Fix it now
Setup asked a domain controller for an Exchange directory object and was told there is no such object. 0x80072030 is the directory-service error ERROR_DS_NO_SUCH_OBJECT. Either the preparation steps have not been run in order, or they have run and the change has not yet reached the controller setup happens to be using.
repadmin /replsummary
repadmin /syncall
E:\Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareSchema
E:\Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareAD
E:\Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareAllDomains
- Open
C:\ExchangeSetupLogs\ExchangeSetup.logand find the distinguished name setup could not read. Everything below turns on that one string. - Decide whether the object exists. Open ADSI Edit against the Configuration naming context and look under the Services container for the Microsoft Exchange organisation.
- If the object is there, this is replication rather than preparation. Run only the first two commands, confirm the object has arrived, and rerun setup. Do not run the preparation steps again.
- If the object is genuinely absent, run the three Setup lines in the order shown and let Active Directory replicate between each one before starting the next.
- Check your rights first:
/PrepareSchemaneeds Schema Admins and Enterprise Admins,/PrepareADand/PrepareAllDomainsneed Enterprise Admins, and/PrepareDomainin a child domain needs Domain Admins there.
Substitute your own installation media drive letter. Add /OrganizationName:"Contoso" to the /PrepareAD line only when you are creating the Exchange organisation for the first time; on an existing organisation the name is read from the directory.
If setup now gets past the directory step you are done. If not, the next section separates the three conditions this code covers, because they need different work.
Why it happens
Exchange keeps its entire organisational configuration inside Active Directory, in the configuration naming context under the Services container, and setup reads and writes that tree continuously. Every one of those operations lands on one domain controller. 0x80072030 is what comes back when that controller does not hold the object being asked for: the low word, 0x2030, is Win32 error 8240, ERROR_DS_NO_SUCH_OBJECT, published as “There is no such object on the server”.
Notice what the code does not say. It does not say the object has been deleted, or that your account is not allowed to see it, or that the schema is wrong. It says this server does not have it. In a healthy forest that is usually a statement about timing rather than about content, which is why the same setup run can succeed twenty minutes later with nothing changed.
The three preparation stages exist to be run in order and to be allowed to replicate between them. The schema is extended, then the organisation-level objects are created, then each domain that will hold mail-enabled objects is prepared. Running the next stage because the last one returned success is the most common route to this error, because success means the write was accepted by one controller, not that the forest knows about it.
The companion codes separate existence from permission. LDAP result 32 is noSuchObject, the protocol-level version of the same complaint. LDAP result 50 is insufficientAccessRights, which means the object is there and your account was refused; the matching directory-service error is 8344, ERROR_DS_INSUFF_ACCESS_RIGHTS. 0x8007200A is Win32 8202, ERROR_DS_NO_ATTRIBUTE_OR_VALUE, “The specified directory service attribute or value does not exist” – an attribute-level miss rather than an object-level one.
The object exists, but not on the controller setup is using
You have this one if You can see the object in ADSI Edit from your workstation, and setup running on another machine cannot.
- Look at the failures rather than the successes:
repadmin /replsummarysummarises which controllers are behind and by how much. - Get the detail for the controllers involved with
repadmin /showrepl, and check overall health withdcdiag /test:replications. repadmin /syncallsynchronises a domain controller with all of its replication partners. Run it, then confirm the object has actually arrived before doing anything else.- Bind the shell to one named controller for the duration of the work with
Set-ADServerSettings -PreferredServer <dc.contoso.com>, so you stop chasing a moving target.
Fix the replication fault rather than working around it. A forest that cannot converge will produce this error again during the next cumulative update, and by then you will have forgotten which controller was behind.
A preparation stage has not been run, or was run out of order
You have this one if The Microsoft Exchange container under Services is missing altogether, or is present but does not contain the objects setup is looking for.
- Run
Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareSchemafrom a machine in the same domain and Active Directory site as the schema master. - Wait for that extension to reach every domain controller, and verify it rather than assuming it.
- Run
/PrepareADnext. Microsoft requires the machine running it to be able to reach every domain in the forest on TCP 389. - Run
/PrepareAllDomainslast, or/PrepareDomain:<domain FQDN>for each domain that will hold mail-enabled objects.
In a multi-domain forest, a domain you skip does not fail today. It fails on the day somebody creates a mailbox there.
The account is refused rather than the object being missing
You have this one if LDAP result 50 in the log, or the failure lands on a write while reads succeed.
- Check the membership the stage actually needs. The schema stage needs Schema Admins and Enterprise Admins; the domain stage needs Domain Admins in the domain being prepared.
- Where the domain was created after
/PrepareADran, Microsoft also requires membership of the Organization Management role group to prepare it. - Check whether inherited permissions have been stripped from the object, or from your own account by a protected-group policy that restores itself on a timer.
- Use an account not subject to that policy for the preparation run rather than fighting the timer.
Setup is aimed at a controller that cannot do the work
You have this one if The error appears on one Exchange server and not another, or comes and goes between attempts on the same server.
- Name the controller explicitly. Both setup and the Exchange cmdlets accept a
/DomainController:<ServerFQDN>or-DomainControllerargument. - Confirm a writable domain controller is available to the server. Preparation writes, so a read-only controller cannot serve it.
- Check that a subnet object in Active Directory Sites and Services actually covers the Exchange server’s address; a server in no defined subnet gets sent anywhere.
- Remove the pin once the work is finished so the server goes back to normal discovery.
