting test: ObjectsReplicated
         DC1 is in domain DC=company,DC=local
         Checking for CN=DC1,OU=Domain Controllers,DC=company,DC=local in domain DC=company,DC=local on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local in domain CN=Configuration,DC=company,DC=local on 1 servers
            Object is up-to-date on all servers.
         ......................... DC1 passed test ObjectsReplicated
      Test omitted by user request: OutboundSecureChannels
      Starting test: Replications
         * Replications Check
         * Replication Latency Check
            DC=ForestDnsZones,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            DC=DomainDnsZones,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            CN=Schema,CN=Configuration,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            CN=Configuration,DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
            DC=company,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
         ......................... DC1 passed test Replications
      Starting test: RidManager
         * Available RID Pool for the Domain is 3101 to 1073741823
         * DC2.company.local is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 2101 to 2600
         * rIDPreviousAllocationPool is 2101 to 2600
         * rIDNextRID: 2344
         ......................... DC1 passed test RidManager
      Starting test: Services
         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: DFSR
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... DC1 passed test Services
      Starting test: SystemLog
         * The System Event log test
         A warning event occurred.  EventID: 0x000003FC
            Time Generated: 02/02/2022   07:44:13
            Event String: Scope, 192.168.1.0, is 84 percent full with only 35 IP addresses remaining.
         A warning event occurred.  EventID: 0x00000560
            Time Generated: 02/02/2022   07:44:13
            Event String: IP address range of scope 192.168.1.0 is 84 percent full with only 35 IP addresses available.
         Found no errors in "System" Event log in the last 60 minutes.
         ......................... DC1 passed test SystemLog
      Test omitted by user request: Topology
      Test omitted by user request: VerifyEnterpriseReferences
      Starting test: VerifyReferences
         The system object reference (serverReference) CN=DC1,OU=Domain Controllers,DC=company,DC=local and backlink on
         CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local are correct.
         The system object reference (serverReferenceBL) CN=DC1,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=company,DC=local and backlink on
         CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local are correct.
         The system object reference (msDFSR-ComputerReferenceBL) CN=DC1,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=company,DC=local and
         backlink on CN=DC1,OU=Domain Controllers,DC=company,DC=local are correct.
         ......................... DC1 passed test VerifyReferences
      Test omitted by user request: VerifyReplicas

      Test omitted by user request: DNS
      Test omitted by user request: DNS

   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : company
      Starting test: CheckSDRefDom
         ......................... company passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... company passed test CrossRefValidation

   Running enterprise tests on : company.local
      Test omitted by user request: DNS
      Test omitted by user request: DNS
      Starting test: LocatorCheck
         GC Name: \\DC1.company.local
         Locator Flags: 0xe00073fc
         PDC Name: \\DC2.company.local
         Locator Flags: 0xe003f1fd
         Time Server Name: \\DC1.company.local
         Locator Flags: 0xe00073fc
         Preferred Time Server Name: \\DC1.company.local
         Locator Flags: 0xe00073fc
         KDC Name: \\DC1.company.local
         Locator Flags: 0xe00073fc
         ......................... company.local passed test LocatorCheck
      Starting test: Intersite
         Skipping site Default-First-Site-Name, this site is outside the scope provided by the command line arguments provided.
         ......................... company.local passed test Intersite
PS C:\Windows\system32> dcdiag /v /s:DC0

Directory Server Diagnosis

Performing initial setup:
   * Connecting to directory service on server DC0.
   * Identified AD Forest.
   Collecting AD specific global data
   * Collecting site info.
   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=company,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded
   Iterating through the sites
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
   Getting ISTG and options for the site
   * Identifying all servers.
   Calling
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Tim Gibney 1 Reputation point
    2022-02-04T16:30:15.297+00:00

    The demotion was mostly successful. Certificate Services had to be removed first but only after a backup and other than local machine automatic certs, certs and CA had not been fully rolled out luckily. CA with a root CA and secondary CA will be rolled out after these DC issues are fixed.

    DDC1 was demoted and put into the workgroup. At first it could not rejoin the domain because the demotion did not remove the object from ADUC and ADSS. The list at the bottom of [this page][1] was followed and will be completed today. How does one do the following:

    3.Verify that FRS member objects (FRS and DFS) are removed, and remove them if they are present. 5.Remove any DFS references to the demoted server, such as links or root replicas.

    DC2, the new Server 2022 DC owned all FSMO roles and was itself a GC as well as DHCP and DNS (primary).

    DC1 was/is a DHCP and DNS server. So once the left-over objects of DC1 was removed from ADUC and ADSS (which also seemed to clean up all the DNS entries) it was allowed to rejoin the domain. DHCP was successfully replicated from DC2 to DC1 and nslookup was used to verify DNS.

    There are still DC issues as can be seen from this listing of dcdiag /c /v /e

    Starting at line 108 thru 234 DC0 is still looking at DC1 (for replication?) and DC0 fails DFSREvent.

    Starting at line 754 thru 851 DC2 is still looking at DC1 (for replication?) and DC2 fails DFSREvent.

    Starting at line 1065 thru 1421 DNS delegation is broken.

    PS C:\Windows\system32> dcdiag /v /c /e
    
    Directory Server Diagnosis
    
    Performing initial setup:
       Trying to find home server...
       * Verifying that the local machine DC2, is a Directory Server.
       Home Server = DC2
       * Connecting to directory service on server DC2.
       * Identified AD Forest.
       Collecting AD specific global data
       * Collecting site info.
       Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=company,DC=local,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
       The previous call succeeded
       Iterating through the sites
       Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
       Getting ISTG and options for the site
       * Identifying all servers.
       Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=company,DC=local,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
       The previous call succeeded....
       The previous call succeeded
       Iterating through the list of servers
       Getting information for the server CN=NTDS Settings,CN=DC0,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
       objectGuid obtained
       InvocationID obtained
       dnsHostname obtained
       site info obtained
       All the info for the server collected
       Getting information for the server CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
       objectGuid obtained
       InvocationID obtained
       dnsHostname obtained
       site info obtained
       All the info for the server collected
       * Identifying all NC cross-refs.
       * Found 2 DC(s). Testing 2 of them.
       Done gathering initial info.
    
    Doing initial required tests
    
       Testing server: Default-First-Site-Name\DC0
          Starting test: Connectivity
             * Active Directory LDAP Services Check
             Determining IP4 connectivity
             * Active Directory RPC Services Check
             ......................... DC0 passed test Connectivity
    
       Testing server: Default-First-Site-Name\DC2
          Starting test: Connectivity
             * Active Directory LDAP Services Check
             Determining IP4 connectivity
             * Active Directory RPC Services Check
             ......................... DC2 passed test Connectivity
    
