DNS zones do not load, event 4000, 4007

Article ID: 2751452 - View products that this article applies to.
Expand all | Collapse all

Symptoms

You may encounter a situation where one of the DNS server's in the environment starts showing an issue where the zones are not loaded on the DNS console and you see Event id 4000 and 4007 logged in the DNS event logs:

Event ID 4000:
The DNS server was unable to open Active Directory.  This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.

Event id 4007:
The DNS server was unable to open zone <zone> in the Active Directory from the application directory partition <partition name>. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.

Also when you try to open the DNS console you get a pop up giving "Access Denied".

You notice that the DNS Server service is up and running.
When you try to perform any operation on the AD integrated zones using DNSCMD you get "Access Denied"

Cause

This happens when that particular DC/DNS server has lost its Secure channel with itself or PDC.
This can also happen in a single DC environment where that DC/DNS server holds all the FSMO roles and is pointing to itself as Primary DNS server.

Resolution

> In case you have other Domain Controller/ DNS server present in the environment then configure the server experiencing the issue to point to other active DNS server in TCP/IP properties.
> Stop the KDC service on the DC experiencing the issue.
> Run the following command with elevated rights: netdom resetpwd /server:<PDC.domain.com> /userd:<Domain\domain_admin> /passwordd:*
>  It will prompt for the password of the Domain Admin account that you used, enter that.
> Once the command executes, reboot the server.
> DNS zones should load now.

If this is the only DC in the environment and there are no other DNS Servers available then perform the same steps but replate the "PDC.Domain.com" with the server's own IP address (since it itself is the PDC)

More Information

If you are facing the issue on a Windows 2008 server (Non R2) then make sure the patch related to KB 2615570 is installed on the server
Note This is a "FAST PUBLISH" article created directly from within the Microsoft support organization. The information contained herein is provided as-is in response to emerging issues. As a result of the speed in making it available, the materials may include typographical errors and may be revised at any time without notice. See Terms of Use for other considerations.

Properties

Article ID: 2751452 - Last Review: December 21, 2012 - Revision: 4.0
Applies to
  • Windows Server 2008 Enterprise
  • Windows Server 2008 R2 Enterprise
Keywords: 
KB2751452

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com