Article ID: 149664 - View products that this article applies to.
This article was previously published under Q149664
If users are having problems getting validated or are experiencing other account-related issues, you should verify that complete synchronization is taking place across all domain controllers in the domain, including in the User Account Database and Machine Account Database. Anytime a change is made in User Manager or Server Manager, the changes occur at the primary domain controller's database, and those changes need to be replicated.
The Netlogon Service tries to maintain synchronization automatically but is sometimes unable to. If you suspect a domain controller is not up to date, locate your situation in the section below and follow the procedures outlined.
In User Manager, changing any of the following requires a complete domain synchronization for all domain controllers in the domain to be able to correctly service the Netlogon request:
To verify Domain Synchronization, individually replicate the User Account Database on each backup domain controller with the primary domain controller.
From within Server Manager, select each BDC in turn and, from the Computer menu, choose "Synchronize with primary domain controller." This will trigger an immediate replication for the selected BDC with the PDC.
From the Event Log on each Domain Controller, verify that one or more of the following is on each server (both event IDs do not need to be present on each computer):
On the PDC:
Event 5711 Source Netlogon
The partial synchronization request from the server <BDC> completed successfully. <Number> changes(s) has(have) been returned to the caller.
Event 5713 Source Netlogon
The full synchronization request from the server <BDC> completed successfully. <Number> object(s) has(have) been returned to the caller.
On the BDC:
Event 5715 Source Netlogon The partial synchronization replication of the SAM database from the primary domain controller <PDC> completed successfully. <Number> change(s) is(are) applied to the database.
Event 5717 Source Netlogon The full synchronization replication of the <SAM or BUILTIN or LSA> database from the primary domain controller <PDC> completed successfully.
Article ID: 149664 - Last Review: November 1, 2006 - Revision: 2.1
Contact us for more help