Fix SYSVOL and Domain Controller Replication | Active Directory DFSR Issues Resolved

Поділитися
Вставка
  • Опубліковано 22 січ 2025

КОМЕНТАРІ • 186

  • @borisminakov7573
    @borisminakov7573 3 роки тому +13

    Dear Sysadmin, after searching for 6 hours manuals of MS website, this 10 min video saved my live! Thank you so much. All works as expected. I can add only 1 note from my end. When new DC controller is set-up and replication is not working:
    1) Proceed all steps in video
    2) If no "Netlogon" and no "Sysvol" shares are available on problematic (New) DC, go to registry and change
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters
    "SysvolReady" to 1
    Restart "Netlogon" service
    If no replication is started and no files created under "Sysvol", create manually directory "Sysvol\Polices" and sync will work as expected
    Thanks

  • @superduperwescooper
    @superduperwescooper 4 роки тому +19

    Even if this does not fix my particular problem. This is the best explanation of an issue I have ever seen on UA-cam.

  • @scottluebke5012
    @scottluebke5012 4 місяці тому +1

    YOU ARE A GAWD. I'm an MCSA on Server 2016, ten years professionally doing this stuff, set up a new DC today and ran into this issue. With the move to the cloud, I don't touch servers a ton anymore, but wow did this fix the issue. I was totally lost, too.

  • @ball_soup
    @ball_soup 2 роки тому

    Life saver! I had an issue where de-promoting the old secondary DC caused the old primary DC to crap itself, and the new DCs took over but had weird issues because it wasn't graceful at all. You've just helped me solve the biggest issue that's been plaguing my domain!

  • @humandestiny3934
    @humandestiny3934 Рік тому

    Been beating my head against my desk all day trying to figure this out. This video worked. Thank you much, sir!

  • @RDeck9
    @RDeck9 Рік тому

    I can't tell you how glad I am to have found this -- I've been stuck on this for way too long that I'm willing to admit! Thank you.

  • @NoneRain_
    @NoneRain_ 3 роки тому +11

    I can't say how much this tutorial is great.
    Right to the point, perfect. Thank you!

  • @gbryant200
    @gbryant200 4 місяці тому

    This is one of the best instructional videos I have seen. Great explanations as to why you're doing what you're doing and what it's supposed to fix and how to do it. Fantastic!

  • @streborz
    @streborz Рік тому

    Been on this thing for 3 days and this fixed 95% of the problems I was having (the other was Netlogon folder missing). Thanks for posting such a clean fix! Thankfully I did all of this on actual copies of may production machines in a VMware Workstation environment. This would have been a major PITA if not. 1000 Thank You's!

  • @chuck1000000
    @chuck1000000 2 роки тому +1

    I cant thank you enough for creating this video. We have had so many replication issues and this fixes them. THANK YOU!

  • @stephanestephane4295
    @stephanestephane4295 Рік тому

    Thank you so much .... just tested in the lab and resolved all my issue straight forward ... Man of the day !!

  • @i80386sx
    @i80386sx 2 роки тому

    I've been chasing this problem for two weeks. Good thing I caught the problem in a test lab. Thank you!

  • @SteveRogers-k8n
    @SteveRogers-k8n 6 місяців тому

    The steps in this video worked like a charm, I'd added a 2019 DC to a 2016 domain running a single DC but noticed no sysvol or netlogon on the new box. Did these steps and replication was fixed.

  • @JonathanCarey-s5r
    @JonathanCarey-s5r 4 місяці тому

    Hi Sysadmin....you are a life saver!!!!!!!! Thank you so much! This is the easiest to follow and most accurate resolution!

  • @Sanxion01
    @Sanxion01 2 роки тому

    Thanks for this video. I have done it in the last six months or so on another DC pair, but this helped me out today when I needed to get this done in a hurry for a customer. Good clear instructions and fixed up a DFS system that had been broken for a long while. Top stuff!

  • @oli1232009
    @oli1232009 Рік тому

    Fantastic video. I do not comment on things at all but this has saved me so much. Just subscribed. Keep up the awesome work bud!

  • @TheMarge99
    @TheMarge99 8 місяців тому

    Just wanted to say thank you, this got my SYSVOL rep working straight away following this guide.

  • @fabianos.martins4221
    @fabianos.martins4221 Рік тому

    I had 2 situations were it help me a lot! I have no words to thank you man!

  • @jasonmorris4eva
    @jasonmorris4eva Рік тому

    The problem I am having is that the Netlogon and Sysvol folder is not on the additional DC. Yet it tells me the replication is working when I run the command to test it.

  • @williamdickinson165
    @williamdickinson165 5 місяців тому

    Excellent, clear and concise walkthrough. Very much appreciated.

  • @sergiorivas1857
    @sergiorivas1857 2 роки тому

    I love it when videos get straight to the point and work. Awesome job!

  • @WalidBaghdady-kv2mm
    @WalidBaghdady-kv2mm Рік тому

    In 2024, the issue with DC Server 2016 has been resolved.
    Thank you very much.

  • @AmirSalehipour
    @AmirSalehipour 4 місяці тому

    Hello Sysadmin,
    That worked perfectly for my issue where I had three domain controllers and migrated the FSMO roles to DC1. When I changed a policy, it didn't fully replicate to the SYSVOL, which was weird because it replicated to DC2, but when I navigated to the domain\sysvol on DC1, it was not there! Really weird! Anyway, it solved my issue. Thank you.

  • @Jake-Cooper
    @Jake-Cooper 5 місяців тому

    Thank you very much this fixed my issue and i cant tell you how long it took me of trying before i found this video

  • @Oper8or
    @Oper8or 3 місяці тому

    You just helped me fix the issue and I did find another article on how to do this but the video was much better.

  • @t4ir1
    @t4ir1 2 місяці тому

    Thanks a bunch! This video helped me solve my problem! Thank you so much mate.
    You just got a new subscriber!

  • @fernandoh4515
    @fernandoh4515 2 роки тому

    Not all heroes wear capes. You sir are great!
    Thank you!

  • @blueyellowtomato
    @blueyellowtomato 2 роки тому +1

    Thank you Paul! Saved the Easter Weekend! :-)

  • @InvisibleChitChat
    @InvisibleChitChat 2 місяці тому

    What if there is only one domain controller and you are getting event ID 4012 DFS Replication. How would I go about fixing this when there is only one domain controller and old domain controller was decommissioned.

  • @TheChewyWun
    @TheChewyWun 7 місяців тому

    I know this is an older video, but any ideas when I'm getting a RPC server is unavailable error when running the replication commands?

  • @RuneInVR
    @RuneInVR 9 місяців тому

    Saved me countless hours of troubleshooting, thanks a lot.

  • @helmannlago7858
    @helmannlago7858 3 роки тому

    Great stuff!
    This is very useful when you need to follow such procedure and don't have time to digest all the steps by simply reading MS article.
    Thanks man.

  • @edddy22
    @edddy22 5 місяців тому

    Worked for me , awesome and concise explanation. Only thing at the end I was wondering what happened to dsrf-options value which wasn’t manually reverted to original but in my case once everything was consistent again and working the value itself got back to 0

  • @nossnitram
    @nossnitram 3 роки тому

    Thanks. This solved my issue. Had 3 DC´s that did not sync at all. And now it works again.

  • @dj4634
    @dj4634 Рік тому

    Thanks so much! I found a client had a netlogon/sysvol replication issue. Looked like it was also impacting all AD replication (GPO et al) but your procedure here fixed everything.

  • @lamok5516
    @lamok5516 7 місяців тому

    why wouldn't you do a non-auth restore and it will copy changes from dc02? what is the reasoning behind doing a auth restore in this scenario -thanks

  • @bert-janfikse4091
    @bert-janfikse4091 2 роки тому +2

    Thx Paul, you saved us as lot of time :)!!

  • @InternetSavage
    @InternetSavage 2 роки тому

    What if your NETLOGON and SYSVOL shares are missing altogether on a domain controller?

  • @ingessish
    @ingessish 2 роки тому

    Thanks for this video. I had an issue where I have upgraded from a SBS 2008 server years ago and must have created a DFS group for SYSVOL during the migration.
    The SBS environment was always a single DC (yes, not good) so I just got around to adding a second DC but the wizard never created the shares or the DFR sync due to a stale sync of over 786 days
    The steps shown here resolved the issue with the sync once I manually added the shares on the second DC.
    Thanks again

  • @varianh1455
    @varianh1455 7 місяців тому

    This was the perfect tutorial, I was able to fix this issue finally. Thanks!😀

  • @DwayneKSmith876
    @DwayneKSmith876 22 години тому

    I found this video while researching 2213 issue. On fixing that issue i'm now getting a 4012 issue with a primary DC that apparently has been having DFS replication issue for 7 years. Would this fix be recommended?