    Doing primary tests
    
       Testing server: Default-First-Site-Name\DC0
          Starting test: Advertising
             The DC DC0 is advertising itself as a DC and having a DS.
             The DC DC0 is advertising as an LDAP server
             The DC DC0 is advertising as having a writeable directory
             The DC DC0 is advertising as a Key Distribution Center
             The DC DC0 is advertising as a time server
             The DS DC0 is advertising as a GC.
             ......................... DC0 passed test Advertising
          Starting test: CheckSecurityError
             * Dr Auth:  Beginning security errors check!
             Found KDC DC2 for domain company.local in site Default-First-Site-Name
             Checking machine account for DC DC0 on DC DC2.
             * SPN found :LDAP/DC0.company.local/company.local
             * SPN found :LDAP/DC0.company.local
             * SPN found :LDAP/DC0
             * SPN found :LDAP/DC0.company.local/company
             * SPN found :LDAP/26aba1bf-c251-47fa-acd9-31cea1bb7d23._msdcs.company.local
             * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/26aba1bf-c251-47fa-acd9-31cea1bb7d23/company.local
             * SPN found :HOST/DC0.company.local/company.local
             * SPN found :HOST/DC0.company.local
             * SPN found :HOST/DC0
             * SPN found :HOST/DC0.company.local/company
             * SPN found :GC/DC0.company.local/company.local
             Checking for CN=DC0,OU=Domain Controllers,DC=company,DC=local in domain DC=company,DC=local on 2 servers
                Object is up-to-date on all servers.
             [DC0] No security related replication errors were found on this DC!  To target the connection to a
             specific source DC use /ReplSource:<DC>.
             ......................... DC0 passed test CheckSecurityError
          Starting test: CutoffServers
             * Configuration Topology Aliveness Check
             * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=company,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=company,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=company,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for CN=Configuration,DC=company,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             * Analyzing the alive system replication topology for DC=company,DC=local.
             * Performing upstream (of target) analysis.
             * Performing downstream (of target) analysis.
             ......................... DC0 passed test CutoffServers
          Starting test: FrsEvent
             * The File Replication Service Event log test
             Skip the test because the server is running DFSR.
             ......................... DC0 passed test FrsEvent
          Starting test: DFSREvent
             The DFS Replication Event Log.
             There are warning or error events within the last 24 hours after the SYSVOL has been shared.  Failing SYSVOL
             replication problems may cause Group Policy problems.
             A warning event occurred.  EventID: 0x80001396
                Time Generated: 02/03/2022   12:12:28
                Event String:
                The DFS Replication service is stopping communication with partner DC2 for replication group Domain System Volume due to an error. The service will retry the connection periodically.
    
                Additional Information:
                Error: 1723 (The RPC server is too busy to complete this operation.)
                Connection ID: FEB53088-DCB1-40E8-A920-CF13C4BBF0CF
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             A warning event occurred.  EventID: 0x80001396
                Time Generated: 02/03/2022   14:40:42
                Event String:
                The DFS Replication service is stopping communication with partner DC1 for replication group Domain System Volume due to an error. The service will retry the connection periodically.
    
                Additional Information:
                Error: 9033 (The request was cancelled by a shutdown)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             An error event occurred.  EventID: 0xC000138A
                Time Generated: 02/03/2022   14:41:12
                Event String:
                The DFS Replication service encountered an error communicating with partner DC1 for replication group Domain System Volume.
    
                Partner DNS address: DC1.company.local
    
                Optional data if available:
                Partner WINS Address: DC1
                Partner IP Address: 192.168.1.80
    
                The service will retry the connection periodically.
    
                Additional Information:
                Error: 1726 (The remote procedure call failed.)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             A warning event occurred.  EventID: 0x80001396
                Time Generated: 02/03/2022   14:54:18
                Event String:
                The DFS Replication service is stopping communication with partner DC1 for replication group Domain System Volume due to an error. The service will retry the connection periodically.
    
                Additional Information:
                Error: 9033 (The request was cancelled by a shutdown)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             An error event occurred.  EventID: 0xC0001390
                Time Generated: 02/03/2022   14:54:54
                Event String:
                The DFS Replication service failed to communicate with partner DC1 for replication group Domain System Volume. This error can occur if the host is unreachable, or if the DFS Replication service is not running on the server. 
    
                Partner DNS Address: DC1.company.local
    
                Optional data if available:
                Partner WINS Address: DC1
                Partner IP Address: 192.168.1.80
    
                The service will retry the connection periodically.
    
                Additional Information:
                Error: 1722 (The RPC server is unavailable.)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             A warning event occurred.  EventID: 0x80001396
                Time Generated: 02/03/2022   15:18:16
                Event String:
                The DFS Replication service is stopping communication with partner DC1 for replication group Domain System Volume due to an error. The service will retry the connection periodically.
    
                Additional Information:
                Error: 9033 (The request was cancelled by a shutdown)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             An error event occurred.  EventID: 0xC000138A
                Time Generated: 02/03/2022   15:18:46
                Event String:
                The DFS Replication service encountered an error communicating with partner DC1 for replication group Domain System Volume.
    
