Accidental Deletion of krbtgt account for RODC

Osama Othman 1 Reputation point
2022-05-17T15:59:46.08+00:00

hi everyone
by mistake we deleted three krbtgt accounts , and we didnt notice any issue for a while , but after latest update we noticed that the replication is stopped , i restored the three accounts from the recycle bin and i can see them on the main DC , but they didn'y copy to RODC servers. how i can move them to there ? the location of RODC is very far and there;s no IT there . please help.
all server are SErver 2012 r2

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,080 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 18,701 Reputation points Microsoft Vendor
    2022-05-25T03:09:48.517+00:00

    Hello OsamaOthman-0863,

    Thank you for posting here.

    Based on the description above, you deleted the krbtgt accounts on main DC by mistake, now the krbtgt accounts are not on RODC servers. As I understand, the deletion action was replicated to other DC servers including RODC servers. So I guess the previous AD replication is normal.

    Based on the description "i restored the three accounts from the recycle bin and i can see them on the main DC , but they didn't copy to RODC servers.", now there may be any issue on the AD replication because the restored krbtgt accounts on main DC can not be replicated to RODC servers.

    We can run the following commands to check if AD replication is working or if there is any issue about AD replication.

    1.Run the command to force AD sync.
    repadmin /syncall /AdeP >c:\repsum.txt

    2.Run the commands below to check AD replication status.
    repadmin /showrepl >c:\repsum.txt1
    repadmin /replsum >c:\repsum.txt2
    repadmin /showrepl * /csv >c:\repsum.csv

    3.Troubleshoot the AD replication issue based on the error massage or error code within the result in step 2.

    I think if there is indeed AD replication issues, after we fixed the AD replication problem, the krbtgt accounts should be replicated to RODC servers.

    Hope the information is helpful. If anything is unclear, please feel free to let us know.

    Tip: Due to data security reasons, please do not upload logs to the forum.

    Best Regards,
    Daisy Zhou

    ============================================
    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments