active directory replication issues and troubleshooting

104
ACTIVE DIRECTORY REPLICATION ISSUES AND TROUBLESHOOTING Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security | [email protected] | www.sevecek.com | GOPAS TECHED 2012

Upload: tab

Post on 23-Feb-2016

94 views

Category:

Documents


3 download

DESCRIPTION

GOPAS TechEd 2012. Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security | ondrej@ sevecek.com | www.sevecek.com |. Active Directory Replication Issues and Troubleshooting. Active Directory Replication Issues and Troubleshooting. Network Services. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Active Directory Replication Issues and Troubleshooting

ACTIVE DIRECTORY REPLICATION ISSUES AND TROUBLESHOOTING

Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security |[email protected] | www.sevecek.com |

GOPASTECHED 2012

Page 2: Active Directory Replication Issues and Troubleshooting

NETWORK SERVICESActive Directory Replication Issues and Troubleshooting

Page 3: Active Directory Replication Issues and Troubleshooting

Central Database

LDAP – Lightweight Directory Access Protocol database query language, similar to SQL TCP/UDP 389, SSL TCP 636 Global Catalog (GC) – TCP/UDP 3268, SSL TCP 3269 D/COM Dynamic TCP – Replication D/COM Dynamic TCP – NSPI

Kerberos UDP/TCP 88

Windows NT 4.0 SAM SMB/CIFS TCP 445 (or NetBIOS)

password resets, SAM queries SMB/DCOM Dynamic TCP

NTLM pass-through Kerberos PAC validation

Page 4: Active Directory Replication Issues and Troubleshooting

Design Considerations

Distributed system DCs disconnected for very long times

several months Multimaster replication

with some FSMO roles

Page 5: Active Directory Replication Issues and Troubleshooting

Design Considerations

Example: Caribean cruises, DC/IS/Exchange on board with tens of workstations and users, some staff hired during journey. No or bad satelite connectivity only. DCs synced after ship is berthed at main office.

Challenge: Must work independently for long time periods. Different independent cruise-liners/DCs can accomodate changes to user accounts, email addresses, Exchange settings. Cannot afford lost of any one.

Page 6: Active Directory Replication Issues and Troubleshooting

Database

Microsoft JET engine JET Blue common with Microsoft Exchange used by DHCP, WINS, COM+, WMI, CA,

CS, RDS Broker %WINDIR%\NTDS\NTDS.DIT

ESENTUTL Opened by LSASS.EXE

Page 7: Active Directory Replication Issues and Troubleshooting

Installed servicesLSASS

Security Accounts Manager

TCP 445SMB + Named

Pipes

Kerberos Key Distribution Center

UDP, TCP 88Kerberos

Active Directory Domain Services

UDP, TCP 389LDAP

NTDS.DIT

D/COM Dynamic TCP

Page 8: Active Directory Replication Issues and Troubleshooting

Installed services

LSASS

SAM

KDC

NTDS

TCP 445SMB + Named

Pipes

UDP, TCP 88Kerberos

UDP, TCP 389, ...LDAP

NT4.0

NTLM Pass-through

PAC validation

Windows 2000+

LDAP/ADSI ClientNTDS Replication

FIM/DRS API Client

Connect to domain

D/COM Dynamic TCP

Page 9: Active Directory Replication Issues and Troubleshooting

Uninstallation

DCPROMO requires working replication connectivity

with other DCs DCPROMO /forceremoval

does not access network at all can run in DS Restore Mode

Page 10: Active Directory Replication Issues and Troubleshooting

NTDSUTIL Metadata Cleanup

Connection Connect to server srv2.idtt.local Quit Select operation target List sites Select site 0 List domains in site Select domain 0 List servers in site Select server 0 Quit Remove selected server

Page 11: Active Directory Replication Issues and Troubleshooting

Metadata Cleanup

Page 12: Active Directory Replication Issues and Troubleshooting

TOPOLOGYActive Directory Replication Issues and Troubleshooting

Page 13: Active Directory Replication Issues and Troubleshooting

Knowledge Consistency Checker (KCC)

runs 5 minutes after boot Repl topology update delay (secs)

runs every 15 minutes periodically Repl topology update period (secs)