                Partner DNS address: DC1.company.local
    
                Optional data if available:
                Partner WINS Address: DC1
                Partner IP Address: 192.168.1.80
    
                The service will retry the connection periodically.
    
                Additional Information:
                Error: 1726 (The remote procedure call failed.)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             A warning event occurred.  EventID: 0x80001396
                Time Generated: 02/03/2022   15:27:18
                Event String:
                The DFS Replication service is stopping communication with partner DC1 for replication group Domain System Volume due to an error. The service will retry the connection periodically.
    
                Additional Information:
                Error: 9033 (The request was cancelled by a shutdown)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             An error event occurred.  EventID: 0xC000138A
                Time Generated: 02/03/2022   15:27:32
                Event String:
                The DFS Replication service encountered an error communicating with partner DC1 for replication group Domain System Volume.
    
                Partner DNS address: DC1.company.local
    
                Optional data if available:
                Partner WINS Address: DC1
                Partner IP Address: 192.168.1.80
    
                The service will retry the connection periodically.
    
                Additional Information:
                Error: 1753 (There are no more endpoints available from the endpoint mapper.)
                Connection ID: 9551F88D-AD9C-491F-9316-AE4CA8FC5790
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             A warning event occurred.  EventID: 0x80001396
                Time Generated: 02/04/2022   00:09:56
                Event String:
                The DFS Replication service is stopping communication with partner DC2 for replication group Domain System Volume due to an error. The service will retry the connection periodically.
    
