Beruflich Dokumente
Kultur Dokumente
after
you
ran
this
command,
on
your
DCs
C-Drive,
you
should
find
text
file
named dcslist.txt Check its content, there are all Domain Controllers for your domain
On all of those Domain Controllers except PDC Emulator holder, you have to perform nonauthoritative SYSVOL restore. But lets start step-by-step.
You should initiate authoritative SYSVOL restore from a DC with PDC Emulator role. If you need to
restore SYSVOL from backup, do it first before you initiate restore.
First of all, stop DFS Replication service. Type in elevated command-line
netstopDFSR
or in PowerShell
StopServiceDFSR
or
StopService"DFSReplication"
Connect to domain partition (Default Naming Context). Click right mouse button (RMB) on root
node in the console and select Connect to
select a well known Naming Context and choose Default Naming Context
and select CN=SYSVOL Subscription entry by RMB in the right pane, choose Properties
msDFSR-Enabled
msDFSR-Options
Search them on the list and edit
Change its state from TRUE to FALSE and accept the change
Change its state from not set to 1 and accept the change
and accept changes to be applied (do not close window, you will use it later)
REPETITIVE TASK
Now, on each of the rest Domain Controllers you need to change msDFSR-Enabled attribute state
from TRUE to FALSE to initiate replication from authoritative Domain Controller with SYSVOL. This
not need to be done directly on Domain Controllers, you can use ADSI Editor on the same DC on
which you changed previous attributes. But this is important to do for evry remaining DC!
Below you can find all required steps. You need to repeat them on the rest of Domain Controllers
In ADSI Editor on Domain Controller where you changed previous attributes, close Attribute
Editor window and go back to the console. Expand each DC to set up msDFSR-Enabled attribute
and stop DFS Replication service on remote DC. Repeat these steps for EVERY remaining Domain
Controller.
or type in PowerShell
StartServiceDFSR
or
StartService"DFSReplication"
Start Active Directory replication on all of your Domain Controllers. Type in elevated command-line
repadmin/syncall/AdP
Note! When you ran dfsrdiag command and it was not recognized, you need to install DFS
Management Tools from features!
In DFS Replication event log, you should see event ID 4602 That means, your authoritative SYSVOL
restore is initiated
Event ID 4602
REPETITIVE TASK
Before you will start DFS Replication service, I would suggest to remove all content from those 2
folders
%WINDIR%SYSVOLdomainPolicies
%WINDIR%SYSVOLdomainScripts
Note! (by default, if you changed SYSVOL location during DC promotion, you need to refer to your
own location)
Go to the another Domain Controller to which you want to replicate SYSVOL and start DFS
Replication service, type in elevated command-line
netstartDFSR
or in PowerShell
StartServiceDFSR
or
StartService"DFSReplication"
review DFS Replication event log and check if there is event ID 4114
and run dfsrdiag command to synchronize with the global information store
dfsrdiagPollAD
You
should
get
SYSVOL
replicated
to
this
Domain
Controller.
Go
to%WINDIR
%SYSVOLdomainPolicies and check if data was replicated. You should see all Group Policies and
scripts there
and go to one more location, %WINDIR%SYSVOLdomainScripts to check if scripts and other files
from NETLOGON share were replicated