question

OsamaOthman-0863 avatar image
0 Votes"
OsamaOthman-0863 asked DaisyZhou-MSFT commented

Accidental Deletion of krbtgt account for RODC

hi everyone
by mistake we deleted three krbtgt accounts , and we didnt notice any issue for a while , but after latest update we noticed that the replication is stopped , i restored the three accounts from the recycle bin and i can see them on the main DC , but they didn'y copy to RODC servers. how i can move them to there ? the location of RODC is very far and there;s no IT there . please help.
all server are SErver 2012 r2

windows-server
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello OsamaOthman-0863,

I would like to know how things are going on your end? If you have any further questions or concerns about this case, please feel free to let us know.


Best Regards,
Daisy Zhou



============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.

0 Votes 0 ·

Hello OsamaOthman-0863,

I have not heard back from you in a few days and wanted to check on the status of your problem. Please let me know the results of your troubleshooting. Your time is greatly appreciated.

Best Regards,
Daisy Zhou



============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.

0 Votes 0 ·

1 Answer

DaisyZhou-MSFT avatar image
0 Votes"
DaisyZhou-MSFT answered

Hello OsamaOthman-0863,

Thank you for posting here.

Based on the description above, you deleted the krbtgt accounts on main DC by mistake, now the krbtgt accounts are not on RODC servers. As I understand, the deletion action was replicated to other DC servers including RODC servers. So I guess the previous AD replication is normal.

Based on the description "i restored the three accounts from the recycle bin and i can see them on the main DC , but they didn't copy to RODC servers.", now there may be any issue on the AD replication because the restored krbtgt accounts on main DC can not be replicated to RODC servers.

We can run the following commands to check if AD replication is working or if there is any issue about AD replication.

1.Run the command to force AD sync.
repadmin /syncall /AdeP >c:\repsum.txt

2.Run the commands below to check AD replication status.
repadmin /showrepl >c:\repsum.txt1
repadmin /replsum >c:\repsum.txt2
repadmin /showrepl * /csv >c:\repsum.csv


3.Troubleshoot the AD replication issue based on the error massage or error code within the result in step 2.


I think if there is indeed AD replication issues, after we fixed the AD replication problem, the krbtgt accounts should be replicated to RODC servers.


Hope the information is helpful. If anything is unclear, please feel free to let us know.


Tip: Due to data security reasons, please do not upload logs to the forum.



Best Regards,
Daisy Zhou

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.