GPO somehow not applied to all users after ransomeware attack.
hi experts,
one of client having issue after ransomware attack, not tell whether ad still in healthy status , when run dcdiag,
starting test: frsevent
there warning or error events within last 24 hours after sysvol has been
shared. failing sysvol replication problems may cause group policy problems.
......................... ms-svr-02 passed test frsevent
starting test: ncsecdesc
error nt authority\enterprise domain controllers doesn't have
replicating directory changes in filtered set
access rights naming context:
dc=forestdnszones,dc=maestroswiss,dc=local
error nt authority\enterprise domain controllers doesn't have
replicating directory changes in filtered set
access rights naming context:
dc=domaindnszones,dc=maestroswiss,dc=local
......................... ms-svr-02 failed test ncsecdesc
failing sysvol replicating seems root cause, im not sure.if yes, how going fix ?
thanks
alfred
failing sysvol replicating seems root cause, im not sure.if yes, how going fix ?
you can couple of things. firstly, see if there missing netlogon , sysvol shares on dc's. these should root cause. secondly, try create new gpo , see happens in sysvol folder. replicated properly? if have small number of dc's can create fake gpo each dc , see if replicating. after read below:
- https://support.microsoft.com/en-us/help/257338/troubleshooting-missing-sysvol-and-netlogon-shares-on-windows-domain-controllers
- https://social.technet.microsoft.com/forums/windowsserver/en-us/d1813eb8-e784-4fae-a448-5e4415ca406b/sysvol-and-netlogon-folders-not-shared?forum=winserverds
mahdi tehrani | | www.mahditehrani.ir
make sure download free powershell scripts:
Windows Server > Directory Services
Comments
Post a Comment