GPO somehow not applied to all users after ransomeware attack.


hi experts,

one of client having issue after ransomware attack, not tell whether ad still in healthy status , when run dcdiag,

    starting test: frsevent

         there warning or error events within last 24 hours after sysvol has been

         shared.  failing sysvol replication problems may cause group policy problems.
         ......................... ms-svr-02 passed test frsevent

      starting test: ncsecdesc

         error nt authority\enterprise domain controllers doesn't have

            replicating directory changes in filtered set
         access rights naming context:

         dc=forestdnszones,dc=maestroswiss,dc=local
         error nt authority\enterprise domain controllers doesn't have

            replicating directory changes in filtered set
         access rights naming context:

         dc=domaindnszones,dc=maestroswiss,dc=local
         ......................... ms-svr-02 failed test ncsecdesc

failing sysvol replicating seems root cause, im not sure.if yes, how going fix ?

thanks

alfred


failing sysvol replicating seems root cause, im not sure.if yes, how going fix ?

you can couple of things. firstly, see if there missing netlogon , sysvol shares on dc's. these should root cause. secondly, try create new gpo , see happens in sysvol folder. replicated properly? if have small number of dc's can create fake gpo each dc , see if replicating. after read below:


mahdi tehrani | | www.mahditehrani.ir
make sure download free powershell scripts:



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Domain migration ERR3:7075 Failed to change domain affiliation, hr=8007054a This operation is only allowed for the Primary Domain Controller of the domain

How do a find data in one file, search for it in another file and if not found, write a custom message to another file