<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Petri IT Knowledgebase Forums - Active Directory</title>
		<link>http://www.petri.co.il/forums/</link>
		<description>For questions and discussions strictly related to AD, Trusts, Migration, you name it.</description>
		<language>en</language>
		<lastBuildDate>Tue, 21 May 2013 06:48:50 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.petri.co.il/forums/images/steelblue/misc/rss.jpg</url>
			<title>Petri IT Knowledgebase Forums - Active Directory</title>
			<link>http://www.petri.co.il/forums/</link>
		</image>
		<item>
			<title>Unified Messaging Dial plan object</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63465&amp;goto=newpost</link>
			<pubDate>Mon, 20 May 2013 04:09:11 GMT</pubDate>
			<description><![CDATA[Hi all. I was wondering if anyone knows the name of the attribute on A UM dial Plan in AD; that tells specifies what servers are associated with the dial plan?  I found the Um Dial Plan in ad but can't find the attribute. 
 
Can anyone help here? 
 
Cheers.]]></description>
			<content:encoded><![CDATA[<div>Hi all. I was wondering if anyone knows the name of the attribute on A UM dial Plan in AD; that tells specifies what servers are associated with the dial plan?  I found the Um Dial Plan in ad but can't find the attribute.<br />
<br />
Can anyone help here?<br />
<br />
Cheers.</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>Jscubafbi</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63465</guid>
		</item>
		<item>
			<title>Administrators Active Directory Report</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63464&amp;goto=newpost</link>
			<pubDate>Sun, 19 May 2013 23:42:01 GMT</pubDate>
			<description>Good evening, 
 
How can I generate a report of administrators users in Active Directory? 
 
Thank you very much.</description>
			<content:encoded><![CDATA[<div>Good evening,<br />
<br />
How can I generate a report of administrators users in Active Directory?<br />
<br />
Thank you very much.</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>leoalvis</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63464</guid>
		</item>
		<item>
			<title>Security for 3rd Party suppliers, developers, VPN access, Group Policy, Leveraging AD</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63450&amp;goto=newpost</link>
			<pubDate>Fri, 17 May 2013 11:05:10 GMT</pubDate>
			<description>Hi 
 I have just come out of a meeting where it was discussed that our  security needs to be greatly improved as well as procedures and  management of our Production environments.  
 
 
 
