Basic steps to troubleshoot AD
What are the basic steps to troubleshoot Active Directory (AD)? 1. DCDIAG To deploy an additional domain controller: dcdiag /test:dcpromo /DnsDomain:domain_name.com /ReplicaDC To deploy a child domain: dcdiag /test:dcpromo /DnsDomain:child_domain_name. forest.com /ChildDomain Test the FSMO dcdiag /s:<DomainControllerName> /test:fsmocheck Check DNS dcdiag /test:dns Check for missing and duplicate SPNs as well as other errors dcdiag /test:checksecurityerror Check the rid pool dcdiag /s:server /v /test:ridmanager 2. NSLOOKUP Test SRV records cmd > nslookup set q=srv _ldap._tcp.dc._msdcs. yourdomain.com _ldap._tcp.gc._msdcs. yourdomain.com _ldap._tcp.pdc._msdcs. yourdomain.com Command to Troubleshoot DNS Issues 3. Repadmin Disable replication repadmin /options <dc-fqdn> +DISABLE_OUTBOUND_REPL Enable replication repadmin /options <dc-fqdn> -DISABLE_OUTBOUND_REPL 4. W32TM Time sync issue in DC w32t...