Problem solve Get help with specific problems with your technologies, process and projects.

Child domains not finding global catalog

Last year I created a Windows 2000 forest containing a root domain and three child domains. Everything worked fine until about five months ago when none of the child domains could find the Global Catalog.

Last year I created a Windows 2000 forest containing a root domain and three child domains. Everything worked fine until about five months ago when none of the child domains could find the Global Catalog (they could before). I don't know what changed but to "resolve" the problem I opened the Active Directory Sites and Services Console from the Administrative Tools of each child domain, expanded the Sites -> Default-First-Site-Name -> Servers and then right clicked on the NTDS Settings and checked the box that says Global Catalog.

Although this allowed the child domains to find the GC did it really resolve my problem or just work around it? This may be related to a more serious problem I'll describe in another question.
Check on the Flexible Single Master Operations roles (FSMO). If the roles got switched around it could cause a problem with replication. Specifically the Infrastructure Master role should not be a Global Catalog Server. If it is, the replication can fool itself into believing that all of the child domain servers are up to date, when they are not. Keep in mind that you will have multiple Infrastructure Masters. Each domain/child domain will have its own. Unless ALL servers are Global Catalog servers -- you will need to make sure the ones running the Infrastructure Master are not be GC's. You may use the DSA to find the information or the NTDSUTIL.exe (my preference):

Open a command prompt and type Ntdsutil (this requires that the Windows Support Tools have been installed from the CD). You get a NTDSUTIL: prompt. Now type…
Ntsdutil: roles
fsmo maintenance: connections
server connections: connect to server [servername of non-PDC emulator system] 
Connected to [servername] using credentials of locally logged on user.
server connections: quit
fsmo maintenance: Select operation target
select operation target: List roles for connected server
The output will be similar to this:
Server "myserver" knows about 5 roles
Schema - CN=NTDS Settings,CN=MYSERVER2,CN=Servers,CN=Default-First-Site-Name,CN=
Domain - CN=NTDS Settings,CN=MYSERVER2,CN=Servers,CN=Default-First-Site-Name,CN=
PDC - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Site
RID - CN=NTDS Settings,CN=MYSERVER2,CN=Servers,CN=Default-First-Site-Name,CN=Sit
Infrastructure - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=Default-First-Site-N
Paul Hinsberg

Additional Expert Help: Be sure to check our Answer FAQ for more expert advice. For faster answers, visit ITKnowledge...


This was last published in December 2004

Dig Deeper on Microsoft Active Directory Tools and Troubleshooting



Find more PRO+ content and other member only offers, here.

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.