Requires Free Membership to View
- C:\>ntdsutil
- ntdsutil: roles
- fsmo maintenance: connections
- server connections: connect to server [myserver]
Binding to msspueblomain ...
Connected to msspueblomain using credentials of locally logged on user
- server connections: quit
- fsmo maintenance: select operation target
- select operation target: list roles for connected server
Schema - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=MYSITE,CN=Sites,CN=Configura tion,DC=MYDOMAIN,DC=com
Domain - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=MYSITE,CN=Sites,CN=Configura tion,DC=MYDOMAIN,DC=com
PDC - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=MYSITE,CN=Sites,CN=Configuratio n,DC=MYDOMAIN,DC=com
RID - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=MYSITE,CN=Sites,CN=Configuratio n,DC=MYDOMAIN,DC=com
Infrastructure - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=MYSITE,CN=Sites,CN=C onfiguration,DC=MYDOMAIN,DC=com
Now just quit until you exit. Repeat this procedure on all of the domain controllers so that you are clear on what they think are the FSMO role holders.
Next you will need to check on replication. Check the Event log's Directory Services and File Replication for errors or warnings. Some of the Microsoft warnings about replication are underrated and really should be errors. If DC's cannot replicate to other DCs eventually you can stall replication altogether. A bad situation to say the least. You can use replmon.exe from the Support tools to get more information. Also, run DCDIAG on each one of the domain controllers and check out any warnings or errors produced. This utility will also let you know if the problem is related to name resolution and DNS.
If there are multiple DCs that believe that they are the Schema master, you may have to demote one DC to get it to clear its information and promote it back up. This may also involve some manual cleanup of AD.
This was first published in August 2004
Enterprise Server Strategies for the CIO
Join the conversationComment
Share
Comments
Results
Contribute to the conversation