                Additional Information:
                Error: 9036 (Paused for backup or restore)
                Connection ID: FEB53088-DCB1-40E8-A920-CF13C4BBF0CF
                Replication Group ID: 379052DE-A489-4267-87C2-847E328CDB38
             ......................... DC0 failed test DFSREvent
          Starting test: SysVolCheck
             * The File Replication Service SYSVOL ready test
             File Replication Service's SYSVOL is ready
             ......................... DC0 passed test SysVolCheck
          Starting test: FrsSysVol
             * The File Replication Service SYSVOL ready test
             File Replication Service's SYSVOL is ready
             ......................... DC0 passed test FrsSysVol
          Starting test: KccEvent
             * The KCC Event log test
             Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
             ......................... DC0 passed test KccEvent
          Starting test: KnowsOfRoleHolders
             Role Schema Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
             Role Domain Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
             Role PDC Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
             Role Rid Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
             Role Infrastructure Update Owner = CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local
             ......................... DC0 passed test KnowsOfRoleHolders
          Starting test: MachineAccount
             Checking machine account for DC DC0 on DC DC0.
             * SPN found :LDAP/DC0.company.local/company.local
             * SPN found :LDAP/DC0.company.local
             * SPN found :LDAP/DC0
             * SPN found :LDAP/DC0.company.local/company
             * SPN found :LDAP/26aba1bf-c251-47fa-acd9-31cea1bb7d23._msdcs.company.local
             * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/26aba1bf-c251-47fa-acd9-31cea1bb7d23/company.local
             * SPN found :HOST/DC0.company.local/company.local
             * SPN found :HOST/DC0.company.local
             * SPN found :HOST/DC0
             * SPN found :HOST/DC0.company.local/company
             * SPN found :GC/DC0.company.local/company.local
             ......................... DC0 passed test MachineAccount
          Starting test: NCSecDesc
             * Security Permissions check for all NC's on DC DC0.
             * Security Permissions Check for
               DC=ForestDnsZones,DC=company,DC=local
                (NDNC,Version 3)
             * Security Permissions Check for
               DC=DomainDnsZones,DC=company,DC=local
                (NDNC,Version 3)
             * Security Permissions Check for
               CN=Schema,CN=Configuration,DC=company,DC=local
                (Schema,Version 3)
             * Security Permissions Check for
               CN=Configuration,DC=company,DC=local
                (Configuration,Version 3)
             * Security Permissions Check for
               DC=company,DC=local
                (Domain,Version 3)
             ......................... DC0 passed test NCSecDesc
          Starting test: NetLogons
             * Network Logons Privileges Check
             Verified share \\DC0\netlogon
             Verified share \\DC0\sysvol
             ......................... DC0 passed test NetLogons
          Starting test: ObjectsReplicated
             DC0 is in domain DC=company,DC=local
             Checking for CN=DC0,OU=Domain Controllers,DC=company,DC=local in domain DC=company,DC=local on 2 servers
                Object is up-to-date on all servers.
             Checking for CN=NTDS Settings,CN=DC0,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=company,DC=local in domain CN=Configuration,DC=company,DC=local on 2 servers
                Object is up-to-date on all servers.
             ......................... DC0 passed test ObjectsReplicated
          Starting test: OutboundSecureChannels
             * The Outbound Secure Channels test
             ** Did not run Outbound Secure Channels test because /testdomain: was not entered
             ......................... DC0 passed test OutboundSecureChannels
          Starting test: Replications
             * Replications Check
             * Replication Latency Check
                DC=ForestDnsZones,DC=company,DC=local
                   Latency information for 2 entries in the vector were ignored.
                      2 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
                DC=DomainDnsZones,DC=company,DC=local
                   Latency information for 2 entries in the vector were ignored.
                      2 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
                CN=Schema,CN=Configuration,DC=company,DC=local
                   Latency information for 2 entries in the vector were ignored.
                      2 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
                CN=Configuration,DC=company,DC=local
                   Latency information for 2 entries in the vector were ignored.
                      2 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
                DC=company,DC=local
                   Latency information for 2 entries in the vector were ignored.
                      2 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).
             ......................... DC0 passed test Replications
          Starting test: RidManager
             * Available RID Pool for the Domain is 3101 to 1073741823
             * DC2.company.local is the RID Master
             * DsBind with RID Master was successful
             * rIDAllocationPool is 1601 to 2100
             * rIDPreviousAllocationPool is 1601 to 2100
             * rIDNextRID: 1675
             ......................... DC0 passed test RidManager
          Starting test: Services
             * Checking Service: EventSystem
             * Checking Service: RpcSs
             * Checking Service: NTDS
             * Checking Service: DnsCache
             * Checking Service: DFSR
             * Checking Service: IsmServ
             * Checking Service: kdc
             * Checking Service: SamSs
             * Checking Service: LanmanServer
             * Checking Service: LanmanWorkstation
             * Checking Service: w32time
             * Checking Service: NETLOGON
             ......................... DC0 passed test Services
          Starting test: SystemLog
             * The System Event log test
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:17:13
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:17:13.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:20:20
                Event String:
                A Kerberos error message was received:
                 on logon session
                 Client Time:
                 Server Time: 12:20:20.0000 2/4/2022 Z
                 Error Code: 0x7  KDC_ERR_S_PRINCIPAL_UNKNOWN
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/NT Authority
                 Target Name: krbtgt/NT Authority@company.LOCAL
                 Error Text:
                 File: 9
                 Line: 1396
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:22:17
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:22:17.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:27:21
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:27:21.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:32:24
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:32:24.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:32:25
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:32:25.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:37:28
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:37:28.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:37:29
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:37:29.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:42:32
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:42:32.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:42:33
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:42:33.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:47:36
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:47:36.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:47:37
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:47:37.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:52:41
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:52:41.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x80000003
                Time Generated: 02/04/2022   07:57:44
                Event String:
                A Kerberos error message was received:
                 on logon session company.LOCAL\DC0$
                 Client Time:
                 Server Time: 12:57:44.0000 2/4/2022 Z
                 Error Code: 0x19 KDC_ERR_PREAUTH_REQUIRED
                 Extended Error:
                 Client Realm:
                 Client Name:
                 Server Realm: company.LOCAL
                 Server Name: krbtgt/company.LOCAL
                 Target Name: krbtgt/company.LOCAL@company.LOCAL
                 Error Text:
                 File: e
                 Line: d48
                 Error Data is in record data.
             An error event occurred.  EventID: 0x8000
    
    0 comments No comments

  2. Tim Gibney 1 Reputation point
    2022-02-08T15:03:44.17+00:00

    I am still having the double domain issue in dcdaig DNS tests, shown as [Broken delegated domain company.local.company.local.]. I first found that DC0 and DC1 had been configured with the additional DNS suffix for this connection set to company.local. That was removed as the servers get their domain listing form AD. DNS replication, after fixing glue records, is working fine.

