Home > Ask the Windows Server Experts > Archive: Microsoft Active Directory Questions & Answers > Child domains not finding global catalog
Ask The Windows Server Expert: Questions & Answers
EMAIL THIS

Child domains not finding global catalog

Paul Hinsberg EXPERT RESPONSE FROM: Paul Hinsberg

Pose a Question
Other Windows Server Categories
Meet all Windows Server Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 19 November 2004
Last year I created a Windows 2000 forest containing a root domain and three child domains. Everything worked fine until about five months ago when none of the child domains could find the Global Catalog (they could before). I don't know what changed but to "resolve" the problem I opened the Active Directory Sites and Services Console from the Administrative Tools of each child domain, expanded the Sites -> Default-First-Site-Name -> Servers and then right clicked on the NTDS Settings and checked the box that says Global Catalog.

Although this allowed the child domains to find the GC did it really resolve my problem or just work around it? This may be related to a more serious problem I'll describe in another question.

>
Check on the Flexible Single Master Operations roles (FSMO). If the roles got switched around it could cause a problem with replication. Specifically the Infrastructure Master role should not be a Global Catalog Server. If it is, the replication can fool itself into believing that all of the child domain servers are up to date, when they are not. Keep in mind that you will have multiple Infrastructure Masters. Each domain/child domain will have its own. Unless ALL servers are Global Catalog servers -- you will need to make sure the ones running the Infrastructure Master are not be GC's. You may use the DSA to find the information or the NTDSUTIL.exe (my preference):

Open a command prompt and type Ntdsutil (this requires that the Windows Support Tools have been installed from the CD). You get a NTDSUTIL: prompt. Now type…
Ntsdutil: roles
fsmo maintenance: connections
server connections: connect to server [servername of non-PDC emulator system] 
Connected to [servername] using credentials of locally logged on user.
server connections: quit
fsmo maintenance: Select operation target
select operation target: List roles for connected server
The output will be similar to this:
Server "myserver" knows about 5 roles
Schema - CN=NTDS Settings,CN=MYSERVER2,CN=Servers,CN=Default-First-Site-Name,CN=
Sites,CN=Configuration,DC=mydomain,DC=com
Domain - CN=NTDS Settings,CN=MYSERVER2,CN=Servers,CN=Default-First-Site-Name,CN=
Sites,CN=Configuration,DC=mydomain,DC=com
PDC - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Site
s,CN=Configuration,DC=mydomain,DC=com
RID - CN=NTDS Settings,CN=MYSERVER2,CN=Servers,CN=Default-First-Site-Name,CN=Sit
es,CN=Configuration,DC=mydomain,DC=com
Infrastructure - CN=NTDS Settings,CN=MYSERVER,CN=Servers,CN=Default-First-Site-N
ame,CN=Sites,CN=Configuration,DC=mydomain,DC=com
Paul Hinsberg

Additional Expert Help:
Be sure to check our Answer FAQ for more expert advice.
For faster answers, visit ITKnowledge Exchange.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Archive: Microsoft Active Directory
Creating user home directories on a Windows 2003 network
Changing NTDS links with Active Directory
Can I add a Win2003 Server to an NT4 domain without AD?
Filtering workstation logon events to log only user activity
Error of event ID 7031 when attempting to move mailboxes
Finding the creation date of objects
Duplicating Windows 2000 domain as Windows 2003 test environment
Backward checking permission for groups in Active Directory
How can I configure user profiles on a Windows 2000 Server?
Changing domain controller names in Windows 2000 Server

Microsoft Active Directory Tools and Troubleshooting
How to find and remove lingering objects in Active Directory
DNS troubleshooting best practices
Generating a DNS health check in Windows
Debugging Windows client logon delays: Narrowing the scope
Troubleshooting poor Windows logon performance in Active Directory environments
New Operations Manager 2007 feature allows for automated agent deployments
Taming the LSASS.exe process for Active Directory performance and security
Active Directory FAQs
Troubleshooting Active Directory database errors
Troubleshooting a cross-forest trust in Active Directory

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Windows Server Solutions - Intel Hardware Solutions
HomeTopicsBlogsITKnowledge ExchangeTipsNewsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts