Article ID: 895085 - Last Review: November 22, 2007 - Revision: 2.6 You receive an "access is denied" error message on a Windows Server 2003-based domain controller when you try to replicate the Active Directory directory serviceImportant This article contains information about modifying the registry.
Before you modify the registry, make sure to back it up and make sure that you
understand how to restore the registry if a problem occurs. For information
about how to back up, restore, and edit the registry, click the following
article number to view the article in the Microsoft Knowledge Base: 256986
(http://support.microsoft.com/kb/256986/
)
Description of the Microsoft Windows Registry On This PageSYMPTOMSWhen you try to replicate the Active Directory directory
service to a domain controller that is running Microsoft Windows Server 2003
with Service Pack 1 (SP1) or an x64-based version of Microsoft Windows Server
2003, you receive the following error message on the destination domain
controller: access is denied CAUSEThis problem occurs when the value of the
RestrictRemoteClients registry entry is 2. Windows Server 2003 SP1 and x64-based versions of Windows Server 2003 read remote procedure call (RPC) settings from this entry. If the entry has a value of 2, RPC traffic must be authenticated. Therefore, Active Directory replication does not succeed. Other RPC services on the domain controller may also be affected. RESOLUTIONWarning If you use Registry Editor incorrectly, you may cause serious
problems that may require you to reinstall your operating system. Microsoft
cannot guarantee that you can solve problems that result from using Registry
Editor incorrectly. Use Registry Editor at your own
risk. To resolve this problem, enable port 135 on Windows Firewall, and then use one of the following methods:
Note By default, port 135 is blocked in Windows Server 2003 SP1 and in x64-based versions of Windows Server 2003.
STATUSMicrosoft
has confirmed that this is a problem in the Microsoft products that are listed
in the "Applies to" section. MORE INFORMATIONFor additional information about the RestrictRemoteClients
registry entry, visit the following Microsoft Web site: http://technet.microsoft.com/en-us/library/209d02c4-877c-4128-8e22-30bcd4aae6d3.aspx
(http://technet.microsoft.com/en-us/library/209d02c4-877c-4128-8e22-30bcd4aae6d3.aspx)
Technical support for Windows x64 editionsYour hardware manufacturer provides technical support and assistance for Microsoft Windows x64 editions. Your hardware manufacturer provides support because a Windows x64 edition was included with your hardware. Your hardware manufacturer might have customized the Windows x64 edition installation with unique components. Unique components might include specific device drivers or might include optional settings to maximize the performance of the hardware. Microsoft will provide reasonable-effort assistance if you need technical help with your Windows x64 edition. However, you might have to contact your manufacturer directly. Your manufacturer is best qualified to support the software that your manufacturer installed on the hardware.For product information about Microsoft Windows XP Professional x64 Edition, visit the following Microsoft Web site: http://www.microsoft.com/windowsxp/64bit/default.mspx
(http://www.microsoft.com/windowsxp/64bit/default.mspx)
For product information about Microsoft Windows Server 2003 x64
editions, visit the following Microsoft Web site:http://www.microsoft.com/windowsserver2003/64bit/x64/editions.mspx
(http://www.microsoft.com/windowsserver2003/64bit/x64/editions.mspx)
APPLIES TO
| Article Translations
|
Back to the top