  • @pilotken8685
    @pilotken8685 2 роки тому

    I do not have msDFSR-Enabled at all on my domain controllers... it is not there... 2012R2... not sure how to proceed..

  • @piyushjain5542
    @piyushjain5542 Рік тому

    Subscribed! this is the very first video I found very useful lol. Thanks very much.

  • @guaripolo69
    @guaripolo69 9 місяців тому

    what if nothing is syncing either way? follow the same stuff, or is there another way to approach it if no replication is happening whatsoever?

  • @Destroyer954
    @Destroyer954 4 роки тому +2

    What if I am facing DNS replication issue? Any tips how to diagnose that? I dont see any warnings/errors in the event log for the DNS server service, apart from 4013 which doesn't really mean anything because then it says it loaded the zones few seconds after.

    • @TheSysadminChannel
      @TheSysadminChannel  4 роки тому +1

      Without knowing your setup or seeing any errors I would probably start here: www.dell.com/support/article/en-us/sln156253/troubleshooting-active-directory-and-dns-replication

  • @Firrefirr
    @Firrefirr 7 місяців тому

    Thank you so much, been stuck on this for way too long! 🙏

  • @mrp9117
    @mrp9117 8 місяців тому

    This solved my domain sysvol replication issues. Thanks for a great video guide :)

  • @pg4694
    @pg4694 2 роки тому

    when u say ur logon scripts are not working how u updated it and logonscripts are store in netlogon folder so the entire trblshooting u did was was netlogon folder I mean im not getting what is the actual connection between netlogon and sysvol folder

  • @rahulprabhakar7886
    @rahulprabhakar7886 2 роки тому

    cn=dfsr-localsettings missing On second DC folder please help 🙏

  • @truefeet7206
    @truefeet7206 3 роки тому

    what is the default msDFSR-Options = 1 on DCs, once the replication is fixed, shouldnt it be reverted on all DCs to default ? please advise.

  • @Rock351
    @Rock351 2 роки тому

    Can't thank you enough. This fixed my DFS replication issues.

  • @phatman1179
    @phatman1179 2 роки тому

    You rock Bro, fantastic tutorial. Hit every step, easy to follow and fixed my issue!

  • @abrahamf7186
    @abrahamf7186 2 роки тому

    does msDFSR-Option on authoritative DC never set back to 0?

  • @davepete9537
    @davepete9537 11 місяців тому

    Very to-the-point video sir. Appreciate for your effort and passing of knowledge. Quick question, how can I intentionally break replication so I can practice this in home lab environment? Any senior AD admin can advise. I am trying to improve my AD troubleshooting skills.

  • @VuTran-se2cj
    @VuTran-se2cj 7 місяців тому

    Thanks bro so much as I was fighting with this case for 3 straight days. xxx

  • @alparzsolt6989
    @alparzsolt6989 2 роки тому

    If I have only 1 problematic server, then I have to change the DFSR to false only on it, or on all DCs in the whole domain? (Master server part is clear)

  • @Physics072
    @Physics072 3 роки тому

    Tried this on Server 2012 STD. Not R2 and every command worked but if I open shares DC1 and DC2 to netlogon and make a text file it does not replicate to the other. But it says replication is working. Makes no sense to me why does it report working but fails this simple test of creating a text file.

  • @abelkabwe3180
    @abelkabwe3180 2 роки тому

    I still have a bit of challenge i followed all the steps but still the results where just like you but my DFS issue was not cleared what else can i try

  • @kim87713
    @kim87713 3 роки тому

    Hi, is it possible that this can cause a miss replication? If i create a user at HQ, it will show up at sites. But if i create a user account at this one site, it will not show up at ADUC hq and other site. I've only found one site that have this problem.
    DCA (hq) | DCB (hq) | DCC (site1) | DCD (site1):
    DCA / DCB ---> DCC / DCD ✅
    DCC / DCD ---> DCA / DCB ❎

  • @victory4abhi
    @victory4abhi 2 роки тому +1

    Really helpful. resolved my GPO replication issue. Thanks a lot

  • @seanhasling5652
    @seanhasling5652 4 роки тому

    what if NONE of the DCs have msDFSR-Options = 1 on them? Yet, we do have one designated as the Operations Master according to the ADUC GUI? Is that completely separate from DFSR?

  • @thbadmin7751
    @thbadmin7751 Рік тому

    Won't DFS Namespace and DFS Replication features be installed first?