Page 14: Active Directory Replication Issues and Troubleshooting

Intrasite Replication Topology

DC1

DC2

DC4

DC3

Page 15: Active Directory Replication Issues and Troubleshooting

Originating Updates and Notifications

DC1

DC2

DC4

DC3

15 sec

3 sec

3 sec

Page 16: Active Directory Replication Issues and Troubleshooting

Notification and Replication

DC1 DC2

I have got some changes

Kerberos AuthenticatedDCOM TCP Rando

m

Give me your replica

Kerberos AuthenticatedDCOM TCP Rando

m

Page 17: Active Directory Replication Issues and Troubleshooting

Intrasite Replication – 3 Hops max.

DC1 DC

4

DC3DC

5DC6

DC7

DC2

Page 18: Active Directory Replication Issues and Troubleshooting

Intersite Replication (no Bridgeheads)

DC1

DC2

DC3

DC5

DC6

DC7DC

4

Page 19: Active Directory Replication Issues and Troubleshooting

Intersite Replication (no Bridgeheads)

DC1

DC2

DC3

DC5

DC6

DC7DC

4

15 sec

3 sec

3 sec3 sec

3 secschedule

Page 20: Active Directory Replication Issues and Troubleshooting

Intersite Replication with a Bridgehead

DC1

DC2

DC3

DC5

DC6

DC7DC

4

15 sec

3 sec

3 sec3 sec

3 sec

schedule

Page 21: Active Directory Replication Issues and Troubleshooting

Intrasite Replication

Uses notifications by default (originating/received) 300/30 sec on Windows 2000 15/3 sec on Windows 2003

Occurs every hour as scheduled nTDSSiteSettings At this frequency KCC detects unavailable partners

HKLM\System\CCS\Services\NTDS\Parameters Replicator notify pause after modify (secs) Replicator notify pause between DSAs (secs)

Page 22: Active Directory Replication Issues and Troubleshooting

Intrasite Replication

DC1 DC2

notification

random TCP

downloadchanges

random TCP

15 sec

downloadchanges

random TCP

schedule

Page 23: Active Directory Replication Issues and Troubleshooting

Intersite Replication

DC1 DC2

downloadchanges

random TCP

schedule

Page 24: Active Directory Replication Issues and Troubleshooting

Intersite Replication

Does not use notifications by default siteLink: options = USE_NOTIFY (1)

Compression used siteLink: options =

DISABLE_COMPRESSION (4) Bridge all site links

Page 25: Active Directory Replication Issues and Troubleshooting

Site Link Design

Page 26: Active Directory Replication Issues and Troubleshooting

Site Link Design (Better?)

London

Olomouc

Roma

Cyprus

Paris

Berlin

Page 27: Active Directory Replication Issues and Troubleshooting

Site Link Design (Worse?)

Olomouc

Roma

Cyprus

Paris

Berlin

London

Page 28: Active Directory Replication Issues and Troubleshooting

Static TCP for Replication HKLM\System\CurrentControlSet\Services NTDS\Parameters

TCP/IP Port = DWORD Replication + NSPI

Netlogon\Parameters DCTcpipPort = DWORD LSASS (Pass-through)

NTFRS\Parameters RPC TCP/IP Port Assignment = DWORD

DFSRDIAG StaticRPC /port:xxx /Member:dc1

Page 29: Active Directory Replication Issues and Troubleshooting

Urgent Replication (Notification)

Intrasite only intersite also if notification enabled

Do not wait for delay (15/3 sec) In the case of

account lockout password and lockout policy RID FSMO owner change DC password or trust account password

change

Page 30: Active Directory Replication Issues and Troubleshooting

Immediate Replication (Notification)

