Resort to the problem that the primary domain and secondary domain policies of the 20008R2 AD domain cannot be synchronized. (
Phenomenon:
1. The new group policy in the primary domain cannot be synchronized to the secondary domain, and the net share sharing is normal. \ domain server, both servers can see sysvol and netlogon shares.
2. Dcdiag-v test results
Directory server diagnostics
Performing initialization settings:
Trying to find the primary server.
Primary server = ADC
Recognized AD forest.
Finished collecting initialization information.
The required initialization tests are in progress
Testing server: Default-First-Site-Name\ ADC
Start testing: Connectivity
. ADC has passed the test Connectivity
Performing major tests
Testing server: Default-First-Site-Name\ ADC
Start testing: Advertising
. ADC has passed the test Advertising
Start testing: FrsEvent
. ADC has passed the test FrsEvent
Start testing: DFSREvent
. ADC has passed the test DFSREvent
Start testing: SysVolCheck
. ADC has passed the test SysVolCheck
Start testing: KccEvent
. ADC has passed the test KccEvent
Start testing: KnowsOfRoleHolders
. ADC has passed the test KnowsOfRoleHolders
Start testing: MachineAccount
. ADC has passed the test MachineAccount
Start testing: NCSecDesc
. ADC has passed the test NCSecDesc
Start testing: NetLogons
. ADC has passed the test NetLogons
Start testing: ObjectsReplicated
. ADC has passed the test ObjectsReplicated
Start testing: Replications
. OVMDC has passed the test Replications
Start testing: RidManager
. ADC has passed the test RidManager
Start testing: Services
. ADC has passed the test Services
Start testing: SystemLog
. ADC failed the test SystemLog
Start testing: VerifyReferences
There are problems with some DC ADC-related objects:
[1] problem: missing required value
Basic objects:
CN=NTDS Settings,CN=ADC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=A,DC=com
Basic object description: "DSA object"
Value object attribute name: serverReferenceBL
Value object description: "SYSVOL FRS member object"
Recommended action: please refer to knowledge base article: Q312862
[1] problem: missing required value
Basic object: CN=ADC,OU=Domain Controllers,DC=A,DC=com
Basic object description: "DC account object"
Value object attribute name: frsComputerReferenceBL
Value object description: "SYSVOL FRS member object"
Recommended action: please refer to knowledge base article: Q312862
. ADC failed the test VerifyReferences
ForestDnsZones
Run partition tests on the
Start testing: CheckSDRefDom
. ForestDnsZones has passed the test CheckSDRefDom
Start testing: CroefValidation
. ForestDnsZones has passed the test CroefValidation
DomainDnsZones
Run partition tests on the
Start testing: CheckSDRefDom
. DomainDnsZones has passed the test CheckSDRefDom
Start testing: CroefValidation
. DomainDnsZones has passed the test CroefValidation
Schema
Run partition tests on the
Start testing: CheckSDRefDom
. Schema has passed the test CheckSDRefDom
Start testing: CroefValidation
. Schema has passed the test CroefValidation
Configuration
Run partition tests on the
Start testing: CheckSDRefDom
. Configuration has passed the test CheckSDRefDom
Start testing: CroefValidation
. Configuration has passed the test CroefValidation
In the process of A
Run partition tests on the
Start testing: CheckSDRefDom
. A has passed the test CheckSDRefDom
Start testing: CroefValidation
. A has passed the test CroefValidation
A.com
Run enterprise tests on the
Start testing: LocatorCheck
. A.com has passed the test LocatorCheck
Start testing: Intersite
. A.com has passed the test Intersite
3. After comparing and testing the AD environment, the option of "CN=DFSR-LocalSettings"-"CN=DomainSystemVolume"-"CN=SYSVOL Subscription" is missing. Can you build this directory structure by yourself? how to build it? I can't build a third layer in it.
I wonder if that's the problem.
If there is any great god who knows how to solve it, please leave a message, thank you.