Windows Server: AD, DNS & Group Policy
Active Directory replication, trusts, DNS, SYSVOL and Group Policy processing.
55 articles
8531
Error 8531 Directory Service cannot start: NTDS database and disk failures
Error 8531 is ERROR_DS_CANT_START: AD DS could not start against its database. Read the codes logged with it, then rebuild…
8565
Error 8565: raise the forest functional level before adding this controller
Error 8565 blocks promotion when the forest level predates the new OS. Retire the legacy DCs, raise the level, then…
8568
Error 8568: the functional level will not rise while legacy DCs remain
Error 8568 means a domain controller still runs an older operating system. Locate it, demote or upgrade it to a…
8340
Error 8340: metadata cleanup after a domain controller that never came back
Error 8340 appears when removing a dead DC's metadata. Clean up with ntdsutil, delete the NTDS Settings object and tidy…
8610
Error 8610: FSMO role ownership cannot be verified until the partition replicates
Error 8610 blocks FSMO work until the partition replicates. Repair replication first, and only seize the role with ntdsutil once…
Event ID 20291
Event ID 20291: DHCP failover partners rejecting each other’s binding updates
Events 20291 and 20292 record a rejected binding update. Where the reason is outdated binding information, Microsoft says these can…
LDAP 533
LDAP 533 and 532: binds refused because of the account state in AD
LDAP 533 means the account is disabled and 532 means the password expired. Map each sub-code to the real account…
Event ID 5719
Event ID 5719: this computer could not set up a secure session with a DC
Event ID 5719 means Netlogon could not build a secure channel at startup. Fix DC locator DNS, ports and the…
LDAP 8
LDAP 8 strong auth required: signing and channel binding enforced on DCs
LDAP 8 appears once DCs require signing or channel binding. Move clients to LDAPS or signed binds, and replace servers…
Event ID 5827
Event ID 5827: Netlogon blocks vulnerable secure channel connections
Event ID 5827 denies devices that cannot use secure RPC under Netlogon enforcement. Patch or replace them, since unsupported builds…
Event ID 4
Kerberos Event ID 4 KRB_AP_ERR_MODIFIED: a duplicate SPN in the directory
Event ID 4 means the service could not decrypt the ticket: the SPN is on the wrong account, or two…
Event ID 27
Kerberos Event ID 27: the target account has no key for the encryption type asked for
Event ID 27 is a service ticket failure: the target account has no key for the etype requested. Set AES…