Password changes from DCs to PDC

Regardless of site boundaries PDC downloads only the single user

object all changed attributes but only single

object From DC/PDC further with normal

replication

Page 31: Active Directory Replication Issues and Troubleshooting

Example Replication Traffic Atomic replication of a single object with

a one byte attribute change Notification + replication

intersite compressed Overall 7536 B 30 packets ~10 round trips

50 ms round trip means 500 ms transfer time consumption at 120 kbps

Useful data ~80 B

Page 32: Active Directory Replication Issues and Troubleshooting

Bridge All Site Links On

Olomouc

London

Prague

ParisRoma

Cyprus

B

B A

site links are transitive

can be disabled on IP transportA

A

A

A

Page 33: Active Directory Replication Issues and Troubleshooting

Bridge All Site Links Off

Olomouc

London

Prague

ParisRoma

CyprusA

A

site links are not transitive

Cyprus partition is cut off

A

A

A

B

B

Page 34: Active Directory Replication Issues and Troubleshooting

GC Replication

Olomouc

London

Prague

ParisRoma

Cyprus

A

A

A

A

A

one-way:from the source NC into the nearest GC

two-way:GCs between themselves

B

GC

GC

GC

Page 35: Active Directory Replication Issues and Troubleshooting

Roma

London

GC Replication

Olomouc

Prague

Paris

Cyprus

A

A

A

A

B

AB

one-way:from the source NC into the nearest GC

two-way:GCs between themselves

GC

Page 36: Active Directory Replication Issues and Troubleshooting

Subnetting in AD (Apps)

10.10.x.x / 16

10.10.0.248 / 29

DC1

DC2

DC3 DC4

DC5Exchang

eExchangeExchang

e

Page 37: Active Directory Replication Issues and Troubleshooting

Subnetting in AD (Recovery)

10.10.x.x / 16

Recovery Site10.10.0.7 / 32

DC1

DC2

DC3 DC4

DC5

Page 38: Active Directory Replication Issues and Troubleshooting

Rebuilding After Failure

Page 39: Active Directory Replication Issues and Troubleshooting

Rebuilding After Failure

Inter-site IntersiteFailuresAllowed MaxFailureTimeForIntersiteLink (secs)

Intra-site (immediate neighbors) CriticalLinkFailuresAllowed MaxFailureTimeForCriticalLink

Intra-site (optimalization for non-critical) NonCriticalLinkFailuresAllowed MaxFailureTimeForNonCriticalLink

Page 40: Active Directory Replication Issues and Troubleshooting

MODIFICATIONSActive Directory Replication Issues and Troubleshooting

Page 41: Active Directory Replication Issues and Troubleshooting

Modification operations

Create new object Modify attributes

change/delete value change distinguishedName = rename

Rename container all subobjects renamed as well

Page 42: Active Directory Replication Issues and Troubleshooting

Replication Metadata

REPADMIN /ShowObjMeta all attributes when originating DC

Page 43: Active Directory Replication Issues and Troubleshooting

Replication conflicts

The later action wins if no one is later then random (USN)

Attribute modified on two DCs “simultaneously” only one change wins

Linked multivalue attribute modified merged (on 2003+ forest level)

Object/container deleted and object modified deleted

Object moved into a deleted container CN=lost and found

Two objects with the same sAMAccountName, cn or userPrincipalName created object renamed, logins duplicit

Page 44: Active Directory Replication Issues and Troubleshooting

Linked Multi-values

Page 45: Active Directory Replication Issues and Troubleshooting

DC1

Replication

Kamil 10:00Helen 11:00

DC2

DC1 9:00

11:05

Page 46: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00

DC2

DC1 11:30Kamil 10:00Helen 11:00

11:30

Page 47: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00

DC2

DC1 11:30Kamil 10:00Helen 11:00

Judith 12:00

12:05

Page 48: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00

DC2

DC1 12:30Kamil 10:00Helen 11:00

Judith 12:00 Judith 12:00

12:30

Page 49: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00 DC2

DC1 12:30Kamil 10:00Helen 11:00

Judith 12:00

Judith 12:00

DC1DC1DC1

DC3

Marie 11:00 Me

12:30

Page 50: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00 DC2

DC1 12:30Kamil 10:00

Helen 11:00

Judith 12:00

Judith 12:00

DC1

DC1DC1

DC3DC1 10:30DC2 7:00

Kamil 10:00 DC1

Marie 11:00 Me

12:30

Page 51: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00 DC2

DC1 12:30Kamil 10:00

Helen 11:00

Judith 12:00

Judith 12:00

DC1

DC1DC1

DC3DC1 10:30DC2 7:00

Kamil 10:00 DC1

Marie 11:00 Me

13:30

Page 52: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00 DC2

DC1 12:30Kamil 10:00

Helen 11:00

Judith 12:00

Judith 12:00

DC1

DC1DC1

DC3DC1 12:30DC2 13:30

Kamil 10:00 DC1

Marie 11:00 Me

13:30

Page 53: Active Directory Replication Issues and Troubleshooting

DC1

Replication Basics

Kamil 10:00Helen 11:00

Kamil 10:00Helen 11:00

Judith 12:00

Judith 12:00

DC1DC1DC1DC3

DC1 12:30DC2 13:30

Marie 11:00 DC2

14:15

Page 54: Active Directory Replication Issues and Troubleshooting

USN

Each object modification increments USN for that object and for the whole DC

Each DC remembers USNs of its replication partners

repadmin /showutdvec

Page 55: Active Directory Replication Issues and Troubleshooting

USN 2USN5001

3USN3001

1USN1001

2 50013 3001

1 10013 3001

1 10012 5001

Page 56: Active Directory Replication Issues and Troubleshooting

USN 2USN5001

3USN3001

1USN1003

2 50013 3001

13 3001

1 10012 5001

Kamil 1002John 1003

1001

Page 57: Active Directory Replication Issues and Troubleshooting

USN 2USN5001

3USN3001

1USN1003

2 50013 3001

13 3001

1 10012 5001

Kamil 1002John 1003

Notify

Give me

1002, 3

1001

Page 58: Active Directory Replication Issues and Troubleshooting

USN 2USN5003

3USN3001

1USN1003

2 50013 3001

1 10033 3001

1 10012 5001

Kamil 5002John 5003

Kamil 1002John 1003

Page 59: Active Directory Replication Issues and Troubleshooting

USN 2USN5004

3USN3001

1USN1003

2 50013 3001

1 10033 3001

1 10012 5001

Kamil 5002John 5003

Maria 5004Kamil 1002John 1003

Page 60: Active Directory Replication Issues and Troubleshooting

USN 2USN5004

3USN3004

1USN1003

2 50013 3001

1 10033 3001

1 10032 5004

Kamil 3002John 3003

Kamil 5002John 5003

Maria 5004

Maria 3004

Kamil 1002John 1003

Page 61: Active Directory Replication Issues and Troubleshooting

2

11

11

USN 2USN5004

3USN3004

1USN1003

2 50013 3001

1 10033 3001

1 10032 5004

KamilJohn

Kamil 1002John 1003

KamilJohn

MariaKamilJohn

50025003

5004

2

11

KamilJohnKamilJohn

Maria

300230033004

Page 62: Active Directory Replication Issues and Troubleshooting

2

11

11

USN 2USN5004

3USN3004

1USN1003

2 50013 3004

1 10033 3001

1 10032 5004

KamilJohn

Kamil 1002John 1003

KamilJohn

MariaKamilJohn

50025003

5004

2

11

KamilJohnKamilJohn

Maria

300230033004

Maria2

Page 63: Active Directory Replication Issues and Troubleshooting

REPLICATION PROBLEMSActive Directory Replication Issues and Troubleshooting

Page 64: Active Directory Replication Issues and Troubleshooting

The Three Problems

Single DC offline for a long time not so long as tombstone! authentication problem

Tombstone lifetime two separate DC zones not a “business” consistency problem

USN rollback restore from snapshot, image, manual

backup total inconsistency!

Page 65: Active Directory Replication Issues and Troubleshooting

DC Offline for Long Time

DC1

DC2

DC3

DC2 PWD 21

DC3 PWD 31

PWD 21

Month 0

OLD PWD -

PWD 31OLD PWD -

MyPWD 11

Page 66: Active Directory Replication Issues and Troubleshooting

DC Offline for Long Time

DC1

DC2

DC3

DC2 PWD 21

DC3 PWD 31

PWD 22

Month 1

OLD PWD 21

PWD 32OLD PWD 31

MyPWD 11

Page 67: Active Directory Replication Issues and Troubleshooting

DC Offline for Long Time

DC1

DC2

DC3

DC2 PWD 21

DC3 PWD 31

PWD 23

Month 2

OLD PWD 22

PWD 33OLD PWD 32

MyPWD 11

Page 68: Active Directory Replication Issues and Troubleshooting

PWD 21

DC Offline for Long Time

DC1

DC2

DC3

DC2 PWD 21

DC3 PWD 31

PWD 23

Month 3

OLD PWD 22

PWD 33OLD PWD 32

Kerberos

KDC TGS Ticket

MyPWD 11

Page 69: Active Directory Replication Issues and Troubleshooting

PWD 23

DC Offline for Long Time

DC1

DC2

DC3

DC2 PWD 21

DC3 PWD 31

PWD 23

Month 3

OLD PWD 22

PWD 33OLD PWD 32

KDC Disabled TGS

Ticket Kerberos

KDC

MyPWD 11

Page 70: Active Directory Replication Issues and Troubleshooting

DC Isolated for Long Time

DC1

DC2

DC3

MyPWD 13

Month 3

Kerberos

KDC

DC1 PWD 11

DC1 PWD 11

KDC Disabled

PWD 13TGT

Ticket

Page 71: Active Directory Replication Issues and Troubleshooting

DC Isolated for Long Time

DC1

DC2

DC3

Month 3

DC1 PWD 14

DC1 PWD 14

NETDOM RESETPWD

PWD 14TGT

Ticket

MyPWD 14

KDC Disabled

Page 72: Active Directory Replication Issues and Troubleshooting

Lingering Objects

When DC didn’t replicate during the tombstoneLifetime, it halts replication

Can be restored by Allow Replication with Divergent and Corrupt Partner HKLM\System\CCS\Services\NTDS\

Parameters turn on, replicate, turn off

Page 73: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Objects and Tombstones

FrankStanTania

FrankStanTania

FrankStanTania

FrankStanTania

Page 74: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Objects and Tombstones

FrankStanTania

FrankStanTania

FrankStanTania

FrankStanTania

Page 75: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Objects and Tombstones

FrankStanTania

FrankStanTania

FrankStanTania

FrankStanTania

Page 76: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Objects and Tombstones

FrankStanTania

FrankStanTania

FrankStanTania

FrankStanTania

Page 77: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Garbage Collection 1/day

Frank

Tania

FrankStanTania

FrankStanTania

Frank

Tania

Page 78: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Garbage Collection 1/day

Frank

Tania

Frank

Tania

Frank

Tania

Frank

Tania

Page 79: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Lingering Objects

FrankStanTania

FrankStanTania

FrankStanTania

FrankStanTania

Page 80: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Lingering Objects

FrankStanTania

FrankStanTania

FrankStanTania

FrankStanTania

Page 81: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Lingering Objects

Frank

Tania

FrankStan

Frank

Tania

FrankStan

Tania

Tania

Page 82: Active Directory Replication Issues and Troubleshooting

DC4

DC3

DC2

DC1

Lingering Objects

Frank

Tania

FrankStan

Frank

Tania

FrankStan

Tania

Tania

Page 83: Active Directory Replication Issues and Troubleshooting

Possible Problems

Inconsistent distributed database Proliferation of partial objects

after modification of some attributes

Allow Replication with Divergent and Corrupt Partner blocks replication after tombstone

lifetime Strict Replication Consistency

detects partial objects if replication allowed

Page 84: Active Directory Replication Issues and Troubleshooting

Lingering Objects

Page 85: Active Directory Replication Issues and Troubleshooting

Lingering Objects

Strict Replication Consistency HKLM\System\CCS\Services\NTDS\

Parameters 1 – do not replicate 0 – request full copy from source

By default only on new Windows 2003+ installations

Page 86: Active Directory Replication Issues and Troubleshooting

Automatic Repair Philosphy? Business logic says “deleted already”

should we investigate? Metadata cleanup?