  • @defkon99
    @defkon99 2 роки тому

    We Had a major power outagelast week- both DC's went downfor hours, and when they came up - DC2 had NetLogon disabled. This should work right?

  • @davepete9537
    @davepete9537 Рік тому

    How did you identify which DC is master server?

  • @joerockwell9198
    @joerockwell9198 6 місяців тому

    Thank you thank you thank you You saved me two days worth of headache just a discover this was the issue

  • @bryanbrookes9291
    @bryanbrookes9291 4 роки тому

    The best video on UA-cam. Thank you so much man.

    • @TheSysadminChannel
      @TheSysadminChannel  4 роки тому +1

      Thank you mate for taking the time to watch. I’m glad it was helpful.

  • @julianaddington-barker7063
    @julianaddington-barker7063 Рік тому

    Fantastic, thank you for this. It sorted my issue with two DC's not replicating.

  • @ithelpmrscaffold1903
    @ithelpmrscaffold1903 3 роки тому

    Mmm this is about 3rd of 4th source i have found that tells you how to do this.
    However for some reason NONE of my 3x DC's have "msDFSR-Options" in ADSI Edit... :-(
    I tried every other step but no luck fixing replication.

  • @twokssei1
    @twokssei1 3 роки тому

    WOW - Super Useful - seems to be a far to frequent issue. saved many hours (after many hours) of headache!!

  • @urielf6122
    @urielf6122 3 роки тому

    Great help! I couldn't follow step by step because there was a difference in my configuration but it worked great!

  • @jimmortoniii
    @jimmortoniii 2 роки тому

    Super well done tutorial! Very clear and concise. Thank you so much for making this video! You saved me a LOT of time and worry.

  • @kaizenbox
    @kaizenbox Рік тому

    nice. what if you have more than 2 domain controllers? do you have to disable the DFSR on all? thank you for this

  • @MartSaluri
    @MartSaluri 3 роки тому

    Thank you for great guide! Does this also work on a more complicated scenario where there are two child domains? Root-DC1 Root-DC2 / Child-DC1 Child-DC2 / Child2-DC1 Child2-DC2. I have a replication issue with Root-DC2 , even the initial replication is not done after dcpromo, there are no sysvol and netlogon shares. Non-authoritative restore did not work. I am a little afraid to do Authoritative restore, as most instructions say you have to change msDFSR-Enabled = False on all DC's.

  • @kobalsky77
    @kobalsky77 2 роки тому

    Thank you very much!! Everyhthing perfect for me. Greetings from Spain!

  • @GillesOfEarth
    @GillesOfEarth Рік тому

    I experienced this identical issue at work and these steps resolved the replication issue perfectly, but I don't know what caused the issue to begin with. How did you set up your lab to have this issue, as I would like to understand what causes this?

  • @andysalinas3082
    @andysalinas3082 2 роки тому

    Thank you! Thank you! Thank you! This solved our replication problems!🎉

  • @DeepFriedLettuce
    @DeepFriedLettuce 2 роки тому

    Thanks for the insight. This didn't resolve my issue, but I was able to resolve one item that was helpful.

  • @indravaish5177
    @indravaish5177 3 роки тому

    Please tell, when shall we remove the ms-dfsr options back to 0 from 1 which we changed of dc01

    • @TheSysadminChannel
      @TheSysadminChannel  3 роки тому

      Once everything is confirmed working and replication is good again, you can revert the settings

  • @dalerija_dh
    @dalerija_dh 2 роки тому

    You are the best. Thank you so much for this video. I can't say how thankfull I am.

  • @theAboodNet
    @theAboodNet 3 роки тому +1

    By just watching this video without doing anything, all DFSR issues got fixed ;p

  • @l1mL
    @l1mL 3 роки тому

    Thanks for this video, following your steps I just resolved problem on my client's DC.

  • @mohdhasan72
    @mohdhasan72 3 роки тому

    Excellent explanation with good efforts...

  • @EstevanRoman-m8t
    @EstevanRoman-m8t Рік тому

    Worked like a charm! Brilliant!

  • @pg4694
    @pg4694 2 роки тому

    I have lot of doubts in the start u told that there is a problem with the sysvol foler replication and we know it uses dfsr service so why u have gone to netlogon folder to check the files created replicating .....Second u have show that changing values in adsi edit tool but have not told what actually it does I got ur point of setting the value of primary to 1 and all other dc to 0 but whyenabled is set to false and changed after what actual it does .....third is this the only fix we have to perform everytime when there is an issue related to sysvol folder or group policy in it is that theonly fix we have to perform or there are some other ways as well

  • @deepthread9804
    @deepthread9804 Рік тому

    So your saying a value of 1 is essentially saying the main server is the PDC. That conflicts with information I was able to find on the web.
    If the "msDFSR-Options" attribute on your Primary Domain Controller (PDC) is set to 1, it means that the PDC is in non-authoritative restore mode for the Distributed File System Replication (DFS-R) service. In this mode, the PDC will discard its current local version of the replicated folders and sync fresh data from other members of the replication group.
    The other domain controllers (DCs), having "msDFSR-Options" set to 0, are in normal mode. They will continue their regular DFS-R operations and will not discard their current data.
    In this scenario, the PDC will essentially become a "learner" and will pull the DFS-R data from the other DCs. It will not push any of its DFS-R data to the other DCs.
    This configuration is typically used when the data on the PDC has become inconsistent or corrupted, and you want to replace it with a fresh copy from the other DCs. However, it's important to note that this operation can generate significant network traffic and should be planned accordingly.
    Remember, changes to the "msDFSR-Options" attribute should be made with caution, as they can have significant impacts on your DFS-R environment. Always make sure to have a backup and plan before making changes to your DFS-R configuration.

  • @yaroslavfedorina5637
    @yaroslavfedorina5637 2 роки тому

    Amazing! It worked like a charm. Thanks a lot for the video - other guides (including the ones from Microsoft) show a bit different actions and they did not work for me.

  • @muhammadhassansiddiqui9129
    @muhammadhassansiddiqui9129 3 роки тому

    Thanks, I appreciate your effort and a great video. I have another issue is the Netlogon folder is missing for additional DC.

  • @dennislans9084
    @dennislans9084 4 місяці тому

    I have been trying to fix this shit for hours, video saved me, THANK YOU!

  • @RidingHard
    @RidingHard 3 роки тому

    Would this be the same for when a DC says SYSVOL is inaccessible?

    • @TheSysadminChannel
      @TheSysadminChannel  3 роки тому

      Not necessarily - you'll want to check why its not accessible. If its not accessible because its not there. You can view this article to get setup. thesysadminchannel.com/solved-sysvol-and-netlogon-shares-missing-2016-2019-domain-controller/

  • @foxfire1112
    @foxfire1112 5 місяців тому

    You're a life saver, subscribed

  • @jaztai1996
    @jaztai1996 3 роки тому

    Thank you so much! this video gave me a good idea to troubleshoot the domain controller sync issue.

  • @aodhang9120
    @aodhang9120 Рік тому

    Thank you so much for your assistance and clear explaination in this video

  • @mcddonyventura8695
    @mcddonyventura8695 4 роки тому

    Some Domain Users are getting this error "The processing of Group Policy failed. Windows attempted to read the file \\domain.com\SysVol\domain.com\Policies\{9ED3C1B0-B1v5-46B4-8B33-1F9F2A123BD3}\gpt.ini from a domain controller and was not successful" Would this process fix this? Domain Admins do not get this error. Also, it looks like that by default, Admins do not have permissions to \\DC\NETLOGON\ so do we change the permissions before the process? Thanks!!

    • @TheSysadminChannel
      @TheSysadminChannel  3 роки тому

      This looks more like a permissions issue rather than a replication issue.

  • @ScottDiFrancesco
    @ScottDiFrancesco 3 роки тому

    Hi Paul/SysAdmin, i have a DC rep issue ,( 2012R ) can you remote in for a fee to fix please .. thks

  • @matthewclark7034
    @matthewclark7034 2 роки тому

    Really appreciate this, I found the same process in a Microsoft guide but being able to watch someone do it was re-assuring, thank you! One quick question, I've followed this process as a newly promoted DC wasn't syncing. I plan to remove the current DC, would I have to manually update the option from 1 to 0 again when transferring the roles?

  • @WallaceTX
    @WallaceTX 2 роки тому

    Thank you very much for helping. This resolve my Problem with four DCs.

  • @thedonfranz
    @thedonfranz Рік тому

    very spot on! works flawlessly! Kudos!

  • @alan7794
    @alan7794 2 роки тому

    Thank's for this nice tutorial, easy to understand it solved my problem :)

  • @MoustafaBorhan
    @MoustafaBorhan Рік тому

    Thank you, that helped me with an ongoing problem :)

  • @samfisher-y3r
    @samfisher-y3r Рік тому

    "and one days someone come in the use of it"
    here is that one day .
    thanks alot