 Being a multi-international company we have numerous 3rd parties who  access our system. Currently we use PPTP...</description>
			<content:encoded><![CDATA[<div>Hi<br />
 I have just come out of a meeting where it was discussed that our  security needs to be greatly improved as well as procedures and  management of our Production environments. <br />
<br />
<br />
<br />
 Being a multi-international company we have numerous 3rd parties who  access our system. Currently we use PPTP connectivity via a Linux server  to provide them access and this is how we provide access to our 3rd  parties as well as internal employees. I am  putting a plan together to move away from this as this is a BIG  security issue as its not controlled and if a 3rd party understood our  systems better they would be able to access any point of the network. <br />
 Our developers, solution architects also have access to our  production systems and we have recently learnt that some changes are not  going from a dev to production environment in a controlled manner, in  some cases any changes are being made directly to production  systems without any proper testing. <br />
 Currently the internal developers will have a local admin access to a  Windows server. historically if a user wanted access they just needed  to put in a request in and they would have access. <br />
<br />
<br />
<br />
 I am just trying to get some advice on how best we can better manage  this, what do other companies do in our situation? I doubt if we are  unique with these problems. I think moving forward a VPN gateway which  authenticates with AD, where we can control access  to what servers/RDP sessions a particular user/group can have access  too (similar to a remote apps/Citrix web session) and also getting away  from multiple users have local admin access to servers. A suggestion was  to use one 'developer' account and use group  policy to create this local account on all PROD/DEV servers in the  enterprise but the problem I see with this is we cannot audit who is  making the changes if there are multiple devs using 1 account. <br />
<br />
<br />
<br />
 Moving onto auditing, any suggestions on how better we can audit our  environment? can this be done straight out of the box on Windows servers  or do we need a 3rd party tool?<br />
<br />
<br />
 Many Thanks</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>ranjb</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63450</guid>
		</item>
		<item>
			<title>The issue with Windows NT still lurking as a Trust</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63418&amp;goto=newpost</link>
			<pubDate>Tue, 14 May 2013 09:28:32 GMT</pubDate>
			<description>Hi All 
I am currently working on a piece to decommission our ldap domain in our offices across the UK and move to a fully Wintel environment. We have a mixture of environments at the moment, we have an old NT Domain, a LDAP domain on Linux and an Active Directory domain. The AD domain is the...</description>
			<content:encoded><![CDATA[<div>Hi All<br />
I am currently working on a piece to decommission our ldap domain in our offices across the UK and move to a fully Wintel environment. We have a mixture of environments at the moment, we have an old NT Domain, a LDAP domain on Linux and an Active Directory domain. The AD domain is the forest root and there are trusts to the NT and Linux domain from here as well other domains from our partner countries. <br />
 <br />
All of our services are hosted in a Data center and we have MPLS Wan links to all of our offices, we have 4 in total. All of our Windows domain controllers are hosted in the DC, with our Linux environment, we have master LDAP/DNS/DHCP/NTP in the DC and have replicas in the office locations, one at a time they have been decommissioned as the local offices have moved over to the Windows equivalents of those services i.e. moving users/computers from Linux to AD domain. <br />
 <br />
I have a question with regards to 1 office where the majority of our users reside. I have removed the dependance of LDAP now and now want to create a DNS and DHCP for this office. That part I am OK with, however because the number of users I see there will likely be a benefit if I install a RODC in this office.<br />
 <br />
My question is in the DC we have 3 DCs, our forest and domain levels are set to 2003. If I was to create another 2008R2 RODC in this office would it have an issue with the NT trust?<br />
 <br />
I read this article and got slightly concerned <br />
<a href="http://blogs.technet.com/b/askds/archive/2010/07/30/friday-mail-sack-newfie-from-the-grave-edition.aspx#nt4" target="_blank">http://blogs.technet.com/b/askds/arc...ition.aspx#nt4</a><br />
It talks about NT trusts and 2008R2 DCs not being compatible... Have others encountered this issue? The NT4 domain is going but I am not in a place to remove it yet due to legacy applications still reliant on this. <br />
 <br />
Thanks</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>ranjb</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63418</guid>
		</item>
		<item>
			<title>Permissions to logon through terminal services</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63400&amp;goto=newpost</link>
			<pubDate>Fri, 10 May 2013 13:04:29 GMT</pubDate>
			<description>Why is this not working... 
  
Forest is domain.com, child domain is ABC.domain.com 
  
Domain admins group at Domain.com is part of the built in administrators group in ABC.domain.com. 
  
Servers local policy states Administrators and Remote Desktop Users are allowed logon through terminal...</description>
			<content:encoded><![CDATA[<div>Why is this not working...<br />
 <br />
Forest is domain.com, child domain is ABC.domain.com<br />
 <br />
Domain admins group at Domain.com is part of the built in administrators group in ABC.domain.com.<br />
 <br />
Servers local policy states Administrators and Remote Desktop Users are allowed logon through terminal services, but yet a user in the domain admins group at domain.com cannot log into a server in ABC.domain.com.<br />
 <br />
 <br />
Did I miss something?</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>Stevenjwilliams83</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63400</guid>
		</item>
		<item>
			<title><![CDATA[How to generate a "last login" report]]></title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63324&amp;goto=newpost</link>
			<pubDate>Sun, 28 Apr 2013 08:55:00 GMT</pubDate>
			<description><![CDATA[Hello, 
 
I would like to know how can I get a report of all users last login time? 
I would like to clean my Active directory from users who haven't login to the domain above X time. 
 
Thanks for your help]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
I would like to know how can I get a report of all users last login time?<br />
I would like to clean my Active directory from users who haven't login to the domain above X time.<br />
<br />
Thanks for your help</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>Tasuooooo</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63324</guid>
		</item>
		<item>
			<title>Sysvol corrupt</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63295&amp;goto=newpost</link>
			<pubDate>Thu, 25 Apr 2013 09:53:47 GMT</pubDate>
			<description>Hi, 
  