we may need some data from the vesel Remove lingering objects

Page 87: Active Directory Replication Issues and Troubleshooting

Removing Lingering Objects REPADMIN /RemoveLingeringObjects

target sourceGUID DN /advisory_mode sourceGUID – healthy DC’s GUID

(without {}) target – suspected DC’s name with

lingering objects DN – naming context DN /advisory_mode just logs the found objects (on the ill DC)

Page 88: Active Directory Replication Issues and Troubleshooting

Lingering Object found/deleted

Page 89: Active Directory Replication Issues and Troubleshooting

Correct Registry Settings

Long term normal operation Strict consistency = 1 Allow divergent partner = 0

Temporary repair operation Strict consistency = 1 Allow divergent partner = 1

Page 90: Active Directory Replication Issues and Troubleshooting

USN Rollback

May or may not be detected Cannot be repaired

not always lingering objects! DC must be denoted/repromoted

unplug network DCPROMO /forceremoval NTDSUTIL Roles NTDSUTIL Metadata Cleanup

Page 91: Active Directory Replication Issues and Troubleshooting

USN Rollback

1001DC1

2USN5001

13 3001

Snapshot

1001

Page 92: Active Directory Replication Issues and Troubleshooting

USN Rollback

Kamil 1002John 1003

Judith 1004Helen 1005

1001DC1

Eva 1006 2USN5001

13 3001

Snapshot

1001

Page 93: Active Directory Replication Issues and Troubleshooting

USN Rollback

Kamil 1002John 1003

Judith 1004Helen 1005

1001DC1

Eva 1006 2USN5001

1 10063 3001

SnapshotKamil 1002John 1003

Judith 1004Helen 1005Eva 1006

Page 94: Active Directory Replication Issues and Troubleshooting

Restore

1001DC1

2USN5001

1 10063 3001

RestoreKamil 1002John 1003

Judith 1004Helen 1005Eva 1006

Page 95: Active Directory Replication Issues and Troubleshooting

USN Rollback (Detectable)

1001DC1

2USN5001

1 10063 3001

RestoreKamil 1002John 1003

Judith 1004Helen 1005Eva 1006

Page 96: Active Directory Replication Issues and Troubleshooting

USN Rollback (Detectable)

1001DC1

2USN5001

1 10063 3001

RestoreKamil 1002John 1003

Judith 1004Helen 1005Eva 1006

Frank 1002Stan 1003

Page 97: Active Directory Replication Issues and Troubleshooting

USN Rollback (Detectable)

Page 98: Active Directory Replication Issues and Troubleshooting

USN Rollback (Detectable)

Page 99: Active Directory Replication Issues and Troubleshooting

USN Rollback (Detectable)

Page 100: Active Directory Replication Issues and Troubleshooting

USN Rollback (Detectable)

Page 101: Active Directory Replication Issues and Troubleshooting

USN Rollback (Non-detect.)

Frank 1002Stan 1003

1001DC1

2USN5001

1 10063 3001

Tania 1004Mark 1005

Martin 1006Victor 1007Leo 1008

RestoreKamil 1002John 1003

Judith 1004Helen 1005Eva 1006

Page 102: Active Directory Replication Issues and Troubleshooting

USN Rollback (Non-detect.)

Frank 1002Stan 1003

1001DC1

2USN5001

1 10083 3001

Tania 1004Mark 1005

Martin 1006Victor 1007Leo 1008

Restore

Victor 1007Leo 1008

Kamil 1002John 1003

Judith 1004Helen 1005Eva 1006

Page 103: Active Directory Replication Issues and Troubleshooting

Restoring VM Snapshots

Restore offline HKLM\System\CurrentControlSet\Services\

NTDS Database Restored from Backup =

DWORD = 1 Restart NTDS service

changes InvocationID of the database instance

Page 104: Active Directory Replication Issues and Troubleshooting

THANK YOU!

Ing. Ondřej Ševeček | GOPAS a.s. | MCM: Directory Services | MVP: Enterprise Security |[email protected] | www.sevecek.com |

GOPASTECHED 2012