Article ID: 262795 - Last Review: March 1, 2007 - Revision: 4.2 "Replication Access was denied" error message when attempting to synchronize domain controllersThis article was previously published under Q262795 SYMPTOMS
When you use the Active Directory Sites and Services snap-in from a child domain to force replication from a parent domain or another child domain at the same level, you may receive the following error message:
The following error occurred during the attempt to synchronize the Domain Controllers: Replication Access was denied
CAUSEBy default, administrators of child domains can only force replication within their own domain. Administrative permissions do not flow down; they need to be assigned. When a child domain is created, the Enterprise Admin global group is added to the built-in Administrators group of the child domain. This allows the administrator of the parent domain to administer and force replication from either the parent domain or the child domain. Administrators of child domains can only force replication within their own domain unless they are granted administrative permissions over the parent domain or another child domain. RESOLUTION
To resolve this issue, give the administrator in the child domain permissions to the parent and/or child domain from which you want to force replication.
Note The following steps use the Microsoft Management Console (MMC) Active Directory Users and Computers snap-in from the domain on which you want to grant administrative permissions.
STATUS
This behavior is by design. MORE INFORMATION
Keep in mind that parent domains are able to manage all of their child domains but you need to perform the steps described in this article for any child domains that want to manage the parent domain or other child domains on the same level.
| Article Translations
|
Back to the top