We had an old Windows 2003 server acting as a domaincontroller for ad.domain.net, this was set to windows 2000 mode if I remember right. What I first done was to raise this to 2003 mode. 
Then I runned this: on the domaincontroller run D:\support\adprep\adprep32/forestprep and...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
 <br />
We had an old Windows 2003 server acting as a domaincontroller for ad.domain.net, this was set to windows 2000 mode if I remember right. What I first done was to raise this to 2003 mode.<br />
Then I runned this: on the domaincontroller run D:\support\adprep\adprep32/forestprep and D:\support\adprep\adprep32 /domainprep<br />
The next step was that I installed active directory services on the Windows 2008 server and did a dcpromo and added this second dc to the domain ad.domain.net. Then I transferred all roles to the new server and finally depromoted the old dc. The old Dc is unfortunately gone now.<br />
 <br />
But during the work i noticed that the sysvol share never was created on this server. Found that file replication service was disabled on the old server, and has been that for several years? So I tried to start that service but got an error message as I understood this was due to that this service has been disabled for a very long time. So I did a search for that and noticed that several others had this problem and that they solved this by stopping the netlogon service on the new server and copied the whole sysvol directory from the old server to C:\Windows\System32 on the new server, and then started the netlogon service again. <br />
<br />
My question is if somebody knows if I can start from scratch in some way with the sysvol without reinstalling the domaincontrollers? There wasn’t so much policies applied so I can recreate those manually.</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>Ruslan</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63295</guid>
		</item>
		<item>
			<title>AD Migration Question</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63288&amp;goto=newpost</link>
			<pubDate>Wed, 24 Apr 2013 15:27:49 GMT</pubDate>
			<description><![CDATA[We are looking at migrating from our current AD setup (parent + child domains) to a new forest utilizing a resource forest for Exchange. How feasible is this (based on info below) and how difficult? I've done forest to forest migrations before; but never from a forest/child domain to a new forest...]]></description>
			<content:encoded><![CDATA[<div>We are looking at migrating from our current AD setup (parent + child domains) to a new forest utilizing a resource forest for Exchange. How feasible is this (based on info below) and how difficult? I've done forest to forest migrations before; but never from a forest/child domain to a new forest with Resource Forest.  <br />
<br />
Just wondering how painful it is to migrate from Parent holding Exchange, Child holding users to Resource Forest setup.<br />
<br />
<br />
CURRENT SETUP<br />
<br />
ParentDomain = holds Exchange server (and DAG) and a couple of DCs<br />
      ChildDomain1 = holds users, couple of DCs for ChildDomain1, and various  resources for ChildDomain1<br />
<br />
      ChildDomain2 = holds users, couple of DCs for ChildDomain2, and various resources for ChildDomain2<br />
<br />
<br />
Parent-Child trust between ParentDomain and each Child. Shortcut trust between ChildDomain1 and ChildDomain2<br />
<br />
<br />
PLANNED SETUP<br />
<br />
ResourceForest = will hold Exchange + DAG<br />
    Domain1Forest = will hold users and resources from ChildDomain1<br />
    Domain2Forest = will hold users and resources from ChildDomain2<br />
<br />
    Trusts built between ResourceForest and Domain1/Domain2. Trust built between Domain1 and Domain2.</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>exoromeo</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63288</guid>
		</item>
		<item>
			<title>FRS will not start.  AD/GPO all messed up.</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63283&amp;goto=newpost</link>
			<pubDate>Tue, 23 Apr 2013 20:20:18 GMT</pubDate>
			<description><![CDATA[IssueServer01: Windows Server 2003 R2 SP2 
 
 
Environment: DCs are: Server 2003/2008/2012 
 
 
I discovered an issue when creating a new GPO to map a network drive.  It wasn't replicating to all DCs.   
 
 
IssueServer01 was the RID/PDC/Infrastructure Operations Master, and I discovered that it's...]]></description>
			<content:encoded><![CDATA[<div>IssueServer01: Windows Server 2003 R2 SP2<br />
<br />
<br />
Environment: DCs are: Server 2003/2008/2012<br />
<br />
<br />
I discovered an issue when creating a new GPO to map a network drive.  It wasn't replicating to all DCs.  <br />
<br />
<br />
IssueServer01 was the RID/PDC/Infrastructure Operations Master, and I discovered that it's FRS service would not start.  Since then, I have transferred the Operations Master roles to a functional DC.  Also, the SYSVOL folder was not shared.  <br />
<br />
<br />
When trying to manually start the FRS service, I get &quot;Error 1067: The Process terminated unexpectedly&quot;<br />
<br />
<br />
We don't need this server to be a DC any longer, so I decided to demote it.  When I try that (as well as dcpromo /forceremoval), I get &quot;The operation failed because: Failed to prepare for or remove the sysvol replication.  The file replication service cannot be started.&quot;<br />
<br />
<br />
I would rather not just shut this server off and manually remove the metadata.  I think if I can get the FRS service running, then I can demote it.  Any ideas?<br />
<br />
<br />
<br />
Thank you in advance for any help you can offer.</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>Rogie</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63283</guid>
		</item>
		<item>
			<title>Home folders</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63277&amp;goto=newpost</link>
			<pubDate>Tue, 23 Apr 2013 14:03:59 GMT</pubDate>
			<description>Win2k3 Servers with AD.  Mixed in some Win2k8 servers, exchange, virtual servers. 
  