    PS E:\scripts> repadmin /replsummary
    Replication Summary Start Time: 2022-02-08 08:41:39
    
    Beginning data collection for replication summary, this may take awhile:
      .....
    
    
    Source DSA          largest delta    fails/total %%   error
     DC0                        05m:42s    0 /   5    0
     DC2                        05m:42s    0 /   5    0
    
    
    Destination DSA     largest delta    fails/total %%   error
     DC0                        05m:42s    0 /   5    0
     DC2                        05m:42s    0 /   5    0
    
    
    PS E:\scripts> dcdiag /e /test:DNS
    
    Directory Server Diagnosis
    
    Performing initial setup:
       Trying to find home server...
       Home Server = DC2
       * Identified AD Forest.
       Done gathering initial info.
    
    Doing initial required tests
    
       Testing server: Default-First-Site-Name\DC0
          Starting test: Connectivity
             ......................... DC0 passed test Connectivity
    
       Testing server: Default-First-Site-Name\DC2
          Starting test: Connectivity
             ......................... DC2 passed test Connectivity
    
    Doing primary tests
    
       Testing server: Default-First-Site-Name\DC0
    
       Testing server: Default-First-Site-Name\DC2
    
             Starting test: DNS
    
    
                   DNS Tests are running and not hung. Please wait a few minutes...
                   Starting test: DNS
                      ......................... DC2 passed test DNS
             ......................... DC0 passed test DNS
    
       Running partition tests on : ForestDnsZones
    
       Running partition tests on : DomainDnsZones
    
       Running partition tests on : Schema
    
       Running partition tests on : Configuration
    
       Running partition tests on : company
    
       Running enterprise tests on : company.local
          Starting test: DNS
             Test results for domain controllers:
    
                DC: DC0.company.local
                Domain: company.local
    
    
                   TEST: Delegations (Del)
                      Error: DNS server: DC0.company.local. IP:192.168.1.60
                      [Broken delegated domain company.local.company.local.]
                      Error: DNS server: DC1.company.local. IP:192.168.1.80 [Broken delegated domain company.local.company.local.]
                      Error: DNS server: DC2.company.local. IP:192.168.50.40 [Broken delegated domain company.local.company.local.]
    
                   TEST: Dynamic update (Dyn)
                      Warning: Failed to delete the test record dcdiag-test-record in zone company.local
    
    
                DC: DC2.company.local
                Domain: company.local
    
    
                   TEST: Delegations (Del)
                      Error: DNS server: DC0.company.local. IP:192.168.1.60
                      [Broken delegated domain company.local.company.local.]
                      Error: DNS server: DC1.company.local. IP:192.168.1.80 [Broken delegated domain company.local.company.local.]
                      Error: DNS server: DC2.company.local. IP:192.168.50.40 [Broken delegated domain company.local.company.local.]
    
                   TEST: Dynamic update (Dyn)
                      Warning: Failed to delete the test record dcdiag-test-record in zone company.local
    
             Summary of test results for DNS servers used by the above domain controllers:
    
                DNS server: 192.168.1.60 (DC0.company.local.)
                   2 test failure on this DNS server
    
                DNS server: 192.168.1.80 (DC1.company.local.)
                   2 test failure on this DNS server
    
                DNS server: 192.168.50.40 (DC2.company.local.)
                   2 test failure on this DNS server
    
             Summary of DNS test results:
    
                                                Auth Basc Forw Del  Dyn  RReg Ext
                _________________________________________________________________
                Domain: company.local
                   DC0                          PASS PASS PASS FAIL WARN PASS n/a
                   DC2                          PASS PASS PASS FAIL WARN PASS n/a
    
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.