Full reference
The preparation stages, and what each one needs
| Stage | Command | Membership Microsoft requires |
|---|---|---|
| Schema | Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareSchema |
Schema Admins and Enterprise Admins |
| Organisation | Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareAD |
Enterprise Admins (plus Schema Admins if this step is also extending the schema) |
| All domains | Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareAllDomains |
Enterprise Admins |
| One domain | Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareDomain:<DomainFQDN> |
Domain Admins in that domain, plus Organization Management if the domain was created after PrepareAD |
The schema and organisation stages must be run from a machine in the same Active Directory domain and site as the schema master, or with /DomainController: naming the schema master. Hybrid organisations add /TenantOrganizationConfig to the /PrepareAD line. Between every stage, Microsoft’s instruction is the same and it is not decoration: wait for Active Directory replication to reach all domain controllers before running the next one.
Reading the code you were given
| Code | Published meaning | What it tells you to do next |
|---|---|---|
0x80072030 |
ERROR_DS_NO_SUCH_OBJECT, “There is no such object on the server” | Find out whether the object exists anywhere, then decide between replication and preparation |
LDAP 32 |
noSuchObject | Same condition at the protocol level. Treat it identically |
LDAP 50 |
insufficientAccessRights | Stop looking for the object. Look at the account |
0x8007200A |
ERROR_DS_NO_ATTRIBUTE_OR_VALUE, “The specified directory service attribute or value does not exist” | An attribute, not an object. Usually points at the schema stage |
Where the evidence lives
C:\ExchangeSetupLogs\ExchangeSetup.logis the primary log and it records the distinguished name that failed. Read it from the bottom.C:\ExchangeSetupLogs\also holds the per-stage logs written by the preparation switches.- The Application log on the Exchange server carries the MSExchange ADAccess entries written at the same moment, which tell you which directory server was in use.
- ADSI Edit connected to the Configuration naming context is the fastest way to answer the only question that matters: is the object there or not.
Event ID 2937 and Event ID 2501 turn up in the same window on servers hitting this error. Microsoft publishes no description for either of them, so do not try to decode the number. Read the event’s own text, which names the object and the attribute involved, and work from that.
When existence, rights and replication are all ruled out
- Confirm there is exactly one Exchange organisation in the forest. Two, created by two people running
/PrepareADwith different organisation names, produce failures that look like missing objects and cannot be quietly undone. - Confirm the domain you are preparing has not been renamed or moved since it was last prepared.
- Check that no controller is stuck in a state where it advertises itself but refuses writes, which
dcdiagreports andrepadmin /replsummarydoes not. - If setup consistently picks a different controller each run, name one with
/DomainController:so the failures become reproducible before you try to explain them. - Repeat the object check against the controller setup actually used, not against the one your management console happens to be bound to.
Preparing a forest you did not build
Inherited estates often carry a partial preparation from a project that stopped. The symptom is a Microsoft Exchange container that exists and looks plausible, with one stage’s objects inside it and not the next. There is no supported way to tell setup to skip ahead: run the stages in order from the beginning. Rerunning a stage that has already completed is safe and quick, and it is far cheaper than guessing which one was missed.
The one thing to check before you start is the organisation name. If the container exists, the organisation already has a name, and /PrepareAD will use it. Passing a different name with /OrganizationName is how a forest ends up with two Exchange organisations, and the recovery from that is a directory restore rather than a command.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80072030 |
ERROR_DS_NO_SUCH_OBJECT: there is no such object on the server. The directory server setup asked does not hold the object | Microsoft Learn |
Event ID 2937 |
Written alongside Exchange directory-object failures. Microsoft publishes no description, so read the object and attribute named in the event text | not published by the vendor |
Event ID 2501 |
Written by Exchange directory access around setup’s reads and writes. No published description; read the event’s own description field | not published by the vendor |
LDAP 32 |
noSuchObject. The protocol-level form of the same complaint as 0x80072030 | Microsoft Learn |
LDAP 50 |
insufficientAccessRights. The object exists and the account was refused | Microsoft Learn |
0x8007200A |
ERROR_DS_NO_ATTRIBUTE_OR_VALUE: the specified directory service attribute or value does not exist | Microsoft Learn |
Confirm the fix worked
- The object named in
ExchangeSetup.logis present on every domain controller Exchange might use, not just on the one you inspected. repadmin /replsummaryreports no failures for the controllers in the Exchange server’s site.- The setup step you were running completes and
ExchangeSetup.logends in success rather than a rollback. - The Microsoft Exchange organisation object is visible under Services in the configuration naming context, and there is only one of it.
Get-ExchangeServerruns without a directory error from a fresh shell.
Questions people ask about this
Does anything here need to be bought?
No. Directory preparation is part of Exchange setup, the replication tools ship with Windows Server, and rights are group membership. There is no licensing condition behind 0x80072030.
How long should I wait between preparation stages?
Long enough for the change to reach every domain controller Exchange might use, which depends on your site links rather than on any general figure. Verify the object on the controllers involved instead of waiting for a fixed interval, because the interval that works in one forest is wrong in another.
Can I run the schema step from any server?
Microsoft requires the machine to be in the same Active Directory domain and site as the schema master, or to name the schema master with the /DomainController switch. Running it across a slow link is a reliable way to end up with a partly applied extension.
The object exists but setup still fails. What now?
Check which controller setup used, and check the object on that one. Then look at the LDAP result in the log: 32 keeps you on the existence question, 50 moves you onto rights, and 0x8007200A moves you onto the schema.
Is it safe to rerun a preparation step that already succeeded?
Yes. The stages are designed to be repeatable and a rerun on an already-prepared forest completes quickly. What is not safe is passing a different organisation name on a forest that already has one.