All of my users can browse all other home folders, this should not happened at all weird. Seems like it just started doing this lately.  Network has been up and running since 2008 with no issues. 
  
everyone is...</description>
			<content:encoded><![CDATA[<div>Win2k3 Servers with AD.  Mixed in some Win2k8 servers, exchange, virtual servers.<br />
 <br />
All of my users can browse all other home folders, this should not happened at all weird. Seems like it just started doing this lately.  Network has been up and running since 2008 with no issues.<br />
 <br />
everyone is connected properly to the Z drive<br />
 <br />
<a href="file://\\myserver\home$\%username%" target="_blank">\\myserver\home$\%username%</a></div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>bigalusn</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63277</guid>
		</item>
		<item>
			<title>Group Policy for Linux desktops</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63191&amp;goto=newpost</link>
			<pubDate>Mon, 15 Apr 2013 13:02:09 GMT</pubDate>
			<description><![CDATA[Hi,  
 
  I would like to know is it possible to set a Group policy in windows 2008 or windows 2012 for Linux desktops also. I have client who is having AD on windows 2008 R2 server and client system on both windows & Linux desktops & now they want to  set group policy for both windows and linux...]]></description>
			<content:encoded><![CDATA[<div>Hi, <br />
<br />
  I would like to know is it possible to set a Group policy in windows 2008 or windows 2012 for Linux desktops also. I have client who is having AD on windows 2008 R2 server and client system on both windows &amp; Linux desktops &amp; now they want to  set group policy for both windows and linux desktops.<br />
<br />
I would like to know is it possible to set group policy for linux OS through windows Ad<br />
<br />
<br />
Regards<br />
<br />
Alex</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>Alexgeorge26</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63191</guid>
		</item>
		<item>
			<title>The choosing of AD DC</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63182&amp;goto=newpost</link>
			<pubDate>Sun, 14 Apr 2013 20:08:48 GMT</pubDate>
			<description>I have been struggling with understand why my local site clients would be accessing a DC across a WAN to authenticate? I have looked at my AD SAS and the DCs are in the correct locations mapped with the right subnets. Also when I open my AD UAC tool from my desktop it just randomly picks a DC, then...</description>
			<content:encoded><![CDATA[<div>I have been struggling with understand why my local site clients would be accessing a DC across a WAN to authenticate? I have looked at my AD SAS and the DCs are in the correct locations mapped with the right subnets. Also when I open my AD UAC tool from my desktop it just randomly picks a DC, then when I change the DC and check the box that saves this configuration for the console, the next time I open it, it picks a random DC again? What is going on?</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>Stevenjwilliams83</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63182</guid>
		</item>
		<item>
			<title>AD Migration (split from hijacked thread)</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63132&amp;goto=newpost</link>
			<pubDate>Tue, 09 Apr 2013 12:52:31 GMT</pubDate>
			<description>Hi.  Trying to perform transition from Windows 2000/Exchange 2000 to Windows 2008R2/Exchange2007. 
 
Created a test virtual environment using VmVConvertor ver 4.0.1.  DCs are converted properly.  I get an error message when I try to replicate DCs indicating USN Rollback.  Cannot run ADPREP32...</description>
			<content:encoded><![CDATA[<div>Hi.  Trying to perform transition from Windows 2000/Exchange 2000 to Windows 2008R2/Exchange2007.<br />
<br />
Created a test virtual environment using VmVConvertor ver 4.0.1.  DCs are converted properly.  I get an error message when I try to replicate DCs indicating USN Rollback.  Cannot run ADPREP32 /FORESTPREP on the Schema master.  It returns error the DC needs to replicate once after reboot to change schema.  This cannot be done because of the USN RollBack.  All the articles refer to restore AD.  Unfortunately ntbackup or other backup utility don't works under DSRM on these VMs. Removed all the references of other DCs, so I only have one DC, yet cannot adprep.  Can anybody help me to overcome this problem?</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>behzad</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63132</guid>
		</item>
		<item>
			<title>Active Directory/Directory Server</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63119&amp;goto=newpost</link>
			<pubDate>Mon, 08 Apr 2013 11:01:39 GMT</pubDate>
			<description>Hi, 
  
I would like to know under what circumstances will Active directory and Directory server be configured in the same environment. 
  
What measures needs to be taken before having this kind of setup.</description>
			<content:encoded><![CDATA[<div>Hi,<br />
 <br />
I would like to know under what circumstances will Active directory and Directory server be configured in the same environment.<br />
 <br />
What measures needs to be taken before having this kind of setup.</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>surdileep</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63119</guid>
		</item>
		<item>
			<title>NtFrs  Event ID:      1350</title>
			<link>http://www.petri.co.il/forums/showthread.php?t=63090&amp;goto=newpost</link>
			<pubDate>Thu, 04 Apr 2013 19:14:06 GMT</pubDate>
			<description>What is this then? 
 
---Quote--- 
Log Name:      File Replication Service 
Source:        NtFrs 
Date:          3/31/2013 10:58:34 AM 
Event ID:      13508 
Task Category: None 
Level:         Warning 
Keywords:      Classic</description>
			<content:encoded><![CDATA[<div>What is this then?<br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="4" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Log Name:      File Replication Service<br />
Source:        NtFrs<br />
Date:          3/31/2013 10:58:34 AM<br />
Event ID:      13508<br />
Task Category: None<br />
Level:         Warning<br />
Keywords:      Classic<br />
User:          N/A<br />
Computer:      RLSSERVER2.rls.local<br />
Description:<br />
The File Replication Service is having trouble enabling replication from RLSSERVER.rls.local to RLSSERVER2 for c:\windows\sysvol\domain using the DNS name RLSSERVER.rls.local. FRS will keep retrying. <br />
 Following are some of the reasons you would see this warning. <br />
 <br />
 [1] FRS can not correctly resolve the DNS name RLSSERVER.rls.local from this computer. <br />
 [2] FRS is not running on RLSSERVER.rls.local. <br />
 [3] The topology information in the Active Directory Domain Services for this replica has not yet replicated to all the Domain Controllers. <br />
 <br />
 This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.<br />
Event Xml:<br />
&lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br />
  &lt;System&gt;<br />
    &lt;Provider Name=&quot;NtFrs&quot; /&gt;<br />
    &lt;EventID Qualifiers=&quot;32768&quot;&gt;13508&lt;/EventID&gt;<br />
    &lt;Level&gt;3&lt;/Level&gt;<br />
    &lt;Task&gt;0&lt;/Task&gt;<br />
    &lt;Keywords&gt;0x80000000000000&lt;/Keywords&gt;<br />
    &lt;TimeCreated SystemTime=&quot;2013-03-31T15:58:34.000000000Z&quot; /&gt;<br />
    &lt;EventRecordID&gt;426&lt;/EventRecordID&gt;<br />
    &lt;Channel&gt;File Replication Service&lt;/Channel&gt;<br />
    &lt;Computer&gt;RLSSERVER2.rls.local&lt;/Computer&gt;<br />
    &lt;Security /&gt;<br />
  &lt;/System&gt;<br />
  &lt;EventData&gt;<br />
    &lt;Data&gt;RLSSERVER.rls.local&lt;/Data&gt;<br />
    &lt;Data&gt;RLSSERVER2&lt;/Data&gt;<br />
    &lt;Data&gt;c:\windows\sysvol\domain&lt;/Data&gt;<br />
    &lt;Data&gt;RLSSERVER.rls.local&lt;/Data&gt;<br />
    &lt;Binary&gt;D5040000&lt;/Binary&gt;<br />
  &lt;/EventData&gt;<br />
&lt;/Event&gt;
			
			<hr />
		</td>
	</tr>
	</table>
</div>The 2 domain controllers are replicating back and forth. I created an object on one, then created another object on the other and after a few moments they have the same object. I've jumped around on the internet and tried several different things. The two DCs can resolve the other via DNS.<br />
<br />
Everything seems functional on each DC.</div>

]]></content:encoded>
			<category domain="http://www.petri.co.il/forums/forumdisplay.php?f=16">Active Directory</category>
			<dc:creator>ant2ne</dc:creator>
			<guid isPermaLink="true">http://www.petri.co.il/forums/showthread.php?t=63090</guid>
		</item>
	</channel>
</rss>
